At a glance
- SecurityRing is a B2B security-awareness platform. Organizations provide workforce data and decide who may receive an authorized simulation.
- We process delivery and interaction signals so the organization can measure and improve security awareness.
- A simulated form may record that it was submitted, but SecurityRing is designed not to intentionally retain the text entered into simulated credential fields.
- We do not sell personal data or share it for cross-context behavioral advertising.
- We do not use Customer workforce data to train general-purpose AI models.
1. Scope and our role
This Privacy Policy (“Policy”) applies to personal data processed through securityring.ai, the SecurityRing administrative application, APIs, email delivery workflows, tracking and landing domains, security-awareness simulations, training pages, reports, support, and related services (collectively, the “Service”). It does not apply to a Customer’s own systems or to a third-party website or service governed by its own privacy notice.
“SecurityRing,” “we,” “us,” or “our” means 9DSEMBER SOFTWARE PRIVATE LIMITED, a private limited company incorporated in India that operates the SecurityRing service. “Customer” means the organization using the Service. “Recipient” means a person included in a Customer-authorized simulation, assessment, notification, or training experience. An applicable customer Order Form may include additional contracting details.
When we act for a Customer
For workforce records, campaign targeting, and Recipient interaction data processed to provide the Service, the Customer generally determines why and how the data is used. The Customer acts as controller, business, or data fiduciary, and SecurityRing acts as processor, service provider, contractor, or data processor on the Customer’s documented instructions. The Customer’s privacy or workforce notice and its agreement with SecurityRing govern that processing.
When we determine the purpose
SecurityRing acts independently as controller or business for data used to operate our website, manage business relationships and accounts, provide support, secure and troubleshoot the Service, prevent abuse, meet legal obligations, and improve the Service without using Customer workforce data for unrelated purposes.
If you are a Recipient or Customer employee, your organization is normally the best first contact for questions about why a simulation was conducted or how results are used. We will assist the Customer with applicable privacy requests.
Public awareness challenge
You can play Real or Fake without providing your name or email. We store an anonymous challenge session, answers and score for up to 24 hours so you can complete the game. A temporary session token is stored in your browser tab. We use short-lived request counters to limit abuse.
When you choose to share, we ask for your name, email and agreement to store them for this challenge. Contact details are stored separately from the public result, are scheduled for deletion after 90 days, and are not added to a marketing subscription. This version does not send emails or issue certificates. Backups may retain deleted records for up to 14 additional days.
A public result contains your score and challenge edition. Your name appears only if you choose to show it. Your email is never included in the result page, share URL or score image. Shared result links expire after 30 days. If you share to a social platform, that platform applies its own privacy policy and may keep a copy of your post or image after the result link expires.
Public challenge data is separate from customer workforce records and does not affect an employee risk score. For access or deletion requests, use the privacy contact listed at the end of this policy.
2. Personal data we process
| Category | Examples |
|---|---|
| Business and contact data | Name, work email, organization, title, telephone number, meeting details, communications, support requests, contract contacts, and billing or procurement information. |
| Administrator account data | Name, work email, Google account identifier, verified domain, workspace, role, authorization status, profile information supplied by the identity provider, login and session records, approval actions, and account preferences. We do not receive the administrator’s Google password. |
| Workforce and organizational data | Work email, first and last name, department, job title, office location, manager name and work email, manager relationship, seniority tier, executive or leadership flag, date of joining, risk tags, status, and Customer-defined custom roster attributes. |
| Campaign and Customer Content | Campaign names and briefs, target rules, schedules, pacing, approvals, email content, sender names and addresses, templates, landing pages, quizzes, training content, uploaded files and images, brand assets, prompts, instructions, source URLs, domains, mailboxes, and configuration settings. |
| Delivery and interaction data | Provider message identifier, send and delivery status, timestamps, bounce and complaint status, opens, clicks, form-submission indicator, phishing reports, quiz answers and correctness, training-video progress, and supported attachment-open, QR-scan, synthetic-video, OAuth-consent, or device-code interaction events. We may store event counts and first or most recent timestamps. |
| Device, network, and security data | IP address, user agent, browser or device type inferred from the user agent, scanner classification, requested host, host-mismatch events, pseudonymous tracking token, session identifiers, API and audit events, error diagnostics, rate-limit events, and security logs. We do not intentionally collect precise GPS location. |
| AI and generated-content data | Prompts, instructions, selected workspace context, uploaded reference material, model configuration, generated drafts, recommendations, summaries, classifications, media-generation inputs and outputs, and usage or cost metadata. |
| Service and usage data | Feature usage, page and API activity, workspace settings, integration status, domain and sender readiness, report generation, administrative changes, and feedback. |
Sensitive data
The Service is not designed to collect personal passwords, authentication codes, payment-card numbers, government identifiers, health information, biometric templates, or other special-category or sensitive personal data from Recipients. Customers must not upload or solicit such data unless SecurityRing has expressly agreed in writing and the processing is lawful. Authentication tokens and similar security data are used only to provide and protect the Service.
Simulated credential fields
A training page may display username, password, device-code, consent, or similar fields to measure whether a Recipient attempted a risky action. SecurityRing records the occurrence and time of the simulated action and is designed not to intentionally retain the text entered into simulated credential fields. Recipients should never enter a real password, authentication code, financial detail, or other secret into a simulation.
3. Sources of personal data
We obtain personal data from the following sources:
- Customers and administrators: through account setup, roster import, direct entry, integrations, campaign configuration, content upload, support, and Order Forms.
- Recipients: through their browser or email client when a message is delivered, opened, clicked, reported, or used to interact with a Customer-authorized training experience.
- Identity and email providers: such as authentication profile, delivery, bounce, complaint, sender, mailbox, and domain-status information.
- Service providers: such as hosting, security, content-generation, media, brand, scheduling, or support providers used for the requested function.
- Automatic collection: from website, application, API, tracking, and training-page requests and from essential cookies or similar security mechanisms.
- Public or Customer-approved sources: for threat intelligence, security news, brand information, and campaign recommendations. We do not use public sources to build Recipient mailing lists.
Recipient contact lists come from the relevant Customer’s internal workforce or directory records. SecurityRing does not purchase, rent, scrape, or combine public lists for simulation delivery.
4. How and why we use personal data
| Purpose | Typical data | Legal basis where required |
|---|---|---|
| Provide accounts, workspaces, support, and contracted functionality | Contact, account, Customer Content, usage, and configuration data | Contract; legitimate interests; Customer instructions |
| Deliver authorized simulations and training | Workforce, campaign, sender, delivery, device, and interaction data | Customer instructions as processor; Customer’s lawful basis may include legitimate interests, legal obligation, or another employment-law basis |
| Measure behavior and generate reports, recommendations, and remediation | Interaction, workforce attributes, campaign, and usage data | Customer instructions; legitimate interests in improving organizational security |
| Generate AI-assisted content or synthetic media requested by Customer | Prompts, reference material, selected context, and output | Contract; Customer instructions; consent or other rights for a person’s likeness where required |
| Authenticate users and secure, debug, and monitor the Service | Account, session, device, network, audit, and diagnostic data | Contract; legitimate interests; legal obligation |
| Manage email reputation, complaints, and abuse | Addresses, message identifiers, delivery status, complaints, and suppression records | Legitimate interests; legal obligation; Customer instructions |
| Manage sales, contracts, billing, and business communications | Business contact, communications, meeting, order, and transaction data | Contract; legitimate interests; legal obligation; consent where required |
| Comply with law and establish, exercise, or defend rights | Relevant account, Customer, security, support, and transaction records | Legal obligation; legitimate interests |
Where processing is based on legitimate interests, we consider necessity, proportionality, reasonable expectations, and the rights of affected people. Where consent is the basis, consent may be withdrawn for future processing. SecurityRing does not determine the Customer’s employment-law basis for conducting a simulation.
We may create aggregated or de-identified statistics that are not reasonably linkable to a person or Customer and use them to operate, secure, and improve the Service. We do not attempt to re-identify such data except to test whether de-identification remains effective, as permitted by law.
5. Simulation and training tracking
Customer-authorized simulation emails may contain a unique pseudonymous link and a small image used to measure delivery and opening. When an email client or security scanner loads the image or link, we may record the associated campaign and Recipient token, time, IP address, user agent, requested host, and whether the request appears to come from an automated scanner. A tracking token is not intended to reveal the Recipient’s identity in the URL; the mapping is held server-side.
Training pages may record clicks, form-submission attempts, phishing reports, quiz responses, video progress, and supported attachment, QR, OAuth-consent, device-code, or synthetic-media events. These signals allow the Customer to evaluate the exercise, distinguish likely automated activity, provide training, and produce reports. Open and click detection is not perfectly accurate because email clients, privacy features, proxies, and security scanners may block or trigger resources automatically.
Notice for Recipients
SecurityRing provides the measurement technology on the Customer’s behalf. The Customer decides the campaign purpose, audience, and use of results. Questions about workplace consequences, internal notices, or the lawful basis for a campaign should be directed to the Customer’s security, privacy, HR, or legal team.
7. How we disclose personal data
We disclose personal data only as reasonably necessary for the purposes above, including to:
- the relevant Customer and its Authorized Users, who can access workforce records, campaign status, interaction results, and reports according to their permissions;
- cloud and infrastructure providers, including hosting, compute, database, storage, content delivery, monitoring, and security services such as Amazon Web Services;
- identity and collaboration providers, such as Google for OAuth authentication and Customer-configured Google Workspace delivery;
- email and messaging providers, depending on configuration, such as Amazon SES, Mailgun, Mailchimp Transactional, Zapmail, Gmail API, or Customer-configured SMTP services;
- AI, media, and content providers, depending on the feature and configuration, which may include OpenRouter, Anthropic, OpenAI, Google Gemini, Amazon Polly, HeyGen, Context.dev, and rendering services;
- domain, DNS, registrar, certificate, and mailbox providers, such as Hostinger, Zapmail, Mailgun, AWS, or a Customer-selected provider when domain workflows are requested;
- professional advisers and business-service providers, such as auditors, counsel, insurers, payment, accounting, sales, support, and scheduling providers;
- authorities or affected parties, where we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or prevent abuse; and
- a successor or transaction participant, in a merger, financing, reorganization, insolvency, or sale, subject to appropriate confidentiality and applicable law.
The exact providers used may depend on Customer deployment, sender route, AI model, media feature, region, and Order Form. Service providers are authorized to process personal data only for contracted services or as required by law. A Customer may request current subprocessor information through its SecurityRing contact.
8. No sale or targeted advertising
SecurityRing does not sell personal data for money or other valuable consideration and does not share personal data for cross-context behavioral advertising, as those terms are defined under California law. We do not use Customer workforce or Recipient interaction data for third-party advertising, data-broker activity, or unrelated marketing. We do not knowingly sell or share personal data of people under 16.
We disclose data to service providers and contractors for business purposes described in this Policy. Those operational disclosures are not a sale or targeted-advertising share when processed under applicable legal restrictions.
9. International data transfers
SecurityRing operates from India and uses providers that may process data in India, the United States, and other countries. A Customer’s Order Form or deployment may specify a primary hosting region, but support, delivery, security, domain, AI, or media providers may operate elsewhere. The laws of those countries may differ from the laws where you live.
Where required, we use contractual and organizational safeguards for cross-border transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, data-processing agreements, transfer risk assessments, or another lawful transfer mechanism. Customers may contact us for information about safeguards relevant to their deployment.
10. Retention and deletion
We retain personal data only as long as reasonably necessary for the purposes described, Customer instructions, security, dispute resolution, and legal obligations. Default or typical periods are below; an Order Form or DPA may specify different periods.
| Data | Typical retention |
|---|---|
| Workforce records and campaign-level results | For the Customer relationship or until deletion is requested or instructed, subject to contract, legal, and backup requirements. A removed workforce record is excluded from active targeting; physical deletion may require a verified Customer request. |
| Detailed interaction-event records | Typically up to 90 days, after which configured time-to-live deletion applies. |
| Campaign target summaries and report metrics | For the Customer relationship or the shorter period in the Order Form or DPA, so Customers can compare campaigns and demonstrate training outcomes. |
| Test-email target data | Typically up to 48 hours. |
| Generated training-video objects | Typically up to 365 days, unless replaced or deleted earlier. |
| Authentication sessions | Access tokens are short-lived; refresh sessions are generally valid for up to 30 days unless revoked or logged out. |
| Operational, security, and audit logs | According to configured log retention and security need, generally 30 days to 1 year, with longer retention where needed for an active investigation or legal requirement. |
| Contracts, invoices, and business records | For the relationship and the period required by tax, accounting, and limitation laws. |
| Support and privacy-request records | As needed to resolve the request and document compliance, generally up to 3 years after closure unless law requires longer. |
When a Customer relationship ends, SecurityRing will delete or return Customer personal data as required by the agreement and DPA. Data may remain temporarily in protected backups until overwritten through normal cycles and may be retained where required by law, to resolve disputes, enforce agreements, preserve security evidence, or prevent abuse. Retained data remains protected and is not used for unrelated purposes.
11. Security
SecurityRing uses administrative, technical, and organizational safeguards designed for the nature and risk of the data processed. Measures include encrypted transport, encryption at rest for primary cloud data stores, role- and workspace-based access controls, tenant partitioning, short-lived access tokens, HttpOnly session cookies, secrets management, least-privilege cloud permissions, logging, rate limits, suppression controls, security headers, and backup and incident-response processes.
No security measure guarantees absolute protection. Customers are responsible for their identity-provider policies, Authorized Users, integrations, devices, sender infrastructure, campaign configuration, and exported copies of reports or data. Please report a suspected vulnerability or misuse to abuse@securityring.ai without publicly disclosing sensitive details.
If we confirm a personal-data incident, we will investigate, mitigate, and notify affected Customers or authorities as required by applicable law and the relevant DPA.
12. Your privacy rights
Depending on your location and the law that applies, you may have rights to request access to or information about personal data; obtain a copy; correct inaccurate data; request deletion; restrict or object to processing; obtain portability; withdraw consent; opt out of certain processing; appeal a denied request; nominate another person where applicable; and complain to a data-protection authority or board. You also may have a right not to be discriminated or retaliated against for exercising privacy rights.
How to make a request
Email neha@securityring.ai with the subject “Privacy Request” and describe the right you wish to exercise, your relationship with SecurityRing, the relevant Customer organization, and the email address associated with the data. Do not send a password, government ID, or other unnecessary sensitive information.
If SecurityRing processes your data for a Customer, we may send the request to that Customer or ask you to contact it directly because the Customer controls the data and decides how to respond. We will support the Customer as required by contract and law.
Verification and authorized agents
We will verify requests proportionately using information already available, such as control of the relevant email address, Customer confirmation, account authentication, or campaign context. We may deny or limit a request where identity or authority cannot be verified, an exception applies, or fulfillment would adversely affect another person’s rights. An authorized agent may submit a request with proof of authority; we may also verify the request directly with the individual.
Appeals and complaints
If you believe a request was handled incorrectly, reply with the subject “Privacy Appeal” and explain why. You may also complain to the supervisory authority in your country or state. In India, where the relevant provisions apply, you may use our grievance process before approaching the Data Protection Board of India. In the EEA or UK, you may complain to your local data-protection authority.
13. California privacy notice
This section applies if the California Consumer Privacy Act, as amended (“CCPA”), applies to SecurityRing’s processing as a business. For data processed solely for a Customer, SecurityRing acts as that Customer’s service provider or contractor and the Customer is responsible for responding to applicable requests.
In the preceding 12 months, we have collected the categories below. We use them for the business purposes in Sections 4–7 and disclose them to the corresponding categories of recipients described in Section 7.
| CCPA category | Examples | Business-purpose disclosure |
|---|---|---|
| Identifiers | Name, work email, IP address, account, user, employee, campaign, and tracking identifiers | Customers; infrastructure, identity, email, security, and support providers |
| California customer-record information | Name, contact information, employment-related details | Customers and contracted operational providers |
| Commercial information | Subscription, Order Form, service usage, and transaction records | Business, accounting, payment, legal, and infrastructure providers |
| Internet or electronic-network activity | Login, browser, API, email delivery, open, click, training, and interaction activity | Customers; infrastructure, email, security, AI, and support providers |
| Geolocation data | General location inferred from IP or Customer-provided office location; not precise GPS | Customers and infrastructure or security providers |
| Audio, electronic, visual, or similar information | Uploaded brand media, training media, and authorized synthetic-media inputs or outputs | Customers; infrastructure, AI, media, and rendering providers |
| Professional or employment-related information | Employer, department, title, manager, seniority, joining date, location, risk tags | Customers and contracted operational providers |
| Inferences | Scanner classification, cohorts, risk indicators, recommendations, and training outcomes | Customers and contracted AI, infrastructure, or reporting providers |
| Sensitive personal information | Account log-in or security tokens used to authenticate administrators; the Service is not designed to collect actual Recipient credentials or other statutory sensitive categories | Identity, infrastructure, and security providers for permitted operational purposes |
Sources are described in Section 3. Retention is described in Section 10. We have not sold or shared these categories for cross-context behavioral advertising in the preceding 12 months. We use sensitive personal information only for permitted purposes such as authentication, security, and providing the requested Service, not to infer characteristics for unrelated purposes.
California residents may request to know, access, correct, or delete personal information and may use an authorized agent, subject to verification and legal exceptions. Because we do not sell or share personal information for cross-context behavioral advertising, there is no need to opt out of those practices. We will not discriminate or retaliate for exercising CCPA rights. Submit requests as described in Section 12.
14. Automated processing and workplace decisions
The Service automates message delivery, event classification, cohorting, metrics, content generation, and recommendations. It may show risk indicators or suggested next steps based on campaign configuration and observed interactions. These outputs support human-led security training and program decisions.
SecurityRing does not intend the Service to make solely automated decisions that produce legal or similarly significant employment effects. Customers are required to review outputs, account for scanner and measurement error, use results proportionately, and not use a score or interaction as the sole basis for termination, discipline, compensation, promotion, hiring, or another significant decision. If a Customer chooses a use beyond this intended scope, it is responsible for additional notices, impact assessments, rights, human review, and legal requirements.
15. Children
The Service is designed for organizations and adult workforce security programs, not for children or personal consumer use. Administrative users must be at least 18. Customers must not submit data about or target a person under 18 without SecurityRing’s prior written agreement and a documented lawful basis, including any required parent or guardian authorization. If you believe a child’s data was provided improperly, contact us so we can investigate and work with the relevant Customer.
16. Policy updates and contact
Updates
We may update this Policy as the Service, providers, or law changes. We will post the revised Policy here and update the date above. If a change materially affects how we use personal data, we will provide additional notice through the Service, by email to Customer contacts, or as required by law. If consent is required for a new purpose, we will seek it before that processing.
Privacy and grievance contact
Questions, requests, grievances, or appeals may be sent to the SecurityRing privacy and grievance contact:
9DSEMBER SOFTWARE PRIVATE LIMITEDOperator of SecurityRing
Attn: Privacy and Grievance Contact
4th Floor, C1-614, Choma (62), Carterpuri Road
Palam Vihar Extension, Gurugram, Haryana 122017, India
GSTIN: 06AADCZ0579R1ZJ
Udyam Registration No.: UDYAM-HR-05-0196052
Email: neha@securityring.ai
For abuse or security reports, email abuse@securityring.ai. A Customer’s Order Form may specify additional notice details.