THREATROOM

Privacy Policy

With the following information we provide you, in accordance with Art. 13 and 14 GDPR, with an overview of the processing of your personal data when using the training platform ThreatRoom (threatroom.io), including the trainer console.

This English translation is provided for convenience only. The German version is the authoritative and legally binding version.

1. Controller

Can Yildiz and Stefan Pilarczyk
Dietrich-Bonhoeffer-Str. 23
61440 Oberursel (Taunus), Germany
E-mail: [email protected]

2. Key points at a glance

  • No cookies, no advertising tracking: ThreatRoom does not use cookies and does not use any advertising or marketing tracking services. For error and stability monitoring we use a technical frontend-monitoring tool (Grafana Faro, see section 10); it serves solely to keep the service secure and error-free.
  • Pseudonymous participation by default: As a rule, neither your real name nor an e-mail address is required to take part in a training session — you simply choose a made-up codename. Only if the organiser has expressly configured a session for real-name participation (e.g. as training or audit evidence) are your first and last name and e-mail address collected when joining (see section 7).
  • Hosting in Germany: The platform is operated at Hetzner Online GmbH in Germany; a data processing agreement pursuant to Art. 28 GDPR is in place.
  • Fonts and music are served locally — no requests are made to Google Fonts or other font/media CDNs.

3. Hosting (Hetzner)

The platform is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (“Hetzner”). When the pages are accessed, the web server automatically processes technical access data (server log files): IP address, date and time of access, requested URL, transferred data volume, referrer and browser identifier (user agent). This data is required for the technical operation, stability and security of the service (e.g. defending against attacks, limiting login attempts) and is not combined with other data sources.

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation). We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR; processing takes place in data centres in Germany.

4. Connectivity via Cloudflare

Public access to threatroom.io is routed through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”) (DNS, TLS termination, DDoS protection). In doing so, Cloudflare processes technical connection data (in particular IP address and HTTP metadata) as our processor. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the security and availability of the service). A transfer to the USA cannot be ruled out; Cloudflare is certified under the EU-US Data Privacy Framework, and the EU standard contractual clauses apply in addition.

5. Browser storage (localStorage / sessionStorage)

ThreatRoom does not use cookies. However, technically required data is stored in your browser’s web storage to operate the application (including the session code, your codename — in real-name sessions your display name —, a random player ID, access tokens and cached game state; in the trainer console the login token; and a random monitoring session ID for the frontend monitoring described in section 10). This data remains on your device, is not read out for tracking purposes and becomes invalid when you leave or log out, or at the latest when the token expires (4 hours for players, 8 hours for the console). You can delete web storage at any time via your browser settings.

Storing and reading this data is strictly necessary to provide the service you have expressly requested (§ 25 (2) no. 2 German TDDDG); consent is therefore not required. Further processing is based on Art. 6 (1) (b) GDPR.

6. Waitlist (“coming soon” notification)

On the landing page you can join a waitlist to be informed by e-mail as soon as ThreatRoom becomes generally available. For this purpose we process the data you provide: name and e-mail address.

Registration uses a double-opt-in procedure: after submitting the form you first receive a confirmation e-mail with a link. Only when you click this link — thereby confirming that you own the e-mail address provided — is your data added to the waitlist. Without confirmation, no data is stored; the confirmation link is valid for 7 days.

The legal basis is your consent (Art. 6 (1) (a) GDPR). You can revoke your consent at any time with effect for the future — via the unsubscribe link in every e-mail or by e-mailing [email protected]. The lawfulness of processing carried out before revocation remains unaffected. Your data is used exclusively to inform you about the launch of ThreatRoom and directly related product news, and is deleted as soon as you revoke your consent or the purpose of the waitlist ceases to apply.

For sending the e-mails and managing the waitlist we use the e-mail service provider Mailjet SAS, 13-13bis, rue de l'Aubrac, 75012 Paris, France (“Mailjet”, part of the Sinch group) as a processor; a data processing agreement pursuant to Art. 28 GDPR is in place, and contact data is stored in data centres in the EU. Insofar as a transfer to third countries within the Sinch group cannot be ruled out, it takes place on the basis of the EU standard contractual clauses (Art. 46 GDPR).

7. Participation in training sessions (players)

When creating a session, the organiser determines how participants identify themselves — either pseudonymously with a codename (default) or with their real name. There is no combination; exactly one of the following two modes always applies.

a) Pseudonymous sessions (default)

When you join a pseudonymous training session, we process: the session code, your freely chosen codename, a randomly generated player ID, the game role assigned to you and your game interactions (votes, answers, free-text input, scores). The codename is visible to the other participants of the session and to the trainer. Real name and e-mail address are not collected in this mode.

We recommend not using your real name as a codename and not entering any personal data or confidential information into free-text fields. Participation in this mode is possible entirely pseudonymously.

b) Real-name sessions (at the organiser’s request)

If the organiser has configured a session for real-name participation (e.g. because participation is to be documented as training, awareness or audit evidence), you provide your first and last name and e-mail address when joining instead of a codename; these details are required for participation in this mode. Your name is then — instead of a codename — visible to the other participants of the session and the trainer. Your e-mail address is not shown to other participants; it is visible exclusively to the trainer and the organiser for participation documentation (session reports, participant list export).

You can tell whether a session is pseudonymous or uses real names before joining by the fields requested on the join page.

Purposes and legal bases

The purpose of the processing is to run the interactive crisis simulation, including live evaluation and debrief; in real-name sessions additionally to document participation for the organiser. The legal basis is Art. 6 (1) (b) GDPR (performance of the usage relationship) and Art. 6 (1) (f) GDPR (legitimate interest in running the training booked by the organiser; in real-name sessions additionally the organiser’s legitimate interest in evidence of training participation, e.g. towards auditors or supervisory authorities). Session-related results may be made available to the organiser of the training (e.g. your employer) — in pseudonymous sessions only under the chosen codename, in real-name sessions under your name including your e-mail address.

8. AI-generated scenarios

The training scenarios (texts, tasks, evaluations and, where applicable, images and voice output) are generated during a session using generative AI models. For this purpose we transmit session configuration data (e.g. scenario parameters and any company profile provided by the organiser), the active game roles and the free-text input entered in the game to our AI gateway provider Requesty (requesty.ai). Processing takes place via its EU endpoint; the gateway routes requests to third-party models (e.g. Anthropic, Google, OpenAI). Participants’ names, contact details or account information are neither needed nor transmitted for this — this also applies to real-name sessions: your name and e-mail address are not included in AI requests. Free-text input is transmitted only to the extent you enter it into the game yourself.

The legal basis is Art. 6 (1) (b) GDPR (provision of the booked simulation functionality) and Art. 6 (1) (f) GDPR. The automated evaluation of game answers serves solely to award points in the game and has no legal or similarly significant effect within the meaning of Art. 22 GDPR.

Information on the labelling of AI-generated content pursuant to Art. 50 of the EU AI Act can be found in our AI transparency notice.

9. Feedback and bug reports

After a session you can voluntarily give feedback (star rating and optional free-text comment). Via the “Report a bug” function you can also send error reports; in addition to your description, the page visited, the session ID and the browser identifier (user agent) are transmitted. We use this data exclusively to improve and fix the platform (Art. 6 (1) (f) GDPR). Feedback is associated with the session and the codename, but not with an identified person.

10. Error and performance monitoring (Grafana Faro)

To ensure stable and error-free operation, we use the frontend-monitoring tool Grafana Faro in the player application and the trainer console. It captures technical events from your browser: JavaScript error messages, load times and performance metrics (Web Vitals), visited page paths, failed network requests, browser and device type (user agent) and a randomly generated monitoring session ID. To associate errors with a training session, the random player ID, the codename (in real-name sessions your display name) and the session code — or, for console accounts, the account ID, role and organisation — are also sent as attributes. No use for advertising or marketing purposes and no cross-site tracking takes place.

The monitoring data is transmitted to Grafana Cloud, a service of Grafana Labs, with which a data processing agreement pursuant to Art. 28 GDPR is in place. Storage takes place in data centres in London (United Kingdom; an adequacy decision of the EU Commission pursuant to Art. 45 GDPR exists for the United Kingdom). When receiving the data, Grafana Labs also processes your IP address as technical connection data. Insofar as a transfer to Grafana Labs, Inc. (USA) cannot be ruled out, it takes place on the basis of the EU standard contractual clauses (Art. 46 GDPR). Monitoring data is deleted automatically after a short time (usually after 30 days).

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the stability, security and troubleshooting of the platform). The storage of the monitoring session ID in your browser’s web storage required for this purpose takes place in accordance with § 25 (2) no. 2 TDDDG.

11. Trainer accounts (console)

For trainers and administrators of the console we process account data: e-mail address (which usually contains name components and thus establishes a personal reference), password (stored exclusively as a bcrypt hash), role and organisation membership. To defend against attacks, failed login attempts are counted and limited per IP address and e-mail address for a short time. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (f) GDPR (account security).

12. Recipients of the data

Personal data is only passed on to the processors named in this policy (Hetzner, Cloudflare, Mailjet, Requesty, Grafana Labs). No data is passed on for advertising purposes and no data is sold. Transfers to third countries take place only as described in sections 4, 6, 8 and 10 on the basis of suitable safeguards (Art. 44 et seq. GDPR).

13. Storage periods

  • Live game data (game state, statements, generated media held in memory) is deleted automatically after at most 2 hours; session configurations after at most 24 hours.
  • Session results (codenames or, in real-name sessions, first and last name plus e-mail address, roles, scores, game history) are stored for debriefing, evaluation and — in real-name sessions — as evidence of participation, and are deleted when the organiser deletes the session or the purpose ceases to apply.
  • Feedback and bug reports are stored for as long as they are needed to improve the platform.
  • Console accounts are stored for the duration of the contractual relationship and deleted afterwards, unless statutory retention obligations require otherwise.
  • Server log files are retained only as long as required for security and error analysis.
  • Frontend-monitoring data (section 10) is deleted automatically in Grafana Cloud, usually after 30 days.
  • Waitlist data (name and e-mail address, section 6) is stored until you revoke your consent or the purpose of the waitlist ceases to apply; unconfirmed registrations are not stored.

14. Your rights

You have the following rights vis-à-vis us regarding your personal data: right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).

You also have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6 (1) (f) GDPR (Art. 21 GDPR).

To exercise your rights, an e-mail to [email protected] is sufficient. Please note: with pseudonymous participation we can only attribute game data to a person if you tell us the session code and codename. In real-name sessions, attribution is possible via your name and e-mail address.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.

15. Data security

All data is transmitted TLS-encrypted. Passwords are stored exclusively as hashes, access to game data is secured by short-lived, signed access tokens, and access to administrative functions is restricted on a role basis.

16. Changes to this privacy policy

We adapt this privacy policy when the platform or the legal situation changes. The version published here applies in each case.

Version: July 2026