Legal
Privacy Policy
Effective: 8 August 2026 · Last updated: 8 August 2026
PhishGuard (“we”, “us”) provides phishing simulation and security awareness analytics for organizations using Google Workspace. This policy explains how we handle personal information for website visitors, prospective customers, and when we process data on behalf of customer organizations.
1. Who we are
PhishGuard is a Canadian-oriented software service. Contact for privacy questions: privacy@phishguard.ca. Security inquiries: security@phishguard.ca.
2. Our roles
- Controller — for marketing leads, website form submissions, and PhishGuard administrator accounts.
- Processor / service provider — for customer employee directory data and simulation results, when a customer connects Google Workspace and runs campaigns. The customer remains the controller (or public-body custodian) of employee personal information.
3. Information we collect
3.1 Website and sales
- Name, work email, organization, role, message content from contact/pilot forms
- Technical logs (IP, user agent, timestamps) for security and reliability
3.2 Customer use of the product
- Admin account identifiers and authentication data
- Directory attributes authorized by the customer (e.g. email, name, OU / department) for targeting simulations
- Simulation events (sent, open, click, report) and campaign configuration
- Support communications
3.3 What we never collect
- Employee passwords or credentials via phishing simulations
- Mailbox content beyond what is required to deliver authorized simulations
4. How we use information
- Respond to inquiries and operate paid pilots / subscriptions
- Provide phishing simulations, analytics, and exports the customer requests
- Secure, maintain, and improve the service
- Meet legal obligations and enforce agreements
- Limited marketing to business contacts who request information (opt-out anytime)
5. Legal bases and Canadian privacy
We design practices around PIPEDA fair information principles for commercial activity, and support public-sector customers under their provincial statutes (e.g. FOIP/FIPPA) as service provider under contract. Where Québec Law 25 applies, we address additional requirements during onboarding.
6. Sharing
We use subprocessors for hosting (Vercel), databases (Neon), bot protection (Cloudflare Turnstile), email delivery, and similar infrastructure. See our subprocessor list. For paid pilots, processing of employee simulation data is also governed by a data processing addendum (DPA) attached to your order form. We do not sell personal information. We may disclose information if required by law or to protect rights and safety.
7. Retention
We retain information only as long as needed for the purposes above, contract requirements, and legal obligations. Default targets (may be adjusted in customer agreements):
- Marketing leads: up to 24 months from last meaningful contact, or sooner on request
- Campaign events: per customer agreement (typical pilot: term + 90 days)
- Security logs: up to 12 months unless needed longer for an incident
At the end of a pilot or subscription we delete or return customer tenant data per the order form / DPA, except limited records we must keep for legal or billing reasons.
8. Security
We use administrative, technical, and organizational measures appropriate to risk, including access controls, encryption in transit, tenant isolation design, dry-run defaults for campaigns, and audit logging of sensitive admin actions. Details: Security overview.
9. International transfers
Production customer data is designed for Canada residency–oriented design. Some support tools or subprocessors may process limited data in other regions; we will disclose material transfers in the subprocessor list and customer agreements.
10. Your rights
Depending on applicable law, you may request access, correction, or deletion of personal information we control (e.g. your lead record). Email privacy@phishguard.ca. If we process your data only as a processor for your employer, contact your organization first; we will assist them under contract.
11. Children
The service is for organizational use. We do not knowingly market to children.
12. Changes
We may update this policy and will revise the “Last updated” date. Material changes affecting customers will be communicated through reasonable channels.
13. Contact
Privacy: privacy@phishguard.ca · Security: security@phishguard.ca · General: contact form