Phishing Simulation & Security Awareness Training — Authorization & Services Agreement
Vaydel is a product of Digitize Solutions. References to "Provider," "we," or "us" below mean Digitize Solutions' registered legal entity, identified in full at the start of the Agreement.
PHISHING SIMULATION & SECURITY AWARENESS TRAINING SERVICES AGREEMENT
This Agreement ("Agreement") is entered into as of the date of electronic acceptance (the "Effective Date") between:
Digitize Solutions, a company registered in Lebanon ("Provider", "we", "us"),
and
[CLIENT COMPANY LEGAL NAME], a company registered under the laws of [___], with its registered address at [___] ("Client", "you"), acting through the undersigned authorized representative.
Provider and Client are each a "Party" and together the "Parties."
1. Background
1.1 Provider operates a software-as-a-service platform (the "Platform") that sends simulated phishing emails to a client's employees for the purpose of security awareness training, tracks employee responses (including whether an employee clicked a simulated malicious link and whether they completed associated training), and provides reporting to the Client.
1.2 Client wishes to engage Provider to run such simulated phishing campaigns and associated training against Client's own employees, and this Agreement sets out the authorization for, and terms governing, that engagement.
1.3 This Agreement is only valid for (a) domains and email addresses that Client has verified ownership/control of through the Platform's domain verification process, or (b) where Client does not operate on a common company email domain (e.g., Client's personnel use personal email accounts), the specific individual email addresses Client has explicitly listed in Schedule A and attested, per Clause 2.2(a-alt), are its own personnel. Provider will not run, and Client may not request, a campaign against any domain or individuals Client does not control, does not employ, or does not have the right to authorize testing against. Accounts proceeding under (b) are subject to Provider's manual verification review before each campaign, rather than the automated domain-verification path.
2. Client Authorization (core clause)
2.1 Client hereby authorizes Provider to:
(a) send simulated phishing emails, using content templates and/or AI-generated content, to the email addresses on the verified domain(s), or the individually-enumerated email addresses per Clause 1.3(b), listed in Schedule A (the "Authorized Recipients");
(b) track and log each Authorized Recipient's interaction with such emails, including whether the email was delivered, opened, clicked, and whether associated training was started, completed, or a quiz was passed (collectively, "Campaign Data");
(c) redirect any Authorized Recipient who clicks a simulated phishing link to a security awareness training module hosted on the Platform;
(d) compile and deliver reports based on Campaign Data to the main contact(s) designated by Client under Schedule A.
2.2 Client represents and warrants that:
(a) *[Domain-based accounts]* Client owns or has the legal right to control the domain(s) listed in Schedule A, and has completed the Platform's domain verification process for each;
(a-alt) *[No-company-domain accounts, in place of (a)]* Client does not operate on a common company email domain; each individual email address listed in Schedule A belongs to a current employee or engaged personnel of Client, and Client accepts sole responsibility for the accuracy of that list in the absence of domain-based verification;
(b) the individual executing this Agreement on Client's behalf has full corporate authority to bind Client to this Agreement and to authorize the activities described in Clause 2.1;
(c) Client has the legal right, under applicable employment law and its own internal policies, to conduct simulated phishing testing and mandatory security awareness training on the Authorized Recipients, and has satisfied any internal notice, works-council consultation, or employee-representative consultation obligations applicable in its jurisdiction before campaigns begin;
(d) Client's employees have been generally informed, through Client's IT/security policy or equivalent, that simulated phishing exercises may occur from time to time (without Client disclosing the timing or content of specific campaigns, which would defeat their purpose).
2.3 Client acknowledges that Provider is relying on the representations in Clause 2.2 in agreeing to provide the Services, and that Provider has no independent means of verifying Client's internal authority, employment-law compliance, or employee-notice practices beyond the domain verification, or manual review of the enumerated-recipient attestation, described in Clause 1.3.
3. Scope of Services
3.1 The specific plan, employee count, campaign frequency, and fees are set out in Schedule A (Order Form) and/or the Client's active subscription plan on the Platform, as may be updated from time to time in accordance with Clause 8.
3.2 Provider will not, as part of the standard Service, request or collect real credentials (passwords, MFA codes, payment details) from Authorized Recipients. Any simulated landing page will disclose that the exercise was a simulation immediately upon interaction and proceed directly to training.
4. Data Processing
4.1 For the purposes of applicable data protection law (including EU GDPR, to the extent applicable, and Lebanon's Law No. 81/2018 on Electronic Transactions and Personal Data), Client is the data controller and Provider is the data processor with respect to Campaign Data and any personal data of Authorized Recipients processed under this Agreement.
4.2 The Data Processing Addendum attached as Schedule B (or incorporated by reference) governs the processing of personal data under this Agreement, including the categories of data processed, processing purposes, sub-processors used, security measures, and — given the transfer of personal data from the EU/EEA to Provider's Lebanon-based processing — the Standard Contractual Clauses module applicable to controller-to-processor transfers, attached as Exhibit 1 to Schedule B.
4.3 Provider will retain Campaign Data for [12–24] months from collection, or such other period agreed in Schedule A, after which it will be deleted or anonymized, except where Client requests earlier deletion or applicable law requires longer retention.
5. Client Obligations
5.1 Client will provide accurate and current employee contact information for the Authorized Recipients and will promptly notify Provider of any employee who should be excluded from future campaigns (e.g., departed employees, employees on protected leave where applicable under local law).
5.2 Client will cooperate with Provider's email deliverability requirements, including configuring its email security platform (e.g., Microsoft Defender for Office 365 Advanced Delivery, or the Google Workspace equivalent) to allow-list Provider's published sending domain(s) and IP range(s), without which the Service may not function as intended. Provider is not responsible for simulated emails blocked by Client's own email security controls where Client has not completed this configuration.
5.3 Client will not use the Platform, or request Provider to use the Platform, to target any individual or domain Client does not have the right to authorize testing against under Clause 2.2.
6. Fees
6.1 Fees are as set out in Client's selected subscription plan or Schedule A, payable in accordance with the payment terms presented at checkout, processed by Provider's selected third-party payment processor.
7. Confidentiality
7.1 Each Party will keep confidential the other Party's non-public business, technical, and Campaign Data information disclosed under this Agreement, and will use it only to perform its obligations under this Agreement, except as required by law.
8. Term, Suspension, and Termination
8.1 This Agreement commences on the Effective Date and continues for the term of Client's active subscription, renewing in accordance with the subscription terms, unless terminated earlier as set out below.
8.2 Provider may suspend or terminate the Service immediately, without liability, if Provider reasonably believes Client has breached Clause 2.2 or 5.3 (including where domain control cannot be re-verified, or where Provider has reasonable grounds to believe the Authorized Recipients are not genuinely Client's own employees).
8.3 Either Party may terminate for the other's uncured material breach on [30] days' written notice, or as otherwise set out in the subscription terms.
9. Disclaimers and Limitation of Liability
9.1 The Service is provided to assess and improve security awareness; it does not guarantee that Client's organization will not experience an actual phishing attack, security incident, or data breach, and Provider makes no warranty as to specific security outcomes.
9.2 To the maximum extent permitted by applicable law, Provider's total aggregate liability arising out of or relating to this Agreement will not exceed the fees paid by Client to Provider in the [12] months preceding the event giving rise to the claim, except for liability arising from Provider's gross negligence, willful misconduct, or breach of confidentiality/data protection obligations, to the extent such exclusion is not permitted by applicable law.
9.3 Neither Party will be liable for indirect, incidental, or consequential damages arising out of this Agreement, to the extent permitted by applicable law.
10. Indemnification
10.1 Client will indemnify and hold Provider harmless from any third-party claim (including from an Authorized Recipient or a regulator) arising out of Client's breach of Clause 2.2 (Client's representations and warranties), including any claim that Client lacked the authority or legal right to authorize the campaigns described in this Agreement.
11. General
11.1 This Agreement, together with Schedules A and B and any DPA/SCCs incorporated by reference, constitutes the entire agreement between the Parties regarding its subject matter.
11.2 Provider may update these terms with [30] days' notice for changes that do not materially reduce Client's rights; material changes require Client's affirmative acceptance.
Signature
By accepting below (whether via the Platform's single-click electronic acceptance flow, or by wet-ink/DocuSign signature where a formal document is required), the signatory certifies, on behalf of the Client company named above, that they hold the authority described in Clause 2.2(b), and that all representations in Clause 2.2 are true and accurate as of the date of acceptance.
Default path — electronic acceptance (self-serve signup):
Captured automatically by the Platform at signup: signer's typed legal name, role/title selection, company name, verified domain(s), timestamp, and IP address. No separate signature block is presented to the client in this path.
Alternative path — formal signature (enterprise deals requiring a countersigned document):
For Client:
Name: _______________________
Title/Role: _______________________ *(e.g., IT Administrator, CISO, HR Director, Owner/Director)*
Company: _______________________
Verified domain(s) or enumerated Authorized Recipients (Schedule A): _______________________
Signature: _______________________
Date: _______________________
For Provider (Digitize Solutions):
Name: _______________________
Title: _______________________
Signature: _______________________
Date: _______________________
Schedule A — Order Form (to complete per client)
- Subscription plan / tier:
- Verification path: ☐ Domain-based (verified domain(s) below) ☐ No-company-domain (enumerated recipients below, per Clause 1.3(b)/2.2(a-alt))
- Verified domain(s) *(if domain-based path)*:
- Enumerated Authorized Recipient email addresses *(if no-company-domain path — list each individually)*:
- Number of Authorized Recipients (employees):
- Main report contact(s):
- Campaign frequency:
- Fees:
Schedule B — Data Processing Addendum
See the separate Data Processing Addendum, incorporated by reference into this Agreement.