Legal
Privacy Policy
Last Updated: September 26, 2026 · Effective Date: January 1, 2025
This Privacy Policy explains how Montimage collects, uses, and protects your personal data when using the Phishing Detection Training platform. We are committed to GDPR compliance and protecting your privacy.
1. Data Controller
The data controller responsible for your personal data is:
Montimage EURL
39 rue Bobillot
75013 Paris, France
Email: privacy@montimage.eu
Website: https://montimage.eu
2. What Data We Collect
2.1 Account Information
- Name (first and last name)
- Email address
- Password (encrypted)
- Organization affiliation (optional)
- Account creation date
2.2 Training Data
- Training session results and scores
- Email classification responses (phishing/legitimate)
- Threat identification selections
- Response timestamps and duration
- Learning progress and skill levels
- Achievement and badge data
- Certificate information
2.3 Technical Data
- IP address (handled by Firebase infrastructure; not stored by the app)
- Browser type and version
- Device information
- Language preference
- Session information
- Error logs (may contain account identifiers)
2.4 Organization Data
- Organization name and domain
- Member role and permissions
- Team statistics (aggregated)
3. How We Use Your Data
3.1 Platform Operation:
- User authentication and account management
- Delivering training content and exercises
- Tracking training progress and performance
- Generating certificates and badges
3.2 Service Improvement:
- Analyzing platform usage patterns (aggregated)
- Improving training content effectiveness
- Optimizing user experience
- Debugging and technical improvements
3.3 Communication:
- Sending important platform updates
- Notifying about new features
- Responding to support requests
- Security notifications (mandatory)
3.4 Research & Development:
- Improving phishing detection heuristics (aggregate statistics)
- Developing new training methodologies
- Academic research (aggregate statistics only)
Important Note:
We never sell your personal data to third parties. All research uses aggregate statistics only.
4. Legal Basis for Processing (GDPR)
Under GDPR, we process your data based on the following legal bases:
Contract Performance (Art. 6(1)(b) GDPR)
Processing necessary to provide the training service you've signed up for.
Consent (Art. 6(1)(a) GDPR)
For optional features like newsletters or organization participation. You can withdraw consent at any time.
Legitimate Interest (Art. 6(1)(f) GDPR)
Platform improvement, security, and fraud prevention.
Legal Obligation (Art. 6(1)(c) GDPR)
Compliance with applicable laws and regulations.
5. Data Storage & Retention
5.1 Storage Location:
Your data is stored on Google Cloud Platform (Firebase). The Firestore database, Authentication and Cloud Functions run in the regions configured for the deployment — see Section 10 for international-transfer safeguards.
5.2 Retention Periods:
- Active accounts: Data retained while account is active
- Inactive accounts: Data retained for 3 years after last login
- Deleted accounts: Personal data deleted within 30 days
- Training statistics: aggregate statistics that cannot identify you may be retained for research
- Legal records: Retained as required by law (typically 6 years)
5.3 Backup & Disaster Recovery:
Firebase-managed backups are used for disaster recovery.
6. Who We Share Data With
We do not sell your personal data. We only share data with:
Service Providers:
- Firebase/Google Cloud: hosting, authentication, database and serverless functions
- Processing is governed by Google's Firebase Data Processing and Security Terms
Your Organization:
- If you join an organization, its admins can see your name, email and training statistics (level, score, emails completed)
- You control your organization membership
Leaderboards:
- Username and scores are publicly visible
- You can use a pseudonym instead of real name
- No email addresses are shown publicly
Legal Requirements:
- When required by law or court order
- To protect rights and safety
- In case of business transfer (with notification)
7. Your Rights Under GDPR
Under GDPR, you have the following rights:
Right to Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate information
Right to Erasure
Delete your personal data ("right to be forgotten")
Right to Restriction
Limit processing of your data
Right to Portability
Receive your data in machine-readable format
Right to Object
Object to certain processing activities
Automated Decisions
Right not to be subject to automated decision-making
Lodge a Complaint
File complaint with supervisory authority
How to Exercise Your Rights:
Email us at privacy@montimage.eu with your request. We will respond within 30 days.
For data deletion, you can also delete your account directly from your Profile Settings.
9. Security Measures
We implement industry-standard security measures:
- Encryption: All data transmission via HTTPS/TLS
- Password Security: passwords are hashed by Firebase Authentication and never stored in plain text
- Access Control: Role-based permissions enforced by Firestore security rules
- Monitoring: platform-level monitoring and security logging provided by Firebase
- Backups: Firebase-managed backups for disaster recovery
- Incident Response: documented breach-notification process (see below)
Data Breach Notification:
In case of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours, as required by GDPR.
10. International Data Transfers
Depending on the regions configured for the deployment, your data may be stored and processed outside the EU/EEA. Where that happens, we ensure:
- Transfers only to countries with adequate protection (Art. 45 GDPR)
- Standard Contractual Clauses (SCCs) with service providers
- Additional safeguards as required by GDPR
Our processor (Firebase/Google Cloud) participates in the EU-US Data Privacy Framework.
11. Children's Privacy
Phishing Detection Training Platform is designed for users aged 16 years and older (or the applicable age in your country under GDPR).
We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately at privacy@montimage.eu.
For educational use with younger students, accounts should be created and managed by parents, guardians, or educational institutions with appropriate consent.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements.
How we notify you:
- Email notification for significant changes
- Prominent notice on the platform
- Updated "Last Updated" date at the top
Continued use of the platform after changes constitutes acceptance. If you disagree with changes, you may close your account.
13. Contact & Complaints
For Privacy Questions or Requests:
Email: privacy@montimage.eu
Mail:
Data Protection Officer
Montimage EURL
39 rue Bobillot
75013 Paris, France
Supervisory Authority:
You have the right to lodge a complaint with your local data protection authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL):
CNIL - Commission Nationale de l'Informatique et des Libertés
3 Place de Fontenoy, TSA 80715
75334 Paris Cedex 07, France
Website: https://www.cnil.fr
We are committed to transparency and your privacy rights. For questions or to exercise your rights, contact us at privacy@montimage.eu