Summary
This article answers the most frequently asked questions from data protection officers about how personal information is handled within the SMARTFENSE platform: what data enters the system, where it resides, how long it is retained, and who can access it.
For a more detailed analysis, you can read the full article on the SMARTFENSE blog: What data does your awareness program leave behind and how long does it live?
Data that enters the platform
The minimum data required to add a user is first name, last name, and email address. From activity on the platform, behavioral metrics are generated: opens, clicks, completions, and risk scores.
The platform does not store credentials entered in phishing simulations. Password fields are either disabled or only verify whether the user entered something, without recording the actual value.
Where data is stored
The primary infrastructure operates in Dublin, Ireland (EU-west-1 region). Protection measures include:
- AES-256 encryption at rest
- TLS 1.2/1.3 encryption in transit
- Separate database schemas per client
Some auxiliary services operate outside the EU through declared sub-processors.
Retention periods
| Data type | Retention period |
|---|---|
| Daily backups | 90 days |
| System logs | 1 year |
| Service data after subscription ends | 30 days (for export or deletion) |
To calculate the actual lifespan of the data, the data protection officer must add the organization's internal retention policy to the provider's retention period.
💡 Best practices
- Review the organization's retention policy before defining the data lifecycle within the platform.
- Coordinate with the security team to export or delete data before the subscription expires.
- Consult the list of declared sub-processors if the client operates in jurisdictions with international data transfer restrictions.