SecurityRing
PlatformHow it worksSecurityPricingPlay the game
Book a Demo
PlatformHow it worksSecurityPricingPlay the game
Legal

Privacy Policy

This Policy explains how SecurityRing handles personal data across our website, administrative platform, authorized security simulations, training experiences, and related services.

Effective:
July 13, 2026
Last updated:
October 3, 2026
On this page
1. Scope and our rolePublic awareness challenge2. Personal data we process3. Sources of personal data4. Uses and legal bases5. Simulation tracking6. Cookies and similar technology7. How we disclose data8. No sale or targeted advertising9. International transfers10. Retention and deletion11. Security12. Privacy rights13. California notice14. Automated processing15. Children16. Updates and contact

On this page

1. Scope and our rolePublic awareness challenge2. Personal data we process3. Sources of personal data4. Uses and legal bases5. Simulation tracking6. Cookies and similar technology7. How we disclose data8. No sale or targeted advertising9. International transfers10. Retention and deletion11. Security12. Privacy rights13. California notice14. Automated processing15. Children16. Updates and contact

At a glance

  • SecurityRing is a B2B security-awareness platform. Organizations provide workforce data and decide who may receive an authorized simulation.
  • We process delivery and interaction signals so the organization can measure and improve security awareness.
  • A simulated form may record that it was submitted, but SecurityRing is designed not to intentionally retain the text entered into simulated credential fields.
  • We do not sell personal data or share it for cross-context behavioral advertising.
  • We do not use Customer workforce data to train general-purpose AI models.

1. Scope and our role

This Privacy Policy (“Policy”) applies to personal data processed through securityring.ai, the SecurityRing administrative application, APIs, email delivery workflows, tracking and landing domains, security-awareness simulations, training pages, reports, support, and related services (collectively, the “Service”). It does not apply to a Customer’s own systems or to a third-party website or service governed by its own privacy notice.

“SecurityRing,” “we,” “us,” or “our” means 9DSEMBER SOFTWARE PRIVATE LIMITED, a private limited company incorporated in India that operates the SecurityRing service. “Customer” means the organization using the Service. “Recipient” means a person included in a Customer-authorized simulation, assessment, notification, or training experience. An applicable customer Order Form may include additional contracting details.

When we act for a Customer

For workforce records, campaign targeting, and Recipient interaction data processed to provide the Service, the Customer generally determines why and how the data is used. The Customer acts as controller, business, or data fiduciary, and SecurityRing acts as processor, service provider, contractor, or data processor on the Customer’s documented instructions. The Customer’s privacy or workforce notice and its agreement with SecurityRing govern that processing.

When we determine the purpose

SecurityRing acts independently as controller or business for data used to operate our website, manage business relationships and accounts, provide support, secure and troubleshoot the Service, prevent abuse, meet legal obligations, and improve the Service without using Customer workforce data for unrelated purposes.

If you are a Recipient or Customer employee, your organization is normally the best first contact for questions about why a simulation was conducted or how results are used. We will assist the Customer with applicable privacy requests.

Public awareness challenge

You can play Real or Fake without providing your name or email. We store an anonymous challenge session, answers and score for up to 24 hours so you can complete the game. A temporary session token is stored in your browser tab. We use short-lived request counters to limit abuse.

When you choose to share, we ask for your name, email and agreement to store them for this challenge. Contact details are stored separately from the public result, are scheduled for deletion after 90 days, and are not added to a marketing subscription. This version does not send emails or issue certificates. Backups may retain deleted records for up to 14 additional days.

A public result contains your score and challenge edition. Your name appears only if you choose to show it. Your email is never included in the result page, share URL or score image. Shared result links expire after 30 days. If you share to a social platform, that platform applies its own privacy policy and may keep a copy of your post or image after the result link expires.

Public challenge data is separate from customer workforce records and does not affect an employee risk score. For access or deletion requests, use the privacy contact listed at the end of this policy.

2. Personal data we process

CategoryExamples
Business and contact dataName, work email, organization, title, telephone number, meeting details, communications, support requests, contract contacts, and billing or procurement information.
Administrator account dataName, work email, Google account identifier, verified domain, workspace, role, authorization status, profile information supplied by the identity provider, login and session records, approval actions, and account preferences. We do not receive the administrator’s Google password.
Workforce and organizational dataWork email, first and last name, department, job title, office location, manager name and work email, manager relationship, seniority tier, executive or leadership flag, date of joining, risk tags, status, and Customer-defined custom roster attributes.
Campaign and Customer ContentCampaign names and briefs, target rules, schedules, pacing, approvals, email content, sender names and addresses, templates, landing pages, quizzes, training content, uploaded files and images, brand assets, prompts, instructions, source URLs, domains, mailboxes, and configuration settings.
Delivery and interaction dataProvider message identifier, send and delivery status, timestamps, bounce and complaint status, opens, clicks, form-submission indicator, phishing reports, quiz answers and correctness, training-video progress, and supported attachment-open, QR-scan, synthetic-video, OAuth-consent, or device-code interaction events. We may store event counts and first or most recent timestamps.
Device, network, and security dataIP address, user agent, browser or device type inferred from the user agent, scanner classification, requested host, host-mismatch events, pseudonymous tracking token, session identifiers, API and audit events, error diagnostics, rate-limit events, and security logs. We do not intentionally collect precise GPS location.
AI and generated-content dataPrompts, instructions, selected workspace context, uploaded reference material, model configuration, generated drafts, recommendations, summaries, classifications, media-generation inputs and outputs, and usage or cost metadata.
Service and usage dataFeature usage, page and API activity, workspace settings, integration status, domain and sender readiness, report generation, administrative changes, and feedback.

Sensitive data

The Service is not designed to collect personal passwords, authentication codes, payment-card numbers, government identifiers, health information, biometric templates, or other special-category or sensitive personal data from Recipients. Customers must not upload or solicit such data unless SecurityRing has expressly agreed in writing and the processing is lawful. Authentication tokens and similar security data are used only to provide and protect the Service.

Simulated credential fields

A training page may display username, password, device-code, consent, or similar fields to measure whether a Recipient attempted a risky action. SecurityRing records the occurrence and time of the simulated action and is designed not to intentionally retain the text entered into simulated credential fields. Recipients should never enter a real password, authentication code, financial detail, or other secret into a simulation.

3. Sources of personal data

We obtain personal data from the following sources:

  • Customers and administrators: through account setup, roster import, direct entry, integrations, campaign configuration, content upload, support, and Order Forms.
  • Recipients: through their browser or email client when a message is delivered, opened, clicked, reported, or used to interact with a Customer-authorized training experience.
  • Identity and email providers: such as authentication profile, delivery, bounce, complaint, sender, mailbox, and domain-status information.
  • Service providers: such as hosting, security, content-generation, media, brand, scheduling, or support providers used for the requested function.
  • Automatic collection: from website, application, API, tracking, and training-page requests and from essential cookies or similar security mechanisms.
  • Public or Customer-approved sources: for threat intelligence, security news, brand information, and campaign recommendations. We do not use public sources to build Recipient mailing lists.

Recipient contact lists come from the relevant Customer’s internal workforce or directory records. SecurityRing does not purchase, rent, scrape, or combine public lists for simulation delivery.

4. How and why we use personal data

PurposeTypical dataLegal basis where required
Provide accounts, workspaces, support, and contracted functionalityContact, account, Customer Content, usage, and configuration dataContract; legitimate interests; Customer instructions
Deliver authorized simulations and trainingWorkforce, campaign, sender, delivery, device, and interaction dataCustomer instructions as processor; Customer’s lawful basis may include legitimate interests, legal obligation, or another employment-law basis
Measure behavior and generate reports, recommendations, and remediationInteraction, workforce attributes, campaign, and usage dataCustomer instructions; legitimate interests in improving organizational security
Generate AI-assisted content or synthetic media requested by CustomerPrompts, reference material, selected context, and outputContract; Customer instructions; consent or other rights for a person’s likeness where required
Authenticate users and secure, debug, and monitor the ServiceAccount, session, device, network, audit, and diagnostic dataContract; legitimate interests; legal obligation
Manage email reputation, complaints, and abuseAddresses, message identifiers, delivery status, complaints, and suppression recordsLegitimate interests; legal obligation; Customer instructions
Manage sales, contracts, billing, and business communicationsBusiness contact, communications, meeting, order, and transaction dataContract; legitimate interests; legal obligation; consent where required
Comply with law and establish, exercise, or defend rightsRelevant account, Customer, security, support, and transaction recordsLegal obligation; legitimate interests

Where processing is based on legitimate interests, we consider necessity, proportionality, reasonable expectations, and the rights of affected people. Where consent is the basis, consent may be withdrawn for future processing. SecurityRing does not determine the Customer’s employment-law basis for conducting a simulation.

We may create aggregated or de-identified statistics that are not reasonably linkable to a person or Customer and use them to operate, secure, and improve the Service. We do not attempt to re-identify such data except to test whether de-identification remains effective, as permitted by law.

5. Simulation and training tracking

Customer-authorized simulation emails may contain a unique pseudonymous link and a small image used to measure delivery and opening. When an email client or security scanner loads the image or link, we may record the associated campaign and Recipient token, time, IP address, user agent, requested host, and whether the request appears to come from an automated scanner. A tracking token is not intended to reveal the Recipient’s identity in the URL; the mapping is held server-side.

Training pages may record clicks, form-submission attempts, phishing reports, quiz responses, video progress, and supported attachment, QR, OAuth-consent, device-code, or synthetic-media events. These signals allow the Customer to evaluate the exercise, distinguish likely automated activity, provide training, and produce reports. Open and click detection is not perfectly accurate because email clients, privacy features, proxies, and security scanners may block or trigger resources automatically.

Notice for Recipients

SecurityRing provides the measurement technology on the Customer’s behalf. The Customer decides the campaign purpose, audience, and use of results. Questions about workplace consequences, internal notices, or the lawful basis for a campaign should be directed to the Customer’s security, privacy, HR, or legal team.

6. Cookies and similar technology

SecurityRing currently uses essential technology needed to authenticate, secure, and operate the Service:

TechnologyPurposeTypical duration
sr_refresh_tokenHttpOnly authentication cookie used to maintain an administrator’s signed-in session and issue new short-lived access tokens. It is Secure and is not readable by application JavaScript.Up to 30 days, or until logout or revocation
sr_tracking_sessionHttpOnly same-browser security cookie used to validate state-changing requests on a simulation training page and reduce forged or automated submissions.Up to 12 hours
Tracking pixel and unique linksMeasure authorized email opens, clicks, scanner activity, and training interactions.Event retention is described in Section 10

These mechanisms are required for requested authentication, security, and Customer-authorized simulation functionality. The SecurityRing marketing site does not currently use advertising cookies. It may load fonts or other basic assets from service providers, which receive standard request information such as IP address and user agent. Following a link to an external scheduling service or other third-party site is governed by that provider’s privacy notice.

Browser “Do Not Track” signals are not governed by a common standard. Because we do not sell personal data or use it for cross-context behavioral advertising, a Global Privacy Control signal does not change those practices; we will honor such signals where legally required.

7. How we disclose personal data

We disclose personal data only as reasonably necessary for the purposes above, including to:

  • the relevant Customer and its Authorized Users, who can access workforce records, campaign status, interaction results, and reports according to their permissions;
  • cloud and infrastructure providers, including hosting, compute, database, storage, content delivery, monitoring, and security services such as Amazon Web Services;
  • identity and collaboration providers, such as Google for OAuth authentication and Customer-configured Google Workspace delivery;
  • email and messaging providers, depending on configuration, such as Amazon SES, Mailgun, Mailchimp Transactional, Zapmail, Gmail API, or Customer-configured SMTP services;
  • AI, media, and content providers, depending on the feature and configuration, which may include OpenRouter, Anthropic, OpenAI, Google Gemini, Amazon Polly, HeyGen, Context.dev, and rendering services;
  • domain, DNS, registrar, certificate, and mailbox providers, such as Hostinger, Zapmail, Mailgun, AWS, or a Customer-selected provider when domain workflows are requested;
  • professional advisers and business-service providers, such as auditors, counsel, insurers, payment, accounting, sales, support, and scheduling providers;
  • authorities or affected parties, where we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or prevent abuse; and
  • a successor or transaction participant, in a merger, financing, reorganization, insolvency, or sale, subject to appropriate confidentiality and applicable law.

The exact providers used may depend on Customer deployment, sender route, AI model, media feature, region, and Order Form. Service providers are authorized to process personal data only for contracted services or as required by law. A Customer may request current subprocessor information through its SecurityRing contact.

8. No sale or targeted advertising

SecurityRing does not sell personal data for money or other valuable consideration and does not share personal data for cross-context behavioral advertising, as those terms are defined under California law. We do not use Customer workforce or Recipient interaction data for third-party advertising, data-broker activity, or unrelated marketing. We do not knowingly sell or share personal data of people under 16.

We disclose data to service providers and contractors for business purposes described in this Policy. Those operational disclosures are not a sale or targeted-advertising share when processed under applicable legal restrictions.

9. International data transfers

SecurityRing operates from India and uses providers that may process data in India, the United States, and other countries. A Customer’s Order Form or deployment may specify a primary hosting region, but support, delivery, security, domain, AI, or media providers may operate elsewhere. The laws of those countries may differ from the laws where you live.

Where required, we use contractual and organizational safeguards for cross-border transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, data-processing agreements, transfer risk assessments, or another lawful transfer mechanism. Customers may contact us for information about safeguards relevant to their deployment.

10. Retention and deletion

We retain personal data only as long as reasonably necessary for the purposes described, Customer instructions, security, dispute resolution, and legal obligations. Default or typical periods are below; an Order Form or DPA may specify different periods.

DataTypical retention
Workforce records and campaign-level resultsFor the Customer relationship or until deletion is requested or instructed, subject to contract, legal, and backup requirements. A removed workforce record is excluded from active targeting; physical deletion may require a verified Customer request.
Detailed interaction-event recordsTypically up to 90 days, after which configured time-to-live deletion applies.
Campaign target summaries and report metricsFor the Customer relationship or the shorter period in the Order Form or DPA, so Customers can compare campaigns and demonstrate training outcomes.
Test-email target dataTypically up to 48 hours.
Generated training-video objectsTypically up to 365 days, unless replaced or deleted earlier.
Authentication sessionsAccess tokens are short-lived; refresh sessions are generally valid for up to 30 days unless revoked or logged out.
Operational, security, and audit logsAccording to configured log retention and security need, generally 30 days to 1 year, with longer retention where needed for an active investigation or legal requirement.
Contracts, invoices, and business recordsFor the relationship and the period required by tax, accounting, and limitation laws.
Support and privacy-request recordsAs needed to resolve the request and document compliance, generally up to 3 years after closure unless law requires longer.

When a Customer relationship ends, SecurityRing will delete or return Customer personal data as required by the agreement and DPA. Data may remain temporarily in protected backups until overwritten through normal cycles and may be retained where required by law, to resolve disputes, enforce agreements, preserve security evidence, or prevent abuse. Retained data remains protected and is not used for unrelated purposes.

11. Security

SecurityRing uses administrative, technical, and organizational safeguards designed for the nature and risk of the data processed. Measures include encrypted transport, encryption at rest for primary cloud data stores, role- and workspace-based access controls, tenant partitioning, short-lived access tokens, HttpOnly session cookies, secrets management, least-privilege cloud permissions, logging, rate limits, suppression controls, security headers, and backup and incident-response processes.

No security measure guarantees absolute protection. Customers are responsible for their identity-provider policies, Authorized Users, integrations, devices, sender infrastructure, campaign configuration, and exported copies of reports or data. Please report a suspected vulnerability or misuse to abuse@securityring.ai without publicly disclosing sensitive details.

If we confirm a personal-data incident, we will investigate, mitigate, and notify affected Customers or authorities as required by applicable law and the relevant DPA.

12. Your privacy rights

Depending on your location and the law that applies, you may have rights to request access to or information about personal data; obtain a copy; correct inaccurate data; request deletion; restrict or object to processing; obtain portability; withdraw consent; opt out of certain processing; appeal a denied request; nominate another person where applicable; and complain to a data-protection authority or board. You also may have a right not to be discriminated or retaliated against for exercising privacy rights.

How to make a request

Email neha@securityring.ai with the subject “Privacy Request” and describe the right you wish to exercise, your relationship with SecurityRing, the relevant Customer organization, and the email address associated with the data. Do not send a password, government ID, or other unnecessary sensitive information.

If SecurityRing processes your data for a Customer, we may send the request to that Customer or ask you to contact it directly because the Customer controls the data and decides how to respond. We will support the Customer as required by contract and law.

Verification and authorized agents

We will verify requests proportionately using information already available, such as control of the relevant email address, Customer confirmation, account authentication, or campaign context. We may deny or limit a request where identity or authority cannot be verified, an exception applies, or fulfillment would adversely affect another person’s rights. An authorized agent may submit a request with proof of authority; we may also verify the request directly with the individual.

Appeals and complaints

If you believe a request was handled incorrectly, reply with the subject “Privacy Appeal” and explain why. You may also complain to the supervisory authority in your country or state. In India, where the relevant provisions apply, you may use our grievance process before approaching the Data Protection Board of India. In the EEA or UK, you may complain to your local data-protection authority.

13. California privacy notice

This section applies if the California Consumer Privacy Act, as amended (“CCPA”), applies to SecurityRing’s processing as a business. For data processed solely for a Customer, SecurityRing acts as that Customer’s service provider or contractor and the Customer is responsible for responding to applicable requests.

In the preceding 12 months, we have collected the categories below. We use them for the business purposes in Sections 4–7 and disclose them to the corresponding categories of recipients described in Section 7.

CCPA categoryExamplesBusiness-purpose disclosure
IdentifiersName, work email, IP address, account, user, employee, campaign, and tracking identifiersCustomers; infrastructure, identity, email, security, and support providers
California customer-record informationName, contact information, employment-related detailsCustomers and contracted operational providers
Commercial informationSubscription, Order Form, service usage, and transaction recordsBusiness, accounting, payment, legal, and infrastructure providers
Internet or electronic-network activityLogin, browser, API, email delivery, open, click, training, and interaction activityCustomers; infrastructure, email, security, AI, and support providers
Geolocation dataGeneral location inferred from IP or Customer-provided office location; not precise GPSCustomers and infrastructure or security providers
Audio, electronic, visual, or similar informationUploaded brand media, training media, and authorized synthetic-media inputs or outputsCustomers; infrastructure, AI, media, and rendering providers
Professional or employment-related informationEmployer, department, title, manager, seniority, joining date, location, risk tagsCustomers and contracted operational providers
InferencesScanner classification, cohorts, risk indicators, recommendations, and training outcomesCustomers and contracted AI, infrastructure, or reporting providers
Sensitive personal informationAccount log-in or security tokens used to authenticate administrators; the Service is not designed to collect actual Recipient credentials or other statutory sensitive categoriesIdentity, infrastructure, and security providers for permitted operational purposes

Sources are described in Section 3. Retention is described in Section 10. We have not sold or shared these categories for cross-context behavioral advertising in the preceding 12 months. We use sensitive personal information only for permitted purposes such as authentication, security, and providing the requested Service, not to infer characteristics for unrelated purposes.

California residents may request to know, access, correct, or delete personal information and may use an authorized agent, subject to verification and legal exceptions. Because we do not sell or share personal information for cross-context behavioral advertising, there is no need to opt out of those practices. We will not discriminate or retaliate for exercising CCPA rights. Submit requests as described in Section 12.

14. Automated processing and workplace decisions

The Service automates message delivery, event classification, cohorting, metrics, content generation, and recommendations. It may show risk indicators or suggested next steps based on campaign configuration and observed interactions. These outputs support human-led security training and program decisions.

SecurityRing does not intend the Service to make solely automated decisions that produce legal or similarly significant employment effects. Customers are required to review outputs, account for scanner and measurement error, use results proportionately, and not use a score or interaction as the sole basis for termination, discipline, compensation, promotion, hiring, or another significant decision. If a Customer chooses a use beyond this intended scope, it is responsible for additional notices, impact assessments, rights, human review, and legal requirements.

15. Children

The Service is designed for organizations and adult workforce security programs, not for children or personal consumer use. Administrative users must be at least 18. Customers must not submit data about or target a person under 18 without SecurityRing’s prior written agreement and a documented lawful basis, including any required parent or guardian authorization. If you believe a child’s data was provided improperly, contact us so we can investigate and work with the relevant Customer.

16. Policy updates and contact

Updates

We may update this Policy as the Service, providers, or law changes. We will post the revised Policy here and update the date above. If a change materially affects how we use personal data, we will provide additional notice through the Service, by email to Customer contacts, or as required by law. If consent is required for a new purpose, we will seek it before that processing.

Privacy and grievance contact

Questions, requests, grievances, or appeals may be sent to the SecurityRing privacy and grievance contact:

9DSEMBER SOFTWARE PRIVATE LIMITED
Operator of SecurityRing
Attn: Privacy and Grievance Contact
4th Floor, C1-614, Choma (62), Carterpuri Road
Palam Vihar Extension, Gurugram, Haryana 122017, India
GSTIN: 06AADCZ0579R1ZJ
Udyam Registration No.: UDYAM-HR-05-0196052
Email: neha@securityring.ai

For abuse or security reports, email abuse@securityring.ai. A Customer’s Order Form may specify additional notice details.

SecurityRing

Security awareness training, phishing simulation and human risk management for CISOs and GRC teams. Build continuous preparedness with relevant simulations, timely learning, and measurable progress.

Book a Demoneha@securityring.ai

Product

Platform overviewWhatsApp simulation (beta)RecommendationsDeepfake trainingEmail simulationsAI builderShort lessonsRisk dashboardReports

Company

Real or Fake? ChallengeCustomer storiesHow it worksSecurity & privacyPricingLoginContact us

Legal

Privacy policyTerms of serviceCookie policy
© 2026 SecurityRing. All rights reserved.Prepare. Protect. Repeat.