Privacy Policy for SimuPhish.

This Privacy Policy explains how SimuPhish LTD collects, uses, shares, and protects personal data in connection with simuphish.com and its subdomains.

Last updated in September 2026

This Website Privacy Policy ("Policy") explains how SimuPhish LTD, a company incorporated in England and Wales with company number 16167880, whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ("SimuPhish," "we," "us," or "our"), collects, uses, shares, and protects personal data in connection with simuphish.com and its subdomains (the "Site"). This Policy is incorporated by reference into, and should be read together with, our Website Terms of Use and our Cookie Notice.

This Policy applies only to the public-facing Site and our sales/marketing interactions with visitors and prospects. It does not govern personal data that SimuPhish processes on behalf of customer organizations through the SimuPhish human-risk-management, phishing-simulation, and security-awareness-training platform (the "Services"), for example simulated-phishing results or training records of an organization's employees. That processing is governed by our Product Privacy Notice and the data processing agreement in place with the relevant customer, who acts as the data controller for that data.

SimuPhish has prepared this Policy to reflect the current regulatory landscape applicable to its operations and international customer base, in accordance with the Applicable Data Protection Laws.

1. Who We Are

SimuPhish LTD is the controller of the personal data described in this Policy, for the purposes of, among others, the UK General Data Protection Regulation and the Data Protection Act 2018 (the "UK GDPR"), the EU General Data Protection Regulation (the "GDPR"), and other applicable data protection laws. Where required under Applicable Data Protection Laws, SimuPhish shall appoint a Data Protection Officer and/or an EU or UK representative, as applicable, who may be approached in the manner set out in Section 18.

2. Scope of This Policy

This Policy covers personal data collected through:

  • The Site, including pages you browse, forms you submit, and content you download;
  • Marketing interactions, such as newsletter sign-ups, webinar registrations, gated content requests, and event badge scans;
  • Sales interactions, such as demo requests, contact-us submissions, and calls or emails with our sales team;
  • Account registration for any resource portal, community, or gated content area of the Site;
  • Job applications submitted through our careers pages; and
  • Cookies and similar tracking technologies used on the Site. See /cookies for full detail.

3. Personal Data We Collect

"Personal data" means information relating to an identified or identifiable natural person. We collect the following categories:

We do not intentionally collect sensitive personal data (e.g., health, biometric, religious, or political data) through the Site. Please do not submit such data through our forms or as User Content.

CategoryExamplesSource
Identity & contact dataName, job title, employer, business email, phone number, countryDirectly from you (forms, emails, calls)
Account/inquiry dataDemo requests, support tickets, message content, preferences, User Content you submitDirectly from you
Event & engagement dataWebinar registrations, event attendance, badge-scan data, content downloadsDirectly from you; event partners
Technical & usage dataIP address, device/browser type, operating system, pages viewed, referring URL, timestampsAutomatically, via cookies/similar technologies
Marketing dataEmail engagement (opens/clicks), campaign source, advertising identifiersAutomatically; marketing/ad platforms
Third-party enrichment dataFirmographic and contact data licensed from data providersThird-party data providers

4. How We Use Personal Data and Our Legal Bases

We do not use automated decision-making that produces legal or similarly significant effects about Site visitors. Where we make AI-enabled features available on the Site (for example, a chat assistant), such features are provided for general information only, consistent with Section 10.2 of our Terms of Use, and any personal data you submit to them is handled in accordance with this Policy.

PurposeExamplesLegal basis (UK GDPR / GDPR)
Responding to inquiriesAnswering questions, scheduling demos, providing quotesConsent / Steps prior to a contract
Marketing communicationsNewsletters, product updates, event invitationsConsent (opt-in); legitimate interest for existing business contacts, subject to opt-out
Site operation & securityFraud prevention, access control, bot/scraping detection, debuggingLegitimate interest / compliance with legal obligation
Analytics & personalizationUnderstanding usage trends, improving content and UXConsent (non-essential cookies); legitimate interest for aggregated analytics
Advertising & retargetingServing relevant ads on third-party platformsConsent (opt-in, required for non-essential cookies)
Legal & complianceResponding to lawful requests, enforcing our Terms of UseLegal obligation / legitimate interest
RecruitmentEvaluating job applicationsSteps prior to a contract; consent where required

5. Cookies and Similar Technologies

We use cookies, pixels, SDKs, and similar technologies to operate the Site, understand usage, and, where you consent, personalize marketing. Full detail on the categories of cookies we use, their purposes, retention periods, and how to manage your preferences is set out in our Cookie Notice, which forms part of this Policy by reference and is available at /cookies. Where required by the Applicable Data Protection Law, we obtain your opt-in consent before placing non-essential cookies, via the cookie banner presented on your first visit.

6. Do We Sell or Share Personal Data?

SimuPhish does not sell personal data in exchange for money. However, our use of certain advertising and analytics cookies may make data available to third-party ad-tech partners for cross-context behavioural advertising. You can opt out at any time; see Section 13.

7. Automated Access, Web Scraping, and AI/Machine Learning

This Section mirrors and complements Section 9 (Automated Access, Web Scraping, Bots, and Rate Limiting) and Section 10 (Artificial Intelligence, Text and Data Mining, and Machine Learning) of our Terms of Use, and sets out how those restrictions apply specifically to personal data.

No unauthorized automated collection of personal data. You may not use any robot, spider, scraper, crawler, or other automated means to collect, harvest, or extract personal data of other visitors or users from the Site. Doing so, in addition to breaching our Terms of Use, may itself constitute unlawful processing of personal data under the UK GDPR, the GDPR, and comparable laws.

No AI/ML training on personal data without a lawful basis. SimuPhish does not use personal data collected through the Site to train, fine-tune, or validate artificial intelligence or machine-learning models for purposes unrelated to operating and improving the Site and Services, and does not permit third parties to text-and-data-mine the Site's Content (which may include personal data) for AI/ML training purposes, consistent with the rights reservation in Section 10.1 of our Terms of Use.

Security and bot-detection measures. We deploy technical measures including rate-limiting, bot detection, IP-based access controls, and access logging to detect and prevent unauthorized scraping and automated access. These measures may themselves involve processing of technical/usage data (such as IP address and request patterns) on the basis of our legitimate interest in protecting the Site and the personal data of our visitors.

Security research. Where a security researcher engages in good-faith vulnerability testing under our Terms of Use, any personal data incidentally encountered must be handled in accordance with that Section and applicable law, and must not be retained, disclosed, or used beyond what is necessary for responsible disclosure.

8. How We Share Personal Data

We share personal data with:

A current list of our sub-processors is available upon request to [email protected].

  • Service providers / processors who support our Site, marketing, sales, and event operations (e.g., cloud hosting, email delivery, marketing automation, analytics, advertising, scheduling, and CRM providers), bound by data processing terms;
  • Event co-sponsors and partners, where you register for a co-hosted webinar or event and have been notified accordingly;
  • Channel and referral partners, where you have been referred to us or ask to be connected with a partner;
  • Professional advisors and authorities, including data protection supervisory authorities and other applicable regulators, where necessary to comply with law, enforce our Terms of Use, or protect our rights and the safety of others; and
  • A successor entity, in connection with a merger, acquisition, financing, or sale of assets.

9. International Data Transfers

SimuPhish is established in the United Kingdom and uses service providers located in various countries. Where we transfer personal data out of the UK, the EEA, or Switzerland, we rely on recognized transfer mechanisms such as the UK International Data Transfer Agreement or Addendum and the European Commission's Standard Contractual Clauses, together with a transfer risk assessment where one is required. Where personal data is transferred out of any other country, we do so in accordance with the transfer rules of that country, using appropriate contractual safeguards or, where required, your explicit consent.

10. Data Retention

We retain personal data only for as long as reasonably necessary to fulfil the purposes described in this Policy, including to satisfy legal, accounting, or reporting obligations, resolve disputes, and enforce our Terms of Use. Marketing contact data is generally retained until you unsubscribe or, if there has been no engagement, for 24 months, after which it is deleted or anonymized. Specific retention periods for each cookie are listed in our Cookie Notice.

11. Your Privacy Rights

Depending on where you are located, you may have some or all of the following rights regarding your personal data.

11.1 United Kingdom, EEA, and Switzerland (UK GDPR and GDPR)

  • Right to be informed about the purposes of processing and the parties with whom your personal data is shared;
  • Right to access, rectify, or erase your personal data;
  • Right to restrict or object to processing (including direct marketing);
  • Right to data portability;
  • Right to withdraw consent at any time, without affecting prior processing;
  • Right to lodge a complaint with your local supervisory authority, including the UK Information Commissioner's Office; and
  • Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you.

11.2 Other Jurisdictions

If you are located elsewhere, you may still have rights under applicable local law. We will honour valid requests consistent with applicable law regardless of where you are located, where reasonably practicable.

12. How to Exercise Your Rights

To exercise any of the rights above, contact us at [email protected]. We may need to verify your identity before completing your request. We aim to respond within 30 days, or such other period as required by applicable law (e.g., the UK GDPR, the GDPR, or relevant U.S. state law). You may also designate an authorized agent to submit a request on your behalf, subject to verification.

13. Managing Your Marketing and Advertising Preferences

Our policy regarding the sale or sharing of Personal Data is set out in Section 6 above. Notwithstanding the foregoing, you may opt out of marketing emails at any time using the unsubscribe link in any email, or by contacting [email protected]. You may also opt out of the sale/sharing of personal data for advertising purposes, and manage cookie-based advertising preferences, through our Cookie Notice and Cookie Preference Center, or by enabling Global Privacy Control in a supporting browser.

14. Who May Use the Site and Children's Privacy

Consistent with Section 3 of our Terms of Use, the Site is intended for business and professional users who are at least 18 years of age (or the age of majority in their jurisdiction, if higher). The Site is not directed at children, and we do not knowingly collect personal data from children through the Site. If we learn that we have inadvertently collected personal data from a child, we will delete it promptly. Parents or guardians who believe we may have collected such data should contact us at [email protected].

15. Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including encryption in transit, access controls, and regular security assessments, consistent with the standard of care described in Section 18 of our Terms of Use. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us. If you discover a security vulnerability affecting the Site, please report it to [email protected] in accordance with Section 11 of our Terms of Use.

16. Governing Law

This Policy is governed by and construed in accordance with the laws of England and Wales, consistent with Section 23 of our Terms of Use, without prejudice to any mandatory data protection rights you may have under the law of your country of residence (including under the GDPR or other applicable law, where relevant).

17. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. The "Last Updated" date at the top of this Policy indicates when it was last revised. Material changes will be highlighted via a notice on the Site or, where required, by direct notice, consistent with Section 4 of our Terms of Use.

18. Contact Us

If you have questions about this Policy or our data practices, please contact: SimuPhish LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom (Company No. 16167880), Attn: Privacy Team.

Privacy inquiries: [email protected]

Security / vulnerability reports: [email protected]

Legal notices: [email protected]