๐ข 1. Data Controller, Data Processor & Governing Legislation
This Privacy Policy governs the processing of personal data across the SafeClick Security Awareness Platform (including gamified simulation missions, minigames, phishing simulators, and multi-tenant management consoles). SafeClick is owned and operated by [TO BE FILLED IN], a company incorporated under the laws of Belgium, having its registered office at [TO BE FILLED IN], registered with the Belgian Crossroads Bank for Enterprises (KBO / BCE) under number [TO BE FILLED IN] ([TO BE FILLED IN]).
Our data processing activities strictly adhere to Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR) and the Belgian Data Protection Act of 30 July 2018 (Act on the protection of natural persons with regard to the processing of personal data).
Allocation of Roles under GDPR Articles 4 and 28
- For Enterprise Employees & Learners (Players): When your employing organization activates a SafeClick subscription, your employer acts as the Data Controller. SafeClick operates strictly as a Data Processor under Article 28 of the GDPR. A comprehensive Data Processing Agreement (DPA) forms an integral part of every enterprise subscription.
- For Corporate Administrators & Website Visitors: For direct contractual administration, tenant provisioning, and billing on safeclick.be, [TO BE FILLED IN] acts as the Data Controller.
๐ 2. Categories of Personal Data Collected
Under the principle of data minimization (Article 5(1)(c) GDPR), SafeClick only processes data strictly required for cyber awareness education and regulatory benchmarking:
- Account Identifiers: First name, last name, business email address, department name, user role, and platform UID.
- Learning Telemetry & Performance: Completed curriculum modules (Chapters 1 to 18), time-on-task, accumulated Experience Points (XP), accuracy percentages, continuous streaks, and earned compliance badges.
- Threat Simulation Metrics & Risk Flags: Behavioral responses during interactive simulations (phishing links, fake credential portals, USB drop triage, QR code lures), aggregated into Risk Flags to identify organizational training requirements.
- Authentication & Technical Logs: Login timestamps, salted Bcrypt password hashes, cryptographically secure session identifiers, and pseudonymized IP addresses utilized solely for brute-force protection and account defense.
โ๏ธ 3. Legal Bases for Processing (GDPR & EU NIS 2)
Personal data is lawfully processed under the following Article 6 GDPR legal grounds:
- Legitimate Interest (Art. 6(1)(f) GDPR): Protecting corporate information systems, sensitive intellectual property, and business operations against ransomware and cyber attacks by training the human firewall.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Supporting organizations in meeting statutory requirements under the Belgian NIS 2 Transposition Act of 26 April 2024 (transposing EU Directive 2022/2555), which mandates continuous cybersecurity hygiene and workforce training under the oversight of the Centre for Cybersecurity Belgium (CCB); the DORA Regulation (Regulation (EU) 2022/2554); and ISO/IEC 27001 awareness controls.
- Performance of a Contract (Art. 6(1)(b) GDPR): Provisioning and maintaining SaaS subscription licenses and enterprise tenant consoles.
๐ฃ 4. Threat Simulations & Ethical Sandbox Guardrails
SafeClick delivers realistic phishing and social engineering exercises within a strictly contained ethical framework:
- Zero Plain-Text Credential Storage: When a user inputs mock login credentials into a simulated landing page, the password is never recorded, transmitted, or logged. The engine immediately records a discrete vulnerability flag ("credentials entered") and instantly discards the plaintext payload from memory.
- Constructive Educational Aim: Simulation telemetry is designed to foster behavioral awareness and must not be used as an arbitrary punitive mechanism without proper workplace dialogue.
๐ 5. Security Architecture & EEA Data Residency
SafeClick maintains robust technical and organizational security controls pursuant to Article 32 GDPR and ISO/IEC 27001:
- Guaranteed European Economic Area (EEA) Storage: All platform data, user databases, and system backups are hosted exclusively within certified Tier-III/IV data centers inside the European Union (Belgium, Germany, and the Netherlands). Cross-border transfers to non-adequate third countries are strictly prohibited unless governed by approved EU Standard Contractual Clauses (SCCs).
- End-to-End Encryption: All data in transit is protected using TLS 1.3 encryption. Passwords and sensitive session tokens utilize hardened cryptographical hashes.
- Logical Multi-Tenant Segregation: Strict database-level isolation guarantees that tenant data remains entirely separate, preventing cross-tenant leakage.
โณ 6. Data Retention Schedules & Secure Erasure
Data is stored strictly for the duration necessary to achieve training and compliance tracking objectives:
- Active player records are maintained for the duration of the customer organization's active subscription.
- When an administrator unenrolls an individual, their training metrics are either anonymized or permanently deleted.
- Upon organizational subscription termination, customers receive a thirty (30) day grace period to export compliance certificates, after which all tenant databases are securely scrubbed.
๐ค 7. Data Subject Rights & Belgian DPA (GBA / APD)
Under the GDPR and the Belgian Data Protection Act of 30 July 2018, data subjects hold the following enforceable rights:
- Right of Access (Art. 15 GDPR): Request confirmation and inspect your stored learning achievements and risk metrics.
- Right to Rectification (Art. 16 GDPR): Correct inaccurate or outdated name and department records.
- Right to Erasure (Art. 17 GDPR): Request account deletion, subject to legitimate employer audit obligations.
- Right to Restriction (Art. 18 GDPR) & Objection (Art. 21 GDPR): Freeze processing or object on legitimate interest grounds.
- Right to Data Portability (Art. 20 GDPR): Export training transcripts in standardized formats (PDF / CSV).
Because SafeClick acts as a Data Processor for employee accounts, requests should first be addressed to your organization's internal Data Protection Officer. SafeClick assists client organizations in satisfying these requests promptly.
โ๏ธ 9. Data Protection Officer & Corporate Identity
For data protection inquiries or to request our standard Art. 28 GDPR Data Processing Agreement (DPA), contact our Data Protection Office:
[TO BE FILLED IN] • Belgium (European Union)