Terms of Service

Version 2026-08-31 · effective 31 August 2026

1. Who these terms are between

These Terms of Service (“Terms”) govern access to and use of the Phishtime phishing-simulation and security-awareness platform (the “Service”), operated by Phishtime (“Phishtime”, “we”, “us”).

They form a binding agreement between us and the organisation that opens an account (the “Customer”, “you”). By clicking “I agree”, by completing signup, or by using the Service, you accept these Terms on behalf of that organisation and warrant that you are authorised to bind it. If you do not have that authority, or do not accept these Terms, do not use the Service.

2. What the Service is for

Phishtime exists for one purpose: to let an organisation run authorised, simulated phishing and social-engineering exercises against its own workforce, measure how people respond, and deliver awareness training on the back of the result.

It is a training and measurement tool. It is not an offensive-security product, not a penetration-testing service against third parties, and not a means of obtaining anyone’s real credentials. Any use outside the purpose stated in this section is a material breach of these Terms.

3. Authorisation is your responsibility

You may only run simulations against people your organisation is entitled to test — your own employees, and contractors operating under your direction — and only on email domains and phone number ranges you control and have verified in the Service.

You represent and warrant, for every campaign you launch, that:

  • you hold current internal authorisation from the people who must give it — typically the organisation’s owner or executive sponsor, and where applicable its security, legal, HR, and communications functions;
  • you have completed any employee notification, works-council consultation, or collective-agreement process your national law requires before the first send, not after;
  • you have a lawful basis for processing the personal data involved, and have given the individuals concerned whatever notice the law requires; and
  • the recipients, sending identity, templates, and landing pages you have configured are within the scope that was approved.

Phishtime enforces some of this technically — campaigns can only target verified domains, and only verified domains can send. Those controls are a safety net, not a substitute for your authorisation. Their existence does not transfer any part of this responsibility to us.

4. Prohibited use

You must not, and must not permit anyone else to:

  • use the Service against anyone outside your own workforce, including customers, suppliers, members of the public, or another organisation’s staff — whether or not that organisation has asked you to;
  • use the Service to conduct a real attack, to commit fraud, or to obtain unauthorised access to any system or account;
  • attempt to capture, store, or use real credentials, multi-factor codes, recovery codes, payment details, or other genuine secrets — the Service is built not to record them, and you must not work around that;
  • use simulation results to harass, discriminate against, or retaliate against an individual, or for any purpose other than security awareness and risk reduction;
  • circumvent or attempt to circumvent the Service’s safety controls, including domain verification, content link scanning, messaging country allowlists, sending limits, or the disclaimers and watermarks embedded in simulated pages;
  • use the Service for anything unlawful in any jurisdiction where you, your organisation, or the recipients are located; or
  • resell, sublicense, or provide the Service to a third party as a service, except under a written partner agreement with us.

5. Your responsibility for how you use the Service

You are solely responsible for how you configure and operate the Service: which people you target, what your templates and landing pages say, which brands and pretexts you imitate, how often you test, and what you do with the results.

You accept the operational risk of running simulated attacks inside your own environment — including recipients acting on a simulated message, reporting it to external parties, or being distressed by it, and the load a campaign places on your own mail, security, and support systems. You are responsible for having a support and escalation path in place for employees who have questions or concerns about a simulation.

We provide the platform. We do not review, approve, or supervise your campaigns, and we have no obligation to do so.

6. Your account and credentials

You are responsible for the security of your Phishtime accounts. That includes keeping credentials confidential, enabling multi-factor authentication or single sign-on, granting administrator access only to people who need it, and removing access promptly when someone leaves.

You are responsible for all activity carried out under your accounts, whether or not you authorised it — including activity following a compromise of your credentials, devices, email, or identity provider. A Phishtime administrator account can send deceptive messages and read simulation results, so treat it as a privileged account.

You must notify us without undue delay at info@phishtime.com as soon as you suspect any unauthorised access to your account, and cooperate with us in containing it. We may suspend an account immediately where we believe it has been compromised.

7. No probing or attacking the platform

The Service is a tool for testing your people, not a target. Without our prior written permission you must not:

  • perform penetration testing, vulnerability scanning, fuzzing, or load or stress testing against the Service or its infrastructure;
  • reverse-engineer, decompile, or attempt to derive the source code or underlying logic of the Service, except to the extent that restriction is unenforceable under applicable law;
  • attempt to access data belonging to another customer, defeat tenant isolation, escalate privileges, or bypass authentication, rate limits, or usage quotas;
  • interfere with the Service’s operation or availability, or use it to distribute malware; or
  • access the Service by automated means beyond the documented API, or misrepresent the identity of a request.

If you discover a security vulnerability in the Service, report it to us privately and promptly at info@phishtime.com and give us a reasonable opportunity to remediate it. Do not exploit it beyond the minimum needed to demonstrate it, do not access or exfiltrate any data that is not yours, and do not disclose it publicly or to a third party before we have addressed it. Good-faith research reported this way is welcome; the exception in this paragraph does not extend to anything beyond it.

8. Compliance with law

You warrant that your use of the Service complies with all laws that apply to it, including computer-misuse and unauthorised-access law, employment and worker-representation law, data-protection law, and the rules governing electronic mail and messaging in each relevant jurisdiction. You will not use the Service where doing so would be unlawful.

Nothing in the Service constitutes legal or compliance advice. Simulation results and reports are evidence you may choose to rely on; deciding whether they satisfy any obligation of yours is your responsibility and, where appropriate, your advisers’.

9. Data protection

For the employee, audience, and simulation-event data you process through the Service, you are the data controller and we are your processor, acting on your documented instructions. Our Privacy Policy describes what we process and why, and our data processing agreement governs the processor relationship; where that agreement and these Terms conflict on data protection, that agreement prevails.

Establishing a lawful basis for including your people in simulations, giving them any required notice, and responding to their data-subject requests are your responsibility as controller. We will assist you as the agreement requires.

10. Availability and changes to the Service

We work to keep the Service available and secure, but it is provided on an “as available” basis. We may modify, add, or withdraw features, and may carry out maintenance that interrupts availability. Features marked beta or preview may change or be removed without notice and carry no availability commitment.

Any service-level commitment applies only where we have agreed one in writing with you. The free plan carries none.

11. Suspension and termination

You may stop using the Service and close your account at any time; paid plans are governed by the billing terms of your plan.

We may suspend or terminate access immediately and without notice where we reasonably believe you have breached sections 3, 4, 6, 7, or 8, where your use puts the platform, its other customers, or third parties at risk, or where we are required to do so by law. Where the circumstances allow, we will tell you why and give you an opportunity to remedy the breach.

On termination your right to use the Service ends. Your data is deleted or returned in line with our Privacy Policy and the applicable agreement. Sections 5 to 8 and 12 to 16 survive termination.

12. Disclaimers

To the fullest extent permitted by law, the Service is provided “as is”, without warranties of any kind, whether express, implied, or statutory, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement.

In particular, we do not warrant that the Service will detect or prevent any real attack, that a simulation accurately predicts how a person will behave when genuinely targeted, that campaign delivery is unaffected by third-party mail systems and security filtering, or that using the Service makes you compliant with any law, standard, or certification. Simulation results are indicative measurements, not a security guarantee.

13. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profit, revenue, goodwill, business, or anticipated savings, however caused.

To the fullest extent permitted by law, our total aggregate liability arising out of or relating to the Service and these Terms is limited to the fees you paid us for the Service in the twelve months immediately before the event giving rise to the claim. Where you use the Service on a free plan and have paid us nothing, our aggregate liability is limited to one hundred euros (€100).

Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that applicable law does not permit to be limited.

14. Indemnity

You will indemnify and hold us harmless against any claim, demand, proceeding, loss, liability, damage, fine, or cost (including reasonable legal fees) brought by a third party — including your own employees, contractors, worker representatives, a regulator, or a supervisory authority — to the extent it arises out of or relates to:

  • your use of the Service, or the content of the campaigns you run;
  • your failure to obtain the authorisation, notice, or consultation described in section 3;
  • your treatment of your workforce in connection with a simulation; or
  • your breach of these Terms or of any law.

We will notify you of any such claim, allow you to control its defence (provided any settlement releases us fully and admits no fault on our part), and cooperate reasonably at your expense.

15. Changes to these Terms

We may update these Terms as the Service, our practices, or the law change. Each version carries a version identifier and an effective date, shown at the top of this page.

When we make a material change we will require administrators to accept the new version in the application before continuing to use it, and may also notify you by email. Continued use after a change takes effect constitutes acceptance of the current version. We keep a record of which version each administrator accepted, and when.

16. Governing law and disputes

These Terms, and any dispute arising out of or in connection with them or the Service, are governed by the laws of the jurisdiction in which Phishtime is established, without regard to its conflict-of-laws rules, and the courts of that jurisdiction have exclusive jurisdiction. This does not deprive a consumer of the protection of mandatory rules of the law of their habitual residence, where those apply.

Before starting proceedings, please contact us — most disputes are resolved faster that way.

17. Contact

Questions about these Terms, requests for our data processing agreement, and security-vulnerability reports under section 7 can be sent to info@phishtime.com.

See also our Privacy Policy.