Privacy Policy

Privacy Policy

Last updated: Sept. 16, 2026
Data controller (the party legally responsible for your personal data): , sole trader (autónomo) registered in Spain under NIF , with tax domicile at , trading as LudiSec ()

1. Introduction

This Privacy Policy explains how LudiSec ("we", "the Platform") collects, uses, and protects personal data of users of our cybersecurity awareness and risk-management platform, covering both client companies ("Client") and their employees ("End Users") who take part in trainings, simulations, and assessments.

2. Data controller

, sole trader (autónomo) registered in Spain under NIF , with tax domicile at , trading as LudiSec. Privacy contact: .

3. What data do we process?

  • Account data: name, corporate email, job title, company, language.
  • Platform usage data: training progress, quiz results, XP, badges, interactions with gamified content.
  • Phishing simulation data: email opens, clicks on simulated links, submissions to simulated forms (never real credentials), response times.
  • Technical data: IP address, browser type, security and audit logs (required for NIS2/DORA traceability).
  • Billing data (for the contracting Client): tax data processed via Stripe and Odoo.

4. Purposes and legal basis

Purpose Legal basis
Provision of the contracted service (training, simulations, risk dashboards) Performance of a contract (art. 6.1.b GDPR) — the Client acts as controller over its employees' data and LudiSec as processor
Human-risk score calculation via the Naive Bayes classifier Client's legitimate interest in cybersecurity risk management, disclosed to the End User
Security, fraud prevention, and regulatory traceability (NIS2/DORA) Legal obligation and legitimate interest
Marketing communications to prospective Clients Consent or legitimate interest, with opt-out on every communication
Billing and tax obligations Legal obligation (art. 6.1.c GDPR)

5. The global classifier (Naive Bayes) and network effect

LudiSec uses a statistical model (Naive Bayes classifier) trained on aggregated, anonymized or pseudonymized data from multiple Clients to improve detection of human-risk patterns (e.g. susceptibility to specific phishing types). This processing:
- Operates on aggregated/pseudonymized data, without individually identifying End Users of other Clients.
- Is not used to make individual automated decisions with legal effects without human intervention.
- Is described in the Data Processing Agreement (DPA) signed with each Client, who must in turn inform its own employees.

6. Client–LudiSec relationship: controller and processor

Regarding End User data, the Client is the data controller and LudiSec acts as data processor, under a DPA (art. 28 GDPR) signed at contracting. For the Client's own data as a business contact (sales, billing), LudiSec is the data controller.

7. Recipients and data processors

We use providers acting as data processors, including cloud infrastructure (AWS), Stripe, Amazon SES, Odoo (Verifactu), Keycloak, and ElevenLabs/Bunny Stream (training video production/delivery, no End User personal data).

8. International transfers

Some providers may be located outside the European Economic Area. Such transfers rely on Standard Contractual Clauses approved by the European Commission or other appropriate safeguards (Chapter V GDPR).

9. Retention period

We retain data for the duration of the contractual relationship with the Client and afterwards for the periods required by tax and commercial law (generally 6 years), or as required by NIS2/DORA traceability obligations.

10. Data subject rights

You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by emailing . You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).

11. Security

We apply appropriate technical and organizational measures (encryption in transit and at rest, role-based access control, hash-chained compliance event logging, backups, environment segmentation) under art. 32 GDPR.

12. Minors

The Platform is intended for a professional/business environment and is not directed at minors.

13. Changes to this policy

We may update this policy to reflect legal, technical, or organizational changes. Material changes will be notified to Clients with reasonable notice.

14. Contact

Back to Home

🍪