Data Processing Agreement for SimuPhish.

This Data Processing Agreement explains how SimuPhish LTD collects, uses, shares, and protects personal data in connection with simuphish.com and its subdomains.

A Data Processing Agreement is where security commitments become clear responsibilities. The DPA explains how SimuPhish processes personal data on behalf of customer organisations, the safeguards we apply, and the rights and obligations that govern that processing.

What's included

Roles (customer as controller, SimuPhish as processor), processing details, sub-processor list, technical and organisational measures, breach notification, audit rights, deletion and return of data, and international transfer clauses including SCCs and the UK IDTA where required.

Sub-processors

We update the list 30 days before any change. Any sub-processor objection is honoured under the DPA terms.

Audit rights

Annual SOC 2 Type 2 and ISO 27001 reports satisfy customer audit rights. On-site or third-party audits are available under reasonable terms with mutual NDA.

Website data and cookies

The DPA governs product processing for customer organisations. Personal data collected through the public Site is described in the Privacy Policy, and the cookie inventory and Cookie Preferences mechanism are described in the Cookie Notice.

Request a copy

Email [email protected] with your legal entity name and jurisdiction. We send a sign-ready PDF within one business day.

Questions? Email [email protected]. The SimuPhish trust team replies within one business day.

Need the DPA for review?

Email [email protected] with your entity name and jurisdiction. We reply with the document inside one business day.

SimuPhish trident, the AI Driven Human Risk Management+ Platform