SafeClick Logo
NL - Nederlands EN - English โœ“
โ† Back to SafeClick
๐Ÿ›ก๏ธ GDPR • Belgian 2018 Privacy Act • EU NIS 2

SafeClick Privacy Policy

Formulated in full compliance with EU Regulation 2016/679 (GDPR), the Belgian Data Protection Act of 30 July 2018, and the Belgian NIS 2 Transposition Act of 26 April 2024.

Last Revised: September 2026 โ€ข Jurisdiction: Belgium & European Union โ€ข Version: 2.4 (Enterprise)
๐Ÿ“‘ Table of Contents
  • 1. Controller & Legal Framework
  • 2. Personal Data Collected
  • 3. Legal Basis & Mandates
  • 4. Simulations & Ethical Guardrails
  • 5. Security & EEA Data Residency
  • 6. Retention & Anonymization
  • 7. Rights & Belgian DPA (GBA)
  • 8. Belgian Telecom Law & Cookies
  • 9. DPO & Corporate Identity

๐Ÿข 1. Data Controller, Data Processor & Governing Legislation

This Privacy Policy governs the processing of personal data across the SafeClick Security Awareness Platform (including gamified simulation missions, minigames, phishing simulators, and multi-tenant management consoles). SafeClick is owned and operated by [TO BE FILLED IN], a company incorporated under the laws of Belgium, having its registered office at [TO BE FILLED IN], registered with the Belgian Crossroads Bank for Enterprises (KBO / BCE) under number [TO BE FILLED IN] ([TO BE FILLED IN]).

Our data processing activities strictly adhere to Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and the Belgian Data Protection Act of 30 July 2018 (Act on the protection of natural persons with regard to the processing of personal data).

Allocation of Roles under GDPR Articles 4 and 28

  • For Enterprise Employees & Learners (Players): When your employing organization activates a SafeClick subscription, your employer acts as the Data Controller. SafeClick operates strictly as a Data Processor under Article 28 of the GDPR. A comprehensive Data Processing Agreement (DPA) forms an integral part of every enterprise subscription.
  • For Corporate Administrators & Website Visitors: For direct contractual administration, tenant provisioning, and billing on safeclick.be, [TO BE FILLED IN] acts as the Data Controller.

๐Ÿ“Š 2. Categories of Personal Data Collected

Under the principle of data minimization (Article 5(1)(c) GDPR), SafeClick only processes data strictly required for cyber awareness education and regulatory benchmarking:

  • Account Identifiers: First name, last name, business email address, department name, user role, and platform UID.
  • Learning Telemetry & Performance: Completed curriculum modules (Chapters 1 to 18), time-on-task, accumulated Experience Points (XP), accuracy percentages, continuous streaks, and earned compliance badges.
  • Threat Simulation Metrics & Risk Flags: Behavioral responses during interactive simulations (phishing links, fake credential portals, USB drop triage, QR code lures), aggregated into Risk Flags to identify organizational training requirements.
  • Authentication & Technical Logs: Login timestamps, salted Bcrypt password hashes, cryptographically secure session identifiers, and pseudonymized IP addresses utilized solely for brute-force protection and account defense.
No Sensitive Data: SafeClick strictly does not process special categories of personal data under Article 9 of the GDPR (including medical records, biometric data, religious beliefs, or political opinions).

โš–๏ธ 3. Legal Bases for Processing (GDPR & EU NIS 2)

Personal data is lawfully processed under the following Article 6 GDPR legal grounds:

  • Legitimate Interest (Art. 6(1)(f) GDPR): Protecting corporate information systems, sensitive intellectual property, and business operations against ransomware and cyber attacks by training the human firewall.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Supporting organizations in meeting statutory requirements under the Belgian NIS 2 Transposition Act of 26 April 2024 (transposing EU Directive 2022/2555), which mandates continuous cybersecurity hygiene and workforce training under the oversight of the Centre for Cybersecurity Belgium (CCB); the DORA Regulation (Regulation (EU) 2022/2554); and ISO/IEC 27001 awareness controls.
  • Performance of a Contract (Art. 6(1)(b) GDPR): Provisioning and maintaining SaaS subscription licenses and enterprise tenant consoles.

๐ŸŽฃ 4. Threat Simulations & Ethical Sandbox Guardrails

SafeClick delivers realistic phishing and social engineering exercises within a strictly contained ethical framework:

  • Zero Plain-Text Credential Storage: When a user inputs mock login credentials into a simulated landing page, the password is never recorded, transmitted, or logged. The engine immediately records a discrete vulnerability flag ("credentials entered") and instantly discards the plaintext payload from memory.
  • Constructive Educational Aim: Simulation telemetry is designed to foster behavioral awareness and must not be used as an arbitrary punitive mechanism without proper workplace dialogue.

๐Ÿ”’ 5. Security Architecture & EEA Data Residency

SafeClick maintains robust technical and organizational security controls pursuant to Article 32 GDPR and ISO/IEC 27001:

  • Guaranteed European Economic Area (EEA) Storage: All platform data, user databases, and system backups are hosted exclusively within certified Tier-III/IV data centers inside the European Union (Belgium, Germany, and the Netherlands). Cross-border transfers to non-adequate third countries are strictly prohibited unless governed by approved EU Standard Contractual Clauses (SCCs).
  • End-to-End Encryption: All data in transit is protected using TLS 1.3 encryption. Passwords and sensitive session tokens utilize hardened cryptographical hashes.
  • Logical Multi-Tenant Segregation: Strict database-level isolation guarantees that tenant data remains entirely separate, preventing cross-tenant leakage.

โณ 6. Data Retention Schedules & Secure Erasure

Data is stored strictly for the duration necessary to achieve training and compliance tracking objectives:

  • Active player records are maintained for the duration of the customer organization's active subscription.
  • When an administrator unenrolls an individual, their training metrics are either anonymized or permanently deleted.
  • Upon organizational subscription termination, customers receive a thirty (30) day grace period to export compliance certificates, after which all tenant databases are securely scrubbed.

๐Ÿ‘ค 7. Data Subject Rights & Belgian DPA (GBA / APD)

Under the GDPR and the Belgian Data Protection Act of 30 July 2018, data subjects hold the following enforceable rights:

  • Right of Access (Art. 15 GDPR): Request confirmation and inspect your stored learning achievements and risk metrics.
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate or outdated name and department records.
  • Right to Erasure (Art. 17 GDPR): Request account deletion, subject to legitimate employer audit obligations.
  • Right to Restriction (Art. 18 GDPR) & Objection (Art. 21 GDPR): Freeze processing or object on legitimate interest grounds.
  • Right to Data Portability (Art. 20 GDPR): Export training transcripts in standardized formats (PDF / CSV).

Because SafeClick acts as a Data Processor for employee accounts, requests should first be addressed to your organization's internal Data Protection Officer. SafeClick assists client organizations in satisfying these requests promptly.

Right to Lodge a Complaint with the Belgian Supervisory Authority:
If you believe the processing of your personal data infringes applicable privacy legislation, you have the statutory right to file a complaint directly with the Belgian Data Protection Authority:

Data Protection Authority (Gegevensbeschermingsautoriteit - GBA / APD)
Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels, Belgium
Phone: +32 (0)2 274 48 00 • Fax: +32 (0)2 274 48 35
Email: contact@apd-gba.be
Official Website: www.dataprotectionauthority.be

๐Ÿช 8. Cookies & Belgian Electronic Communications Act (Art. 129 WEC)

In accordance with Article 129 of the Belgian Electronic Communications Act of 13 June 2005 (WEC) (transposing the EU ePrivacy Directive), SafeClick notifies you regarding its strictly functional cookies:

  • SA_GAME_SESS: Essential session token verifying user authentication and CSRF defense.
  • cg_lang / lang: Functional identifier storing your chosen language (Dutch or English).
  • localStorage: Browser storage for workspace preferences (such as sidebar collapsed/expanded state).
Consent Exemption under Belgian Law: Because SafeClick exclusively relies on strictly necessary technical tokens necessary to deliver the service requested by the user (Article 129 ยง1, 2ยฐ WEC), intrusive cookie consent banners are legally not required. SafeClick operates zero commercial tracking, third-party analytics, or behavioral advertising cookies.

โœ‰๏ธ 9. Data Protection Officer & Corporate Identity

For data protection inquiries or to request our standard Art. 28 GDPR Data Processing Agreement (DPA), contact our Data Protection Office:

SafeClick Data Protection Office
safeclick.be
[TO BE FILLED IN] • Crossroads Bank for Enterprises (KBO/BCE): [TO BE FILLED IN]
[TO BE FILLED IN] • Belgium (European Union)
Security Engine SafeClick v2.4 โ€ข © 2026 SafeClick Security. All rights reserved.
Terms of Service Cookie Settings

๐Ÿช Cookie Settings

SafeClick gebruikt uitsluitend strikt noodzakelijke sessie- en beveiligingscookies.