How BrainyMaster and BrainyGRC, operated by Ashal Technologies, collect, use and protect information.
Last updated: 21 July 2026
Ashal Technologies ("we", "us", "our") operates BrainyMaster, a security awareness training and phishing simulation platform, and BrainyGRC, a governance, risk and compliance platform (together, the "Services"). This Privacy Policy explains what information we collect through our website and Services, how we use it, and the choices you have.
This policy applies to visitors of www.brainymaster.com, and to administrators and end users of the BrainyMaster and BrainyGRC platforms, whether deployed as SaaS or on-premise. For on-premise deployments, your organization acts as the data controller for data processed within your own environment; this policy describes our practices where we act as controller or processor on your behalf.
We collect information in the following ways:
We use collected information to:
BrainyMaster is designed to be deployed by organizations to train their own employees. Simulated phishing and smishing campaigns are configured and authorized by your employer or organization administrator, not by Ashal Technologies directly. Data generated by these simulations - such as whether a simulated email was opened, clicked, or reported - is made available to your organization's administrators for training and risk-reduction purposes, in line with your employer's internal policies.
If you are an employee whose organization uses BrainyMaster, questions about how your simulation and training data is used should be directed to your employer's IT, security or HR department in the first instance.
We do not sell personal information. We may share information with:
BrainyMaster and BrainyGRC are available as a fully managed SaaS deployment or as an on-premise deployment hosted within your own infrastructure. Where we host data (SaaS), we apply administrative, technical and physical safeguards designed to protect information against unauthorized access, alteration, disclosure or destruction, including role-based access control and encryption in transit. Where you deploy on-premise, data security is governed primarily by your own environment and configuration.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Our website may use cookies and similar technologies to remember preferences, understand site usage, and support essential functionality such as keeping you signed in. You can control cookies through your browser settings; disabling cookies may affect some site functionality.
Depending on your location and applicable law, you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to certain processing. Where your organization is the administrator of your BrainyMaster or BrainyGRC account, some requests may need to be directed to your organization first. To exercise these rights with respect to information we control directly (such as demo request submissions), contact us using the details below.
We retain information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Training, campaign and compliance records within a customer deployment are generally retained according to that organization's configuration and retention settings.
Our Services are intended for business use by working professionals and are not directed to children. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last updated" date. Material changes may be communicated through the website or directly to administrators.
If you have questions about this Privacy Policy or our data practices, contact us at: