Tech
Galaxy
Award
tga.org
Effective 1 March 2026 · Last reviewed 1 March 2026
This policy describes what Tech Galaxy Award ("TGA", "we") collects, why we collect it, how long we keep it, and what rights you have. It applies to www.tga.org, the Chinese pages at /zh-cn/, the certificate verification tools, and the email we exchange with applicants, families, schools, partners, and press. It does not apply to third-party sites we link to, including the science-fair, iGEM, Dyson, Imagine Cup, or Scholar’s Cup pages mentioned in The Field.
TGA is an academic challenge, not a social network. We collect as little as we can and still run a safe, auditable cohort in Singapore. If a sentence below is vaguer than you need, write to info@tga.org with the subject "Privacy".
The controller of personal data described here is Tech Galaxy Award, reachable at info@tga.org. Correspondence about this policy should use that address. We convene in Singapore; we correspond with people in many countries. Where a local law gives you additional rights, we will honour the stricter of that law and this policy when we can identify which law applies.
From a casual visitor to the public website we collect ordinary server logs (IP address, user agent, time, path) for security and to keep the site up. We do not run advertising pixels. We do not sell lists. We do use a local language-preference flag in your browser (localStorage key tga.lang) so the language banner can remember a choice you already made. That flag never leaves your device.
From an applicant or adult lead we collect the information on the Stage 1 and Stage 2 forms: names, dates of birth or school year, nationality and passport details where needed for invitation letters, school or team affiliation, contact emails and phones, dietary and accessibility needs, a team statement, and a written response to a TGA prompt. From a parent or guardian we collect consent signatures and emergency contacts. From a bursary applicant we collect the financial documents we request in writing at Stage 3, and only those.
From a certificate verification query we collect the code you typed and the time of the query, so we can investigate abuse. We do not require an account to verify. Sample codes published on the Verify page are demonstration records, not a licence to scrape.
From email we collect whatever you send us. Please do not put extra identity documents in the first message. We will ask if we need them.
To select a cohort of twelve teams; to house, feed, and teach them safely in Singapore; to issue and later verify TGA-CERT records; to answer press and partner mail; to meet safeguarding and immigration duties; and to keep a minimum archive so that a certificate presented in 2036 still means something. We do not use applicant data to train public machine-learning models. We do not send newsletters unless you asked for one.
Where GDPR or similar frameworks apply: contract (processing an application you submitted), legitimate interests (running a safe academic event, preventing certificate fraud), legal obligation (safeguarding, immigration paperwork, accounting), and consent (photographs of identifiable minors used in public, optional mailing lists, any special-category data you volunteer such as health information needed for meals or access). You may refuse photographs. You may not refuse the safeguarding information we need to host a minor.
The cohort is photographed. Accepted teams receive a media-consent form. We will not put a minor's full name next to a photograph on this website without a signed release. Campus photographs already on the site are used as documentary images of the programme, not as identified portraits of named students. If you believe we have published an image of you that should come down, write to us. We will answer.
A TGA-CERT identity is a public verification record: holder name as printed, cohort year, and any Galaxy honor. That is the point of a verifiable certificate. We do not publish home addresses, passport numbers, or school emails as part of the record. See Certificates and Verify.
Housing and catering vendors in Singapore, and only the fields they need (name, gender for rooming, meal plan, emergency contact). Immigration authorities when we issue invitation letters you asked for. Mentors and panelists, who see team work product and first names during the week. Our email host and web host, under contract. We do not sell personal data. We do not share bursary documents with other teams. We will share information with authorities if we believe someone is at risk of harm.
If you apply from outside Singapore, your information will be processed in Singapore and may pass through mail servers in other countries. By submitting an application you understand that a Singapore-hosted intensive cannot be run entirely inside your home jurisdiction. We will not transfer bursary documents to a public cloud folder with open sharing turned on. That sentence exists because it has happened at other programmes. It will not happen here.
Unsuccessful Stage 1 expressions of interest: deleted or anonymised within 24 months. Unsuccessful Stage 2 files: 24 months. Accepted cohort operational files (rooming, meals, medical notes): 36 months after the intensive, then reduced to a safeguarding stub if law requires. TGA-CERT records: retained as a permanent public verification archive, which is the purpose of issuing them. Financial records: as required by accounting law. Server logs: 90 days unless an incident investigation is open.
The staff issuance tools on this domain are noindexed and are not part of the public site. Certificate issuance is restricted to authorised operators. Verification is a read of a record, not an edit. We cannot promise that any website is unhackable. We can promise that we will notify affected people if we become aware of a breach that puts them at material risk.
Subject to law, you may ask to access, correct, or delete personal data we hold about you, or to restrict or object to certain processing, or to receive a portable copy of data you provided. Parents and guardians may make these requests on behalf of a minor. We will not delete a TGA-CERT record merely because a holder dislikes the honor they received; we will correct a factual error. We will not delete safeguarding records we are required to keep. Send requests to info@tga.org with the subject "Privacy rights". We may need to verify that you are the person you claim to be.
TGA is built for secondary-school and university students, which includes minors. We do not try to attract children below secondary-school age. We do not knowingly collect data from them. If you believe we have, tell us.
The public pages are static HTML. We do not set a tracking cookie for advertising. A language-preference value may be stored locally in your browser. Swup page transitions run in JavaScript in your browser; they do not phone home with a profile of your reading. If we add an essential cookie later, this policy will say so before the cookie does.
If we change this policy in a way that affects people we already hold data about, we will update the date at the top and, for accepted teams, send a note to the adult lead. Continued use of the site after a posted change constitutes acceptance of the revised policy for website data. Contractual data (applications, certificates) is governed by the version in force when you submitted, unless a law says otherwise.
Privacy questions: info@tga.org, subject "Privacy". We answer every email — usually within two business days, always within five. If you are in a jurisdiction with a supervisory authority, you may also complain to that authority. We would rather you write to us first, because most issues are a wrong email or a certificate code typed with a zero instead of an O.