Data Processing Addendum

Last updated September 20, 2026

When your organization runs an assessment, phish.co necessarily processes some personal data about the employees and contractors you enroll. This Addendum summarizes that processing. It supplements our Master Services & Authorized-Use Agreement and Privacy Policy; defined terms carry their meaning from those documents.

Roles

For the personal data processed in the course of your assessments, you are the controller and phish.co (a service of Fulcrum LLC) is the processor. You decide who is enrolled, which campaigns run, and why; we process that data only to provide the Service and only on your documented instructions, which the Service's configuration expresses.

What we process, and why

CategoryExamplesPurpose
Roster data you upload Employee/contractor name, work email address, and — only where you enable that channel — work phone number; optional group label. To address assessment messages to the people you enrolled, at your verified domain(s).
Interaction results Structured states: whether a message was delivered, opened, clicked, submitted-to, or reported, each with a timestamp. To produce the aggregate and per-target reporting that is the point of the assessment.
Account data The email addresses of your own administrators who sign in. To operate accounts and log consequential authorization events (for example, accepting the rules of engagement).
What we deliberately never process: the actual values a person types into a simulated page. If someone submits a simulated login or form, we record only that a submission occurred — a boolean and a timestamp — never the password, account number, or any other value entered. There is no field anywhere in the Service to hold it. We also do not solicit or store protected health information, by design.

Data subjects

Your own current employees and contractors, at domains your organization has verified. The Service enforces this on every send; it cannot be used to process data about anyone outside your verified workforce.

Our obligations as processor

Sub-processors

phish.co does not engage sub-processors to process your personal data.

Retention

We keep roster and interaction data for as long as your account is active and as needed to provide the reporting you rely on. After termination we retain your data for 90 days and then delete or return it, except where a longer period is required by law or other legal requirement.

Contact

Questions about this Addendum, or to request the executable version: hello@phish.co.