Privacy Policy
Last updated: August 22, 2026
Data controller (the party legally responsible for your personal data): LudiSec (admin.ludisec@gmail.com)
1. Introduction
This Privacy Policy explains how LudiSec ("we", "the Platform") collects, uses, and protects personal data of users of our cybersecurity awareness and risk-management platform, covering both client companies ("Client") and their employees ("End Users") who take part in trainings, simulations, and assessments.
2. Data controller
LudiSec. Privacy contact: admin.ludisec@gmail.com.
3. What data do we process?
- Account data: name, corporate email, job title, company, language.
- Platform usage data: training progress, quiz results, XP, badges, interactions with gamified content.
- Phishing simulation data: email opens, clicks on simulated links, submissions to simulated forms (never real credentials), response times.
- Technical data: IP address, browser type, security and audit logs (required for NIS2/DORA traceability).
- Billing data (for the contracting Client): tax data processed via Stripe and Odoo.
4. Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Provision of the contracted service (training, simulations, risk dashboards) | Performance of a contract (art. 6.1.b GDPR) — the Client acts as controller over its employees' data and LudiSec as processor |
| Human-risk score calculation via the Naive Bayes classifier | Client's legitimate interest in cybersecurity risk management, disclosed to the End User |
| Security, fraud prevention, and regulatory traceability (NIS2/DORA) | Legal obligation and legitimate interest |
| Marketing communications to prospective Clients | Consent or legitimate interest, with opt-out on every communication |
| Billing and tax obligations | Legal obligation (art. 6.1.c GDPR) |
5. The global classifier (Naive Bayes) and network effect
LudiSec uses a statistical model (Naive Bayes classifier) trained on aggregated, anonymized or pseudonymized data from multiple Clients to improve detection of human-risk patterns (e.g. susceptibility to specific phishing types). This processing:
- Operates on aggregated/pseudonymized data, without individually identifying End Users of other Clients.
- Is not used to make individual automated decisions with legal effects without human intervention.
- Is described in the Data Processing Agreement (DPA) signed with each Client, who must in turn inform its own employees.
6. Client–LudiSec relationship: controller and processor
Regarding End User data, the Client is the data controller and LudiSec acts as data processor, under a DPA (art. 28 GDPR) signed at contracting. For the Client's own data as a business contact (sales, billing), LudiSec is the data controller.
7. Recipients and data processors
We use trusted third-party providers acting as data processors on our behalf, covering categories such as cloud hosting and infrastructure, payment processing, transactional email delivery, invoicing and accounting, and authentication/identity services. We don't publish the specific vendor names here for operational security reasons, but each provider is bound by a data processing agreement consistent with art. 28 GDPR, and further details can be provided on request at admin.ludisec@gmail.com.
8. International transfers
Some providers may be located outside the European Economic Area. Such transfers rely on Standard Contractual Clauses approved by the European Commission or other appropriate safeguards (Chapter V GDPR).
9. Retention period
We retain data for the duration of the contractual relationship with the Client and afterwards for the periods required by tax and commercial law (generally 6 years), or as required by NIS2/DORA traceability obligations.
10. Data subject rights
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability by emailing admin.ludisec@gmail.com. You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).
11. Security
We apply appropriate technical and organizational measures (encryption in transit and at rest, role-based access control, hash-chained compliance event logging, backups, environment segmentation) under art. 32 GDPR.
12. Minors
The Platform is intended for a professional/business environment and is not directed at minors.
13. Changes to this policy
We may update this policy to reflect legal, technical, or organizational changes. Material changes will be notified to Clients with reasonable notice.
14. Contact
admin.ludisec@gmail.com