Phishmake

Phishmake Privacy Policy

Effective Date: August 21, 2026

Phishmake is a phishing simulation and cybersecurity awareness training platform operated by Cynomake Technologies Private Limited ("Cynomake," "Phishmake," "we," "us," or "our").

This Privacy Policy explains how we collect, use, store, protect, and disclose personal data when you use the Phishmake platform, website, managed services, or other services provided by us (collectively, the "Services").

1. Who This Privacy Policy Applies To

This Privacy Policy applies to:

  • Website visitors;
  • Prospective customers who contact us;
  • Customers and account owners who purchase or use the Services;
  • Authorized administrators and users of customer accounts;
  • Employees or other individuals whose email addresses are uploaded to the Phishmake platform by an authorized customer ("End Users"); and
  • Users of our Managed Services.

For End User data uploaded by a customer, the customer is generally responsible for determining that it has the appropriate authority and legal basis to provide such data to Phishmake for use in connection with the Services.

2. Information We Collect

Depending on how you interact with Phishmake, we may collect the following categories of information.

A. Customer and Account Information

This may include:

  • Name;
  • Business or organization name;
  • Business email address;
  • Phone number;
  • Job title;
  • Account and login information;
  • Billing and subscription information;
  • Communications with our sales, support, legal, or billing teams; and
  • Other information voluntarily provided by you.

B. Employee or End User Information

Customers may upload or provide employee or other authorized End User email addresses and related information for the purpose of operating phishing simulations and cybersecurity awareness training.

Depending on the Services used, this information may include:

  • Name;
  • Business or work email address;
  • Organizational or department information, where provided by the customer;
  • Phishing simulation participation and interaction data;
  • Training assignment, notification, and completion information; and
  • Other information necessary to deliver the Services selected by the customer.

3. How We Use Employee Email Addresses

We want to be clear about how employee and End User email addresses are handled.

Phishmake does not use employee email addresses uploaded by a customer for Phishmake's own marketing, promotional campaigns, newsletters, or unrelated transactional communications.

Employee or End User email addresses are used only as necessary to provide the Services, including:

  • Sending phishing simulation emails authorized or configured by the customer;
  • Sending cybersecurity awareness training assignment or notification emails;
  • Providing reminders or other communications directly related to assigned training or phishing simulations;
  • Recording participation, completion, and interaction data necessary for reporting and service delivery;
  • Maintaining and securing the Services; and
  • Meeting applicable legal, security, or compliance obligations.

We do not treat a customer's employee list as a marketing contact list for Phishmake.

4. How We Use Customer and Account Owner Information

We may use the information of customers, account owners, administrators, and other authorized contacts to:

  • Create and manage accounts;
  • Provide, operate, and support the Services;
  • Process subscriptions, payments, invoices, and billing matters;
  • Communicate important information regarding the account or Services;
  • Send service updates, security notices, product announcements, and operational communications;
  • Send newsletters, marketing communications, or information about Phishmake and its Services where permitted by applicable law;
  • Respond to inquiries, support requests, and complaints;
  • Prevent fraud, abuse, unauthorized access, and security incidents;
  • Improve and develop our Services; and
  • Comply with legal and regulatory obligations.

You may opt out of marketing or promotional communications where an opt-out option is provided or by contacting us. However, you may continue to receive essential service, billing, security, legal, and account-related communications.

5. Website and Technical Information

When you visit our website or use our Services, we may collect certain technical and usage information, such as:

  • IP address;
  • Browser type and version;
  • Device and operating system information;
  • Pages or features accessed;
  • Login and activity information;
  • Date and time of access;
  • Cookies or similar technologies, where used; and
  • Security and diagnostic logs.

We use this information to operate, secure, analyze, troubleshoot, and improve our Services.

6. Managed Services

Where a customer purchases Phishmake Managed Services, authorized Phishmake personnel may manage phishing simulations, cybersecurity awareness training activities, campaign configuration, reporting, scheduling, and other agreed activities on the customer's behalf.

We process customer-provided and End User information only to the extent reasonably necessary to provide the agreed Managed Services and operate the platform.

The customer remains responsible for ensuring that it has the necessary authority, permissions, notices, and legal basis to provide relevant employee or End User information to Phishmake.

7. How We Share Information

We do not sell employee email addresses or customer personal information for third-party marketing purposes.

We may share information with:

  • Service providers that help us operate the platform, hosting, infrastructure, email delivery, authentication, analytics, customer support, billing, or security;
  • Professional advisers, auditors, insurers, or similar service providers where reasonably necessary;
  • Authorities, regulators, or other parties where disclosure is required by applicable law; and
  • Other parties in connection with a merger, acquisition, corporate restructuring, financing, or sale of all or part of our business, subject to applicable law.

Third-party service providers are permitted to process information only as necessary to provide services to us or as otherwise permitted by applicable law and contractual arrangements.

8. Data Security

We take reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, or misuse.

These measures may include access controls, authentication, encryption or secure transmission where appropriate, monitoring, logging, and internal security procedures.

However, no system, network, or method of transmission or storage can be guaranteed to be completely secure.

9. Data Retention

We retain personal information only for as long as reasonably necessary for:

  • Providing the Services;
  • Maintaining customer accounts and subscriptions;
  • Security, fraud prevention, and troubleshooting;
  • Legal, tax, accounting, and compliance requirements;
  • Resolving disputes; and
  • Enforcing our agreements.

The applicable retention period may vary depending on the type of information and the purpose for which it is processed.

10. Customer Responsibilities for Employee Data

If you upload, import, or otherwise provide employee or End User information to Phishmake, you represent and warrant that you have the necessary authority and legal basis to do so.

You are responsible for providing any notices and obtaining any permissions or authorizations required under applicable laws or your internal policies in relation to your use of the Services.

11. International Data Processing

Your information may be processed in India and other locations where Phishmake or its service providers operate, subject to applicable legal requirements and appropriate safeguards where required.

12. Your Rights and Choices

Depending on applicable law, you may have rights regarding your personal information, including rights to access, correct, update, or request deletion of certain information.

Requests may be submitted using the contact details below. We may need to verify your identity and evaluate requests in accordance with applicable law.

If you are an employee or End User whose information was provided by a Phishmake customer, you may also need to contact your employer or organization directly because that organization controls the purpose and scope of the Services for its account.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Services, data practices, operational requirements, or legal obligations.

The updated version will be posted on our website with a revised Effective Date. Where required by applicable law, we will provide additional notice or obtain consent before material changes take effect.

14. Contact Us

For privacy-related questions, legal requests, complaints, or concerns, contact:

Phishmake / Cynomake Technologies Private Limited
Email: legal@phishmake.com

For billing-related matters, contact:
Email: billing@phishmake.com

© 2026 Phishmake. Operated by Cynomake Technologies Private Limited. All rights reserved.
Get Started

Ready to Strengthen Your Defense?

Empower your team with realistic phishing simulations to build resilience, recognize threats, and create a security-first culture across your organization.