sentivaro
Resilience assessmentEmployee training
Why Sentivaro
Phishing without secretsMake good decisionsRead between the linesVerify through another channelProtect the processWhen everything looks rightThe final decisionConnect the eventsKeep exceptions under controlVerify the evidenceContain the impact
ContactHelp Centre
Sign in
Product
Resilience assessmentEmployee training
Why Sentivaro
Knowledge
Phishing without secretsMake good decisionsRead between the linesVerify through another channelProtect the processWhen everything looks rightThe final decisionConnect the eventsKeep exceptions under controlVerify the evidenceContain the impact
ContactSign in

Sentivaro · Legal documents

Acceptable Use Policy

Version 1.0

Sentivaro Fair Use Policy

Version: 1.0

Valid from: July 30, 2026

1. Purpose

Sentivaro may only be used for authorized, controlled and proportionate cybersecurity awareness raising and to evaluate the effectiveness of educational activities.

2. Authorization required

The User may only launch a Campaign if:

  • acts on behalf of a verified Organization;
  • is authorized to commission a Campaign;
  • the recipients are within the approved range;
  • The organization has established a legal basis;
  • The organization has met or properly planned information obligations;
  • The campaign has been approved in accordance with the Organization's procedure;
  • The organization has assessed whether a balance test or DPIA is needed in its case.

3. Strictly prohibited activities

It is prohibited:

  • sending the Campaign without the knowledge and consent of the authorized authorities of the Organization;
  • using Sentivaro to engage in actual phishing, fraud, harassment, tracking or unauthorized access;
  • targeting campaigns to private individuals or addresses outside the approved range;
  • collecting or attempting to collect passwords, MFA codes, keys, session tokens, card data, PESEL, document numbers or health data;
  • saving the content entered in the simulated form;
  • using malicious code, macros, executable files, exploits or security bypass mechanisms;
  • impersonating a third party without the right to use its brand and materials;
  • using scenarios that refer, without justification, to dismissal, death, serious illness, family problems, remuneration or criminal liability;
  • disclosing results to unauthorized persons;
  • publishing rankings that embarrass employees;
  • discrimination, harassment or retaliation against participants;
  • basing automatic personnel decisions solely on the Sentivaro result;
  • testing children without separate legal agreement and written consent of the Operator;
  • resell access or share the account with other people;
  • bypassing limits, security and verification checks;
  • disrupting the operation of the Service or testing its security without the Operator's consent.

4. Allowed scenarios

The scenario should:

  • reflect the Organization's realistic risks;
  • not cause disproportionate stress;
  • lead to a safe educational site;
  • measure only necessary events;
  • include the option to report a message;
  • take into account corrections resulting from the operation of scanners;
  • be combined with an educational or corrective action.

Preferred are:

  • scenarios based on the Organization's own brand;
  • neutral, fictitious brands provided by Sentivaro;
  • security and HR/data protection approved scenarios;
  • grading of difficulty according to the results of the risk assessment.

5. Results

The organization should:

  • use primarily aggregated data;
  • limit access to individual results;
  • verify the result before acting on the person;
  • take into account the context of the position and the possibility of error;
  • use educational activities, not repressive ones;
  • delete data when it is no longer needed.

6. Operator's reaction

In the event of a suspected violation, the Operator may:

  • pause the Campaign;
  • block the shipment;
  • limit the account;
  • request an authorization document;
  • secure the necessary evidence of the event;
  • terminate the account;
  • notify the injured Organization or the competent authorities if required by law or necessary to protect persons.

7. Reporting abuse

Abuse should be reported to contact@sentivaro.com with the subject "ABUSE". The report should contain as safe a description as possible, the message or Campaign ID and contact details.

© 2026 SentivaroTermsPrivacy PolicyDPAAcceptable use