EU-U.S. Privacy Shield & Swiss-U.S. Privacy Shield

Note: The policies and practices described herein apply only to EU and Swiss Personal Information subject to the Privacy Shield Frameworks. The Security Mentor Privacy Shield Policy (EU-U.S. Privacy Shield & Swiss-U.S. Privacy Shield) incorporates the Security Mentor Privacy Policy.

Security Mentor participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States, respectively. Security Mentor is committed to subjecting all personal data received from European Union (EU) member countries and Switzerland, respectively, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield program, visit https://www.privacyshield.gov/; or to view Security Mentor’s certification on the Privacy Shield List, visit https://www.privacyshield.gov/list.

Security Mentor is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and uses third parties that act as agents on our behalf and to whom we may transfer personal information. Security Mentor complies with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.

With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Security Mentor is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Security Mentor may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

If we are unable to satisfactorily resolve your Privacy Shield-related complaint according to the terms of our Privacy Policy, or if we fail to acknowledge your complaint in 30 days, you can submit your complaint to VeraSafe, which provides an independent third-party dispute resolution service based in the United States. You can learn more about VeraSafe’s dispute resolution services or you can refer a Privacy Shield-related complaint to VeraSafe, at https://www.verasafe.com/privacy-services/dispute-resolution/.

Security Mentor is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). Under certain conditions, you may be entitled to invoke binding arbitration.

Security Awareness Training Personal Information

Security Mentor provides services and collects information under the direction of our customers and has no direct relationship with the individuals whose personal data it processes.

Access, Correction or Removal of Personal Information from Training

If you are the employee, contractor, or associate of one of Security Mentor’s customers, Security Mentor acknowledges that you have the right to access, correct, amend, or delete your personal information. However, Security Mentor has no direct relationship with the individuals whose personal data it processes through our training. Therefore, an individual who wishes to seek to correct, amend, or delete inaccurate data, or has been processed in violation of the Principles, the individual should direct his/her query to Security Mentor’s customer (the data controller). If our customer requests Security Mentor correct, amend, or delete your data, we will respond to their request within 30 business days.

Security Mentor will retain and use personal information as necessary to provide services to its customers, analyze our services, comply with its legal obligations, resolve disputes, and enforce its agreements.

Website Personal Information

As is common for business websites, Security Mentor gathers information about how visitors use our website. Many of our web pages can be visited without visitors revealing any personal information. However, we may track your visit for trends and statistics. Once you choose to disclose any personal information to us, you are then identifiable to us. When you request general or sales information, a demonstration of our service, or otherwise submit a request to or post information on the Site, it is necessary for us to collect certain personally-identifiable information from you.

Access, Correct, Amend or Delete Personal Information from Website (excluding Training Platform Personal Information)

Upon request, Security Mentor will provide you with information about whether we hold any of your personal information. You may request to access, correct, amend, or delete your personal information by emailing us at privacy@securitymentor.com. We will respond to your request within 30 days. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.


Last Updated: November 29, 2018