Skip to content
PHISHNOVA

Legal

Data Processing Addendum

Last updated: July 3, 2026


This Data Processing Addendum ("DPA") forms part of the agreement between you ("Controller") and PhishNova, Inc. ("Processor") for the provision of the Services. It reflects the parties’ agreement on the processing of personal data under the GDPR and India’s DPDP Act.

Roles and scope

You act as the Controller (or Data Fiduciary) of personal data processed through the Services, and PhishNova acts as the Processor (or Data Processor), processing personal data only on your documented instructions.

Nature and purpose of processing

PhishNova processes personal data to provide phishing-simulation, coaching, training, and risk-analysis services, including delivering simulations, recording outcomes, and generating reports.

Categories of data and data subjects

  • Data subjects: your employees and authorized users enrolled in your program.
  • Personal data: name, work email, department/role, simulation and training interactions, and related program metadata.

Processor obligations

  • Process personal data only on documented instructions from the Controller.
  • Ensure personnel authorized to process personal data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures.
  • Assist the Controller with data-subject requests and with security, breach-notification, and impact-assessment obligations.

Security measures

PhishNova maintains encryption in transit and at rest, role-based access control, multi-tenant isolation, an approval queue for simulation sends, audit logging, and least-data collection practices.

Sub-processors

The Controller authorizes PhishNova to engage sub-processors (for hosting, email delivery, and analytics) under written contracts imposing data-protection obligations no less protective than this DPA. We will inform you of intended changes and give you the opportunity to object.

Data-subject requests

PhishNova will, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures in responding to requests to exercise data-subject rights.

Personal-data breaches

PhishNova will notify the Controller without undue delay after becoming aware of a personal-data breach and will provide information reasonably necessary for the Controller to meet its notification obligations.

International transfers

Where processing involves cross-border transfers, the parties will rely on appropriate safeguards such as Standard Contractual Clauses.

Audit

PhishNova will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and security controls.

Return and deletion

Upon termination, PhishNova will, at the Controller’s choice, delete or return personal data, save to the extent retention is required by law.

Contact

Data-protection enquiries can be sent to privacy@phishnova.com.