Privacy Policy — weakestlink
Last updated: 2 July 2026
This policy describes how weakestlink processes personal data for which we are ourselves the data controller. If your employer uses weakestlink for security training, your employer is the data controller for employee data, and weakestlink acts as a data processor — see Annex A.
1. Data controller
WEAKESTLINK ApS (Danish company registration number, CVR 46614011) is the data controller for the processing of personal data on weakestlink.io. Contact: info@weakestlink.io.
2. What data we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) | Deleted |
|---|---|---|---|
| Customer contact person (name, email, job title) | Create and administer your workplace's account | Contract (Art. 6(1)(b)) | When the customer relationship ends |
| Billing information | Invoicing and accounting | Legal obligation (Art. 6(1)(c)) | 5 years, per the Danish Bookkeeping Act |
| Server logs (IP, timestamp) | Operations and security | Legitimate interest (Art. 6(1)(f)) | 90 days |
We do not process Danish CPR numbers or any special category data (GDPR Art. 9).
3. AI processing
We use AI (Anthropic's Claude) to write the training content — nano-lessons and quizzes — offline, before it's published. The AI does not process employee or customer personal data, and no AI runs on your data in production. Anthropic processes data under a data processing agreement and does not train on our input.
4. Data processors and sub-processors
We use the following data processors. For providers outside the EU/EEA, transfers are based on the European Commission's adequacy decision (the EU-U.S. Data Privacy Framework) and/or Standard Contractual Clauses (SCCs):
| Provider | Service | Country | Transfer basis |
|---|---|---|---|
| Anthropic PBC | AI authoring of training content (offline) | USA | DPF/SCC |
| Brevo (Sendinblue SAS) | Outgoing transactional and notification email (e.g. email verification) | Frankrig | — |
| Cloudflare, Inc. | Network, TLS, and DDoS protection | USA | DPF/SCC |
Hosting takes place on our own infrastructure in Denmark.
If you pay by card, your card details and payment data are processed by Revolut (Revolut Bank UAB, Lithuania) as an independent data controller under payment legislation — not as our data processor. We never receive your full card number. Revolut's own privacy policy applies to that processing.
5. Disclosure
We only disclose information when necessary to deliver the service, when required by law, or with consent. We never sell your data.
6. Retention and deletion
Specific retention periods are set out in the table in section 2. Accounting records are kept for 5 years from the end of the financial year, in accordance with the Danish Bookkeeping Act. The data is then deleted or anonymised.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection (GDPR Art. 15–21). If you have given consent, you can withdraw it at any time with future effect. Write to info@weakestlink.io — we will respond within one month of your request. If you're an employee of a customer, you can also contact your employer, who is the data controller (see Annex A).
8. Complaints
You can lodge a complaint about our processing with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk. If you are in the UK or Ireland, you can also complain to the ICO (ico.org.uk) or the DPC (Ireland).
9. Cookies
We only use strictly necessary cookies: a session cookie when you log in, and — if you choose a language yourself in the language switcher — a cookie that remembers your choice. Both deliver a function you have specifically requested, and therefore do not require consent. We do not use any tracking or marketing cookies, so no cookie-consent banner is shown.
10. Changes
Material changes to this policy will be announced on weakestlink.io and/or by email.
Annex A — division of roles in employee training
When a company (your employer) uses weakestlink for security training and phishing simulation, the company is the data controller for the employee data, and weakestlink acts as the data processor. Processing takes place per instructions in a data processing agreement entered into at setup. This policy then applies only to the data for which we are ourselves the data controller (the customer's contact and billing data, plus operations).
Phishing simulations are only run on a documented legal basis (consent from your workplace and an approved legitimate-interest assessment), and results are always shown in aggregate — never as exposing individual employees. We never store what an employee types into a simulation, only that an incident occurred.