This notice explains what personal data MakSisu Technologies collects through this website and through the training programs we run for client organisations, why we collect it, and what rights you have over it.
DECISION NEEDED — Insert the registered legal entity name, company number and registered address. A privacy notice without an identifiable controller is not compliant.
Who the controller is
For data collected through this website — the booking form and site analytics — MakSisu Technologies is the data controller.
For personal data inside a client's training program — staff names, email addresses, exercise completion records, phishing-simulation results — the client organisation is the controller and MakSisu is a processor, acting on the client's documented instructions under a written data processing agreement. If you are an employee of a client and want your training records corrected or erased, contact your own employer first; we act on their instruction.
What we collect through this website
| Data | Why | Legal basis |
|---|---|---|
| Work email address | To reply to a walkthrough request and send a calendar invitation | Steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b)) |
| Company size, preferred time slot | To prepare a relevant walkthrough and quote | Same as above |
| IP address and country, briefly | Rate-limiting the booking form against automated abuse | Legitimate interest in keeping the service available (Art. 6(1)(f)) |
| Aggregate page views | Understanding which pages are useful | Legitimate interest (Art. 6(1)(f)) |
Cookies
This site sets no cookies and uses no cross-site tracking. Analytics are collected via Cloudflare Web Analytics, which measures page views without cookies, without fingerprinting, and without building a profile of you across sites. That is why you are not being shown a consent banner — there is nothing to consent to.
What we collect when running a training program
On a client's instruction we process the staff details needed to enrol people and record their progress: name, work email address, department or role where the client supplies it, exercise completion and scores, and phishing-simulation outcomes such as whether a simulated link was opened.
Phishing simulations are run only with the client organisation's written authorisation, against that organisation's own staff. We do not run simulations against anyone outside the client's authorisation, and results are reported to the client in aggregate by default. Individual-level results are shared only where the client has asked for them and has a lawful basis for receiving them.
Who we share data with
We keep the number of subprocessors deliberately small:
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, security, cookieless analytics | Global edge network |
| [Email provider] | Transactional email — invitations, reminders, notifications | [Region] |
| [Training delivery platform] | Delivery of interactive training exercises | [Region] |
We do not sell personal data, and we do not share it with advertisers.
International transfers
We serve clients in multiple regions, so personal data may be processed outside your country. Where data leaves the UK or EEA, transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or an adequacy decision.
How long we keep it
- Booking enquiries that don't become clients: 12 months, then deleted.
- Client training records: for the life of the engagement plus the period the client needs for audit evidence, then returned or deleted on the client's instruction. Typically 24 months.
- Rate-limiting records: one hour.
- Billing records: as required by tax law [confirm the period your jurisdiction requires — commonly 6–7 years].
Your rights
Depending on where you live, you have some or all of the following rights: access to your data, correction of inaccuracies, erasure, restriction of processing, objection to processing based on legitimate interests, data portability, and the right not to be subject to solely automated decisions with legal effects. We make none such decisions.
To exercise any of these, email privacy@maksisu.com. We respond within 30 days. If you are unhappy with our response you may complain to your national supervisory authority — in the UK the Information Commissioner's Office, in the EU your member-state authority, in Canada the Office of the Privacy Commissioner.
Security
Our technical and organisational measures are described on the security page.
Changes
If we change this notice materially we will update the date above and, for active clients, notify the named contact directly.
Contact
Email privacy@maksisu.com for anything in this notice.
DECISION NEEDED — Do you need a designated representative in the EU or UK? If you have no establishment there but monitor or offer services to people there, GDPR Article 27 may require one. Confirm with counsel and add the details here if so.