Skip to content

Legal

Privacy notice

How SafeLoop handles personal data, as controller and as processor.

Last updated

SafeLoop processes two categories of personal data: the account data of administrators who use the console, and the workforce data your organisation instructs us to process on your behalf in order to run a security awareness programme.

What we process

  • Administrator account data — name, work email, role, authentication metadata and console audit events.
  • Workforce data — name, work email, mobile number where SMS or voice simulations are in scope, department, manager and location.
  • Programme events — simulation delivery, opens, clicks, submissions, reports, training assignments and completions, each with a timestamp.

What we never process

We do not store the credentials anybody types into a simulated login page. The submission is recorded as an event; the characters are discarded at the collector before any write to storage occurs. This is enforced in code, not by policy, and is covered by our third-party penetration testing.

We do not read mailbox contents. The optional mail add-in accesses only a message that a person explicitly chooses to report. There is no background scanning, journaling or mail-flow copy.

Roles

For workforce data your organisation is the controller and SafeLoop is the processor, governed by the data processing agreement. For administrator account data, billing records and website analytics, SafeLoop is the controller.

Retention

DataDefault retentionNotes
Programme events13 monthsConfigurable per tenant
Training certificatesAs long as required as evidenceSurvives event-data deletion
Audit log13 months minimumAppend-only; extended on request
Administrator accountsLife of the subscription + 90 daysThen deleted
Support correspondence24 monthsHeld by our support subprocessor

Location

Data residency is selected per tenant at provisioning — EU (Ireland), UK (London) or US (Virginia) — and processing, including backups, remains within the selected region. The subprocessor register lists the region applicable to each processor.

Rights and requests

Where SafeLoop is the processor, individual rights requests should be directed to your employer as controller; we assist promptly on instruction. Where SafeLoop is the controller, contact privacy@safeloop.com. Deletion requests are completed within 30 days.

Questions about this document? Email legal@safeloop.com or contact us.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.