Data Processing Addendum
Last updated September 20, 2026
When your organization runs an assessment, phish.co necessarily processes some personal data about the employees and contractors you enroll. This Addendum summarizes that processing. It supplements our Master Services & Authorized-Use Agreement and Privacy Policy; defined terms carry their meaning from those documents.
Roles
For the personal data processed in the course of your assessments, you are the controller and phish.co (a service of Fulcrum LLC) is the processor. You decide who is enrolled, which campaigns run, and why; we process that data only to provide the Service and only on your documented instructions, which the Service's configuration expresses.
What we process, and why
| Category | Examples | Purpose |
|---|---|---|
| Roster data you upload | Employee/contractor name, work email address, and — only where you enable that channel — work phone number; optional group label. | To address assessment messages to the people you enrolled, at your verified domain(s). |
| Interaction results | Structured states: whether a message was delivered, opened, clicked, submitted-to, or reported, each with a timestamp. | To produce the aggregate and per-target reporting that is the point of the assessment. |
| Account data | The email addresses of your own administrators who sign in. | To operate accounts and log consequential authorization events (for example, accepting the rules of engagement). |
Data subjects
Your own current employees and contractors, at domains your organization has verified. The Service enforces this on every send; it cannot be used to process data about anyone outside your verified workforce.
Our obligations as processor
- Process personal data only on your documented instructions and only to provide the Service.
- Ensure people authorized to process the data are bound by confidentiality.
- Apply appropriate technical and organizational security measures — including the tenant isolation described in our Security overview, so one customer's data is never reachable by another.
- Assist you, taking into account the nature of the processing, with data-subject requests and with your own security, breach-notification, and impact-assessment obligations.
- On termination, delete or return personal data as described under "Retention," except where law requires us to keep it.
- Notify you without undue delay after becoming aware of a personal-data breach affecting your data.
Sub-processors
phish.co does not engage sub-processors to process your personal data.
Retention
We keep roster and interaction data for as long as your account is active and as needed to provide the reporting you rely on. After termination we retain your data for 90 days and then delete or return it, except where a longer period is required by law or other legal requirement.
Contact
Questions about this Addendum, or to request the executable version: hello@phish.co.