Legal review notice: This is professional placeholder legal content and should be reviewed, revised, and approved by qualified legal counsel before production use.
1. Overview
This Privacy Policy explains how the Cyverra Security Awareness Platform may process account information, employee training records, simulation activity, and related administrative data when organizations use the product to manage security-awareness and compliance-support workflows.
2. Account Data
The platform may process account identifiers such as names, business email addresses, login metadata, role assignments, organization membership, authentication settings, and profile preferences. Organizations are responsible for ensuring that user access is provisioned appropriately and removed when no longer required.
3. Employee Training Records
The platform may store training assignments, lesson progress, module completion history, quiz attempts, scores, issued certificates, badge history, and related operational records. These records are used to support awareness workflows, completion tracking, and reporting.
4. Simulation Events
The platform may record events related to internal phishing simulations, chat simulations, and voice-message scenarios. Examples include delivered messages, open events, reports, simulated link interactions, response actions, and feedback completion. These records are intended for controlled training and reporting rather than real-world surveillance outside the agreed product scope.
5. Voice Recordings
If an organization enables optional voice-response workflows, the platform may store protected references to audio files, transcripts, and evaluation metadata. Organizations should review retention expectations, employee notice requirements, and consent obligations before enabling voice recording features.
6. AI Processing
The platform may use configured AI providers to help generate draft training content, assessments, or simulation scenarios. Prompt and response handling should remain subject to the organization’s governance choices, provider agreements, and configuration decisions. Sensitive credentials are intended for protected storage, and AI activity may be logged for operational review.
7. Data Retention
Organizations may configure or define retention practices for certain categories of records, exports, simulations, and voice-related artifacts. Retention should be aligned with legal requirements, internal policy, and operational needs. The platform itself does not automatically determine all legally required retention periods.
8. Cookies and Similar Storage
The public website may use essential first-party storage for session continuity, security controls, and consent preferences. Optional analytics preferences should remain disabled unless explicitly enabled by the organization or visitor and backed by a configured analytics integration.
9. Security
The platform is designed around role-based access, organization scoping, protected storage patterns, request validation, and audit-oriented operational controls. No security measure guarantees absolute protection, and organizations remain responsible for secure deployment, configuration, and access governance.
10. Data Subject Rights
Depending on applicable law and the role of each party, individuals may have rights related to access, correction, deletion, objection, restriction, portability, or complaint submission. Requests should usually be directed first to the organization administering the training program unless the vendor’s role requires direct handling.
11. International Transfers and Vendors
Organizations should assess where hosting, subprocessors, support systems, and AI providers operate. Cross-border data-transfer requirements depend on actual deployment choices, contractual arrangements, and applicable law.
12. Contact Information
Replace this section with the appropriate privacy contact details, legal entity information, and escalation channels before production use. Example placeholder: privacy@example.com.