Privacy
Short version: the only personal data we collect is what you type into the join form. We use it to read your application and to write back. We don't sell it, we don't track you around the web, and you can have it deleted by asking.
What we collect
The join form asks for: what you're applying as (founder, investor, media, content, factory, or partner), your name, your Hacklab profile, how you can be useful, how you heard about us, what excites you most, and a confirmation that you've read the house rules. That is the whole form. There are no hidden fields, and nothing else about you is captured when you submit it.
If you email us or book a call instead, we obviously end up with whatever you put in that email or booking. Same rules apply.
Where it goes
Submissions are written to our Notion workspace, which is the CRM we review applications in, and mirrored into a Neon Postgres database as a backup so a Notion outage can't lose your application. The site itself runs on Vercel, so requests pass through Vercel's infrastructure on the way there. All three act as processors on our instructions, and all three are US providers — the backup database currently runs in a US region — so your data is transferred outside the EEA under their standard contractual clauses.
Access is limited to the people in the house who review applications. We do not sell your data, we do not rent it, and we do not hand it to sponsors, partners, or anyone else for their own marketing.
Why we're allowed to
You asked us to consider you. Under the GDPR, that's our legitimate interest in reviewing an application you sent us and contacting you about it — nothing more. We do not use the form to build a mailing list, and we won't send you unrelated broadcasts.
Members shown on the community page are people who are part of the house and whose profile we publish with their agreement. Applicants are never published.
Tracking
There is no analytics on this site. No Google Analytics, no Plausible, no PostHog, no pixels, no advertising tags, and no cookie banner, because we don't set cookies to track you. Fonts and event images are served from our own domain rather than fetched from someone else's, so loading a page here doesn't announce you to a third party. Links you click through to — the event calendar, the booking link, our social profiles — run under their own privacy policies, not ours.
Our hosting provider keeps standard server logs (IP address, page requested, timestamp) for operational and security reasons, the way every web server does.
How long we keep it
Until you ask us to delete it. Applications stay in the CRM because the house is a long game — someone who was too early in spring is often exactly right by autumn, and we'd rather re-read your application than make you rewrite it. If you'd rather not be on that list, say so and you're off it.
Your rights
You can ask for a copy of what we hold on you, ask us to correct it, ask us to delete it, or object to us holding it at all. Email contact@hackerbloc.com from the address you applied with — or tell us which address to look for — and we'll handle it, from both Notion and the Postgres backup, within 30 days. No form, no fee, no argument.
If we get it wrong, you can complain to your local data protection authority; in Poland that is the President of the Personal Data Protection Office (UODO). We'd rather you told us first.
Questions about any of this go to the same address as everything else: contact.