1. Who is responsible for your data
If your employer enrolled you, your employer (our client) decides why and how your training data is used and is the controller of that data. ParoCyber processes it on your employer's behalf as a processor, under our Data Processing Agreement. Questions about how your employer uses your results should go to your employer first; we will help them respond.
For everything else — website visitors, organisations enquiring about AwareClick, billing contacts, and people who create an account themselves — ParoCyber is the controller.
2. What we collect
Account information
- Name and email address.
- Your password, which is stored only as a secure hash by our authentication provider — we never see it.
- If you choose "Continue with Google", the name and email address Google shares with us.
Organisation information
- Which organisation you belong to, your role in it (for example employee or training coordinator), and any department or group your organisation assigns you to.
Training activity
- Training assigned to you, your progress, and when you started and completed each module.
- Quiz answers, scores and number of attempts, and time spent on modules.
- Certificates issued to you, and points and badges earned.
Security behaviour assessments
- Your answers to scenario-based assessment questions and the resulting behavioural risk indicators.
Phishing simulations
Your organisation may send you simulated phishing emails as part of your training. We record whether and when a simulated email was opened and whether its link was clicked, and may assign follow-up training. Simulation pages are educational only: we never collect passwords or anything else you type on them.
Support and enquiries
- Messages your organisation sends to our support team, and details submitted through our enquiry form (organisation name, contact name, email, message).
Billing information (organisations)
- Plan, number of seats, payment amounts, dates and payment references. Card details are handled entirely by our payment provider and are never stored by AwareClick.
Technical and security information
- IP address and basic request information, used to protect sign-in and prevent abuse (for example rate limiting and bot checks).
- A record of actions taken by platform staff and organisation administrators (an audit log).
3. How we use it
- To provide the training: delivering modules, scoring quizzes, issuing certificates and tracking completion.
- To give your organisation the reports it needs to run its awareness programme (see section 4).
- To send service emails: invitations, training assignments, reminders and certificates.
- To keep the platform and your account secure: authentication, rate limiting, bot protection, idle sign-out and audit logging.
- To bill organisations for their subscription.
- To provide support and respond to enquiries.
- To improve AwareClick using aggregated, de-identified statistics. Industry benchmarks only ever show figures combined across several organisations, and never identify an individual or a single organisation.
We do not sell personal data, use it for advertising, or use your training data to train AI models.
4. What your organisation can see
Your organisation's training coordinators can see your training assignments, progress, quiz scores, certificates, behavioural risk indicators and phishing simulation results, individually and in department-level reports. They use this to manage the programme and target further training. AwareClick staff access client data only where needed to operate, support and secure the service.
5. Why we are allowed to use it
- To perform our contract with your organisation (or with you, if you signed up yourself).
- Legitimate interests in keeping the service secure, preventing fraud and improving it — balanced against your rights.
- Legal obligations, for example keeping billing records.
- Consent, where the law requires it. Where your employer enrolls you, your employer is responsible for having a lawful basis and for telling you about the training and any phishing simulations.
6. Who we share it with
We use the following service providers (sub-processors) to run AwareClick. Each may only use the data to provide its service to us.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication and account storage | All account, organisation, training, assessment and billing records | EU (Ireland) |
| Cloudflare | Hosting, content delivery, training video streaming (Stream) and bot protection (Turnstile) | Network and request data (e.g. IP address); training videos; security-check signals | Global network |
| Resend | Sending service emails (invitations, assignments, reminders, certificates) | Name, email address, email content | United States |
| Upstash | Rate limiting to protect sign-in and other endpoints | IP addresses and one-way hashed identifiers, kept for minutes to hours | Global (region per configuration) |
| Paystack | Subscription payments | Billing contact details and payment information (card details are handled by Paystack, never stored by AwareClick) | Nigeria and other Paystack regions |
| Anthropic | AI-assisted drafting of phishing simulation templates | Organisation name, industry and template settings only — no employee personal data | United States |
| Optional "Continue with Google" sign-in | Name and email address shared by Google at sign-in, when a user chooses it | Global |
We may also disclose data where required by law, or to protect the rights, property or safety of our users, clients or the public.
7. Where your data is stored
Our primary database is hosted in the European Union (Ireland). Some providers listed above process data in other countries. Where data is transferred internationally, we rely on our providers' contractual commitments and safeguards to protect it.
8. How long we keep it
- Training and account data: for as long as your organisation's subscription is active. After it ends, we delete or anonymise it within 90 days, unless your organisation asks for an export first or the law requires us to keep it longer.
- Billing records: as long as accounting and tax rules require.
- Audit and security logs: kept to investigate and prevent misuse, then deleted.
- Rate-limiting data: minutes to hours.
9. How we protect it
- Encryption in transit (HTTPS) and encrypted storage at our hosting providers.
- Strict role-based access: employees, coordinators and platform staff each see only what their role requires, enforced on every request.
- Strong password rules, rate-limited sign-in, bot protection and automatic sign-out after 15 minutes of inactivity.
- An audit trail of administrative actions.
No system is perfectly secure. If a personal data breach affects you, we will inform your organisation (and you, where required) promptly.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, and to object to or restrict certain uses. If your employer enrolled you, please contact your employer first — they control your training data and we will help them respond. Otherwise, email us at [email protected]. You may also complain to your local data protection authority.
11. Cookies and browser storage
We use only what is strictly necessary to run the service:
- A session cookie that keeps you signed in (it expires after 15 minutes without activity).
- A last-activity timestamp in your browser's local storage, used for automatic sign-out across tabs.
- Cloudflare Turnstile on sign-in pages to tell people from bots.
We do not use advertising or third-party analytics cookies.
12. Children
AwareClick is designed for workplaces and is not intended for children.
13. Changes to this policy
We may update this policy as AwareClick evolves. We will post the new version here with a new effective date and, for significant changes, notify organisations in advance.
14. Contact
For privacy questions or requests, email [email protected].