SecurityTools

Policy

Privacy policy

Last updated: 14 July 2026 · Operated by securitytools.co.za

1. Who this applies to

This policy describes limited processing related to domains operated by securitytools.co.za for authorized internal IT and security programmes (including security-awareness and phishing-simulation infrastructure) for participating organisations.

2. What we process

Depending on how you interact, we may process:

  • Technical logs (for example IP address, user agent, timestamps, requested URL)
  • Simulation engagement events (for example whether a training link was opened, clicked, reported, or a form was submitted during an authorized exercise)
  • Identifiers tied to a simulation recipient (such as work email and assigned tracking token)

Informational pages on this site are not designed to collect account passwords. Do not enter credentials here.

3. Why we process it

  • Operate and secure the infrastructure
  • Deliver authorized security-awareness programmes
  • Measure simulation outcomes and improve training
  • Investigate abuse, misuse, or technical incidents
  • Meet internal governance and audit requirements

4. Legal basis / organisational context

Processing for employees and similar users is carried out as part of the relevant organisation’s legitimate security and training programmes, subject to internal policy and applicable data-protection law.

5. Sharing

Data is handled by authorized operators and service providers needed to run the programme (for example infrastructure and simulation tooling). It is not sold. It is not used to market products to the public via these domains.

6. Retention

Technical logs and programme records are kept only as long as needed for security, reporting, and audit purposes under the relevant organisation’s retention schedules, then deleted or anonymised.

7. Security

Access to operational systems is restricted to authorized personnel. Related hosts may expose only the minimal paths required for tracking or training workflows.

8. Your choices

If you believe you received a simulation message or have questions about your data in a training programme, contact your organisation’s IT / security team through normal internal channels. They can explain reporting options and programme records that apply to you.

9. Changes

We may update this policy as the service changes. The “Last updated” date will be revised when a new version is published.