# Stoïk Protect Privacy Policy

### What is the purpose of our Privacy Policy?

STOIK France, which manages the Stoik Protect platform, STOIK SAS, STOIK GmbH, STOIK GmbH Austria, STOIK Iberia and STOIK-CERT (hereinafter "STOIK") attach great importance to the protection and confidentiality of your personal data, which we consider to be a guarantee of our reliability and trustworthiness.

As such, our Privacy Policy clearly demonstrates our commitment to ensuring compliance within STOIK with the applicable rules on personal data protection, in particular those of the General Data Protection Regulation ("GDPR").

In particular, our Privacy Policy aims to inform you about how and why we process your personal data in the context of the services we provide to you.

### Who is our Privacy Policy intended for?

Our Privacy Policy applies to you, regardless of your place of residence, as long as you are at least 15 years old and are a user of our Stoik Protect platform.

If you are under the legal age specified above, you are not authorised to use our services without the prior and explicit consent of one of your parents or the holder of parental authority, which must be sent to us by email at <dpo@stoik.io>.

If you believe that we hold personal data about your children without your consent, please contact us at the dedicated address above.

### Why do we process your personal data and on what basis?

We process your personal data primarily for the following reasons:

* To use and benefit from our service and all its features (e.g. phishing simulator management, emergency call management, etc.) on the basis of our general terms and conditions of use.
* To manage user accounts (e.g. account creation, access to the service and account deletion) on the basis of our general terms and conditions of use.
* To score/rate your profile in order to activate or deactivate features of our services based on our legitimate interest.
* To write free comments on the management of your files based on our general terms and conditions of use.
* To communicate with our support service via our chat/chatbot based on our terms and conditions of use.
* To receive our technical emails (e.g. password changes, etc.) that are essential to the proper functioning of our service based on our terms and conditions of use.
* To be able to download and import documents onto our platform based on our terms and conditions of use.
* To guarantee and enhance the security and quality of our services on a daily basis (e.g. statistics, data security, etc.) based on our legal obligations, our terms and conditions of use and our legitimate interest in ensuring the proper functioning of our services.

Your data is collected directly from you when you use our Stoik Protect platform, and we undertake to process your data only for the reasons described above.

#### How do we handle data accessed through Google APIs?

As part of its services, Stoïk provides the Stoïk Protect platform, which includes a module for sending phishing awareness campaigns to the customer's employees. Through this module, Stoïk processes certain categories of data related to the Google Workspace environment via the Google Admin SDK Directory API. As such, we inform you that Stoïk acts as a processor within the meaning of Article 28 of the GDPR, in the context of providing the Stoïk Protect platform.

* Why we process your data and on what basis: Stoïk enables the client to synchronise groups of employees, based on the performance of the contract concluded with the client.<br>
* Categories of data processed: Stoïk processes identification data and professional contact details from the customer's Google Workspace directory (e.g. surname, first name, email address, job title, company, etc.) and stores them for the duration of the service provision.

As a processor, Stoïk undertakes to use its customers' personal data solely for the purpose of providing the service and exclusively on the basis of documented instructions from the customer.

Our use and transfer of information received from Google APIs complies with Google's policy on API service user data, including limited use requirements.

For further information, please refer to the other sections of this policy.

### What personal data do we process and for how long?

We have summarised below the categories of personal data and their respective retention periods:

* Professional identification data (e.g. surname, first name, position, company, etc.) and contact details (e.g. email address and work telephone number, etc.) are retained for the entire duration of the service provision, plus the statutory limitation periods, which are generally 5 years.
* Email address for receiving our technical messages is retained until your account is deleted.
* Connection data (e.g. logs, IP address, etc.) stored for a period of 1 year.

Once the applicable retention periods have expired, the deletion of your personal data is irreversible and we will no longer be able to communicate it to you after this period. At most, we can only retain anonymous data for statistical purposes.

Please also note that in the event of a dispute, we are obliged to retain all data concerning you for the entire duration of the case, even after the expiry of the retention periods described above.

### What rights do you have to control the use of your personal data?

The applicable data protection regulations grant you specific rights that you can exercise at any time and free of charge in order to control how we use your data.

* Right to access and copy your personal data, provided that this request does not conflict with business secrecy, confidentiality or the secrecy of correspondence.
* Right to rectify personal data that is inaccurate, obsolete or incomplete.
* Right to object to the processing of your personal data when it is based on our legitimate interest, unless there are legitimate and compelling reasons that justify this processing and prevail over your interests, rights and freedoms.
* Right to request the erasure (“right to be forgotten”) of your personal data that is not essential to the proper functioning of our services.
* Right to restrict your personal data, which allows you to photograph the use of your data in the event of a dispute over the legitimacy of processing.
* Right to data portability, which allows you to retrieve some of your personal data in order to store it or easily transfer it from one information system to another.
* Right to give instructions on the fate of your data in the event of death, either through you, a trusted third party or a beneficiary.

For a request to be considered, it must be made directly by you or your representative at <dpo@stoik.io>.

Requests cannot be made by anyone other than you or your representative. We may therefore ask you to provide proof of identity if we have any doubts about the identity of the applicant, as well as proof of representation.

We will respond to your request as soon as possible, within a maximum of one month of receipt, unless the request is technically complex or we receive numerous requests at the same time. In this case, the response time may be up to three months.

Please note that we may refuse to respond to any excessive or unfounded requests, particularly if they are repetitive in nature.

### Who can access your personal data?

Your personal data is processed by our teams, including those of other entities within the group, and by our technical service providers for the sole purpose of operating our service.

We would like to point out that we check all our technical service providers before recruiting them to ensure that they strictly comply with the applicable rules on personal data protection.

### Can your personal data be transferred outside the European Union?

The personal data processed by our Stoik Protect platform is hosted exclusively on servers located within the European Union.

Furthermore, we do our utmost to use only technical tools whose servers are also located within the European Union. If this is not the case, we take great care to ensure that they implement the appropriate safeguards required to ensure the confidentiality and protection of your personal data.

### How do we protect your personal data?

We implement the following technical and organisational measures to ensure the security of your personal data on a daily basis and, in particular, to combat any risk of destruction, loss, alteration or disclosure.

| Technical security measures                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Organisational security measures                                                                                                                                                                                                                                                                                 |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Encryption of user passwords (front end)</li><li>Encryption of user passwords (back end)</li><li>Double user authentication (front end)</li><li>Two-factor user authentication (back-end)</li><li>Complex passwords required for users (front end) when logging in</li><li>Complex passwords required for users (back end) when logging in</li><li>Encryption of the "users" database at rest and in transit</li><li>A/B testing</li><li>HTTPS protocol</li><li>Regular intrusion tests</li><li>Access traceability</li><li>Antivirus and firewall on STOIK team terminals</li><li>Complex passwords on STOIK team terminals</li><li>BCP/DRP for STOIK teams</li><li>VPN for STOIK teams</li><li>Duplication of the user database on backup servers</li><li>Managed Detection and Response (MDR)</li><li>Multi-factor authentication (MFA)</li><li>(more information available on our <a href="https://trust.stoik.io/">trust portal</a>)</li></ul> | <ul><li>Information systems charter</li><li>Authorisation and password management policy</li><li>Information Systems Security Policy</li><li>Data breach management procedure</li><li>Individual Rights Management Procedure</li><li>Rules of Conduct</li><li>Team awareness and training twice a year</li></ul> |

### Do we use cookies when you browse our platform?

We guarantee that we do not use any advertising cookies for the operation of this platform.

However, we would like to inform you that we use statistical cookies when you browse our platform. For more information, please see our Cookie Policy.

### Who can you contact for more information about the use of your personal data?

To best ensure the protection and integrity of your data, we have officially appointed an independent Data Protection Officer (“DPO”) to our supervisory authority.

You can contact our DPO at any time, free of charge, at <dpo@stoik.io> to obtain more information or details about how we process your data.

### How can you contact the CNIL?

You can contact the “Commission nationale de l'informatique et des libertés” or “CNIL” at any time at the following address: CNIL Complaints Department, 3 place de Fontenoy – TSA 80751, 75334 Paris Cedex 07 or by telephone on 01.53.73.22.22.

### Can the Privacy Policy be changed?

We may modify our Privacy Policy at any time to adapt it to new legal requirements and to new processing methods that we may implement in the future.

Certified compliant by Dipeeo ®

<br>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.stoik.io/stoik-protect-privacy-policy.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
