Privacy policy
This policy explains what personal information NCPS Information Security, Inc. (“NCPS InfoSec”, “we”, “us”) collects through this website and in the course of providing security services, why we collect it, how long we keep it, and the choices available to you.
1. Information we collect
Information you give us
- Enquiry details submitted through our contact form: name, work email address, organisation, telephone number, industry, approximate endpoint count, the service you are interested in, your timeline, and the message you write.
- Correspondence you send by email, telephone, or during a scheduled call, including notes our staff take.
- Contractual and billing information if you become a client, including signatory details and remittance information.
Information collected automatically
- Server logs. Our web server records the requested URL, timestamp, HTTP status, referring page, and user-agent string. IP addresses are truncated before storage.
- No advertising or cross-site tracking. This site sets no advertising cookies, embeds no third-party trackers, and does not participate in any advertising network.
- Local storage. One key,
ncps.billing, remembers whether you last viewed monthly or annual pricing. It contains no identifier and never leaves your browser. Clearing site data removes it.
Information we process on behalf of clients
When we deliver security services we process security telemetry from client systems, which may contain personal information such as usernames, device names, IP addresses, and email metadata. We process this strictly as a service provider under the client's instructions and the master services agreement, and, where applicable, under a Business Associate Agreement or Data Processing Addendum.
2. How we use information
- To respond to your enquiry and prepare a proposal or scope of work.
- To deliver, support, and improve the services you have contracted for.
- To meet legal, regulatory, insurance, and audit obligations.
- To secure our own systems, including detecting abuse of this website.
We do not sell personal information, we do not share it with advertisers or data brokers, and submitting the contact form does not subscribe you to any mailing list.
3. Legal bases
Where the GDPR or UK GDPR applies, we rely on: legitimate interests for responding to business enquiries and securing our systems; performance of a contract for service delivery and billing; consent where you have given it, which you may withdraw at any time; and legal obligation for retention and reporting duties.
4. Sharing and sub-processors
We share personal information only with: service providers who host our infrastructure, deliver our email, or process payments, each under written contract and confidentiality obligations; professional advisers such as auditors, counsel, and insurers; and authorities where we are legally compelled. A current list of sub-processors used in service delivery is available to clients and prospective clients on request.
All processing of client security telemetry is performed within the United States by United States personnel. We do not offshore or subcontract monitoring and response.
5. Retention
- Website enquiries: 24 months from last contact, unless you become a client or ask us to delete them sooner.
- Web server logs: 90 days.
- Client records: for the term of the agreement plus seven years, or longer where a regulator, contract, or legal hold requires it.
- Security telemetry: per the retention tier in the client's plan, then deleted on the published schedule.
6. Security
We apply the controls we sell: encryption in transit and at rest, least-privilege and role-based access, multifactor authentication on all administrative access, continuous monitoring of our own estate, annual independent penetration testing, and an annual SOC 2 Type II examination of our operation. No system is perfectly secure, but we hold ourselves to the standard we hold clients to, and we publish the result.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information; to object to or restrict certain processing; and to withdraw consent. Residents of California, Colorado, Connecticut, Delaware, Virginia, and other states with comprehensive privacy laws have equivalent rights, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
To exercise a right, email privacy@ncpsinfosec.com. We verify requests before acting and respond within 45 days, or within the shorter period your law requires. If we process your information on behalf of a client, we will refer your request to that client, who controls the data.
8. Children
This website is directed to businesses. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
9. International visitors
Our systems are located in the United States. If you contact us from outside the United States, your information will be transferred to and processed in the United States under the safeguards described in this policy and, where required, standard contractual clauses.
10. Changes
We will post any change to this policy on this page and update the “last updated” date. Material changes affecting clients are also communicated directly under the notice provisions of the applicable agreement.
11. Contact
Privacy enquiries: privacy@ncpsinfosec.com
Security issues with this website: security@ncpsinfosec.com
Post: NCPS Information Security, Inc., 1000 N. West Street, Suite 1200, Wilmington, DE 19801, US
Telephone: (833) 761-0695
This document is a starting template supplied with the site build. Have counsel review and adapt it to your actual data practices and jurisdictions before publication.