Privacy Policy

Last updated: July 1, 2026
This Privacy Policy explains what personal data UTGARD ("we", "us", "our") collects through the UTGARD DFIR Division training platform, why we collect it, and what rights you have over it. We only collect what is strictly necessary to authenticate you, deliver your purchased tier content, and keep the Platform secure.
Contents
  1. 1. Who We Are
  2. 2. Age Requirement
  3. 3. Data We Collect
  4. 4. Why We Process It
  5. 5. How We Use Your Data
  6. 6. Data Retention
  7. 7. Cookies & Local Storage
  8. 8. Third-Party Services
  9. 9. Security Measures
  10. 10. International Data Transfers
  11. 11. Data Breach Notification
  12. 12. Your Rights
  13. 13. External Links
  14. 14. Changes to This Policy
  15. 15. Contact

1. Who We Are

UTGARD operates this training platform and acts as the party responsible for the personal data described in this Policy. We do not have a dedicated privacy office or email address at this time — all privacy-related matters must be raised through a support ticket in our official Discord server.

By using the Platform, you acknowledge that you have read this Privacy Policy. We recommend reading it in full before creating an account or making a purchase.

2. Age Requirement

The Platform is available only to individuals who are at least 15 years old. We do not knowingly collect personal data from anyone below this age. If we become aware that an account belongs to someone under 15, we will delete the associated data and revoke access.

Age is self-reported at sign-up; we do not currently operate a separate age-verification system beyond what Discord itself requires of its users.

3. Data We Collect

3.1 Discord Profile Data

When you sign in, we retrieve the following from Discord via OAuth 2.0:

This data is fetched fresh at every login and stored only inside your encrypted session (see 3.2) — we do not keep a separate database of Discord profiles.

3.2 Session & Authentication Data

Your session is a single encrypted, tamper-proof cookie — there is no server-side session database. It contains your Discord ID, display info, tier, an expiry timestamp, and a random session ID, encrypted with AES-256-GCM. A short-lived, encrypted state cookie is also used during login only, to prevent cross-site request forgery (CSRF), and is deleted immediately once login completes.

3.3 Device & Anti-Sharing Data

To enforce a one-account-per-device policy and reduce subscription sharing, we set two additional first-party cookies and record a binding record on our server:

This binding record is stored server-side in a private data file (not a public or third-party database) and is used exclusively to detect and block a purchased account being used from more than one device.

3.4 Security & Rate-Limiting Data

We temporarily track request counts per IP address in server memory to enforce rate limits (e.g. to slow down automated login attempts). These counters reset automatically and are never written to disk. Server logs may include IP addresses and request paths for a short period for debugging and abuse investigation.

3.5 Local Browser Storage

A small UI preference (your chosen presence indicator — online / idle / do not disturb / offline) is saved using your browser's own local storage. This value never leaves your device and is not transmitted to us.

3.6 What We Do Not Collect

We do not currently collect or store lesson-progress history, quiz results, bookmarks, personal notes, uploaded videos, or any file-analysis submissions — these features do not exist on the Platform today. If any of them are introduced in the future, this Policy will be updated accordingly beforehand.

4. Why We Process It

We only process personal data where it is necessary to:

We do not process your data for advertising, profiling, or any purpose unrelated to running the Platform. We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you — tier access is checked against your actual Discord roles, not an automated profile of you.

5. How We Use Your Data

6. Data Retention

DataRetention
Session cookie24 hours, or immediately destroyed on logout
Login state (CSRF) cookie10 minutes, deleted after login completes
Device identifier & fingerprint cookiesUp to 1 year, refreshed on use
Device/account binding recordRetained while your account remains linked to a device; removed on a valid deletion request or staff unbind
Rate-limiting countersIn-memory only; auto-expire every 60 seconds; cleared on server restart
Server logsShort-lived, kept only as long as reasonably needed for debugging/abuse review

7. Cookies & Local Storage

All cookies we set are strictly necessary for authentication and security. We do not use advertising, analytics, or third-party tracking cookies.

A single local-storage value on your own device stores your chosen presence indicator (Section 3.5) and is never sent to our servers.

8. Third-Party Services

8.1 Discord

We use Discord as our sole authentication provider and community platform. When you sign in, Discord processes your login under its own Privacy Policy and Terms of Service. We only receive and store the profile fields described in Section 3.1.

8.2 Fonts & Icons

The Platform loads typography and icon assets from Google Fonts and a public content-delivery network (jsDelivr). Loading these resources may expose your IP address to those providers under their own respective policies; we do not share any personal data with them ourselves.

8.3 No Sale of Data

We do not sell, rent, or trade your personal data to any third party, and we do not share it with advertisers or data brokers.

9. Security Measures

10. International Data Transfers

The Platform may be hosted and operated from infrastructure located outside your own country of residence. By using the Platform, you understand that your data may be processed in a different country than where you live, which may have different data protection laws than your own. We take reasonable steps to keep your data secure regardless of where it is processed, as described in Section 9.

11. Data Breach Notification

If we become aware of a security incident that results in unauthorized access to or disclosure of your personal data, we will notify affected users through our official Discord server without undue delay, describe the nature of the incident to the extent known, and outline the steps we are taking in response.

12. Your Rights

Regardless of where you live, we aim to honour the following rights over your personal data. To exercise any of them, open a support ticket via our official Discord server:

13. External Links

The Platform may link to external websites or services, including Discord. We have no control over their content or privacy practices and are not responsible for them. We recommend reviewing the privacy policy of any external site you visit.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced on our Discord server at least 7 days before they take effect. The date at the top of this page always reflects the latest revision. Continuing to use the Platform after a change takes effect means you accept the revised Policy.

15. Contact

For any privacy-related question or request, please open a support ticket via our official Discord server. We do not currently provide email or web-based support.