Companies and other organizations engage us to train their employees.
This Data Processing Notice (“Notice”) applies to CybeReady’s Cyber Security Readiness Program and is intended to provide the trainees with details about the processing of their personal data in connection with such training.
This Notice assumes that your employer is a customer of CybeReady’s and has enrolled you as a trainee in one of our programs (the “Purpose”). Please contact your Security Team in your organization if you are not sure whether you have been enrolled in our training program.
For us to be able to send you phishing messages as part of our training program, your employer has provided us (or will provide us once you are enrolled in in our program) with the following information:
Throughout our training program, we gather and analyze your responses to our phishing messages (such as whether you have ignored a message or clicked a link) (behavioral data) and keep tabs through automatic means (profiling’) on the aspects of training that might need strengthening.
Based on this data, we then adjust automatically (automatic decision making’), or at the choice of your employer the messages we send you, to better match your training needs (for example through more frequent phishing messages or by referring you to additional learning activities).
The basic underlying logic for the automatic adjustment of the training experience is that repeated failures of a trainee in identifying phishing messages (or certain types of such messages) call for an increase in the frequency of the drills.
As to the expected consequences of profiling – usually, they are limited to the inner behavior of our program as explained above, with the employer only receiving statistical or group-related performance data (such as the overall performance of an organizational division) rather than the competence level of any specific trainee. Please contact your employer should you have any queries in that regard.
We only process your personal information for the purpose of training you against phishing attacks as detailed above, and act exclusively on behalf of your employer, and in accordance with its written instructions, in that regard.
Under data privacy legislation (including Regulation (EU) 2016/679 of the European Parliament and of the Council of Europe (“GDPR”)), your employer – as the one that determines the purposes and means of the processing of your personal data – is considered the ‘controller’, while CybeReady fulfills the role of a ‘processor’, i.e. an entity which processes personal data on behalf of the controller.
In connection with CybeReady’s anti-phishing training programs, the legal basis for the processing of personal data would usually be the legitimate interest of the employer (in accordance with GDPR Article 6(1)(f)) in mitigating cyber security risks through hands-on training of its staff.
Please note that due to its role as the Controller, your employer, rather than CybeReady, is the one responsible for determining the purpose and legal basis for the processing of your personal data, and you are advised to contact it should you have any queries in that regard.
CybeReady utilizes the services of renowned international companies to securely store your personal information on their distributed collection of computer servers (‘cloud’) residing in the EU.
For details of the service providers we use and their respective locations, please see the section below about ‘Transferring and sharing your information’.
Unless otherwise instructed by your employer, CybeReady will keep your personal information as long as you are enrolled in one of our training programs, and for an additional short transition period (usually up to 60 more days) intended to allow for the final deletion of your data from our backup systems.
In the course of providing our training programs, we use the services of the following third-party subcontractors (‘sub processors’) with whom we share your personal data (or part of it), to the extent required (and allowed by your employer) for that purpose:
Though the Personal Data we receive and collect for the phishing training is stored on EU servers, CybeReady itself, as well as some of its sub-processors, are non-EU companies or international ones, which in turn requires (or allows for the possibility of) data transfers to non-EEA third countries.
CybeReady uses one of two mechanisms prescribed by the GDPR for lawful cross-border transfers of Personal Data:
CybeReady uses a variety of technical and organizational measures to ensure a high level of security for the personal data that we process.
Those include, among other measures, the encryption of Personal Data; its storage and handling by reputed third parties that utilize physical and cyber security safeguards to ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services; adoption of security by design development and security by default standards and ongoing risk assessment and management processes (including the performance of periodic penetration tests and IT Security audits).
CybeReady has in place and works according to comprehensive security and privacy policies and procedures and adheres to industry best practices in the field. CybeReady has been certified to the ISO/IEC 27001:2022 and the SOC2 standards.
Since your enrollment in the training program is arranged through your employer, you should contact them to determine whether you are legally required to participate. They can also explain the scope of your right to object and the potential consequences of your decision.
Data privacy laws (including, where applicable, the GDPR) grant you certain rights in connection with the processing of your personal data.
In addition to being provided with the information included in this Notice, you have the right (by approaching your employer) to:
You might also have additional rights under the privacy or labor laws of your country of residence or the country you are employed in, or otherwise under your employment contract.
If you are in the European Union, you also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred within the EU. You can find a list of the data protection authorities in the European Commission’s website.
We keep this Notice under regular review and will place any updates on this web page. We might also alert you to material changes through your employer or (if so instructed by it) by sending you an email.
You can see when this Notice was last updated by checking the date at the top of this document.
Please contact us if you have any questions about this Notice or the Personal Information we might hold about you.