Skip to main content
Threat Intelligence Lab
    • CoursesBuild practical knowledge
    • ExamsAssess your understanding
    • LeaderboardSee public achievements
  • Resources
  • Tools
  • Teams
  • Login
  • Create account
TIL Teams agreement

Data Processing Addendum

This addendum explains how Threat Intelligence Lab processes personal data on behalf of a TIL Teams customer.

Version: 2026-08-23Effective when accepted during team creation

1. Parties, scope and roles

This Data Processing Addendum (“DPA”) forms part of the agreement for TIL Teams between the customer identified during team creation (“Customer”) and Threat Intelligence Lab (“TIL”). It applies when TIL processes personal data in team memberships, assigned learning, assessments and team reporting on Customer’s behalf.

For that processing, Customer is the controller and TIL is the processor. Each party remains independently responsible for processing for which it determines the purposes and means. This includes TIL’s processing for account security, fraud prevention, legal compliance and subscription administration.

2. Customer instructions

TIL processes Customer personal data only to provide, secure, support and improve the contracted TIL Teams service, as described in this DPA, the agreement and Customer’s use of the service. This includes managing team access, delivering assignments, recording results, providing reports, sending service messages, maintaining security records and deleting data.

Customer confirms that it is authorized to provide these instructions, has an appropriate lawful basis, and gives team users the information required by applicable data-protection law. TIL will inform Customer if an instruction would, in TIL’s reasonable view, infringe applicable data-protection law.

3. Processing details

People concernedCustomer-authorized managers, employees, contractors and other invited team users
Data categoriesDisplay name; account or invitation email; team membership and role; assignment requirements, schedules and completion; assessment outcomes and competency points; leaderboard preference; necessary audit, authentication and security records; minimal subscription references
PurposePrivate team learning, assessment, competency reporting, access management, service communication, security, support, export and deletion
DurationFor the term of the TIL Teams service and the documented retention or recovery period, unless law requires longer retention

TIL does not store PayPal card or bank-account details. The platform records assessment outcomes needed for progress and competency reporting; it does not retain raw submitted answer selections as part of the team result.

4. Confidentiality and security

TIL limits access to people who need it to operate or support the service and who are bound by appropriate confidentiality obligations. Measures appropriate to the risk include team and role authorization, server-side sessions, recent account confirmation for sensitive actions, optional multi-factor authentication, transport encryption, encryption for selected sensitive fields, hashed one-time tokens, audit logging, backups, vulnerability management and incident-response procedures.

Customer remains responsible for managing its users, assigning appropriate manager roles, protecting its account credentials, reviewing exports and configuring the service in a lawful manner.

5. Subprocessors and international transfers

Customer gives TIL general authorization to use the providers identified on the current subprocessor page. That page describes their purpose, relevant data and primary processing location. TIL requires subprocessors to protect personal data through written terms appropriate to their role and remains responsible for the processing duties it delegates to them.

TIL will give reasonable advance notice of a material new or replacement subprocessor where required, allowing Customer to raise a reasonable objection based on data-protection grounds. If personal data is transferred outside the European Economic Area, TIL or the relevant provider will use a legally recognized transfer mechanism and supplementary measures where required.

6. Assistance and personal-data breaches

Taking account of the nature of the processing and information available to it, TIL will reasonably assist Customer with requests from data subjects, security obligations, data-protection impact assessments and consultations with supervisory authorities.

TIL will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer personal data. The notification will include available information reasonably needed for Customer to meet its obligations, and TIL will provide relevant updates as the investigation progresses.

7. Return, export and deletion

Managers can export available team reports while the workspace permits access. When a membership is removed or a team subscription ends, access is restricted and the applicable recovery or export window begins. Team data is then scheduled for deletion after 30 days unless the service is reactivated or applicable law requires retention.

At the end of the service, TIL will delete or return Customer personal data as required by Customer and applicable law. Protected backup copies are not restored for ordinary use and expire according to the applicable backup cycle.

8. Information and audits

TIL will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Where that information is insufficient, the parties may agree on a proportionate audit subject to reasonable advance notice, confidentiality, security safeguards and measures that protect other customers. Customer bears its audit costs unless applicable law requires otherwise.

9. Priority and contact

For processing covered by this DPA, this DPA prevails over conflicting terms in the general service agreement. The organization details, accepting user, DPA version and acceptance timestamp recorded during team creation form the Customer-specific acceptance record.

Questions about this DPA or TIL’s processing can be sent to [email protected].

Threat Intelligence Lab

Practical threat intelligence learning, assessments and team capability management.

Learn

  • Courses
  • Exams
  • Leaderboard

Explore

  • Resources
  • Tools
  • EUVD
  • RSS feed

For organizations

  • TIL Teams
  • Services
  • Partners

Company

  • About us
  • Contact

Privacy and legal

  • Privacy notice
  • Cookie notice
  • Terms
  • Teams DPA
  • Subprocessors
© 2026 Threat Intelligence Lab. All rights reserved.·Your trusted Threat Intelligence partner