Privacy notice

How Threat Intelligence Lab handles account and TIL Teams data.

Last updated: 22 August 2026

Who is responsible?

For account authentication, platform security and our own billing administration, Threat Intelligence Lab determines the processing purpose. For employee learning assigned through TIL Teams, your organization determines the purpose and is normally the controller; TIL processes those records under the Teams Data Processing Addendum.

Data we use

We use your display name, normalized email, password hash and necessary security records. If you join a team, we also use your membership role, assigned requirements, completion outcomes and competency scores. Billing records contain the team’s PayPal subscription, plan, quantity and status identifiers—not payer profile, address, funding source or payment instrument details.

We do not request date of birth, home address, telephone, job title, department, employee number or raw exam answers. We do not use advertising trackers or behavioral page-view analytics.

Visibility and use

Team managers see only outcomes generated through their own team’s assignments. Personal exam attempts and attempts for another team do not enter team reports. Team leaderboards are unpublished by default; other members see your name and score only when you opt in for that team. Managers retain a private reporting view for administering the assignment.

Retention

Providers and transfers

We may use PayPal for subscriptions and approved providers for transactional email, hosting, database/backup and network security. The current categories and production entities are described on our subprocessor page. Appropriate contractual and transfer safeguards must be in place where processing crosses jurisdictions.

Your choices and rights

You can export account data and request deletion from your account. If a request concerns employer-assigned learning, we may coordinate with your organization as controller. Depending on applicable law, you may have rights of access, correction, erasure, restriction, objection, portability and complaint to a supervisory authority.

Security and contact

We use TLS, hashed credentials and tokens, encrypted MFA secrets, server-side sessions, access controls and retention jobs. No internet service can promise absolute security. Contact [email protected] for privacy questions or rights requests.