Privacy Policy
How NOUSEC handles personal data across the nousec.com website, the platform at login.nousec.com, and the Phishing Reporter add-on for Gmail.
Last updated: 24 September 2026
This policy explains what personal data NOUSEC collects, why, where it is processed, and the rights people have over it. It covers three things:
- The nousec.com website, including the "Book a demo" form.
- The NOUSEC platform at login.nousec.com, which our customers use to run security-awareness programmes for their employees.
- The NOUSEC Phishing Reporter, our Google Workspace (Gmail) add-on.
NOUSEC ("NOUSEC", "we", "us") is based in İzmir, Türkiye.
1. Our role: controller or processor
- Website visitors and people who contact us. We decide why and how this data is used, so we are the data controller.
- Employees of our customers. When a customer uses the NOUSEC platform or the Phishing Reporter, the customer (the employer) decides which employees are included and for what purpose. The customer is the data controller and NOUSEC is the data processor. We process that data only on the customer's documented instructions, under a data processing agreement (DPA). If you are an employee of one of our customers, please send requests about your data to your employer first. We will help them respond.
We process personal data in line with the EU General Data Protection Regulation (GDPR). As a company based in Türkiye, we also comply with applicable Turkish data protection law.
2. The nousec.com website
What we collect.
- "Book a demo" form: your name, work email, company, and (optionally) country and area of interest. The form sends this to us as an email so we can reply. We do not add you to a mailing list.
- Technical data: our website is served through Cloudflare, which processes IP addresses and request metadata to deliver the site and protect it from abuse.
What we do not do. We do not run third-party analytics, advertising trackers or session recording on nousec.com. The site does not set cookies for tracking.
Legal basis. Replying to your request (GDPR Art. 6(1)(b), steps prior to a contract) and our legitimate interest in operating a secure website (GDPR Art. 6(1)(f)).
3. The NOUSEC platform (login.nousec.com)
When a customer uses the platform, we process data about the customer's employees on the customer's behalf:
- Identity and work details: name, work email, phone number (only if the customer adds it), job title, department, role.
- Account security: password hash (bcrypt), multi-factor authentication secret, session data.
- Programme activity:
- results of phishing simulations (for example: email opened, link clicked, data entered, message reported);
- training progress, quiz scores and certificates;
- policy acknowledgements.
- Derived data: a human-risk score, points and badges computed from the activity above.
- Technical data: IP address, user agent, audit logs.
- Optional modules, only if the customer enables them:
- breached-credential records for the customer's own domain (dark web monitoring);
- phone numbers and call data for SMS and voice simulations;
- voice samples for deepfake-awareness scenarios.
We use this data only to provide the service the customer has contracted for. We do not sell personal data, and we do not use customer data to advertise.
4. The NOUSEC Phishing Reporter (Gmail add-on)
The Phishing Reporter adds a "Report phishing" button to Gmail. A customer's Google Workspace administrator installs it for their organisation. Installation and troubleshooting are documented in the Phishing Reporter for Gmail guide.
When it reads anything. The add-on reads a message only when the employee opens that
message and presses Report. It uses Google's
gmail.addons.current.message.action permission, which gives access to the single open message,
and only during that action. It cannot read other messages, the inbox, contacts or calendar.
It cannot send, delete or move email. The reported message stays in the employee's mailbox.
What it sends to NOUSEC when an employee presses Report:
- the sender address, the subject and the date;
- these technical headers:
Message-ID,Reply-To,Return-Path,Authentication-Results, and NOUSEC's own simulation identifier if the message was one of our simulations; - the web links (URLs) found in the message, up to 50;
- attachment names, sizes and file types. The attachment files themselves are never sent;
- a Google-signed identity token, so we can confirm which Google Workspace user made the report and which organisation they belong to.
The add-on does not send the message body text or the attachment files.
Why. To:
- record the report for the employee's security team;
- check whether the message was a NOUSEC simulation, and if so credit the employee for reporting it;
- help the security team decide whether a real message is a threat.
Threat analysis (only if the customer enables it). If the customer's organisation turns on analysis engines, links and indicators from a reported message may be checked against threat-intelligence services (see section 6). If the customer enables AI features, report details may be processed by an AI model provider (see section 6).
Google user data: Limited Use. NOUSEC's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide the reporting feature described above;
- we do not use it for advertising;
- we do not sell it;
- no human reads it, except where the customer's security team reviews its own reports, where needed for security or to comply with law, or with the user's consent.
5. Where data is stored
Platform data is stored and processed in the European Union:
- the application runs on Render in Frankfurt, Germany;
- the database runs on Neon in AWS eu-central-1, Frankfurt, Germany;
- files are stored in Cloudflare R2's EU jurisdiction.
Transactional and simulation email is sent through Resend on Amazon SES in eu-west-1 (Ireland).
6. Sub-processors
We use the following service providers to run NOUSEC. Each one processes data only as needed for the service listed.
| Provider | Purpose | Location |
|---|---|---|
| Render | Application hosting | Frankfurt, Germany |
| Neon | Database | Frankfurt, Germany (AWS eu-central-1) |
| Cloudflare | DNS, content delivery, security; website hosting; file storage (R2) | Global edge network; R2 in EU jurisdiction |
| Resend / Amazon SES | Email delivery | Ireland (eu-west-1) |
| Runs the Gmail add-on inside the customer's Google Workspace | Google Cloud | |
| Twilio | SMS and voice simulations (only if enabled) | Disclosed on request — privacy@nousec.com |
| ElevenLabs | Synthetic voice for deepfake-awareness scenarios (only if enabled) | Disclosed on request — privacy@nousec.com |
| AI model provider | AI features such as template generation and report classification (only with the customer's consent) | Disclosed on request — privacy@nousec.com |
| VirusTotal, urlscan.io, Google Safe Browsing, AbuseIPDB, URLhaus | Checking links, files and IP addresses from reported messages (only if the customer enables analysis engines) | Provider's own infrastructure |
| Have I Been Pwned | Checking the customer's domain for breached credentials (only if enabled) | Provider's own infrastructure |
Where a provider processes personal data outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and on the equivalent transfer mechanisms required by Turkish data protection law. We will update this list before adding a new sub-processor that handles customer personal data. Customers with a DPA are notified in advance.
7. How long we keep data
- Customer platform data, including Phishing Reporter reports, is kept for as long as the customer's contract is active. The customer can delete users and data during the contract. When the contract ends, we delete the customer's organisation data within 30 days of the customer's request, unless the law requires us to keep it longer.
- "Book a demo" enquiries are kept for as long as needed to handle the enquiry and any business relationship that follows, and deleted on request.
8. Security
We protect data with:
- encryption in transit (TLS);
- encryption at rest provided by our database and storage providers;
- bcrypt password hashing and optional multi-factor authentication;
- per-organisation access controls.
Every database query that returns customer data is scoped to the customer's organisation. To report a vulnerability, see nousec.com/security.
9. Your rights
Under the GDPR you can ask to:
- access your personal data;
- correct it;
- delete it;
- restrict or object to its processing;
- receive it in a portable format;
- learn whether it has been transferred and to whom.
You can also complain to a supervisory authority — in the EU, your local data protection authority; in Türkiye, the Personal Data Protection Authority.
- If you are a website visitor or contacted us: write to privacy@nousec.com.
- If you are an employee of a NOUSEC customer: contact your employer, who controls your data. If you write to us, we will pass your request to them and help them answer it.
We respond within 30 days.
10. Children
NOUSEC is a business service. It is not directed at children, and we do not knowingly collect data from anyone under 18.
11. Changes
If we change this policy, we will update the date at the top. If a change materially affects how customer personal data is processed, we will tell customers before it takes effect.
12. Contact
NOUSEC, İzmir, Türkiye
Privacy requests: privacy@nousec.com
Phishing Reporter and Google Workspace Marketplace: applications@nousec.com