Privacy notice
Last updated: 6 September 2026
AfriPhish is a product of SilverLock SARL, a company registered in Morocco. This notice explains what personal data we collect when you visit afriphish.com and its sub-domains, use the free tools hosted there, contact us, or open an account on the AfriPhish platform — and what your rights are. We wrote it to be read, not skimmed; if anything is unclear, ask us at privacy@afriphish.com.
1. Who is responsible
The data controller for the website, the free tools and your platform account is:
SilverLock SARL
Bluzelle Centre, 56 rue Brahim Roudani, Imm. 56, Appt. N°2, Océan, 10040 Rabat, MoroccoEmail: privacy@afriphish.com
SilverLock SARL is subject to Morocco's Law 09-08 on the protection of individuals with regard to the processing of personal data and to the supervision of the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel). Where the EU or UK GDPR, South Africa's POPIA, Nigeria's NDPA, Kenya's DPA or another law applies to you, you have the rights those laws give you and we honour them.
2. The AfriPhish platform: who does what
Customer organisations use the platform to enrol their own employees in security-awareness training and phishing simulations. For those employees' data, the customer is the controller and SilverLock is the processor, acting on the customer's instructions under a data processing agreement. If you are an employee who received a simulation or a training invitation, your employer decides why and how your data is used; contact them first, and we will support any request they pass to us.
This notice therefore covers, in full, the situations where we decide the purposes: visiting the website, using the free tools, writing to us, and the accounts of the administrators who sign their organisation up.
3. What we collect and why
3.1 Browsing the website
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| Server logs: IP address, time, page requested, browser type | Keeping the site secure and available, detecting abuse | Legitimate interest | 30 days |
| Your theme, language and cookie choice | Remembering your preferences | Legitimate interest (strictly necessary storage) | Until you clear it; consent choice 180 days |
| Analytics events (pages viewed, clicks, scroll depth, approximate region) via Google Analytics 4 and Microsoft Clarity | Understanding how the site is used so we can improve it | Consent — nothing is loaded until you accept in the cookie banner | GA4: 14 months; Clarity: 13 months |
Details of every cookie are in our cookie policy. We do not use advertising or social-media trackers, and we do not build profiles of visitors.
3.2 Human Risk Maturity Assessment (free tool)
- Your answers and optional organisation profile (country, industry, size) — to compute your score and build your report. We store a one-way hash of your IP address for rate-limiting and abuse detection; never the address itself. Legal basis: legitimate interest in providing the tool you asked for. Anonymous responses are deleted after 90 days.
- Contact details you give to receive your full report (name, work email, company, optional phone) — to send you the report link. Legal basis: performance of the service you requested. Kept until you ask us to delete them.
- Marketing opt-in — a separate, unticked checkbox. Only if you tick it do we send you anything beyond your report. Legal basis: consent, withdrawable at any time via the link in every email or by writing to us.
3.3 Domain spoofing checker (free tool)
You enter a domain name; we query its public DNS records (SPF, DKIM, DMARC) and show a grade. We log the domain queried and a hash of your IP for rate-limiting, for 30 days. A domain name is normally not personal data; if yours is, the legitimate-interest basis above applies.
3.4 Writing to us
If you email sales or privacy addresses, we keep the correspondence for as long as needed to answer you and to keep a record of our dealings, then for the legal limitation period. Legal basis: legitimate interest and, where relevant, taking steps at your request before a contract.
3.5 Opening an account on the AfriPhish platform
- Identity and login — name, work email address, hashed credentials or single sign-on identity, two-step-verification status, sign-in times and IP addresses. Our identity provider is Clerk (Clerk, Inc., United States). Legal basis: performance of the contract and legitimate interest in securing accounts.
- Organisation profile — company name, size, industry, region, job title, optional phone number and logo, collected in the onboarding questionnaire to configure your workspace. Legal basis: performance of the contract.
- Billing — contact and invoicing details; we do not store card numbers. Legal basis: contract and legal obligation (accounting records, kept 10 years under Moroccan law).
- Audit and usage logs — administrator actions in the workspace. Legal basis: legitimate interest in security and in providing you with an audit trail; kept for the life of the account plus 12 months.
We refuse sign-ups from consumer mailbox providers because the platform sends simulated phishing from our infrastructure; we need to know a real organisation stands behind each workspace.
4. Who receives your data
We do not sell personal data. We share it only with providers who process it for us under contract, and only as needed to run the service:
| Provider | Role | Location |
|---|---|---|
| Google Cloud (Google Ireland Limited) | Hosting of the website, API and database (Cloud Run and Cloud SQL, region europe-west1, Belgium) | EU |
| Clerk, Inc. | Sign-up, sign-in and two-step verification for platform accounts | United States |
| Resend, Inc. | Transactional email delivery (reports, invitations, notifications) | United States / EU |
| Meta Platforms (WhatsApp Business) | WhatsApp messages, only for customers who enable that channel | Ireland / United States |
| Google Analytics 4, Microsoft Clarity | Website analytics, only with your consent | EU / United States |
We may also disclose data where the law requires it, to protect our rights or the safety of others, or to a successor if our business is transferred (you would be told).
5. International transfers
Our servers are in the European Union. Some providers above process data in the United States. For those transfers we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses, together with the safeguards required by Law 09-08 for transfers out of Morocco. You can ask us for a copy of the relevant safeguards.
6. How long we keep data
The retention periods are stated section by section above. As a rule: we keep data for as long as needed for the purpose we collected it, then delete or anonymise it, except where a law requires us to keep it longer (for example accounting records). Platform customer data is deleted within 30 days of the end of the contract, as set out in our terms of service.
7. Security
We protect data with encryption in transit (TLS) and at rest, two-step verification for administrator accounts, role-based access, audit logging, network isolation of the database, and regular reviews. No system is perfectly secure; if a breach affects you, we will tell you and, where required, the competent authority, without undue delay.
8. Your rights
You have the right to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data, where we have no overriding reason to keep it;
- object to processing based on legitimate interest, and to direct marketing at any time;
- withdraw consent for analytics (use the "Cookie settings" link in the footer) or marketing (link in every email), without affecting what was done before;
- restrict processing, and receive your data in a portable format, where the law applying to you provides for it;
- complain to a supervisory authority: in Morocco the CNDP (www.cndp.ma), or the authority of the country where you live.
To exercise a right, email privacy@afriphish.com or write to the address in section 1. We answer within 30 days and may ask you to confirm your identity first. There is no charge unless a request is manifestly unfounded or excessive.
9. Children
The website and the platform are aimed at organisations and their adult staff. We do not knowingly collect data from anyone under 18; if you believe we have, contact us and we will delete it.
10. Changes to this notice
We update this notice when our processing changes. The date at the top tells you when. For significant changes we will show a notice on the site or, for account holders, send an email.
11. Contact
Data protection: privacy@afriphish.com · Commercial: sales@afriphish.com SilverLock SARL, Bluzelle Centre, 56 rue Brahim Roudani, Imm. 56, Appt. N°2, Océan, 10040 Rabat, Morocco