Parties and roles
Your organisation is the controller: you decide what the data is used for. We, secctl.io, are the processor and process the data only on your instructions.
This agreement is part of every agreement with secctl.io, including the trial. It applies for as long as we process personal data for you. For a signed copy, email privacy@secctl.io.
Which data, about whom, and why
- Awareness
- Data about your employees: name, email address, team and role, sign-in details and second factor, the training they take, results of the baseline test and training, the risk score, and the log of what happens in the environment. Purpose: training employees and showing you their progress.
- Active Directory assessment
- Data we come across in your network within the agreed scope, such as user names, group memberships and computer names. Purpose: carrying out the assessment and writing the report.
We don’t process special categories of personal data, such as health data, and ask you not to put such data into Awareness.
Only on your instructions
We use the data only to deliver the service you have chosen, never for our own purposes. If we believe an instruction breaches the GDPR, we tell you straight away.
Confidentiality
Everyone at secctl.io who works with the data is bound by confidentiality.
Security
We take appropriate measures to protect the data, including:
- a separate environment with its own database for each customer;
- sign-in with a password and a second factor or passkey;
- hosting in the European Union, and in the Netherlands only if you ask;
- for the Active Directory assessment: tooling that refuses anything outside the scope, and a log of every action.
The current measures are listed on the Security and privacy page.
Sub-processors
You authorise us to engage sub-processors, for example for hosting and email. We send you the list on request. We bind every sub-processor to the same obligations as this agreement. If we add or change a sub-processor, we tell you beforehand. If you have reasonable grounds to object, we look for a solution together, or you may cancel free of charge.
Your environment is hosted in the European Union.
Helping with data subject rights
Employees can view, download and delete their own data in Awareness. If you receive a request they can’t handle themselves, we help you. If a request reaches us directly, we forward it to you.
Personal data breaches
If we discover a security breach affecting the data, we notify your contact person without undue delay. We tell you what happened, which data is affected, what the consequences may be and what we are doing about it, so you can decide whether to notify the supervisory authority and the people concerned.
Audits
We give you the information you need to demonstrate compliance with the GDPR. If you want an audit carried out, we agree its set-up together beforehand. You bear the cost of the audit.
End of the agreement
When the service ends, we delete the personal data unless the law requires us to keep it. If you want it back first, let us know before the end and we will agree how to hand it over.
Liability
Liability is governed by the terms and conditions. If this English text and the Dutch text differ, the Dutch text prevails.