Privacy

Last updated 24 August 2026

This explains what the Treasure Hunt at Noite Europeia dos Investigadores collects, why it is allowed to, who else sees it, and how to get it removed. It is written to be read rather than skimmed past, so it is longer than a banner and shorter than a contract.

Who is responsible

The controller is NOVA Information Management School (NOVA IMS), Universidade NOVA de Lisboa, Campus de Campolide, 1070-312 Lisboa, Portugal. The game is built and run by the Nova Blockchain Lab team there.

For anything about your data, including the rights listed at the end, write to daraujo@novaims.unl.pt. The University has a Data Protection Officer, who can be reached through the same address if you would rather your request went to them.

What is collected, why, and on what legal basis

Different parts of the game rest on different legal grounds. Where the ground is consent, you can withdraw it at any time and nothing else stops working. Where it is performance of a contract, that is the game itself: the terms you accept by playing.

WhatWhyLegal basis
Wallet address, username, account record To have an account, hold your tokens and tell players apart Contract, Art. 6(1)(b)
Tags you found and when; tokens earned To run the hunt and score it Contract, Art. 6(1)(b)
Merch purchases, unit numbers, collection status To hand you the right item once, and to settle disputes at the stand Contract, Art. 6(1)(b)
E-mail address for a voucher item To send you that voucher. Used for nothing else Contract, Art. 6(1)(b)
Optional profile fields: name, photo, role, company, e-mail, phone, website, LinkedIn, X, Instagram, Telegram, GitHub So you can swap contact details with people you meet. Every field is optional and separately clearable, except the phone number and the e-mail address: both are proved rather than typed, so each is replaced by verifying a new one, and erasing your account removes them outright Consent, Art. 6(1)(a)
Which groups of your profile you release when you accept a connection (phone number, e-mail, socials) So you decide what a person you accept receives. It is a setting on your own profile, not something the other player can see or change Consent, Art. 6(1)(a)
Connections: which players you met, when, and any private note you write about them To show your contacts and pay the connection reward Contract, Art. 6(1)(b)
Tag reports, including a photo if you attach one To find and fix physical tags that have gone missing or moved Consent, Art. 6(1)(a)
Phone number verified over WhatsApp So a connection can message you. See below Consent, Art. 6(1)(a)
E-mail address verified by a code, plus the address awaiting proof and the code itself while it is live So a connection can e-mail you, and so we know the address is yours. The pending address and code are deleted the moment the code is used or expires. See below Consent, Art. 6(1)(a)
Server logs, anti-abuse and anti-fraud checks To keep the game working and stop people farming rewards Legitimate interests, Art. 6(1)(f)
Aggregate page analytics (no cookies, no identifiers) To see which screens are used and where the app is slow Legitimate interests, Art. 6(1)(f)

Do you have to provide any of it?

Only a wallet address and a username, which are created for you when you join. Everything else is optional. Not filling in profile fields costs you the small token rewards attached to them and means other players see less on your card. Nothing else in the game is withheld.

What other players can see

Your username and wallet address appear on the public leaderboards, which anyone can read without an account. That pairing is worth understanding, because it is what links your name to the permanent record described below.

Your profile fields are shown to another player only after you both confirm the connection. Private notes you write about someone are never shown to them or to anyone else.

Verifying a phone number

If you choose to verify your number, the app shows you a one-time code and you send it to us from your own WhatsApp. We do not message you first and we never upload your number to Meta. Meta processes the message you send, as the operator of WhatsApp, under its own privacy policy. Your number reaches us from Meta, as the sender of that message: that is the source, and it is the only way this field is ever filled in. Nobody types it.

Verifying is optional. Without it, your card simply has no WhatsApp button.

Verifying an e-mail address

This one runs the other way round: we send a six-character code to the address you enter and you type it back into the app. Until you do, we hold that address and the code and nothing else happens with either; once the code is used or expires, both are deleted and only the proved address remains. The message goes out through Resend and is not used for anything else.

If you signed in with an e-mail address, thirdweb already holds it and we fill the field in from there instead, with no message sent. Either way you can replace the address later by proving a different one, which is how you would swap a personal address for a work one.

Who else processes your data

The application and the database both run in Frankfurt, inside the EEA. Vercel, Neon and thirdweb are United States companies operating that European infrastructure, so standard contractual clauses cover any administrative access from outside the EEA. Meta and Resend process in the United States under the same clauses, and are involved only if you verify a phone number, verify an e-mail address, or buy a voucher.

Nothing is sold, and nothing is shared for advertising.

Cookies and what is stored on your device

Two cookies, both strictly necessary and neither of them requiring consent: a sign-in token, so you stay logged in, and your choice of language, so the app keeps speaking the language you picked. No advertising or tracking cookies are used, and the analytics are cookieless.

The app also keeps a few things in your browser's own storage so it works when the venue wifi drops: your username, a wallet token from thirdweb, your redeem codes and purchase list, and a voucher e-mail address if you entered one. That data stays on your device. Clearing your browser storage removes it.

What cannot be deleted

This part is worth reading properly. Token rewards, tag finds, player connections and merch purchases are written to a blockchain. That record is permanent, and cannot be edited or erased by anyone, including us.

What is on it:

It does not contain your name, photo, phone number, e-mail address or notes. Those live in the ordinary database and are deleted normally.

A wallet address is pseudonymous, not anonymous: on its own it is a string of characters, but anyone who learns which address is yours can read its history, and the public leaderboard pairs addresses with usernames. If that matters to you, the game is fully playable without filling in a single profile field. This is a real and permanent limit on the right to erasure, which is why it is stated here rather than buried.

How long it is kept

WhatKept for
Profile fields, connections, private notesUntil you clear them or ask us to delete your account. Removed within 30 days of a request, and in any case no later than 12 months after the event
Voucher e-mail addressesDeleted once the event is over and all vouchers have been redeemed
Tag reports and their photosDeleted when the report is resolved, and in any case after the event
Purchase records (unit numbers, collection status)Kept to the end of the event plus 12 months, so a disputed handover can still be checked
Server logsAs kept by Vercel under its own retention, typically weeks
Aggregate statistics in the post-event reportIndefinitely. These contain no personal data
On-chain recordsPermanently, as explained above

Children

Noite Europeia dos Investigadores is attended by under-16s, and the hunt is open to them. Playing the game rests on the terms rather than on consent, so no parental permission is needed simply to take part.

The optional profile fields are consent-based. If you are under 16, do not fill them in without asking a parent or guardian first: a name, a photo and a phone number shown to strangers you meet at a convention deserve that conversation. If a parent or guardian wants a child's profile data removed, write to the address above and it will be deleted, no questions asked and no proof demanded.

Automated decisions

There are none in the sense the GDPR means. Leaderboard positions and merch prices are arithmetic over totals, not decisions about you as an individual, and nothing about you is decided automatically in a way that has legal or similarly significant effects.

Your rights

Under the GDPR you can:

Write to daraujo@novaims.unl.pt and we will answer within 30 days. You can also complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (cnpd.pt), at any time and without asking us first.

Terms of use

← Back to Treasure Hunt