Privacy Policy
Last updated: 8 August 2026
1. Who we are
Phishtime (“Phishtime”, “we”, “us”) provides a phishing-simulation and security-awareness training platform. This policy explains what personal data we process, why, and the rights available to individuals whose data we handle.
When an organisation (our “Customer”) uses Phishtime to run simulations for its own staff, the Customer is the data controller and Phishtime acts as a data processor on the Customer’s instructions, under a data processing agreement meeting Article 28 GDPR. For account-level, billing, and our own marketing data, Phishtime is the controller.
We are established in the European Union and this policy is written around the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the national laws implementing it. Where we serve individuals outside the EEA, comparable local rules may also apply.
2. Data we collect
- Account data — names, work email addresses, hashed passwords, role, and authentication metadata (including MFA and SSO identifiers) for administrators and users.
- Audience data — employee names, email addresses, and group or department attributes uploaded or synced by a Customer to define simulation recipients.
- Simulation event data — records of email deliveries, opens, link clicks, form submissions, and attachment interactions generated while a campaign runs, together with timestamps, coarse user-agent, and IP-derived data used for bot filtering.
- Usage and technical data — log data, device and browser information, and diagnostic events needed to operate and secure the service.
- Billing data — plan, contract, and invoicing details for Customers.
Simulations are designed to measure behaviour, not to capture secrets. Credentials typed into a simulated landing page are not stored; only the fact that a submission occurred is recorded.
3. How we use data
- To deliver phishing simulations and record their outcomes.
- To generate awareness training, reporting, and risk scoring for Customers.
- To authenticate users and secure the platform against abuse.
- To provide support, administer accounts, and process billing.
- To send product news and offers to our Customers’ business contacts — see section 4, which explains the strict limits on this.
- To meet legal, audit, and security obligations.
4. Marketing communications
We may send product news, feature announcements, and offers about our own services to business contacts — the administrators and billing contacts at our Customers, and people who start a trial, request a demo, or otherwise ask to hear from us.
- Never to simulation audiences. Employee and audience data that a Customer uploads or synchronises in order to run simulations is never used for our own marketing, and is never sold, rented, or shared for anyone else’s marketing. We process it only on that Customer’s documented instructions.
- Always reversible. Every marketing message carries a one-click unsubscribe, and you can object at any time using the contact details below.
- Separate from service messages. Opting out of marketing does not stop operational messages you need — security alerts, billing notices, maintenance and incident notifications.
5. Legal bases
Under Article 6 GDPR we rely on: performance of a contract (Art. 6(1)(b)) to provide the service; legitimate interests (Art. 6(1)(f)) to secure and improve the platform, and for our Customers’ interest in training their workforce; compliance with legal obligations (Art. 6(1)(c)); and, where required, consent (Art. 6(1)(a)).
For the marketing described in section 4 we rely on legitimate interests in promoting our own similar products to existing business customers, or on consent where the applicable national ePrivacy rules require it — in both cases subject to an unconditional right to opt out. Where we rely on consent you may withdraw it at any time under Art. 7(3), without affecting processing carried out beforehand.
Customers are responsible for establishing a lawful basis for including their employees in simulations, for any works-council or employee-representative consultation their national law requires, and for giving those employees notice.
6. Data sharing and sub-processors
We do not sell personal data and we do not share it for cross-context behavioural advertising. We share data only with sub-processors that help us run the service — cloud hosting, transactional email delivery, and error monitoring — each under a written contract imposing Article 28 GDPR obligations and appropriate safeguards. A current list of sub-processors is available to Customers on request, and we give Customers advance notice of intended changes so they can object.
We may also disclose data where required by law, to establish or defend legal claims, or to protect the rights and safety of our users.
7. Where we host and process data
The Phishtime platform and its primary database are hosted in the European Union. Simulation content, audience data, and event data are stored there, and our application monitoring is likewise configured to keep data in the EU.
Some sub-processors are established outside the EEA or may process limited personal data outside it — most notably transactional email delivery, which carries recipient addresses and message content. Where personal data is transferred outside the EEA we rely on the safeguards recognised in Chapter V GDPR: the European Commission’s Standard Contractual Clauses, an adequacy decision, or an equivalent mechanism, backed by a data processing agreement. We can supply details of the mechanism used for any given sub-processor on request.
8. Retention
Simulation event data is retained for the period configured by the Customer or as required to produce historical reporting, after which it is deleted or aggregated. Account and billing data is retained for the life of the account and for any period required by law. On termination, Customer data is deleted or returned in line with the applicable agreement.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, tenant isolation, role-based access control, multi-factor authentication, and audit logging. No system is perfectly secure; we maintain an incident-response process and will notify the competent supervisory authority and affected parties of personal-data breaches as required by Articles 33 and 34 GDPR.
10. Your rights under the GDPR
If you are in the EEA you have the following rights over your personal data, free of charge and normally answered within one month:
- Access (Art. 15) — a copy of the data we hold about you.
- Rectification (Art. 16) — correction of inaccurate data.
- Erasure (Art. 17) — deletion, where no overriding ground to keep it applies.
- Restriction (Art. 18) — pause processing while a dispute is resolved.
- Portability (Art. 20) — a machine-readable copy of data you gave us.
- Objection (Art. 21) — including an absolute right to object to direct marketing at any time.
- Withdraw consent (Art. 7(3)) — where processing is based on consent.
Because employee and audience data is processed on behalf of a Customer, requests from an employee are usually best directed to their employer, who is the controller for that data; we will assist our Customer in responding within the statutory deadline. For account-level and marketing data we control, contact us using the details in section 12.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), in the EEA member state of your habitual residence, place of work, or the place of the alleged infringement. We would appreciate the chance to address your concern first.
11. Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated through the service or by email. The “Last updated” date above reflects the current version.
12. Contact
Questions about this policy, requests to exercise the rights in section 10, or requests for our sub-processor list can be sent to info@phishtime.com.