Legal and Policy

Privacy Policy

Current public version of the Privacy Policy.

Legal counsel review required

This page contains professional placeholder legal content. It should be reviewed, revised, and approved by qualified legal counsel before production use. Product capabilities do not by themselves create legal compliance or contractual commitments.

Version

1.0

Effective date

August 13, 2026

Last updated

August 14, 2026

Legal review notice: This is professional placeholder legal content and should be reviewed, revised, and approved by qualified legal counsel before production use.

1. Overview

This Privacy Policy explains how the Cyverra Security Awareness Platform may process account information, employee training records, simulation activity, and related administrative data when organizations use the product to manage security-awareness and compliance-support workflows.

2. Account Data

The platform may process account identifiers such as names, business email addresses, login metadata, role assignments, organization membership, authentication settings, and profile preferences. Organizations are responsible for ensuring that user access is provisioned appropriately and removed when no longer required.

3. Employee Training Records

The platform may store training assignments, lesson progress, module completion history, quiz attempts, scores, issued certificates, badge history, and related operational records. These records are used to support awareness workflows, completion tracking, and reporting.

4. Simulation Events

The platform may record events related to internal phishing simulations, chat simulations, and voice-message scenarios. Examples include delivered messages, open events, reports, simulated link interactions, response actions, and feedback completion. These records are intended for controlled training and reporting rather than real-world surveillance outside the agreed product scope.

5. Voice Recordings

If an organization enables optional voice-response workflows, the platform may store protected references to audio files, transcripts, and evaluation metadata. Organizations should review retention expectations, employee notice requirements, and consent obligations before enabling voice recording features.

6. AI Processing

The platform may use configured AI providers to help generate draft training content, assessments, or simulation scenarios. Prompt and response handling should remain subject to the organization’s governance choices, provider agreements, and configuration decisions. Sensitive credentials are intended for protected storage, and AI activity may be logged for operational review.

7. Data Retention

Organizations may configure or define retention practices for certain categories of records, exports, simulations, and voice-related artifacts. Retention should be aligned with legal requirements, internal policy, and operational needs. The platform itself does not automatically determine all legally required retention periods.

8. Cookies and Similar Storage

The public website may use essential first-party storage for session continuity, security controls, and consent preferences. Optional analytics preferences should remain disabled unless explicitly enabled by the organization or visitor and backed by a configured analytics integration.

9. Security

The platform is designed around role-based access, organization scoping, protected storage patterns, request validation, and audit-oriented operational controls. No security measure guarantees absolute protection, and organizations remain responsible for secure deployment, configuration, and access governance.

10. Data Subject Rights

Depending on applicable law and the role of each party, individuals may have rights related to access, correction, deletion, objection, restriction, portability, or complaint submission. Requests should usually be directed first to the organization administering the training program unless the vendor’s role requires direct handling.

11. International Transfers and Vendors

Organizations should assess where hosting, subprocessors, support systems, and AI providers operate. Cross-border data-transfer requirements depend on actual deployment choices, contractual arrangements, and applicable law.

12. Contact Information

Replace this section with the appropriate privacy contact details, legal entity information, and escalation channels before production use. Example placeholder: privacy@example.com.

Next steps before production use

  • Confirm legal entity names, governing law, and contact details with counsel.
  • Review privacy, retention, AI provider, and employee-notice language against real deployment choices.
  • Validate cookies, analytics, voice-recording, and subprocessors language against actual configuration.