Privacy Policy

Last updated: September 2, 2026

1. Who we are

SecureAware is an authorized phishing simulation and security training platform, operated by SECUREAWARE S.R.L., CUI 55515209, J2026052392005. For questions about this policy, you can reach us through our contact page.

2. What data we collect

Depending on your role (client administrator/manager, or an employee targeted in a campaign), we collect:

  • Account data — name, email, role, department, preferred language, for users of a client organization.
  • Campaign data — email and name of employees targeted in a simulation campaign, used solely for the authorized testing purpose.
  • Interaction events — whether an email was opened, whether a link was clicked, whether a form was submitted (not the content entered — see section 3), together with the IP address and browser type used at the time.
  • Training data — which modules you completed, the score obtained on the quiz.
  • Contact leads — if you submit the form on the public page, we retain your name, company, email, phone (if provided) and the message sent.
  • Audit log — administrative actions relevant to security (e.g. who launched a campaign), kept for traceability.

3. What we never collect

The fake pages used in phishing simulations intercept any form submission directly in your browser, before the data entered (passwords, other information) leaves your device. Our server only learns the fact that a submit happened, never its content.

4. Legal basis and purpose of processing

Account and campaign data are processed under the contract between your organization and SecureAware (or your organization's legitimate interest in testing and improving its security posture), to deliver the agreed service. Contact leads are processed based on the implicit consent of submitting the form, so we can respond to you.

5. How long we keep data

Account and organization data is kept for the duration of the contract with the client organization, plus up to 3 additional years afterwards, as needed to resolve any disputes or legal obligations. Contact leads that don't become clients are kept for a maximum of 24 months from the last interaction. Documents subject to legal archiving obligations (invoicing, accounting) are kept per the terms of Romanian law (e.g. Accounting Law no. 82/1991). The calculated risk score uses a rolling 12-month window of recent activity.

6. Who we share data with

We use the following providers (subprocessors) to operate the platform:

  • Database hosting — provider with a region in the European Union.
  • Email sending — our own server (Postfix), hosted in the European Union.
  • Application/server hosting — infrastructure provider with a region in the European Union.
  • Web interface hosting — Vercel, Frankfurt, Germany region (European Union).
  • Advertising conversion measurement — Google Ads, only after explicit consent (see section 9).
  • Website traffic analysis (no cookies, only aggregate page-view counts) — Vercel Web Analytics.

We do not sell or rent your data to third parties for marketing purposes.

7. Data security

Each client organization is isolated at the database level (Row-Level Security), not just through application code. Multi-factor authentication secrets are encrypted. Administrative access is recorded in an audit log.

8. Your rights

Under GDPR, you have the right to:

  • Access — you can download a copy of your data (profile, campaign history, training history) directly from your authenticated account.
  • Rectification— you can request correction of inaccurate data, by contacting your organization's administrator or our team.
  • Erasure— you can request deletion of your data, except what we're legally required to keep.
  • Objection and portability — you can object to processing or request an export of your data in a structured format.

To exercise any right, contact us.

9. Cookies and advertising

The public pages of the site (not the authenticated platform) use Google Ads cookies to measure the effectiveness of advertising campaigns — for example, to know if someone reached the site from an ad and submitted a form. These cookies load only after you choose "Accept"in the banner shown on your first visit — if you choose "Decline", no advertising cookie is set, and the site works identically.

We do not use advertising cookies to show you ads on other sites (cross-site retargeting) — only to measure our own campaign conversions. Full details, plus the option to change your choice at any time, in the Cookie Policy.

10. Changes to this policy

We may update this policy periodically. The date of the last update is shown at the top of this document.