Employee Terms of Use
Last updated: 1 August 2026
1. Why you are reading this
Your employer uses Brightside AI to help its people recognise and resist cyber attacks. Because your employer enrolled you, you may receive security awareness training through our platform, and you may receive simulated attacks — practice attacks that look real but are not.
These Employee Terms of Use (the “Terms”) are an agreement between you and Brightside Technologies SA, doing business as Brightside AI (“Brightside,” “we,” “us,” “our”), a company registered in Switzerland at Route des Flumeaux 46, 1008 Prilly, Vaud.
They cover how you use the platform. They do not change your employment terms, and they do not create any employment relationship between you and us.
By using the platform, you agree to these Terms. If you do not agree, please speak to your employer — your access is arranged by them, not by us.
2. Definitions
“Employer” means the organisation that enrolled you and that is our customer.
“Platform” means the Brightside AI security awareness platform, including the participant application, training courses, and any Slack, Microsoft Teams or LMS delivery of that content.
“Services” means the Platform and the security awareness training and simulated attacks delivered through it.
“Simulation” means a simulated social-engineering exercise sent to you through the Services — for example a simulated phishing email or a simulated telephone call — which is a training exercise and not a genuine attack.
“you” means the individual using the Services.
3. Your Employer is in charge of your participation
Your Employer decides:
- whether you are enrolled and which training you are assigned;
- which Simulations you receive and how often;
- what reporting it sees about your participation and results; and
- when your access starts and ends.
We operate the Platform on your Employer’s instructions. We do not decide who is trained, who is tested, or what your Employer does with the results. Your Employer’s own use of the Services is governed by our Terms of Use.
If you have questions about why you are being trained or tested, what your results are used for, or how your personal data is handled, contact your Employer. We explain why in Section 7.
4. What the Services do
Through the Services you may:
- complete interactive security awareness courses, which may include quizzes, mini-games and achievements;
- receive simulated phishing emails designed to look like genuine messages;
- receive simulated telephone calls that use an artificial, computer-generated voice, which may be automatically dialled and may adapt to what you say during the call;
- receive combined exercises that pair a call with an email; and
- see feedback, scores and follow-up training after an exercise.
You must be at least 18 years old to use the Services.
5. Simulated attacks — what to expect
Simulations are deliberately realistic. They are meant to resemble genuine attacks so that practice is meaningful. This means:
- a simulated email may appear to come from a colleague, a supplier, a well-known brand, or a senior person at your organisation;
- a simulated call may come from a local telephone number, may not identify Brightside, and may use a synthetic voice, including one generated to resemble a specific person where your Employer has arranged that and confirmed to us that it holds that person’s consent;
- content used in Simulations is artificially generated. It does not represent anything the person it resembles actually said, wrote, or believes; and
- if you click, reply, or provide information during a Simulation, no genuine attacker receives it. Passwords and other credentials you type into a simulated page are never stored. The Platform records only that credentials were entered, as a training result — never the credentials themselves.
Simulations are training exercises. They are not tests of your honesty or loyalty, and the content of a Simulation is not a real statement by anyone it appears to come from.
6. Information about you used in the Services
To make training relevant and simulations realistic, we process information about you on your Employer’s behalf. This may include:
Information your Employer gives us. Your name, work email address, work telephone number, job role, department, language and location — supplied directly or through systems your Employer connects, such as an HR system, an identity provider (for example Microsoft Entra ID or Okta), or a communication tool such as Slack or Microsoft Teams.
Information from public and third-party sources. Where your Employer instructs us to, we may use lawfully available information about you — for example from professional networking and social media profiles, company websites, online directories, and public data-breach records — to assess how exposed you are to targeted attacks and to make simulations reflect the way a real attacker would approach you.
Information generated by your use. Whether you opened, clicked or reported a simulated message; whether and how you responded during a simulated call; course progress and scores; and, where enabled, a recording and transcript of a simulated call.
Recordings. Simulated calls may be recorded and transcribed, and an automated analysis may be produced. Your Employer chooses whether recording is switched on. Where it is switched off, the call is analysed as it happens and the audio is not retained.
Automated analysis. Scores, pass/fail outcomes and risk indicators are produced in part by artificial intelligence and may be wrong. They are intended to guide training, not to serve as the sole basis for any decision that materially affects you.
7. Privacy — who to ask
For all of the information described in Section 6, your Employer is the data controller and we act as its processor. Your Employer determines why and how your data is used.
This means that if you want to access your data, correct it, object to processing, or exercise any other data protection right in relation to your training and simulation data, you should contact your Employer, not us. We will support your Employer in responding.
Our own Privacy Policy explains the personal data we handle as a controller in our own right — for example if you contact us directly.
8. How you may and may not use the Services
You agree to use the Services responsibly and in line with your Employer’s instructions. You must not:
- a. deliberately interfere with or disrupt the delivery of training or Simulations to yourself or to colleagues — for example by circulating the identifying details of a live Simulation so that others can filter it out before they see it;
- b. reverse-engineer, bypass or disable any technical or security measure in the Services;
- c. introduce malicious code, or attempt to gain access to any account, data or part of the Platform that is not yours;
- d. share, publish or forward training content, simulated messages, or simulation results outside your organisation, or in a way that would undermine ongoing exercises for colleagues;
- e. use another person’s credentials, or let anyone else use yours; or
- f. use the Services for anything other than the training your Employer has arranged.
Reporting a message is never a breach of these Terms. If you think something is suspicious, report it through your organisation’s normal security channel — whether it turns out to be a Simulation or a genuine attack. Reporting is the behaviour this training exists to build. The ordinary operation of your spam and security filters is likewise never a breach.
9. Fairness in training design
The Platform’s achievement and gamification features are designed as positive reinforcement. We do not build features whose purpose is to shame individual participants for failing a Simulation.
How your Employer uses results is your Employer’s decision and outside our control. If you have concerns about how results are being used, raise them with your Employer or your employee representative body.
10. Availability and no warranty
We provide the Services with reasonable skill and care, but they are provided to you “as is” and “as available”. We do not guarantee that they will be uninterrupted or error-free, that every message or call will reach you, or that training will produce any particular result.
11. Our liability to you
To the fullest extent permitted by law, we are not liable to you for indirect or consequential loss, or for loss of data, profits or opportunity, arising from your use of the Services.
Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under Swiss law, including liability for death or personal injury caused by negligence, for unlawful intent, or for gross negligence. Nothing in these Terms limits your rights against your Employer, or your data protection rights under applicable law.
12. Ending your access
Your Employer controls your access and may end it at any time. We may suspend or end your access if you breach Section 8, or where we reasonably believe it is necessary for security or legal reasons.
13. Changes to these Terms
We may update these Terms. We will post the updated version with a new “Last updated” date. Where a change is material, we will make it visible in the Platform before it takes effect. Continuing to use the Services after that means you accept the updated Terms.
14. Governing law
These Terms are governed by the substantive laws of Switzerland, excluding its conflict-of-law rules. The courts of the Canton of Vaud, Switzerland have jurisdiction, subject to any mandatory place of jurisdiction available to you under the law of your country of residence.
15. Contact
Questions about these Terms, or about the Platform itself:
Brightside Technologies SA (doing business as Brightside AI)Route des Flumeaux 46, 1008 Prilly, Vaud, Switzerland
support@brside.com
Questions about your own data, your results, or why you were enrolled: please contact your Employer.