1. Who is responsible for your data
FENSIVO acts in two distinct roles, depending on the context in which the data is collected:
As Data Controller, when you browse the Website, request a demo, communicate with us, or apply for a job opening. In these cases, FENSIVO determines the purposes and means of the processing.
As Data Processor, when we process the personal data of our clients' employees within the Platform. In this case, the client company is the Controller and defines the purposes; FENSIVO acts on its behalf and following its instructions, in accordance with the data processing agreement signed between the parties.
2. What personal data we process
2.1. When FENSIVO acts as Controller
The data is provided directly by you or generated by your interaction with the Website:
| Category | Examples |
|---|---|
| Identification | First name, last name, job title |
| Contact | Email, phone, company |
| Professional | Company, job title, LinkedIn profile, tenure |
| Communications | Content of your inquiries, date and subject, recordings of sales meetings when you authorize them |
| Applications | Information included in your résumé and selection process |
| Browsing | IP address, device and browser type, operating system, pages visited, date and time of connection, collected through cookies |
2.2. When FENSIVO acts as Processor
Within the Platform, we process the data of the client company's employees that the company provides to us or that is generated by use of the service:
| Category | Examples |
|---|---|
| Registration | Name, corporate email, job title, department, country, language |
| Simulation behavior | Reactions to phishing simulations (email ignored, opened, reported, credentials submitted), adaptive test results |
| Training | Microtraining history, completed modules, awareness level |
| Credential monitoring | Detection of corporate emails exposed in public breach databases |
| Risk score | Individual and aggregate risk score calculated by the Platform |
Some open-source information enrichment features are in development and will only be activated with the prior authorization of the client company and in accordance with applicable regulations.
FENSIVO does not intentionally collect sensitive data. If a feature were to require it, the prior and express authorization of the data subject will be requested in accordance with the law.
2.3. Data obtained from Google Workspace
If the client company's administrator connects the Google Workspace integration, Fensivo obtains, via the Google Admin SDK Directory API in read-only mode, the domain employees' basic profile data: name, corporate email, job title, department/area, and direct manager. Fensivo does not access emails, files, calendars, or any other content of the Google accounts.
This data is used exclusively to create and keep synchronized the list of employees who receive the simulations and training contracted by the client company, in accordance with the purposes described in this policy. It is not sold, not shared with third parties other than the processors described here, and not used for advertising or to train artificial intelligence models.
Fensivo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. The administrator may revoke access at any time from the Fensivo settings or the Google Admin console, and may request deletion of the synchronized data.
3. Why we process your data
3.1. As Controller
| Purpose | Legal basis |
|---|---|
| Handle demo and contact requests | Pre-contractual measures and consent |
| Send commercial and marketing communications | Data subject's consent |
| Manage personnel selection processes | Pre-contractual measures and consent |
| Operate and improve the Website and Platform, measure audience and protect their security | FENSIVO's legitimate interest and consent for cookies |
| Invoice and manage the contractual relationship | Performance of the contract |
| Address legal requirements and exercise or defend rights | Compliance with a legal obligation and legitimate interest |
3.2. As Processor
When we act as Processor, we process the data solely to provide the services contracted by the client company: creating and managing access accounts, running simulations and training, monitoring exposed credentials, generating the risk score, and producing awareness statistics. The client company is the Controller and defines the applicable legal basis with respect to its employees.
4. Who we share your data with
FENSIVO does not sell personal data. We may share it with the following recipients, always under agreements that guarantee its protection:
- Technology providers that support the operation of the Website and the Platform, such as cloud hosting providers, analytics tools, email delivery, and support.
- Client companies, with respect to the data of their own employees processed within the Platform.
- Administrative or judicial authorities, when there is an express and justified legal requirement.
- External advisors, in the context of audit, merger, acquisition, or corporate reorganization processes.
5. International data transfers
FENSIVO operates from Colombia, but some of its technology providers are located in other countries. This means your personal data may be transferred or transmitted outside Colombia.
When this occurs, FENSIVO adopts the measures required by Colombian law to guarantee an adequate level of protection, including signing contractual clauses with providers and verifying that the receiving country offers equivalent guarantees or that the data subject has granted authorization.
For data subjects located in the European Economic Area, FENSIVO processes their data in accordance with the principles of the General Data Protection Regulation (GDPR). In the absence of an adequacy decision, transfers are covered by standard contractual clauses approved by the European Commission. You may request a copy of these safeguards by writing to contacto@fensivo.co.
6. How we protect your data
FENSIVO implements reasonable technical, human, and administrative measures to protect personal data against unauthorized access, loss, alteration, or improper disclosure. These measures include encryption of information, access controls, and confidentiality commitments with its personnel and providers.
No system is completely infallible. If you identify a vulnerability or wish to report a security incident, you can write to contacto@fensivo.co.
7. How long we keep your data
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, or for the period required by law. As a general reference:
- Demo request data: up to three (3) years for commercial purposes.
- Contact request data: until the request is fully resolved.
- Job application data: up to two (2) years from the last contact, unless deletion is requested.
- Browsing data: up to thirteen (13) months from its collection.
- Data processed as Processor: for the duration of the contractual relationship with the client company and, once terminated, it is deleted or anonymized unless there is a legal retention obligation.
8. What your rights are
As a data subject, Law 1581 of 2012 grants you the rights to know, update, rectify, and delete your data, request proof of authorization, be informed about the use given to your data, revoke authorization where applicable, and file complaints with the Superintendence of Industry and Commerce.
When FENSIVO acts as Controller, you may exercise these rights by writing to contacto@fensivo.co. We will address your request within the time frames provided by law: inquiries within a maximum of ten (10) business days and claims within a maximum of fifteen (15) business days, extendable as provided by the regulation.
When FENSIVO acts as Processor, you must direct your request to the company you work for, which is the Controller of your data. If you contact us directly, we will forward your request to that company.
For data subjects in the European Economic Area, the GDPR additionally grants the rights of access, rectification, erasure, restriction of processing, portability, and objection, which may be exercised through the same means.
9. Changes to this Policy
FENSIVO may modify this Policy at any time to reflect changes in the Website, the Platform, or applicable regulations. Updates will be published on the Website with their effective date. We recommend reviewing it periodically.
Company identification
- FENSIVO S.A.S.
- NIT 902.017.093-1
- Calle 18 A SUR No. 41 A 29, Medellín, Colombia
- contacto@fensivo.co