Legal

Privacy Policy

This policy explains what personal data GraphLattice collects, why, who we share it with, and the choices you have. We collect as little as possible and never sell your data.

Last updated September 24, 2026

Who we are

GraphLattice ("we", "us") provides GraphLattice Range, hands-on incident-response training for identity and cloud attacks. This policy covers the marketing website at graphlattice.com and the training application at range.graphlattice.com. For anything in this policy, reach us through our Support page.

What we collect, and why

We only collect data for a specific purpose. We do not run advertising or analytics trackers, and we do not build profiles of you. See our Cookie & Storage Notice for the browser-storage detail.

WhenWhat we collectWhy (purpose)
Browsing the website Standard server request logs (IP address, browser type, pages requested), handled by our hosting provider for security and reliability. A local flag if you dismiss the cookie notice. Serve the site, keep it secure, prevent abuse. No tracking or advertising.
Asking the AI support assistant The question you type and a bot-check token. We do not require your identity to ask. Answer your question. Questions are processed by our AI provider to generate a reply.
Requesting a human support ticket Your email address and the conversation transcript you choose to send. Let a person follow up with you by email.
Creating a Range account Your email, name, and a provider account id from the sign-in service you choose (Google, Discord, or GitHub). For team accounts, your organization and role. Create and secure your account, and identify you to your team's administrators.
Using Range Your scenario progress and scores, any certificates you earn, and security audit events (such as sign-ins) tied to your account. Run the training, show your progress, issue verifiable certificates, and keep accounts secure.

How we use your data

We use the data above to operate the website and the training service, respond to your requests, secure our systems and prevent abuse, issue and verify certificates, and meet legal obligations. We do not sell your personal data, and we do not use it for third-party advertising.

Legal bases (EEA/UK)

Where GDPR or UK GDPR applies, we rely on: performance of a contract (running your account and the training), our legitimate interests (securing the service, answering support requests, preventing abuse), your consent where required, and compliance with legal obligations.

Who we share it with

We share data only with service providers that help us run GraphLattice, under agreements that require them to protect it. We do not sell data or share it with advertisers.

  • Cloudflare - hosting, content delivery, database storage, and bot protection (Turnstile) for the website and Range.
  • Our AI provider - processes questions you send to the AI support assistant to generate a reply. Do not put sensitive information into the assistant.
  • Sign-in providers you choose - Google, Discord, or GitHub authenticate you and share a basic profile (email, name, account id) with us when you sign in. Their handling of your data is governed by their own privacy policies.

We may also disclose data if required by law, or to protect the rights, safety, and security of GraphLattice, our users, or the public.

How long we keep it

We keep account data for as long as your account is active, and support correspondence for as long as needed to resolve your request and keep records. Server security logs are kept for a limited period by our hosting provider. When you close your account, we delete or anonymize your personal data unless we must keep it to meet a legal obligation.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, contact us through our Support page and we will respond as required by law. You can also clear anything the website stored in your browser at any time (see the Cookie & Storage Notice).

Security

We protect your data with encryption in transit, scoped access controls, and bot protection on public forms. No system is perfectly secure, but we design GraphLattice to collect little and guard what it holds.

International transfers

Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for those transfers.

Children

GraphLattice is intended for professionals and is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the "last updated" date above. Material changes will be made clear on the site.

Contact

Questions or requests about your privacy? Reach us through our Support page and we will route it to the right person.