WizerFamily
Sign in

Privacy Policy

Last updated: June 2026

1. About This Policy

This Privacy Policy explains how Wizer ("we", "us", or "our") collects, uses, and protects information when you use Wizer Family — a cybersecurity awareness training platform intended for adults who register on behalf of their household.

Because the household may include minors, we comply with the Children's Online Privacy Protection Act (COPPA), the General Data Protection Regulation (GDPR), and applicable state privacy laws. Only the adult family head registers and operates the account; children do not create their own accounts.

Note: This policy reflects our current data practices. It is pending final review by external counsel; minor wording adjustments may follow without changes to the underlying practices described.

2. Who We Are

Wizer is the data controller responsible for your information. You can reach our privacy team at privacy@wizer-training.com.

3. Information We Collect

Family Head (adult account holder)

  • First and last name, and email address (encrypted at rest)
  • Password (stored as a one-way cryptographic hash — we cannot read it)
  • Two-factor authentication secret (used only to verify login)
  • Age confirmation that you are 18 years or older
  • Parental/guardian consent timestamp
  • Email verification status and timestamp
  • Delayed confirmation timestamp (sent ~24 hours after signup as part of our verifiable parental consent mechanism)
  • Last login timestamp

Family Members (learners, including children)

We deliberately collect minimal data for family members. Specifically:

  • A labelchosen by the family head — this is typically a nickname or role (e.g., "Kid 1", "Grandma") and is not required to be a real name
  • Training progress data: video watch intervals, PDF views, quiz answers, promises completed
  • Completion timestamp and certificate token (if training is completed)

We do not collect the name, email address, date of birth, photographs, geolocation, or any other personally identifiable information from family members.

Automatically collected

  • Server-side logs for security and abuse prevention (IP addresses, request timestamps)
  • We do not use cookies for tracking or advertising. A session cookie is used solely to keep the family head logged in.
  • No third-party analytics, advertising, or behavioural tracking is loaded by our pages.

4. How We Use Your Information

  • To provide the training service and track completion for certificates
  • To send transactional emails (email verification, delayed parental consent confirmation, password reset, completion notifications)
  • To authenticate the family head securely via password and 2FA
  • To comply with COPPA, GDPR, and other applicable laws
  • To operate, maintain, and improve our service

We do not use your data for advertising, profiling, behavioural tracking, cross-context behavioural advertising, or sale to third parties. We do not share data for marketing purposes with anyone.

5. Verifiable Parental Consent & COPPA

Wizer Family is designed so that only an adult family head can create an account. We verify parental consent through the following process, in this order:

  1. Age confirmation at signup. The family head must confirm they are 18 years of age or older before the account can be created.
  2. Parental consent statement. The family head confirms they are the parent or legal guardian of any children they enroll and consents to the data collection described in this policy on their behalf.
  3. Email verification.Account activation requires clicking a unique verification link sent to the family head's email address. The account is not active until this step completes.
  4. Delayed confirmation email.Approximately 24 hours after account creation, we send a separate confirmation email summarising the account and family members enrolled, with instructions to delete the account immediately if it was not created by the recipient. This step satisfies the FTC's "Email Plus" verifiable parental consent method for services that do not share children's data externally.
  5. Two-factor authentication. The family head must set up TOTP-based 2FA on first login.

We collect only a label (nickname) for child learners — no name, email, photograph, or other PII. The family head may remove a child's access or permanently delete all associated data at any time from the Account Settings page.

Parents or guardians may contact us at privacy@wizer-training.com to review, update, or delete any information associated with their children.

6. Data Security

  • All data is transmitted over HTTPS (TLS 1.2+); HSTS is enforced
  • Sensitive PII fields (family head name, email) are encrypted at rest using AES-256-GCM with a per-field encryption key
  • Passwords are hashed using bcrypt (cost factor 12) and are never stored in plaintext
  • Two-factor authentication (TOTP) is required for all family head accounts
  • Server-side rate limiting is applied to authentication and signup endpoints
  • Our database is hosted on Neon (a SOC 2-compliant Postgres provider) and the application on Vercel (also SOC 2-compliant)
  • All administrative actions are recorded in an immutable audit log

7. Data Retention

We retain your data for as long as your account is active. When you delete your account from the Account Settings page, all associated data — including family member progress, certificates, and personal information — is permanently deleted from our database immediately. Backup copies are purged within 30 days.

Server logs may be retained for up to 90 days for security purposes.

8. Sub-Processors and Service Providers

We share data only with the following service providers, and only as necessary to operate:

  • Resend— transactional email delivery (receives the family head's email address and email content only)
  • Neon — database hosting (stores all data in encrypted form)
  • Vercel — application hosting and edge CDN
  • Wistia— video hosting and delivery (no personal data from learners is sent to Wistia; video playback is anonymous from Wistia's perspective)
  • BetterStack — operational logs and uptime monitoring (no learner PII; application and security event logs only)

We do not sell, rent, share for cross-context behavioural advertising, or trade your data with any third parties. All sub-processors are bound by data processing agreements prohibiting use of your data outside of providing the service to Wizer.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — correct inaccurate personal data
  • Erasure — request permanent deletion of your account and all associated data
  • Portability — receive your data in a portable format
  • Objection — object to processing of your personal data

You can exercise several of these rights directly from the Account Settings page:

  • Download a copy of your data — generates a JSON file containing your account, family members, and all training progress
  • Edit your name — update first and last name directly
  • Delete your account — permanently erases all data immediately

For other requests (email changes, rectification of other fields, objection), contact us at privacy@wizer-training.com.

10. Children's Privacy and California Minors

Because we collect minimal data for family members and do not sell, share, or use any data for cross-context behavioural advertising, the CCPA/CPRA "under-16 opt-in" requirement does not apply to our data practices. We similarly do not engage in any of the data processing activities that would require a Consent Management Platform.

11. Changes to This Policy

We may update this policy as our service evolves or as legal requirements change. We will notify family heads of material changes by email. Continued use of the service after notice constitutes acceptance of the updated policy.

12. Contact

For privacy questions, data requests, or COPPA-related inquiries, please contact:

Wizer Privacy Team

Email: privacy@wizer-training.com