SOC LIVE / Threats blocked today 14,382 · Events processed 96,220,145 · Median response 4m 12s
Legal

Privacy Policy

This policy explains how NovaShield Cyber handles personal information collected through novashieldlabs.io and in the course of our business relationships — who we collect it from, why we use it, who we share it with, and the choices available to you.

Last updated: July 17, 2026

1. Overview

NovaShield Cyber ("NovaShield", "we", "us") is a cybersecurity company headquartered in Boston, Massachusetts. We sell to organizations rather than consumers, so most of the personal information we handle is business contact information belonging to people who work at current, former, or prospective clients, partners, and vendors.

This policy covers our public website, our marketing and sales activities, our recruiting process, and the administration of our client relationships — that is, information for which we act as a controller.

What this policy does not cover. When NovaShield monitors or assesses a client's environment, we process data that lives inside that client's infrastructure — logs, network and endpoint telemetry, alerts, security events, and any personal information those records happen to contain. We handle that data on the client's instructions, as a service provider or processor, under the applicable services agreement and Data Processing Addendum. Those documents, not this policy, govern how it is used, retained, and returned or deleted. If you are an employee or customer of one of our clients and have questions about telemetry from their systems, contact that organization directly — they are the controller of that data.

2. Information We Collect

We collect information you give us directly, information generated automatically when you use the website, and information we receive from third parties.

Information you provide

  • Contact and professional details submitted through our assessment request form or by email — name, work email address, phone number, company, role, and the primary environment you selected.
  • The content of your message. Please do not include sensitive personal data or confidential technical detail in an initial inquiry.
  • Records of correspondence, meeting notes, and assessment scheduling details.
  • Billing and account administration details for clients, including the names of authorized contacts.
  • Application materials if you apply for a role with us.

Information collected automatically

  • IP address, approximate location derived from it, browser and device type, operating system, and referring URL.
  • Pages viewed, time on page, and interactions with the site, collected through cookies and similar technologies where permitted.
  • Server and security logs for our own site, which we keep to detect abuse and troubleshoot problems.

Information from other sources

  • Publicly available business information used to verify a company's profile.
  • Referrals and introductions from partners, resellers, and existing clients.

3. How We Use Information

  • Responding to inquiries, scoping a security assessment, and preparing proposals.
  • Delivering and administering contracted services, including onboarding, support, and invoicing.
  • Sending service announcements and — where you have opted in or where permitted for existing business contacts — occasional threat intelligence briefings and product updates. Every marketing message includes an unsubscribe link.
  • Operating, maintaining, and improving the website.
  • Protecting our own systems against fraud, abuse, and unauthorized access.
  • Meeting legal, tax, and contractual obligations, and establishing or defending legal claims.
  • Evaluating candidates who apply for employment.

We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law. We do not use automated decision-making that produces legal or similarly significant effects about individuals.

4. Legal Bases and Business Purposes

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract — to take steps at your request before entering an agreement and to perform a contract with you or your employer.
  • Legitimate interests — to run and secure our business, to market our services proportionately, and to understand how our website is used. We weigh these against your rights and expectations.
  • Consent — for non-essential cookies and for marketing where consent is required. Withdrawal does not affect processing carried out beforehand.
  • Legal obligation — where retention or disclosure is required of us by law.

5. Cookies and Tracking

We use a small number of cookies and similar technologies. Strictly necessary cookies keep the site functioning and remember your cookie choice. Analytics cookies help us see which pages are read and where visitors drop off; these are set only where you have accepted them or where local law permits.

You can change your choice at any time through the cookie banner or your browser settings, and blocking cookies will not prevent you from reading this site. Full detail on the categories we use and their retention periods is in our Cookie Policy. We do not respond to browser Do Not Track signals in a standardized way; we do honor Global Privacy Control signals where required by law.

6. Data Sharing and Subprocessors

We share personal information only where there is a reason to, and we contractually restrict what recipients may do with it. Categories of recipients include:

  • Cloud hosting and infrastructure providers that run our website and internal systems.
  • CRM, email delivery, and support tooling used by our sales and service teams.
  • Web analytics providers, subject to your cookie choices.
  • Professional advisers — accountants, auditors, and legal counsel — under duties of confidentiality.
  • Payment processors and banks for invoicing and collection.
  • Government bodies, regulators, or law enforcement where we are legally required to disclose, or where disclosure is necessary to protect our rights or the safety of others. We review such requests and push back where they are overbroad or lack a valid legal basis.
  • An acquirer or successor entity in a merger, financing, or sale of assets, subject to this policy continuing to apply.

A current list of the subprocessors used to deliver contracted services is maintained for clients and provided under the applicable services agreement. If we transfer personal information out of the European Economic Area or the UK, we use Standard Contractual Clauses or another lawful transfer mechanism.

7. Security of Your Data

We apply administrative, technical, and physical safeguards proportionate to the information we hold: encryption in transit and at rest, role-based access control with multi-factor authentication, network segmentation, logging and monitoring of access to internal systems, background screening of personnel with access to client environments, and periodic review of our controls and vendors.

No system, ours included, can be guaranteed secure. Any organization that promises absolute security is overstating what security engineering can deliver. What we commit to is a defensible set of controls, honest disclosure when something goes wrong, and notification to affected parties and regulators within the timeframes the law requires.

8. Data Retention

We keep personal information only as long as we have a reason to, then delete it or render it non-identifying.

  • Inquiry and prospect records: up to 24 months from the last meaningful contact, unless a relationship begins.
  • Client records and correspondence: for the term of the agreement, then as needed to meet contractual, tax, and limitation-period requirements.
  • Website analytics data: typically no longer than 14 months.
  • Recruiting records: up to 12 months after a decision, or longer with your consent.

Records subject to a legal hold are retained until the hold is lifted. Retention of data inside client environments is set by the client under the services agreement, not by this policy.

9. Your Privacy Rights

California (CCPA/CPRA). If you are a California resident, you may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; request deletion; request correction; and limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of on that front. We will not discriminate against you for exercising these rights.

EEA and UK (GDPR). You may request access, correction, erasure, restriction of processing, or portability; object to processing based on legitimate interests, including direct marketing; and withdraw consent where we rely on it. You may also lodge a complaint with your national supervisory authority, though we would appreciate the chance to address your concern first.

Other states and countries. Residents of other US states with comprehensive privacy laws, and individuals elsewhere, may have comparable rights. We honor them where they apply.

To exercise any right, email [email protected]. We will verify your identity before acting, usually by confirming details we already hold, and respond within the period the applicable law allows — generally 45 days in California and one month under the GDPR, with an extension where a request is complex. An authorized agent may submit a request on your behalf with written permission.

Note If your request concerns data held inside a client's environment, we will forward it to that client and support their response, but we cannot act on it independently.

10. Updates to This Policy

We revise this policy when our practices, technology, or legal obligations change. The date at the top reflects the most recent revision. If a change materially affects how we use personal information, we will give notice on this page and, where appropriate, by email before it takes effect.

11. Contact Us

Questions, requests, and complaints about this policy or our handling of personal information can be directed to:

Please mark privacy correspondence for the attention of the Privacy Team so it reaches the right people without delay. If you are reporting a suspected security issue rather than a privacy question, use the same address and we will route it to our security team.