List of active policies

Name Type User consent
USCC Privacy Policy Privacy policy All users
GDPR Policy Privacy policy All users

Summary

This privacy policy covers how your data will be used by US Cyber Challenge.

Full policy

PRIVACY STATEMENT:
All information will be used in connection with the activities associated with US Cyber Challenge, including statistical reporting for accounting of performance metrics regarding the participants.


Summary

This is the SANS/Counter Hack GDPR Policy, explaining your rights under EU law.

Full policy

Counter Hack provides training related to cybersecurity and the safe use of technology within your organization. To provide this training, Counter Hack captures and processes personal data and as such has been identified as a “controller” of your information.

The information provided to Counter Hack for training purposes may include name, email address, phone number(s), address, company, department, job function, industry, organizational memberships, and geographic region. Counter Hack may also collect data about devices and software used to access the training and training systems; this data includes browser version, operating system version, IP addresses, access times, connection duration, and other browser analytics. As training is delivered, Counter Hack processes and stores data associated with training assignments, completion, and scores on any learning activity that is delivered. Counter Hack may also utilize third party processors to provide these services.

If your information is provided by your employer, this information is used as part of the initial or ongoing training cycle. The purpose for collecting this data is to allow Counter Hack and your employer to assign, deliver, record and report on your cybersecurity training. Your information and training records will be shared only with you and your employer.

At any time you have the right to receive a copy of the personal data you have provided to us in an electronically readable format.

A data protection regime is in place to oversee the effective and secure transmission, processing, storage, and eventual disposal of your personal data, and data related to your training. Counter Hack will retain your data until you request that it be removed, after which it will be securely disposed of. Counter Hack will never sell your personally identifiable data and will only share your personally identifiable data with Counter Hack cyber security solutions partners when you provide agreement to do so.

When you consent to us using your information for the purposes of sending you information on Counter Hack products or services you are providing us with your consent to send you materials detailing our products and services that we consider will be of interest to you, based on your use of the educational material that we provide as resources. We profile you this way to make the materials more relevant to you. We will only send you information on products from within the Counter Hack services portfolio.

If, at any point, you believe your personal information to be incorrect, you may request to see a copy of your data, ask to have the errant data corrected, or ask that it be securely disposed of. If your information is provided by your employer, Counter Hack will work directly with your employer to promptly address the matter. If you wish to raise a complaint or concern, or have questions relating to GDPR, please contact the Data Protection Officer via gdprprivacy@sans.org.

Counter Hack has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to the EU Data Protection Authorities (DPAs), or where applicable instead, to the Swiss Federal Data Protection and Information Commissioner. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit the following web site for more information and to file a complaint with the EU DPAs: http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm

You may, at any time, withdraw your consent; to do so, please contact gdprprivacy@sans.org.

Counter Hack is a U.S. company founded in 2010 that specializes in information security and cybersecurity training. All information provided to Counter Hack will be transferred to and processed in the United States. Counter Hack is committed to comply with the Privacy Shield Framework which has been found adequate by the European Commission to enable international data transfer under EU law. For more information, please see www.sans.org or contact gdprprivacy@sans.org.