Privacy policy
Last updated 8 October 2026
The short version
- We collect as little as we can. For learners, that is a first name, a surname, a work email, an optional department, and training results stored as a score per field mark.
- We never ask learners for a password, and we don't collect free-text answers.
- Personal information is stored in South Africa.
- Card details go to Paystack, our payment provider. We never see your card number.
- If your employer signed up for Underwing, your employer decides how your information is used. We process it on their behalf, under a written agreement.
- Training results are for learning, never for discipline. Our terms forbid clients from using individual results in disciplinary action.
- We don't sell personal information, and we don't use advertising trackers.
Who we are
Underwing is a security-awareness training programme run by Under Bridges Entity (Pty) Ltd, trading as Underwing, registration number 2016/469951/07, of 127 East Road, 47 3rd on East, Pomona, Kempton Park, South Africa.
In this policy, "Underwing", "we" and "us" mean that business. "You" means anyone whose personal information we handle.
Our Information Officer is P.J. Mbedzi. You can reach them at privacy@underwing.co.za. Their details are also at the end of this policy.
Who this policy covers, and what our role is
The Protection of Personal Information Act (POPIA) gives two different roles to organisations that handle personal information:
- A responsible party decides why and how personal information is processed.
- An operator processes personal information on behalf of a responsible party, under a contract, and does not decide the purpose.
Our role depends on who you are.
| You are | Who decides how your information is used | Our role |
|---|---|---|
| A visitor to underwing.co.za | Underwing | Responsible party |
| A manager or billing contact at a client | Underwing, for your account and billing | Responsible party |
| A learner enrolled by your organisation | Your organisation | Operator (POPIA sections 20 and 21) |
| A Team Spot Check participant | The organisation that invited you | Operator |
| A Voice Test participant (add-on) | Underwing, with your explicit written consent | Responsible party |
When we act as an operator, we process your information only on the client's instructions and under a written data processing agreement. That agreement requires us to keep it secure and to tell the client immediately if we suspect a security compromise. If you are a learner and want to know how your organisation uses Underwing, you can ask your organisation, or ask us and we will help.
We are also the responsible party for anonymised benchmarks across clients. See "Benchmarks" below.
What we collect and why
Visitors to our website
- The one-minute test. Your answers are not linked to your name or email. We count results in aggregate to see how many people spot each scam.
- Founding-team reservations, quote requests and messages. If you fill in a form, we collect what you give us: usually your name, work email, organisation, team size and your message. We use it to reply, prepare a quote or hold your place.
- Bot protection. Our public forms use Cloudflare Turnstile. It checks technical signals from your browser to tell people from bots.
- No analytics. We don't run analytics on the website, the portal or the learner pages.
- Server and security logs. Like any website, our hosting records technical details such as IP address, browser type and the time of a request. We use these to keep the service running and secure.
Managers and billing contacts
- Your name, work email, organisation, team size, and your role (owner or admin).
- Your sign-in method: an email link, plus a passkey. We don't store a password because there isn't one. For a passkey, we store only a public key; the private part stays on your device.
- The billing contact's name and email, the plan, invoices and payment status. Paystack processes card payments and tells us whether a payment succeeded. We never see or store your card number.
- An audit log of important actions: sign-ins, exports, viewing an individual learner's results, billing changes, and any action by Underwing staff.
We use this to run your account, bill you, keep your account secure, send service messages (such as reports, receipts and security notices) and support you.
Learners
- First name, surname and work email.
- An optional department or group, if your manager adds one.
- Which lessons you have started and completed, and when.
- Quiz results, stored as a score for each field mark: urgency, authority, fear, reward, borrowed trust and secrecy. Once your answers have been turned into these scores, we don't keep your answer to each question against your name.
- Your Field Guide cards and certificate of completion.
- Email delivery events (for example, delivered or bounced), so we can tell your manager if our emails aren't reaching you.
We don't collect free-text answers. You never set a password, and nothing we send will ask you for one.
We use this to deliver the programme, show your progress, send reminders, issue certificates, and give your manager the results described in the next section.
Team Spot Check participants
The Team Spot Check is a free check of 12 realistic messages that a manager sends to up to 30 colleagues. We collect the same kind of information as for learners: name, work email and optional department. Results are kept as totals (a score, and how many were right by field mark, by channel and by whether the person felt sure), never the answers themselves. The manager receives a team report with the team's figures, the field marks and channels that caught the team out, and where to start. Nobody's individual results are shown.
Voice Test participants (add-on)
The Voice Test is an optional live demonstration for executives in which we create a short clone of a consenting person's voice. POPIA treats voice recognition as biometric information, which is special personal information. So:
- We do this only with your explicit, written consent, given for that session.
- The consent form states the purpose, what we record, which service creates the clone and where it is processed.
- We delete the recording and the clone on the same day.
- We will not send a voice recording to a service outside South Africa unless the law allows it, including any prior authorisation the Information Regulator requires.
What we don't collect
- Passwords for learners.
- Card numbers.
- Free-text answers.
- Special personal information, except for the Voice Test described above.
- Information from advertising networks or data brokers.
What managers can see about learners
We tell every learner this up front, in their welcome email and on the programme pages.
Managers at your organisation can see:
- whether you have started and completed each lesson;
- your results by field mark, shown as bands such as "needs support", never as "failed";
- your department, if one is set;
- whether our emails to you are being delivered.
Managers can't see your answer to each question. Every time a manager opens an individual's results, it is recorded in the audit log.
Results are for learning, never discipline. Our terms of service forbid clients from using individual results in disciplinary action. Scams are designed to work on smart people; the point is to find out who needs more support.
Our lawful basis for processing
POPIA section 11 allows processing on certain grounds. Where we are the responsible party, these are the grounds we rely on.
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Running a manager's account and providing the service the client signed up for | Performance of a contract (s11(1)(b)) |
| Keeping billing and tax records | Legal obligation (s11(1)(c)) |
| Security monitoring, audit logs and preventing abuse of free tools | Our legitimate interest in keeping the service and its users safe (s11(1)(f)) |
| Replying to a reservation, quote request or message | Your request, and our legitimate interest in answering it (s11(1)(b) and (f)) |
| Marketing emails | Your consent (s69), or the existing-customer exception (see below) |
| Anonymised cross-client benchmarks | Our legitimate interest in giving clients useful comparisons (s11(1)(f)) |
| Voice Test | Your explicit written consent (s11(1)(a) and s27(1)(a)) |
Where we are an operator, the client is responsible for having a lawful basis to enrol its people. Most employers rely on their legitimate interest in training staff to protect the organisation and its clients. Our terms require each client to have a lawful basis and to tell its people about the programme.
You can object to processing based on legitimate interests (see "Your rights").
Benchmarks
We compare a team's results with similar teams, for example "teams your size tend to miss borrowed trust". To do this, we combine results across clients into anonymised statistics. Benchmarks contain no names, no email addresses and no organisation names. We report a benchmark only when it draws on enough organisations that no team or person can be identified [minimum group size: to confirm, for example at least five organisations]. We tell clients about this in our terms and data processing agreement.
Marketing
We don't send unsolicited marketing email.
- We send marketing emails only to people who have given consent, in line with POPIA section 69 and the consent form the regulations prescribe (Form 4).
- If you are an existing customer, we may email you about our own similar services, as section 69 allows. You can say no at any time.
- Every marketing email has a one-click way to opt out.
- Service messages (new lessons, reminders, reports, receipts and security notices) are not marketing, so they don't depend on marketing consent.
Where your information is stored
Personal information is stored in South Africa, in Amazon Web Services' Cape Town region (af-south-1). Our application runs on Vercel, with server functions in Vercel's Cape Town region.
Some of our service providers process limited information outside South Africa. Where they do, we have data processing agreements with them that include standard contractual clauses, so the information keeps substantially similar protection, as POPIA section 72 requires.
Who helps us (our processors)
| Provider | What they do for us | Where |
|---|---|---|
| Amazon Web Services | Database and encrypted backups | South Africa (Cape Town, af-south-1) |
| Resend | Delivers our emails, such as sign-in links, lessons and reminders | Ireland (European Union) |
| Vercel | Hosts the website and application | Global edge network; server functions in Cape Town |
| Paystack | Takes card payments and runs subscriptions. Card details are handled only by Paystack. | Ireland (European Union), on Amazon Web Services |
| Cloudflare | DNS, bot protection on forms (Turnstile) and video streaming (Cloudflare Stream). Videos contain no personal information. | Global network |
We don't sell personal information or share it with advertisers. We may disclose information if the law requires it, for example under a court order, and we will tell the client first where we are allowed to.
How long we keep it
| Information | How long |
|---|---|
| Learner information | For the length of the client's contract. Deleted within 90 days after the contract ends. We may keep anonymised aggregates. |
| A learner removed by their manager during a contract | Deleted within 30 days, except the audit log |
| Team Spot Check participants, where the organisation doesn't subscribe | Deleted within 30 days after the report is sent |
| Manager accounts | While the account is open, then deleted within 90 days, except billing records and audit logs |
| Billing records and invoices | 5 years, as the Tax Administration Act requires |
| Audit logs | 2 years |
| Reservation, quote and contact form submissions | 12 months if no subscription follows |
| Voice Test recordings and clones | Deleted the same day |
| Encrypted backups | Overwritten on a rolling cycle of 14 days |
How we protect it
A security-awareness company has to practise what it teaches. Our main controls:
- No passwords. Managers sign in with an email link plus a mandatory passkey. Learners use short-lived, single-purpose links behind a "Start" page. Underwing staff use hardware security keys on a separate admin app.
- Minimum data. We collect only what the programme needs, and delete it on schedule.
- Separation between clients. Every record carries its organisation. The database enforces this as a second lock behind the application, and automated tests try to read across organisations on every build.
- Encryption. Encrypted connections everywhere, and encrypted storage and backups.
- Payments. Card details are entered only on Paystack.
- Application security. Security headers, input checks on every endpoint, rate limits and bot checks on public forms, and logs that contain no personal information.
- Audit trail. An append-only log of sign-ins, exports, views of individual results, billing changes and every staff action.
- People and process. Multi-factor authentication on every team account, quarterly access reviews, tested backups, an incident response plan, and an independent penetration test before our first corporate client goes live.
Underwing staff can't "log in as" a client. To report a vulnerability, email security@underwing.co.za.
If something goes wrong
If we suspect that personal information has been accessed or acquired by someone without authority:
- Where we are the operator, we tell the client immediately, as POPIA section 21(2) requires, and help them respond.
- Where we are the responsible party, we notify the Information Regulator through its eServices portal (the required channel since 1 April 2025) and the people affected, as soon as reasonably possible, as section 22 requires.
Your rights
Under POPIA you have the right to:
- Know whether we hold personal information about you, and ask for a copy.
- Ask us to correct information that is inaccurate, out of date or incomplete.
- Ask us to delete information we no longer have a lawful reason to keep.
- Object to processing based on legitimate interests, on reasonable grounds relating to your situation.
- Object to direct marketing at any time, and refuse marketing by email.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects. Underwing doesn't make decisions like that; field-mark scores guide learning and are not used to make decisions about you.
- Complain to the Information Regulator, and go to court if your rights are infringed.
How to ask. Email privacy@underwing.co.za and say what you would like us to do. We may need to confirm your identity first. The POPIA regulations also provide forms: Form 1 for objections and Form 2 for correction or deletion. We'll send them on request, but an email is enough to get started. Requests for a copy of your records can also be made under our PAIA manual.
We'll respond within 30 days. Asking whether we hold your information is free. If a fee applies to copies of records, it will be the fee prescribed under PAIA, and we'll tell you before doing the work.
If you are a learner or Spot Check participant, your organisation is the responsible party. We will help with your request, but some decisions belong to your organisation, for example whether your training record should be deleted while you still work there. In that case we pass your request to them promptly and tell you we have done so.
Complaints to the Information Regulator
We'd like the chance to fix a problem first, so please contact us. You can also complain to the Information Regulator at any time:
- Website: inforegulator.org.za
- POPIA complaints: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Telephone: 010 023 5200 (toll-free 0800 017 160)
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Complaints use Form 5 under the POPIA regulations. Check the Regulator's website for its latest contact details.
Children
Underwing is a workplace training programme. It isn't intended for anyone under 18, and we don't knowingly collect information about children. Clients must not enrol anyone under 18 without agreeing it with us in writing first. If you think we hold information about a child, email privacy@underwing.co.za and we will delete it.
Changes to this policy
We'll update this policy when our processing changes, and change the date at the top. If a change materially affects how we use your information, we'll tell clients and managers by email at least 30 days before it takes effect, and show a notice on the website.
Contact us
- Information Officer: P.J. Mbedzi, privacy@underwing.co.za
- Privacy questions and requests: privacy@underwing.co.za
- Security reports: security@underwing.co.za
- Everything else: hello@underwing.co.za
- Post: Under Bridges Entity (Pty) Ltd, trading as Underwing, 127 East Road, 47 3rd on East, Pomona, Kempton Park, South Africa
Underwing will never ask you for a password, a one-time code or new banking details by email. If a message claiming to be from us asks for any of these, it isn't from us.