Last updated: August 2026
When you create an account, we collect your name and email address through our authentication provider, Clerk. If your organization is onboarded as a customer, we also store basic company details: company name, a primary contact name, email, and phone number.
When you use the platform to run phishing simulations, your administrators upload an employee directory (names, emails, and departments) so campaigns can be sent and results tracked. This data belongs to your organization, and we process it only to operate the platform on your behalf.
When a simulated phishing email is opened or clicked, we record the timestamp, a coarse device and browser type, and an IP address, so your organization can measure and improve its security awareness. This data is used only for the reporting and analytics features inside your own dashboard, and only your organization's administrators can see it.
A small number of trusted service providers help us run the platform:
None of these providers are permitted to use your data for their own purposes.
We keep your data for as long as your account is active. If you close your account or ask us to delete your organization's data, we will remove it, including employee records, campaign history, and audit logs, within a reasonable timeframe.
All traffic to and from the platform is encrypted with HTTPS. Access to your organization's data is restricted by role, and administrative actions are recorded in an audit log that your own admins can review.
If you have questions about this policy or want to request a copy or deletion of your data, email us at info@wcspl.net or support@wcspl.net.