Privacy Policy
Who we are
Nordvakt provides phishing-simulation training for EU organisations. For the personal data described below, the customer organisation is the controller and Nordvakt acts as its processor under a Data Processing Agreement (DPA).
What we process
- Account users: name, work email, role.
- Recipients (the customer's employees): name, work email, team, preferred language, and simulation outcomes (sent / opened / clicked / reported).
- Audit and billing records needed to run and account for the service.
Why, and on what basis
We process this data only to deliver security-awareness training the customer has commissioned. The lawful basis is the employer's legitimate interest in security training, or, for individual-mode customers, each recipient's consent.
The no-harvest rule
Simulations never capture what a recipient types. A click is recorded as metadata only and the recipient is shown a short training page. We do not store passwords or submitted form data, ever.
Where it lives, and sub-processors
Data is hosted in the EU. To send simulations we use a phishing-simulation engine (GoPhish) and an LLM provider that drafts the email copy; only the minimum recipient fields needed to send are shared with them, under sub-processor terms. A current list is available on request.
Retention
Personal data is retained for the period the customer configures (90 days by default) and then deleted. Customers can erase an organisation's data on request.
Your rights
You may request access, correction, or erasure of your personal data, and may lodge a complaint with your supervisory authority. Requests from a recipient are routed to their employer (the controller); contact privacy@nordvakt.eu and we will help.