Skip to content
MakSisu Book a walkthrough

Privacy notice

Last updated 08 September 2026

This notice explains what personal data MakSisu Technologies collects through this website and through the training programs we run for client organisations, why we collect it, and what rights you have over it.

DECISION NEEDED — Insert the registered legal entity name, company number and registered address. A privacy notice without an identifiable controller is not compliant.

Who the controller is

For data collected through this website — the booking form and site analytics — MakSisu Technologies is the data controller.

For personal data inside a client's training program — staff names, email addresses, exercise completion records, phishing-simulation results — the client organisation is the controller and MakSisu is a processor, acting on the client's documented instructions under a written data processing agreement. If you are an employee of a client and want your training records corrected or erased, contact your own employer first; we act on their instruction.

What we collect through this website

DataWhyLegal basis
Work email addressTo reply to a walkthrough request and send a calendar invitationSteps taken at your request prior to entering a contract (GDPR Art. 6(1)(b))
Company size, preferred time slotTo prepare a relevant walkthrough and quoteSame as above
IP address and country, brieflyRate-limiting the booking form against automated abuseLegitimate interest in keeping the service available (Art. 6(1)(f))
Aggregate page viewsUnderstanding which pages are usefulLegitimate interest (Art. 6(1)(f))

Cookies

This site sets no cookies and uses no cross-site tracking. Analytics are collected via Cloudflare Web Analytics, which measures page views without cookies, without fingerprinting, and without building a profile of you across sites. That is why you are not being shown a consent banner — there is nothing to consent to.

What we collect when running a training program

On a client's instruction we process the staff details needed to enrol people and record their progress: name, work email address, department or role where the client supplies it, exercise completion and scores, and phishing-simulation outcomes such as whether a simulated link was opened.

Phishing simulations are run only with the client organisation's written authorisation, against that organisation's own staff. We do not run simulations against anyone outside the client's authorisation, and results are reported to the client in aggregate by default. Individual-level results are shared only where the client has asked for them and has a lawful basis for receiving them.

Who we share data with

We keep the number of subprocessors deliberately small:

SubprocessorPurposeLocation
Cloudflare, Inc.Website hosting, security, cookieless analyticsGlobal edge network
[Email provider]Transactional email — invitations, reminders, notifications[Region]
[Training delivery platform]Delivery of interactive training exercises[Region]

We do not sell personal data, and we do not share it with advertisers.

International transfers

We serve clients in multiple regions, so personal data may be processed outside your country. Where data leaves the UK or EEA, transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or an adequacy decision.

How long we keep it

Your rights

Depending on where you live, you have some or all of the following rights: access to your data, correction of inaccuracies, erasure, restriction of processing, objection to processing based on legitimate interests, data portability, and the right not to be subject to solely automated decisions with legal effects. We make none such decisions.

To exercise any of these, email privacy@maksisu.com. We respond within 30 days. If you are unhappy with our response you may complain to your national supervisory authority — in the UK the Information Commissioner's Office, in the EU your member-state authority, in Canada the Office of the Privacy Commissioner.

Security

Our technical and organisational measures are described on the security page.

Changes

If we change this notice materially we will update the date above and, for active clients, notify the named contact directly.

Contact

Email privacy@maksisu.com for anything in this notice.

DECISION NEEDED — Do you need a designated representative in the EU or UK? If you have no establishment there but monitor or offer services to people there, GDPR Article 27 may require one. Confirm with counsel and add the details here if so.