Legal notice & terms of use
This page governs your use of this website (afriphish.com) and the free tools it hosts. Use of the AfriPhish platform by customer organisations is governed by the service agreement signed with us, which prevails over this page for platform use.
Who we are
AfriPhish is a human-risk management platform — security-awareness training, phishing simulation and compliance evidence — built for African organisations. Contact: sales@afriphish.com (commercial) · privacy@afriphish.com (data protection).
Acceptable use
You may browse this site and use its free tools for lawful purposes only. In particular, you must not:
- use the Human Risk Maturity Assessment or any other tool to probe, disrupt or overload the service;
- attempt to access data belonging to another person or organisation;
- use content from this site to build or improve phishing attacks against any party — our simulation content exists to defend organisations, and simulated phishing must only ever be run against your own organisation with proper authorisation;
- scrape, resell or republish site content without written permission.
Simulated phishing — a note on authorisation
Phishing simulation is lawful when an organisation tests its own people under an agreement with us. AfriPhish does not provide services for attacking third parties, and we cooperate with authorities in cases of misuse.
Intellectual property
The AfriPhish name, logo, site design, course content, simulation scenarios and reports are our intellectual property or that of our licensors. Regulation names (POPIA, NDPA, etc.) and framework names (ISO 27001, NIST CSF, SOC 2, PCI DSS) belong to their respective owners; references to them describe compatibility and coverage, not affiliation or endorsement.
Content and liability
Content on this site — including blog articles about publicly reported security incidents and summaries of regulations — is provided for general information only. It is not legal advice, and despite our care it may contain inaccuracies or become outdated. Incident write-ups are based on public reporting, cited in each article; if you believe something is inaccurate, contact us and we will review it promptly. To the maximum extent permitted by law, we accept no liability for decisions taken on the basis of this site's content.
Your data
How we handle personal data on this site — including the 90-day retention rule for anonymous assessment responses — is described in our privacy notice.
Changes
We may update this page as the site evolves; the current version is always at this address.