Privacy Policy
Last updated: 8 September 2026
This page is maintained by the PhishHaven team to explain how we handle personal data collected through our security awareness training platform. It is provided for transparency and is not a substitute for independent legal advice or certification.
1. Who we are
PhishHaven provides simulated phishing campaigns and security awareness training to organizations. When an organization ("Customer") uses PhishHaven to train its employees, PhishHaven acts as a data processor on behalf of that Customer.
2. What data we process
- Employee contact details supplied by the Customer (name, work email, department).
- Simulation activity: whether a simulated phishing email was sent, opened, or clicked, and the timestamp.
- Training results, quiz answers, and completion certificates.
- Administrator account details for the Customer's admins (email, authentication metadata).
- Basic technical data such as IP address and browser type when interacting with our services.
3. Purposes and legal bases
We process personal data to deliver the training service the Customer has requested, to measure human risk, and to generate educational feedback for employees. The legal basis is our Customer's legitimate interest in protecting its organization against phishing, and the contract between PhishHaven and the Customer.
4. Where your data is stored
Employee and campaign data is stored and processed within the European Union on infrastructure with encryption in transit and at rest. Access is restricted to authenticated administrators of the Customer's organization through role-based access controls and row-level security. PhishHaven staff access is limited to what is strictly necessary to operate and support the service.
5. Retention
We retain employee simulation data for as long as the Customer's subscription is active, unless the Customer instructs us to delete it earlier. Upon termination, personal data is deleted or anonymized within a reasonable period, subject to any legal retention obligations.
6. Sharing and subprocessors
We use a small number of subprocessors to deliver the service (cloud hosting, database, AI content generation, and email delivery). Each is contractually bound to protect personal data consistent with GDPR. We do not sell personal data.
7. Your rights under GDPR
Employees can ask their organization's PhishHaven administrator to access, correct, export, or delete their personal data. Because PhishHaven acts as a processor, requests are handled through the Customer. You also have the right to lodge a complaint with your local data protection authority.
8. Cookies
We use strictly necessary cookies to keep you signed in and to remember your consent preferences. Optional analytics cookies are only set after you choose "Accept All" in the cookie banner. You can change your choice at any time by clearing site data in your browser.
9. Contact
For privacy questions, contact privacy@phishhaven.example.