PhishShield

Phishing Simulation

20+ realistic attack templates across every vector

Cyber Essentials

NCSC-backed certification against common cyber threats

Threat Analytics

Real-time human risk intelligence dashboard

Compliance Reports

Board-ready audit documentation and audit trails

View all platform features →

Enterprise

Full security suite with dedicated support and SLAs

Financial Services

FCA, PCI-DSS and BEC fraud defence for finance teams

Education

DfE-aligned cyber security for schools and MATs

Healthcare

DSPT-aligned phishing defence for NHS and private care

View all solutions →

Documentation

Setup guides, API reference, and integrations

Cyber News

Live threat intelligence from Krebs, NCSC, Bleeping Computer and more

Case Studies

Real customer outcomes and measurable ROI data

Threat Intelligence

Latest phishing campaign TTPs and analysis

Explore all resources →
Pricing

Campaign login

Admin dashboard

Training portal

Employee learning

Get started

Privacy Policy

Last updated: 1 April 2026 · Effective: 1 April 2026

1. Who we are

PhishShield is operated by PhishShield, Inc. ("we", "us", "our"). We provide a security awareness training and phishing simulation platform. Our registered address is in London, United Kingdom. For data protection queries, contact us at [email protected].

2. Information we collect

We collect information you provide directly, such as your name, work email address, organisation name, and billing details when you register or subscribe. We also collect information automatically when you use our platform, including log data (IP address, browser type, pages visited), usage data (campaign results, click events), and cookies for session management and analytics.

3. How we use your information

We use your information to provide and improve the PhishShield service, process payments, send transactional emails (account confirmations, password resets, support replies), send security awareness training materials to your nominated targets (only with your explicit instruction), and comply with legal obligations. We do not sell your personal data to third parties.

4. Phishing simulation data

When you run phishing simulations, we process data about your employees' interactions with simulation emails (opens, clicks, credential submissions). This data is processed on your behalf as a data controller — you instruct us to run the simulation, and we act as data processor. You are responsible for obtaining appropriate consent or having a legitimate basis under your employment agreements.

5. Data sharing

We share data with: (a) payment processors (Stripe) for billing; (b) cloud infrastructure providers (Supabase/AWS) for hosting; (c) email delivery providers for transactional emails. All sub-processors are bound by data processing agreements and GDPR-compliant terms. We will disclose data to law enforcement where required by law.

6. Data retention

We retain your account data for the duration of your subscription plus 90 days after cancellation, after which it is permanently deleted. Campaign results and training records are retained for 24 months by default. You may request earlier deletion at any time by contacting [email protected].

7. Your rights

Under GDPR and UK data protection law, you have the right to access, rectify, erase, restrict, or port your personal data. You also have the right to object to processing and to withdraw consent at any time. To exercise any of these rights, contact [email protected]. You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use strictly necessary cookies for authentication and session management. We use analytics cookies (only with your consent) to understand how the platform is used. You can manage cookie preferences in your browser settings. We do not use advertising cookies.

9. Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest (AES-256), access controls, and regular security testing. For more detail, see our Security page.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notification at least 14 days before the changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.

Questions about this policy? Email us at [email protected]

PhishShield

Enterprise phishing simulation and security awareness training for modern organisations. Built by security people, for security teams.

SOC 2 Type IIISO 27001GDPR

Product

  • Features
  • Template Library
  • Pricing
  • Status

Company

  • About
  • Testimonials
  • Cyber News
  • Careers
  • Contact Sales
  • Enterprise

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR
  • Security

© 2026 PhishShield, Inc. All rights reserved.

For authorised security awareness testing only.