Privacy Policy

Last updated: 8 September 2026

This page is maintained by the PhishHaven team to explain how we handle personal data collected through our security awareness training platform. It is provided for transparency and is not a substitute for independent legal advice or certification.

1. Who we are

PhishHaven provides simulated phishing campaigns and security awareness training to organizations. When an organization ("Customer") uses PhishHaven to train its employees, PhishHaven acts as a data processor on behalf of that Customer.

2. What data we process

  • Employee contact details supplied by the Customer (name, work email, department).
  • Simulation activity: whether a simulated phishing email was sent, opened, or clicked, and the timestamp.
  • Training results, quiz answers, and completion certificates.
  • Administrator account details for the Customer's admins (email, authentication metadata).
  • Basic technical data such as IP address and browser type when interacting with our services.

3. Purposes and legal bases

We process personal data to deliver the training service the Customer has requested, to measure human risk, and to generate educational feedback for employees. The legal basis is our Customer's legitimate interest in protecting its organization against phishing, and the contract between PhishHaven and the Customer.

4. Where your data is stored

Employee and campaign data is stored and processed within the European Union on infrastructure with encryption in transit and at rest. Access is restricted to authenticated administrators of the Customer's organization through role-based access controls and row-level security. PhishHaven staff access is limited to what is strictly necessary to operate and support the service.

5. Retention

We retain employee simulation data for as long as the Customer's subscription is active, unless the Customer instructs us to delete it earlier. Upon termination, personal data is deleted or anonymized within a reasonable period, subject to any legal retention obligations.

6. Sharing and subprocessors

We use a small number of subprocessors to deliver the service (cloud hosting, database, AI content generation, and email delivery). Each is contractually bound to protect personal data consistent with GDPR. We do not sell personal data.

7. Your rights under GDPR

Employees can ask their organization's PhishHaven administrator to access, correct, export, or delete their personal data. Because PhishHaven acts as a processor, requests are handled through the Customer. You also have the right to lodge a complaint with your local data protection authority.

8. Cookies

We use strictly necessary cookies to keep you signed in and to remember your consent preferences. Optional analytics cookies are only set after you choose "Accept All" in the cookie banner. You can change your choice at any time by clearing site data in your browser.

9. Contact

For privacy questions, contact privacy@phishhaven.example.