Salient
ServicesApproachSalient.secSelf-checkContact
About
RO EN RU
Book an assessment
← Back to home

Salient.sec Privacy & Data-Processing Notice

How Salient.sec processes employees' personal data on behalf of an employer who uses it for security-awareness training and phishing simulation, with the employer as controller and Salient.sec as processor.

Last updated: [EFFECTIVE_DATE]

Draft template, pending review by a qualified Moldovan lawyer. Not legal advice.

Draft status - not legal advice

This is a placeholder draft template prepared for Salient. It is informational only and is pending review by a qualified Moldovan lawyer. It is not legal advice, it does not constitute legal advice, and it is not final. Defined terms in square brackets (e.g. Salient, [EMAIL]) are placeholders to be completed after legal review.

1. About this notice and who it is for

Salient.sec is a security-awareness training and phishing-simulation product operated by Salient (IDNO [IDNO]), a Moldovan cybersecurity consultancy, the same team behind Salient. Salient.sec is provided to employer organisations (each, an "Employer") who deploy it across their workforce.

This notice is written for the employees and other workforce members of an Employer whose personal data is handled within Salient.sec. It explains what Salient.sec does with that data, on what legal footing, and how rights are exercised. It is a companion to the Employer's own privacy notice to its staff, which remains the primary source of information for employees.

This notice is aligned with Regulation (EU) 2016/679 (GDPR) as best practice and with Moldovan data-protection law: Law No. 133/2011 on the protection of personal data (in force now) and Law No. 195/2024 on personal data protection, which applies from 23 August 2026 and modernises data-subject rights, introduces a 72-hour breach-notification timeline, and aligns Moldovan law with the GDPR.

2. Controller vs processor roles, and the Data Processing Agreement

When an Employer uses Salient.sec, the Employer is the data CONTROLLER: it decides which employees are enrolled, which modules and simulations run, and how long records are kept. Salient, operating Salient.sec, is the PROCESSOR: it processes employees' personal data only on the Employer's documented instructions and only to deliver the Salient.sec service.

This split is governed by a Data Processing Agreement (DPA) between the Employer and Salient, intended to meet the requirements of Article 28 GDPR and the equivalent processor obligations under Moldovan law (Law 133/2011 now, and Law 195/2024 from 23 August 2026). The DPA covers confidentiality, security, use of sub-processors, assistance with data-subject rights, breach notification, and return or deletion of data at the end of the service.

Salient does not use employee data processed through Salient.sec for its own purposes, does not sell it, and does not use it to train unrelated models or for advertising.

3. What personal data Salient.sec processes on the Employer's behalf

On the Employer's instructions, Salient.sec processes a limited set of workforce data needed to run training and measure security awareness:

  • Identity and contact: employee name and work email address
  • Training assignment: the modules and campaigns assigned to the employee
  • Progress: completion status, with start and completion timestamps
  • Assessment: quiz and knowledge-check scores
  • Phishing-simulation results: whether a simulated message was opened, clicked, reported, or whether simulated credentials were submitted, with timestamps
  • Limited technical metadata generated by use of the platform (for example, the device or browser type used to complete a module), to the extent necessary to operate and secure the service

4. Lawful basis

The lawful basis is the Employer's legitimate interests as controller (GDPR Art. 6(1)(f); and the corresponding legitimate-interests basis under Moldovan law, Law 133/2011 now and Law 195/2024 from 23 August 2026) in protecting its workforce, systems and data against social-engineering and phishing attacks, and in meeting its regulatory obligations. Where applicable, the Employer may also rely on compliance with a legal obligation.

This processing is NOT based on employee consent. In an employment relationship consent is rarely freely given, so it is not a sound basis for mandatory workforce security training. Employees are not asked to consent, and training is not optional in the way consent would imply. (Consent and performance of a contract remain available lawful bases for other situations, but they are not the basis relied on here.)

A concrete driver is Moldovan cybersecurity law: Law 48/2023 and HG 562/2025 set NIS2-style minimum measures for in-scope entities, and HG 562/2025 Chapter VIII makes security-awareness training a minimum measure. For such Employers, running Salient.sec supports compliance overseen by the Agency for Cybersecurity (ASC). The Employer, as controller, remains responsible for selecting and documenting its own lawful basis and legitimate-interests assessment; this notice does not make that determination for it.

5. Phishing simulations done lawfully

Phishing simulations are a training tool, not a trap to catch and punish individuals. Salient.sec is built and configured to run them proportionately and fairly:

  • Reporting to management is aggregated and pseudonymised by default (for example, click rates by department or campaign), not individual league tables
  • There is no public "name-and-shame": individual results are not posted, broadcast, or shared beyond those with a genuine need within the controller
  • Employees can object to processing based on legitimate interests; objections are routed to the Employer, who decides and can, for example, exclude an individual from simulations
  • A single click on a simulated phishing message does not trigger disciplinary action; the intended response is targeted follow-up training, and any repeated-pattern review is the Employer's decision under its own HR rules
  • A Data Protection Impact Assessment (DPIA) is recommended for the Employer before running phishing simulations across the workforce; Salient provides information to support it. Whether a DPIA is legally required is for the Employer to assess as controller

6. Sub-processors

Salient uses a small number of vetted sub-processors to deliver Salient.sec, each bound by a written contract with data-protection terms equivalent to those in the DPA. The current categories are placeholders pending finalisation:

  • Cloud hosting and storage: [SUB-PROCESSOR - HOSTING PROVIDER]
  • Transactional email / message delivery (training notices and simulated messages): [SUB-PROCESSOR - EMAIL PROVIDER]

7. Data retention

Retention is set by the Employer as controller. Salient.sec keeps training and simulation records only for the period the Employer instructs, after which the data is deleted or returned in line with the DPA.

In the absence of a specific instruction, Salient applies a conservative default and prompts the Employer to confirm a retention period. On termination of the service, Salient deletes or returns the Employer's data per the DPA, subject to any retention required by law.

8. Security measures

Salient applies technical and organisational measures appropriate to the risk, consistent with GDPR Art. 32, Moldovan data-protection law (Law 133/2011 now and Law 195/2024 from 23 August 2026), and the minimum-measures regime of Law 48/2023 and HG 562/2025:

  • Encryption of data in transit and at rest
  • Role-based access control and least-privilege, with access limited to authorised personnel
  • Authentication controls and logging of access to personal data
  • Network and application hardening, patching, and monitoring
  • Staff confidentiality undertakings and security-awareness training
  • Backup, and incident-response procedures including breach notification to the Employer without undue delay so the Employer can meet its own obligations (including the 72-hour notification timeline under Law 195/2024 from 23 August 2026 and GDPR Art. 33 where it applies)

9. Data-subject rights

Subject to the conditions and exemptions in applicable law, employees have the following rights in relation to their personal data:

  • Access to their personal data
  • Rectification of inaccurate or incomplete data
  • Erasure
  • Restriction of processing
  • Objection to processing based on legitimate interests
  • Data portability
  • Withdrawal of consent, where and only where consent is ever the lawful basis (it is not the basis relied on for the processing described here)
  • Lodging a complaint with the National Center for Personal Data Protection (CNPDCP / Centrul Național pentru Protecția Datelor cu Caracter Personal) and, where GDPR applies, with the relevant EU supervisory authority

10. International transfers

Where a sub-processor stores or processes data outside the Republic of Moldova or the EU/EEA, Salient aims to ensure an appropriate safeguard is in place before any transfer. On the EU side this may be an adequacy decision or Standard Contractual Clauses with supplementary measures (consistent with GDPR Chapter V); on the Moldovan side, transfers are made on a basis recognised under Moldovan law (Law 133/2011 now, and Law 195/2024 from 23 August 2026), which may include an adequate-protection determination or a safeguard or authorisation recognised by the CNPDCP. Details of transfer locations and the specific safeguards relied on are recorded in the DPA and available to the Employer on request.

11. Changes to this notice

Salient may update this notice to reflect changes to the service, sub-processors, or the law. Material changes are communicated to Employers, who are responsible for informing their workforce. The version in force is identified by its effective date.

12. Contact

Operator (processor): Salient, IDNO [IDNO], [ADDRESS], Republic of Moldova. General: [EMAIL]. Data-protection contact: [DPO_CONTACT]. Web: [WEBSITE].

For requests about your own data, contact your employer (the controller) and its data-protection contact in the first instance.

Effective date: [EFFECTIVE_DATE].

Salient
PrivacySalient.sec PrivacyTerms

© 2026 Salient - proof-of-concept.

3D laptop: MacBook Pro M3 16″ by jackbaeten, CC BY 4.0

We only use strictly necessary cookies to run this site. With your consent, we may also enable anonymous statistics. Privacy Policy