Privacy Policy

Draft. This policy is being finalized ahead of launch and is not yet the binding version. For any question about your data, email privacy@nordvakt.eu.

Who we are

Nordvakt provides phishing-simulation training for EU organisations. For the personal data described below, the customer organisation is the controller and Nordvakt acts as its processor under a Data Processing Agreement (DPA).

What we process

  • Account users: name, work email, role.
  • Recipients (the customer's employees): name, work email, team, preferred language, and simulation outcomes (sent / opened / clicked / reported).
  • Audit and billing records needed to run and account for the service.

Why, and on what basis

We process this data only to deliver security-awareness training the customer has commissioned. The lawful basis is the employer's legitimate interest in security training, or, for individual-mode customers, each recipient's consent.

The no-harvest rule

Simulations never capture what a recipient types. A click is recorded as metadata only and the recipient is shown a short training page. We do not store passwords or submitted form data, ever.

Where it lives, and sub-processors

Data is hosted in the EU. To send simulations we use a phishing-simulation engine (GoPhish) and an LLM provider that drafts the email copy; only the minimum recipient fields needed to send are shared with them, under sub-processor terms. A current list is available on request.

Retention

Personal data is retained for the period the customer configures (90 days by default) and then deleted. Customers can erase an organisation's data on request.

Your rights

You may request access, correction, or erasure of your personal data, and may lodge a complaint with your supervisory authority. Requests from a recipient are routed to their employer (the controller); contact privacy@nordvakt.eu and we will help.