Legal

Privacy Policy

Last Updated: September 26, 2026 · Effective Date: January 1, 2025

This Privacy Policy explains how Montimage collects, uses, and protects your personal data when using the Phishing Detection Training platform. We are committed to GDPR compliance and protecting your privacy.

1. Data Controller

The data controller responsible for your personal data is:

Montimage EURL

39 rue Bobillot

75013 Paris, France

Email: privacy@montimage.eu

Website: https://montimage.eu

2. What Data We Collect

2.1 Account Information

  • Name (first and last name)
  • Email address
  • Password (encrypted)
  • Organization affiliation (optional)
  • Account creation date

2.2 Training Data

  • Training session results and scores
  • Email classification responses (phishing/legitimate)
  • Threat identification selections
  • Response timestamps and duration
  • Learning progress and skill levels
  • Achievement and badge data
  • Certificate information

2.3 Technical Data

  • IP address (handled by Firebase infrastructure; not stored by the app)
  • Browser type and version
  • Device information
  • Language preference
  • Session information
  • Error logs (may contain account identifiers)

2.4 Organization Data

  • Organization name and domain
  • Member role and permissions
  • Team statistics (aggregated)

3. How We Use Your Data

3.1 Platform Operation:

  • User authentication and account management
  • Delivering training content and exercises
  • Tracking training progress and performance
  • Generating certificates and badges

3.2 Service Improvement:

  • Analyzing platform usage patterns (aggregated)
  • Improving training content effectiveness
  • Optimizing user experience
  • Debugging and technical improvements

3.3 Communication:

  • Sending important platform updates
  • Notifying about new features
  • Responding to support requests
  • Security notifications (mandatory)

3.4 Research & Development:

  • Improving phishing detection heuristics (aggregate statistics)
  • Developing new training methodologies
  • Academic research (aggregate statistics only)

Important Note:

We never sell your personal data to third parties. All research uses aggregate statistics only.

5. Data Storage & Retention

5.1 Storage Location:

Your data is stored on Google Cloud Platform (Firebase). The Firestore database, Authentication and Cloud Functions run in the regions configured for the deployment — see Section 10 for international-transfer safeguards.

5.2 Retention Periods:

  • Active accounts: Data retained while account is active
  • Inactive accounts: Data retained for 3 years after last login
  • Deleted accounts: Personal data deleted within 30 days
  • Training statistics: aggregate statistics that cannot identify you may be retained for research
  • Legal records: Retained as required by law (typically 6 years)

5.3 Backup & Disaster Recovery:

Firebase-managed backups are used for disaster recovery.

6. Who We Share Data With

We do not sell your personal data. We only share data with:

Service Providers:

  • Firebase/Google Cloud: hosting, authentication, database and serverless functions
  • Processing is governed by Google's Firebase Data Processing and Security Terms

Your Organization:

  • If you join an organization, its admins can see your name, email and training statistics (level, score, emails completed)
  • You control your organization membership

Leaderboards:

  • Username and scores are publicly visible
  • You can use a pseudonym instead of real name
  • No email addresses are shown publicly

Legal Requirements:

  • When required by law or court order
  • To protect rights and safety
  • In case of business transfer (with notification)

7. Your Rights Under GDPR

Under GDPR, you have the following rights:

Right to Access

Request a copy of your personal data

Right to Rectification

Correct inaccurate information

Right to Erasure

Delete your personal data ("right to be forgotten")

Right to Restriction

Limit processing of your data

Right to Portability

Receive your data in machine-readable format

Right to Object

Object to certain processing activities

Automated Decisions

Right not to be subject to automated decision-making

Lodge a Complaint

File complaint with supervisory authority

How to Exercise Your Rights:

Email us at privacy@montimage.eu with your request. We will respond within 30 days.

For data deletion, you can also delete your account directly from your Profile Settings.

8. Cookies & Tracking

8.1 Essential Cookies:

  • Authentication tokens (required for login)
  • Session management
  • Language preference
  • Security features

8.2 Analytics:

We do not run analytics or advertising trackers in the app.

8.3 Third-Party Cookies:

We do not use third-party advertising cookies. Only essential service provider cookies are used.

Cookie Management:

You can control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.

9. Security Measures

We implement industry-standard security measures:

  • Encryption: All data transmission via HTTPS/TLS
  • Password Security: passwords are hashed by Firebase Authentication and never stored in plain text
  • Access Control: Role-based permissions enforced by Firestore security rules
  • Monitoring: platform-level monitoring and security logging provided by Firebase
  • Backups: Firebase-managed backups for disaster recovery
  • Incident Response: documented breach-notification process (see below)

Data Breach Notification:

In case of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours, as required by GDPR.

10. International Data Transfers

Depending on the regions configured for the deployment, your data may be stored and processed outside the EU/EEA. Where that happens, we ensure:

  • Transfers only to countries with adequate protection (Art. 45 GDPR)
  • Standard Contractual Clauses (SCCs) with service providers
  • Additional safeguards as required by GDPR

Our processor (Firebase/Google Cloud) participates in the EU-US Data Privacy Framework.

11. Children's Privacy

Phishing Detection Training Platform is designed for users aged 16 years and older (or the applicable age in your country under GDPR).

We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us immediately at privacy@montimage.eu.

For educational use with younger students, accounts should be created and managed by parents, guardians, or educational institutions with appropriate consent.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements.

How we notify you:

  • Email notification for significant changes
  • Prominent notice on the platform
  • Updated "Last Updated" date at the top

Continued use of the platform after changes constitutes acceptance. If you disagree with changes, you may close your account.

13. Contact & Complaints

For Privacy Questions or Requests:

Email: privacy@montimage.eu

Mail:

Data Protection Officer
Montimage EURL
39 rue Bobillot
75013 Paris, France

Supervisory Authority:

You have the right to lodge a complaint with your local data protection authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL):

CNIL - Commission Nationale de l'Informatique et des Libertés

3 Place de Fontenoy, TSA 80715

75334 Paris Cedex 07, France

Website: https://www.cnil.fr

We are committed to transparency and your privacy rights. For questions or to exercise your rights, contact us at privacy@montimage.eu