This policy describes how SecurityTask handles personal data when you visit our site, create an account, or use the security-awareness platform. For employee data uploaded by a customer organization, SecurityTask acts as a processor on behalf of the customer (the controller); see the Data Processing Agreement (DPA).
SecurityTask (“we”) is the controller for data collected through the website and for account data we manage directly. Contact: privacy@securitytask.com.
Account data: name, email address, language, organization and role.
Training usage data: modules completed, quiz scores, progress, streaks and certificates.
Phishing-simulation outcomes: whether a simulated message was opened, clicked or reported (for training and aggregate reporting).
Technical data: IP address, browser and device type, and security logs needed to run and protect the service.
Providing and delivering the service and your account (performance of a contract, Art. 6(1)(b) GDPR).
Security, fraud prevention and diagnostics (legitimate interest, Art. 6(1)(f)).
Legal and compliance obligations, including retention of training evidence (legal obligation / legitimate interest).
Essential service communications; any marketing communications only with your consent (Art. 6(1)(a)).
When a customer organization enrolls its staff, the customer is the controller and SecurityTask processes that data as a processor, only on its documented instructions and under the DPA. Data-subject requests about that data should be directed to the employer.
We do not sell personal data. We share it only with the vendors (sub-processors) needed to deliver the service, listed on the Trust & Security page and bound by data-protection obligations, and where required by law.
Data is hosted in the European Union (Frankfurt). Where a sub-processor processes data outside the EU/EEA or Switzerland, appropriate safeguards (e.g. Standard Contractual Clauses) apply.
We retain data for the life of the account and for as long as needed for the purposes above or legal obligations. Training evidence is exportable at any time; on termination, data is deleted or returned per the DPA.
We use appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation, append-only logs, role-based access control and backups. Details on the Trust & Security page.
Under the GDPR and the Swiss FADP you have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent at any time.
You also have the right to lodge a complaint with a supervisory authority (in Switzerland, the FDPIC; in the EU, your local authority).
We use strictly necessary cookies and, only with your consent, optional cookies. See the Cookie Policy.
The service is intended for professional use and is not directed to children; we do not knowingly collect children’s data.
We may update this policy; we will post the updated version on this page with its date.
To exercise your rights or for any privacy question, contact privacy@securitytask.com.