Privacy Policy

Last Updated: 01/26/2026

This Privacy Policy sets forth the practices of Right-Hand Cybersecurity Pte. Ltd. (“Company”, “we”, “us”, or “our”) regarding the collection, use, processing, and disclosure of personal data through our website and Human Risk Management (HRM) platform. Our platform includes, but is not limited to:

  • Security Awareness and Training
  • Phishing Simulation
  • Security Alerts Ingestion and Behavioral Coaching
  • Email Threat Reporting and Remediation
  • AI-enabled Deepfake Vishing Simulation
  • AI-generated Policy-based Training Content
  • AI-enabled Phishing Template Generation

We are compliant with SOC 2 Type II and follow best practices from internationally recognized privacy frameworks, including the GDPR, CCPA/CPRA, and PDPA (Singapore), even though we are not formally certified under these regimes. Our internal privacy practices are designed to safeguard personal data and ensure operational integrity.

1. Roles and Responsibilities

  • Data Controller: For customer relationship data, support interactions, billing, marketing communications, and website analytics.
  • Data Processor: For personal data provided by customers in connection with their authorized use of the platform (e.g., employee data, behavioral signals, email metadata, phishing reports).

Customers are responsible for ensuring they have obtained appropriate consents and legal bases for any data provided to the Company. Our processing is governed by the Master Service Agreement (MSA) and Data Processing Agreement (DPA).

2. Categories of Data Collected

  • Identity and Contact Information: Names, email addresses, voice samples (optional), phone number (optional), employee type (optional), user group (optional), departments (optional), office location (optional)
  • Demographic data: such as your city, state, and country of residence.
  • Communications data based on our exchanges with you, including when you contact us through the Service, social media, or otherwise.
  • Technical and Usage Data: IP addresses, browser/device metadata, access logs, page interactions.
  • Security Metadata: Reported emails, phishing indicators, user responses to simulations
  • AI Training and Simulation Data: Interactions used to generate personalized training, simulated vishing content, and template content
  • Content and Communication Data: Uploaded files, feedback, and inputs submitted by users via the platform

2.1 Tracking  Technologies

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including your email address. We (or service providers on our behalf) may then send communications and marketing to these emails. You may opt out of receiving this advertising by contacting Right-hand support team. You also have the option to opt out of the collection of your personal data in compliance with GDPR. To exercise this option, please visit https://www.rb2b.com/rb2b-gdpr-opt-out.

We use session replay and analytics technologies, such as Microsoft Clarity, which utilize software code to capture and analyze user interactions with our Services. These technologies record interaction data such as clicks, taps, mouse movements, scrolling behavior, and keystrokes during a session, allowing us to review anonymized replays. This information helps us understand how users engage with the Services, diagnose usability issues, and identify opportunities for improvement. Microsoft Clarity processes this data in accordance with its privacy practices, which are available at https://privacy.microsoft.com/privacystatement.

3. Purposes of Processing

  • Provision of contracted services and platform features
  • Coaching based on ingested threat alerts from third-party tools
  • Customization of training simulations and phishing templates
  • Behavioral analysis and risk reporting (anonymized where applicable)
  • Administrative tasks (billing, account creation, support, analytics)
  • System maintenance, security enforcement, and fraud detection

The legal basis for processing is rooted in contract performance, legitimate interests (security, platform performance), and compliance with applicable law where required.

4. AI Systems and Deepfake Technology

Our platform utilizes artificial intelligence for:

  • Generating security awareness content from customer policies
  • Generating phishing templates based on user requests and context provided by admins
  • Producing synthetic voice-based simulations for vishing training
  • Classification and categorization of reported emails

All such systems are governed by internal ethical use policies. No biometric profiling or actual voice cloning is performed without explicit contractual agreement and consent. AI interactions are confined within customer environments and not used to train general-purpose models.

5. Subprocessors and Third-Party Access

We rely on carefully vetted subprocessors to support cloud hosting, analytics, email services, and AI functionality. Subprocessors operate under contractual obligations to maintain confidentiality, security, and purpose-limited use of data. A full list of subprocessors is available upon request.

All third-party service providers are contractually obligated to uphold privacy and security commitments equivalent to those outlined in this policy.

6. Data Retention

We retain personal data only for the duration required to fulfill the purposes outlined above:

  • Account, billing, and support data: Retained for 10 years
  • User behavior and simulation data: Deleted upon request or contract termination
  • AI-generated simulations: Retained in de-identified form for product improvement
  • Email remediation metadata: Deleted upon request or contract termination
  • Voice samples: Deleted upon request or contract termination
  • Company policies: Deleted upon request or contract termination

7. International Data Transfers

Our services are primarily hosted in secure environments on Amazon Web Services (AWS). Where personal data is transferred across borders, we implement best-practice safeguards, including:

  • Use of contract clauses modeled on Standard Contractual Clauses (SCCs)
  • Vendor selection based on adequate jurisdictional data protection standards

Although we are not GDPR-certified, these measures are intended to offer a comparable level of protection.

8. Individual Data Rights

While our platform is offered on a business-to-business basis, individuals whose data is processed under customer control may request:

  • Access to personal data
  • Correction or deletion
  • Restriction or objection to processing
  • Export of their data (portability)

Requests must be submitted via the data controller (your employer).

9. Email and Threat Remediation Operations

Our platform supports security operations such as:

  • Quarantining or removing confirmed malicious emails via authorized integrations
  • Issuing user-level alerts and adaptive training post-incident

These actions are conducted in accordance with contractual terms and logged for auditability.

10. Data Security Practices

We maintain a robust, independently audited information security management program, aligned with SOC 2 Type II standards, which includes:

  • End-to-end encryption
  • Zero-trust access control models
  • Role-based permissions and multifactor authentication
  • Regular penetration testing and vulnerability management
  • 24/7 monitoring and incident response

11. Use by Minors

Our platform is not intended for individuals under the age of 18. We do not knowingly collect data from minors.

12. Changes to this Policy

This Privacy Policy may be updated to reflect service improvements or regulatory guidance. Customers will be notified of material changes through appropriate channels.

Contact

To submit a privacy request or raise concerns:

Email: security[@]right-hand.ai
DPO: Mr. Uzair Ahmed
Address: 6192 Coastal Highway Lewes, DE, USA – 19958