Skip to content

Legal

Terms of Service & Pilot Terms

Effective: 8 August 2026 · Last updated: 8 August 2026

These terms govern use of the PhishGuard website, free interactive demo, and paid pilot or subscription services. Paid engagements may also be governed by an order form or statement of work that controls if there is a conflict.

1. Website and free demo

The public demo uses sample data only and does not connect to your Google Workspace. You may explore the product for evaluation. Do not attempt to misuse the site, probe without authorization, or submit unlawful content via forms.

2. Paid pilots

  • Scope — seats, duration, packages, and success criteria are defined in the order form.
  • Customer authority — you represent that you have authority to enroll users in phishing simulations and to connect Google Workspace under your policies and applicable law.
  • Dry-run first — live send is an explicit step after dry-run unless otherwise agreed.
  • No credential harvesting — simulations must not capture employee passwords; we design the product accordingly.
  • Fees — stated in CAD unless noted; payment terms on the order form. Pilot fees may credit toward an annual plan if specified in writing.

3. Customer data and privacy

For employee simulation data, you are the controller/custodian and we process under your instructions as described in our Privacy Policy and the pilot data processing terms (DPA addendum provided with your order form). You are responsible for notices to your personnel required by your policies or law.

4. Acceptable use

You will not use PhishGuard to:

  • Run simulations against individuals or domains you do not control
  • Harass, discriminate, or publicly shame individuals using results
  • Attempt to bypass security, tenancy, or billing limits
  • Resell the service without a written partner agreement

5. Intellectual property

We own the PhishGuard software, branding, and documentation. You own your data. You receive a limited license to use the service during the paid term.

6. Warranties and disclaimers

The service is provided professionally and with reasonable skill. Except as required by law, we disclaim other warranties. Phishing simulations reduce but do not eliminate risk; we do not guarantee that employees will never fall for real attacks.

7. Limitation of liability

To the maximum extent permitted by law, our aggregate liability under a paid engagement is limited to fees paid for that engagement in the twelve months before the claim. We are not liable for indirect or consequential damages. Nothing excludes liability that cannot be limited under applicable law.

8. Term and termination

Either party may terminate a pilot for material breach if not cured within the period in the order form (or 15 days if silent). Upon end of service we will delete or return customer tenant data as described in the privacy terms, subject to legal retention.

9. Compliance claims

We maintain readiness programs for SOC 2 and ISO standards. Unless we provide a formal report or certificate from an independent firm or accredited body, we do not claim to be SOC 2 or ISO certified.

10. Governing law

These terms are governed by the laws of the Province of Alberta and the federal laws of Canada applicable therein, unless your order form specifies another Canadian jurisdiction.

11. Contact

Contact form · privacy@phishguard.ca · security@phishguard.ca