Special Terms for Simulated Phishing Campaigns
Last updated: August 22, 2026
Applies together with: the general Terms of Service, the Privacy Policy, and, where applicable, the Data Processing Agreement (DPA).
1. Purpose
These Special Terms govern use of LudiSec's simulated phishing campaign feature, through which the Client sends simulated emails to its own employees for the exclusive purpose of training and assessing human cybersecurity risk.
2. Client representations and responsibility
Before launching any campaign, the Client represents and warrants that:
- (a) It is entitled to direct these communications to the selected recipients, as they are its own personnel or duly authorized third parties.
- (b) It has assessed the need to inform employee representatives (works council/staff delegates) in advance, in line with applicable Spanish labor law (art. 64 Estatuto de los Trabajadores) and data protection rules, where its specific circumstances require it.
- (c) It has, at a general level, referenced this type of training action in its internal IT acceptable-use policy or equivalent document.
- (d) Recipients are adult natural persons within an employment or professional relationship with the Client.
LudiSec does not verify or supervise the Client's compliance with these obligations; the Client bears full responsibility toward its employees and third parties for launching the campaign.
3. Technical limits of the simulation
- Simulated emails and pages are generated for training purposes only.
- The Platform does not store or process real credentials: any data entered by an End User into a simulated form is discarded or pseudonymized, per campaign configuration; only the event (that a submission occurred) is logged, not its content.
- LudiSec does not reuse real third-party logos, trademarks, or identities in a way that could cause unlawful confusion beyond what is reasonably necessary for the simulation's training effectiveness.
4. Training-only purpose
Campaign results (opens, clicks, submissions) are used exclusively to: (a) generate aggregate human-risk indicators; (b) personalize training paths; (c) feed the global classifier described in the Privacy Policy, in aggregated/pseudonymized form.
5. No automated disciplinary use
LudiSec does not endorse or recommend using individual campaign results as the sole basis for disciplinary action against an End User. Any such decision is the Client's exclusive responsibility and must comply with applicable labor law, respecting the End User's right not to be subject to decisions based solely on automated processing without human intervention.
6. Informing End Users
The Client is encouraged to inform its employees, at a general level, of the existence of this type of training program (without revealing specific upcoming campaigns, so as not to undermine their effectiveness), including its purpose, legal basis, and applicable rights.
7. Frequency and volume limits
The Client agrees to a reasonable and proportionate use of the feature, avoiding a volume or frequency of simulations that could amount to harassment or undue pressure on End Users.
8. Incident handling
If a campaign triggers a real security alert (e.g., escalated by the Client's own security team), the Client is responsible for coordinating internal communication to avoid unnecessary consumption of incident-response resources. LudiSec can provide identifying headers/metadata for the simulation upon request.
9. Indemnification
The Client shall indemnify LudiSec against any third-party claim (including from End Users) arising from the Client's breach of the representations in section 2, or from use of the feature contrary to these Special Terms.
10. Governing law
These Special Terms are governed by Spanish law and form part of the main contract with the Client.
11. Contact
admin.ludisec@gmail.com