• Phishing IQ
  • Pricing
  • FAQ
securitytask
Sign In
Sign Up
securitytask

Swiss-made gamified security awareness training for SMBs. Turn compliance into a habit your team actually keeps — with NIS2, ISO 27001 & nFADP training evidence.

© Copyright 2026 SecurityTask. All Rights Reserved.

Product
  • Pricing
  • Phishing IQ test
  • FAQ
Get Started
  • Sign In
  • Sign Up
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Trust & Security
  • DPA

Privacy Policy

How we handle personal data (GDPR & Swiss FADP)

Draft — to be reviewed by your legal counsel. This template is provided for information and should be adapted and reviewed before final publication.

This policy describes how SecurityTask handles personal data when you visit our site, create an account, or use the security-awareness platform. For employee data uploaded by a customer organization, SecurityTask acts as a processor on behalf of the customer (the controller); see the Data Processing Agreement (DPA).

1. Data controller

SecurityTask (“we”) is the controller for data collected through the website and for account data we manage directly. Contact: privacy@securitytask.com.

2. What we collect

Account data: name, email address, language, organization and role.

Training usage data: modules completed, quiz scores, progress, streaks and certificates.

Phishing-simulation outcomes: whether a simulated message was opened, clicked or reported (for training and aggregate reporting).

Technical data: IP address, browser and device type, and security logs needed to run and protect the service.

3. Purposes & legal bases

Providing and delivering the service and your account (performance of a contract, Art. 6(1)(b) GDPR).

Security, fraud prevention and diagnostics (legitimate interest, Art. 6(1)(f)).

Legal and compliance obligations, including retention of training evidence (legal obligation / legitimate interest).

Essential service communications; any marketing communications only with your consent (Art. 6(1)(a)).

4. Our role for customer employee data

When a customer organization enrolls its staff, the customer is the controller and SecurityTask processes that data as a processor, only on its documented instructions and under the DPA. Data-subject requests about that data should be directed to the employer.

5. Sharing & sub-processors

We do not sell personal data. We share it only with the vendors (sub-processors) needed to deliver the service, listed on the Trust & Security page and bound by data-protection obligations, and where required by law.

6. International transfers

Data is hosted in the European Union (Frankfurt). Where a sub-processor processes data outside the EU/EEA or Switzerland, appropriate safeguards (e.g. Standard Contractual Clauses) apply.

7. Retention

We retain data for the life of the account and for as long as needed for the purposes above or legal obligations. Training evidence is exportable at any time; on termination, data is deleted or returned per the DPA.

8. Security

We use appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation, append-only logs, role-based access control and backups. Details on the Trust & Security page.

9. Your rights

Under the GDPR and the Swiss FADP you have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent at any time.

You also have the right to lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local authority).

10. Cookies

We use strictly necessary cookies and, only with your consent, optional cookies. See the Cookie Policy.

11. Children

The service is intended for professional use and is not directed to children; we do not knowingly collect children’s data.

12. Changes

We may update this policy; we will post the updated version on this page with its date.

To exercise your rights or for any privacy question, contact privacy@securitytask.com.