01
Who we are
Florent Venture Partners ("we", "us") is the data controller responsible for your
personal data collected through the Florent Code League website and platform (together,
the "Service"). Contact:
christian@florent.vc.
02
Scope
This policy applies to the Florent Code League landing site and to the competition
platform application (sign-up, teams, submissions, ladder, and related features).
03
Data we collect
- Account & profile data: name, email address, profile image,
whether you identify as a student, country, affiliation/organization, your Discord
username, your LinkedIn profile URL, and referral codes (yours and, if
applicable, who referred you).
- Authentication data: because sign-in is exclusively via Discord OAuth,
we store Discord OAuth tokens (access/refresh/ID tokens and granted scopes) needed to
keep your session authenticated. We do not collect or store passwords.
- Session data: your session token, IP address, and browser user agent,
to keep you securely signed in and detect suspicious activity.
- Discord server membership: to verify and sync your membership/role in
our Discord community, we store your Discord user ID, Discord username, and when you
joined/were last synced.
- Team & competition data: team name/bio, your role on the team
(owner/member), team invite codes, your code submissions (stored in cloud storage
together with version and bot name/status metadata), match results and replays, and
your ladder rating history.
- Automated code security review: submitted code is automatically
analyzed by an automated process (which may use a third-party AI model provider) to
detect attempts to exploit or escape the competition sandbox. We store the scan status,
severity, a summary, any specific findings (file/line/snippet/explanation), and which
model performed the review, along with whether/why staff dismissed a finding.
- AI coding assistant usage (optional feature): if you use the in-editor
AI assistant, your code and chat messages for that session are sent to a third-party AI
provider to generate a response. We store only aggregate daily token-usage counters per
account (to enforce fair-use limits) — the content of your conversations is kept in
your browser's local storage, not on our servers.
- Analytics data: we use PostHog, a third-party analytics service, on
both the website and the platform, to understand feature usage and improve the
Service. This includes page views and, on the platform, in-app navigation events, along
with standard technical identifiers (e.g., a device/browser identifier).
04
How we use your data
We use your data to: operate your account and team; run matches and compute ladder
standings; enforce fair play and investigate suspected violations; operate optional
features like the AI coding assistant, subject to usage limits; communicate with you
about the competition; and understand and improve how the Service is used, via aggregated
analytics.
05
Legal basis for processing (GDPR)
We process your data on the following bases:
- Performance of a contract — to create your account, run your
team/submissions/matches, and deliver the Service you signed up for;
- Legitimate interests — to secure the platform, detect fair-play
violations (including automated code review), and improve the Service through
analytics, balanced against your rights;
- Consent, where required — for example, for optional features you
actively choose to use, or where local law requires opt-in consent for analytics
cookies. You may withdraw consent at any time where consent is the basis for
processing.
06
Who we share data with
We use the following third-party service providers ("processors") to run the Service:
- Discord — for authentication (OAuth) and to sync your community
membership/roles. Discord's own privacy policy applies to your Discord account.
- AWS (Amazon Web Services) — for hosting, file storage, and running
competition infrastructure (matches, submissions processing). Where practical, we
choose EU-based AWS regions for infrastructure hosting.
- A third-party AI model provider — to power the automated code security
review of Submissions, and, if you use it, the optional in-editor AI coding assistant.
- PostHog — for product analytics. We use PostHog's EU-hosted
infrastructure, so this data is processed within the European Economic Area (EEA).
We do not sell your personal data, and we do not use Google sign-in or any Google
services to process your account data.
07
Cookies and similar technologies
We use a small number of essential cookies/local storage items to keep you signed in (a
session token) and to remember interface preferences (e.g., unsent AI-chat drafts, stored
only in your browser). If analytics are enabled, PostHog may also set cookies or use
local storage to recognize your browser across visits for analytics purposes. Where
required by your local law, we will provide a way to manage non-essential cookie consent.
08
International data transfers
Some of our service providers, such as our third-party AI model provider, may process
data outside the European Economic Area (EEA). Where this occurs, we rely on appropriate
safeguards recognized under EU data protection law, such as the European Commission's
Standard Contractual Clauses, to protect your data when it is transferred
internationally. Our analytics provider (PostHog) and cloud hosting (AWS) are configured
to process data within the EEA.
09
How long we keep your data
-
Account data: retained while your account is active, and for 30 days after you request
deletion (to allow recovery / handle abuse), after which it is deleted or anonymized.
-
Submissions: deleted when you re-upload a new version (superseding the old one) or when
you delete them; the underlying match replays generated from a Submission are retained
indefinitely for competition integrity and historical record, even after the Submission
itself is deleted.
-
Ladder ratings and match history: retained during the competition; anonymized
(disassociated from your identity) after the competition concludes, retaining only
aggregate/competitive results.
-
Server/session logs (IP address, user agent): retained for 90 days for security and
abuse-prevention purposes, then deleted.
-
Automated code-review findings: retained alongside the related Submission for fair-play
enforcement and appeals purposes.
-
AI chat usage counters: retained in aggregate for as long as needed to enforce fair-use
limits and detect abuse; conversation content itself lives only in your browser, not on
our servers.
10
Your rights
Depending on your location, you may have rights under the EU General Data Protection
Regulation (GDPR) or equivalent local law, including the right to: access the personal
data we hold about you; request correction of inaccurate data; request erasure ("right to
be forgotten"); request restriction of processing; receive a portable copy of your data;
and object to processing based on legitimate interests. To exercise any of these rights,
contact us at christian@florent.vc.
11
Age requirement
You must be at least 16 years old to use the Service. If you are 16 or 17, your parent or
legal guardian must consent to your participation and to this Privacy Policy on your
behalf. If we learn we have collected personal data from someone below the required age
without appropriate authorization, we will delete it.
12
Security
We use technical and organizational measures to protect your data, including sandboxed
execution of submitted code, encrypted storage of sensitive credentials, and access
controls limiting who can view personal data. No system can be guaranteed 100% secure,
but we take reasonable steps appropriate to the risk.
13
Complaints
If you are unhappy with how we handle your data, please contact us first at
christian@florent.vc so we can try
to resolve it. You also have the right to lodge a complaint with the Swedish Authority
for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at
imy.se,
or with your local data protection authority if you are located elsewhere in the EU/EEA.
14
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be
communicated to active participants (e.g., via Discord or email), and the "last updated"
date at the top of this page will reflect the most recent revision.
Florent Venture Partners -- florent.vc Code League 2026