Privacy Policy

Last updated: August 20, 2026

1. Overview

This Privacy Policy explains what information Sense Six Cyber Inc. collects through the GRC Lab (the “Service”), a free GRC/TPRM training platform, how it’s used, and the choices available to you. It applies to anyone who joins the waitlist at grc.sensesixcyber.com/waitlist, and to anyone who creates a student account.

2. Information we collect

  • Waitlist information: email address, name (if you provide one), how you found us, your own referral code, and whether you agreed to receive marketing email (see Section 6)
  • Account information: name, email address, and role, used to create and secure your login
  • Authentication data: hashed password, and a second-factor secret if you enroll in 2FA
  • Practice work: the risk register entries, policy drafts, checklist progress, reflections, and comments you create while working through the training scenario. This is practice against a fictional company, not real business data (see the Terms of Service, Section 5)
  • Usage and audit data: an audit log of key actions taken in the Service, and standard technical data such as IP address, used for authentication security and rate limiting

3. How we use information

We use the information above to:

  • Provide, maintain, and secure the Service, including authenticating logins and applying rate limits to protect against abuse
  • Run the training program itself: track your progress, let your instructor review and grade your work, and generate your certificate
  • Send transactional email, such as waitlist confirmations, seat-availability notices, password resets, grading and feedback, and due-date reminders
  • Send marketing/update email, only if you’ve agreed to it (Section 6)
  • Maintain an audit trail of actions taken in accounts, for accountability and troubleshooting
  • Investigate and respond to security incidents
  • Monitor and fix application errors (see Section 4)

We don’t sell your information, and we don’t use it to serve advertising.

4. Third-party service providers

The Service relies on the following sub-processors to operate. Each processes data only as needed to provide its function to us:

  • Supabase: database, authentication, and file storage
  • Resend: all email delivery, transactional and marketing
  • Vercel: application hosting
  • Sentry: error monitoring, so we can detect and fix real bugs — captures technical details about what went wrong (e.g. the request that failed), not your practice work itself

File-upload malware scanning (VirusTotal) is built into the Service but is not currently active in production — the integration is intentionally left off until a privacy-respecting, non-public scanning tier is in place, rather than running the free tier (which shares scanned files with the wider VirusTotal community) against real uploads. This section will be updated the moment that changes.

5. Data security

Data is stored in Supabase with row-level security policies that restrict each student’s data to that student and Sense Six Cyber instructors/admins. Accounts support two-factor authentication, and repeated sign-in attempts are rate-limited. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.

6. Marketing email and your choices

Joining the waitlist or creating an account requires agreeing to receive occasional marketing/update email from us — this is separate from, and doesn’t affect, the transactional email you get just from using the Service (a seat-availability notice, grading, password resets, and similar, see Section 3).

You can withdraw marketing consent at any time using the unsubscribe link included in every marketing email, or by emailing admin@sensesixcyber.com. Unsubscribing stops future marketing email; it doesn’t remove you from the waitlist or delete your account, and you’ll still get the transactional email the Service itself depends on.

7. Data retention

We retain waitlist and account data for as long as it’s useful for the purpose it was collected for (e.g. running the waitlist, or keeping your training record), and for a reasonable period afterward to meet legal or accounting obligations. Contact us if you’d like your data deleted sooner; some records may need to be retained where required by law.

8. Your rights

Depending on your location, you may have rights to access, correct, or request deletion of your personal information, object to certain processing, or withdraw consent. To exercise these rights, contact us at admin@sensesixcyber.com. We’ll respond within a reasonable time and may need to verify your identity first.

We don’t sell or share personal information for cross-context behavioral advertising, so there’s no “opt out of sale” mechanism to offer — there’s nothing to opt out of.

9. Cookies

The Service uses only the essential cookies needed to keep you signed in and maintain your session. We don’t use advertising or third-party tracking cookies, and web fonts used on this site are served from our own servers rather than loaded live from a third party.

10. International data transfers

Our service providers (Section 4) may process and store data outside your own country, including in the United States. Where required, we rely on those providers’ own standard safeguards for cross-border transfer.

11. Children’s privacy

The Service is intended for people old enough to independently consent to online services in their own jurisdiction, and isn’t directed at children. We don’t knowingly collect personal information from children.

12. Governing law

This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict-of-law principles. Sense Six Cyber Inc. is incorporated federally under the Canada Business Corporations Act, with its registered office in Ontario.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active accounts. The “last updated” date at the top of this page reflects the most recent revision.

14. Contact

Questions about this Privacy Policy can be directed to admin@sensesixcyber.com.

← Back to homepage