1. Roles
The Client is the controller of personal data about its personnel processed in AwareClick. ParoCyber is the processor and processes that data only to provide AwareClick to the Client.
2. Details of the processing
| Subject matter | Provision of the AwareClick security awareness training platform. |
| Duration | The Client's subscription, plus up to 90 days afterwards for deletion or return of data. |
| Nature and purpose | Hosting, storing and organising data to deliver training, quizzes, assessments, phishing simulations, certificates, reporting, notifications and support. |
| Data subjects | The Client's employees, contractors and other personnel enrolled in AwareClick, including its training coordinators. |
| Personal data | Name; work email; organisation, role, department and groups; training assignments, progress and completion times; quiz answers and scores; certificates; behavioural risk assessment responses and indicators; phishing simulation interactions (email opened, link clicked, timestamps); support messages; technical security data (e.g. IP address). |
| Special categories | None are required. The Client should not upload special category data to AwareClick. |
3. Processor obligations
ParoCyber will:
- process Client personal data only on the Client's documented instructions — which include the Client's use of AwareClick's features and settings — unless the law requires otherwise, in which case it will inform the Client unless legally prohibited;
- ensure everyone authorised to process the data is bound by confidentiality;
- implement the security measures in section 4;
- help the Client respond to requests from data subjects exercising their rights, taking into account the nature of the processing;
- help the Client meet its security, breach-notification and impact-assessment obligations, where relevant to AwareClick;
- make available the information reasonably needed to demonstrate compliance with this DPA (see section 8).
4. Security measures
- Encryption of data in transit (HTTPS/TLS) and encrypted storage at our hosting providers.
- Access control: role-based access enforced on every request and at the database level; organisations can only access their own data; platform staff roles are restricted and changes to them are logged.
- Authentication: strong password policy, rate-limited sign-in, bot protection, automatic sign-out after 15 minutes of inactivity.
- Application security: input validation on all endpoints, protection against cross-site request forgery and clickjacking, security headers.
- Accountability: audit logging of administrative and billing actions.
- Data minimisation: phishing simulations record only opens and clicks — never credentials or anything typed; rate-limiting uses hashed identifiers.
- Hosting: primary database hosted in the European Union (Ireland) with a reputable cloud provider.
5. Sub-processors
The Client authorises ParoCyber to use the sub-processors below. ParoCyber will impose data-protection obligations on each that are no less protective than this DPA, and remains responsible for their performance. ParoCyber will give at least 30 days' notice before adding or replacing a sub-processor, during which the Client may object on reasonable data-protection grounds.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication and account storage | All account, organisation, training, assessment and billing records | EU (Ireland) |
| Cloudflare | Hosting, content delivery, training video streaming (Stream) and bot protection (Turnstile) | Network and request data (e.g. IP address); training videos; security-check signals | Global network |
| Resend | Sending service emails (invitations, assignments, reminders, certificates) | Name, email address, email content | United States |
| Upstash | Rate limiting to protect sign-in and other endpoints | IP addresses and one-way hashed identifiers, kept for minutes to hours | Global (region per configuration) |
| Paystack | Subscription payments | Billing contact details and payment information (card details are handled by Paystack, never stored by AwareClick) | Nigeria and other Paystack regions |
| Anthropic | AI-assisted drafting of phishing simulation templates | Organisation name, industry and template settings only — no employee personal data | United States |
| Optional "Continue with Google" sign-in | Name and email address shared by Google at sign-in, when a user chooses it | Global |
6. International transfers
Where Client personal data is transferred outside the country where it was collected, ParoCyber will ensure appropriate safeguards are in place as required by applicable data protection law, including contractual commitments from its sub-processors.
7. Personal data breaches
ParoCyber will notify the Client without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client personal data. The notice will describe, as far as then known, the nature of the breach, the data and data subjects affected, likely consequences, and the measures taken or proposed.
8. Audits
On reasonable written request, and no more than once a year unless required by a regulator or following a breach, ParoCyber will provide information reasonably necessary to demonstrate compliance with this DPA, such as answers to security questionnaires and descriptions of its controls.
9. Return and deletion
At the end of the subscription, the Client may request an export of its data. ParoCyber will then delete or anonymise Client personal data within 90 days, except where the law requires it to be kept (for example billing records).
10. Precedence
If this DPA conflicts with the Terms of Use on the processing of personal data, this DPA prevails. See also our Privacy Policy.