Trainees Data Processing Notice

We, CybeReady Learning Solutions Ltd. (“CybeReady” or “We”), are an Israeli private company headquartered in Tel Aviv, Israel. (You can find our corporate and contact details here
Companies and other organizations engage us to train their employees.

What does this Notice cover?

This Data Processing Notice (“Notice”) applies to CybeReady’s Cyber Security Readiness Program and is intended to provide the trainees with details about the processing of their personal data in connection with such training.
This Notice assumes that your employer is a customer of CybeReady’s and has enrolled you as a trainee in one of our programs (the “Purpose”). Please contact your Security Team in your organization if you are not sure whether you have been enrolled in our training program.

For information about CybeReady’s processing of personal data in other contexts (such as when you use our website or contact us with a business query), please see our Privacy Policy.

What’s in this Notice?

This Notice tells you:

What information do we hold and collect about you?

a. Information provided by your employer

For us to be able to send you phishing messages as part of our training program, your employer has provided us (or will provide us once you are enrolled in in our program) with the following information:
  • Your organizational e-mail address
  • The language in which your organization communicates with you Your employer might also choose to provide us with some, or all of the following additional details, to enhance the functionality of the training:
  • Your first name
  • The department or section within your organization to which you belong
  • Your mobile phone number – for serving you with SMS Phishing (‘Smishing’) training

b. Information collected automatically

When you interact with our phishing messages, by opening a phising email. clicking a link or browsing our instrumental feedback web pages, we document these interactions (including by embedding invisible tiny images) and collect:
  • Transmission data – details about emails you have opened (such as when you opened them and the device you used). the links you have followed and web pages you have visited as well as the data and time of the connection and its length.

c. collated information and data analysis (profiling’ and ‘automatic decision making’)

Throughout our training program, we gather and analyze your responses to our phishing messages (such as whether you have ignored a message or clicked a link) (behavioral data) and keep tabs through automatic means (profiling’) on the aspects of training that might need strengthening.
Based on this data, we then adjust automatically (automatic decision making’), or at the choice of your employer the messages we send you, to better match your training needs (for example through more frequent phishing messages or by referring you to additional learning activities).
The basic underlying logic for the automatic adjustment of the training experience is that repeated failures of a trainee in identifying phishing messages (or certain types of such messages) call for an increase in the frequency of the drills.
As to the expected consequences of profiling – usually, they are limited to the inner behavior of our program as explained above, with the employer only receiving statistical or group-related performance data (such as the overall performance of an organizational division) rather than the competence level of any specific trainee. Please contact your employer should you have any queries in that regard.

How might we use the information about you?

We only process your personal information for the purpose of training you against phishing attacks as detailed above, and act exclusively on behalf of your employer, and in accordance with its written instructions, in that regard.
Under data privacy legislation (including Regulation (EU) 2016/679 of the European Parliament and of the Council of Europe (“GDPR”)), your employer – as the one that determines the purposes and means of the processing of your personal data – is considered the ‘controller’, while CybeReady fulfills the role of a ‘processor’, i.e. an entity which processes personal data on behalf of the controller.
In connection with CybeReady’s anti-phishing training programs, the legal basis for the processing of personal data would usually be the legitimate interest of the employer (in accordance with GDPR Article 6(1)(f)) in mitigating cyber security risks through hands-on training of its staff.
Please note that due to its role as the Controller, your employer, rather than CybeReady, is the one responsible for determining the purpose and legal basis for the processing of your personal data, and you are advised to contact it should you have any queries in that regard.

Where is your information stored?

CybeReady utilizes the services of renowned international companies to securely store your personal information on their distributed collection of computer servers (‘cloud’) residing in the EU.
For details of the service providers we use and their respective locations, please see the section below about ‘Transferring and sharing your information’.

How long will we keep your personal information?

Unless otherwise instructed by your employer, CybeReady will keep your personal information as long as you are enrolled in one of our training programs, and for an additional short transition period (usually up to 60 more days) intended to allow for the final deletion of your data from our backup systems.

Transferring and sharing your information

In the course of providing our training programs, we use the services of the following third-party subcontractors (‘sub processors’) with whom we share your personal data (or part of it), to the extent required (and allowed by your employer) for that purpose:
Full Legal Name Location of Service Center Process Sub Processors List
Amazon Web Services Europe Hosting, Email Delivery https://aws.amazon.com/compliance/sub-processors/
Google Europe Hosting https://cloud.google.com/terms/subprocessors
Azure (Microsoft BI) Germany, Netherlands Data Visualization https://servicetrust.microsoft.com/DocumentPage/7a132d00-29c2-4d26-b0f5-486923c41223
Snowflake Inc. Ireland Data Warehousing https://www.snowflake.com/en/legal/privacy/snowflake-sub-processors/
Kiteworks Germany Secured File Transfer See Appendix 1 to the Kiteworks DPA
Kiteworks DPA
PostMastery Netherlands Email Delivery Consulting Google (see above)
Mandrill (*) USA Email Delivery https://mailchimp.com/legal/subprocessors/
(*) The US email delivery vendors will serve US customers and serve EU customers as a backup only if authorized.

Would Personal Data be transferred outside the EEA?

Though the Personal Data we receive and collect for the phishing training is stored on EU servers, CybeReady itself, as well as some of its sub-processors, are non-EU companies or international ones, which in turn requires (or allows for the possibility of) data transfers to non-EEA third countries.
CybeReady uses one of two mechanisms prescribed by the GDPR for lawful cross-border transfers of Personal Data:
  • Adequacy decisions (GDPR Art. 45) – for the transfer of Personal Data to Israel or to US or international companies that are certified under the new EU-US Data Privacy Framework endorsed by the EU Commission in July 2023;
  • Standard Contractual Clauses (GDPR Art. 46(2)(c)) – for other transfers of Personal Data outside the EEA.

How we protect your personal information

CybeReady uses a variety of technical and organizational measures to ensure a high level of security for the personal data that we process.
Those include, among other measures, the encryption of Personal Data; its storage and handling by reputed third parties that utilize physical and cyber security safeguards to ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services; adoption of security by design development and security by default standards and ongoing risk assessment and management processes (including the performance of periodic penetration tests and IT Security audits).
CybeReady has in place and works according to comprehensive security and privacy policies and procedures and adheres to industry best practices in the field. CybeReady has been certified to the ISO/IEC 27001:2022 and the SOC2 standards.

Are you legally obligated to provide information?

Since your enrollment in the training program is arranged through your employer, you should contact them to determine whether you are legally required to participate. They can also explain the scope of your right to object and the potential consequences of your decision.

Your rights and control of your personal information

Data privacy laws (including, where applicable, the GDPR) grant you certain rights in connection with the processing of your personal data.
In addition to being provided with the information included in this Notice, you have the right (by approaching your employer) to:
  • Obtain confirmation of whether your personal data is processed by CybeReady
  • access your data, and rectify inaccurate, incomplete or illegible information as well as information which is out of date/li>
  • request the erasure of data that is no longer needed for the Purpose or has been unlawfully processed
  • object to the processing of your information or request its restriction
  • object to the profiling activity if it produces legal effects concerning you or similarly significantly affects you
You might also have additional rights under the privacy or labor laws of your country of residence or the country you are employed in, or otherwise under your employment contract.

Lodging a complaint with a Supervisory Authority

If you are in the European Union, you also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred within the EU. You can find a list of the data protection authorities in the European Commission’s website.

Changes to this Notice

We keep this Notice under regular review and will place any updates on this web page. We might also alert you to material changes through your employer or (if so instructed by it) by sending you an email.
You can see when this Notice was last updated by checking the date at the top of this document.

How to contact us

Please contact us if you have any questions about this Notice or the Personal Information we might hold about you.

Our Corporate details and registered address:

  • CybeReady Learning Solutions Ltd.
  • Israeli Private Company No. 515167104
  • 5 Rav-Ashi St, Tel Aviv, Israel

Our Data Protection Officer (DPO):

Our Representative in the EU (in accordance with GDPR Art. 27):

4a34e52d-562b-4e1e-8b71-5c005a7559a9