01 / OVERVIEW
Overview
NSIGNIS LTD ("NSIGNIS," "we," "our," or "us") is committed to protecting the privacy and security of information entrusted to us by our clients, partners, and website visitors. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you interact with our website at nsignis.com, our products, or our services.
Given the nature of our work; providing artificial intelligence solutions for defense, security and business sector, we operate under heightened data governance standards. All data handling practices are designed to comply with applicable U.S. federal regulations, the EU General Data Protection Regulation (GDPR), and applicable export control requirements.
This policy applies to information collected through our public-facing website and marketing activities. Operational data processed under government contracts is governed by the applicable contract terms, classified data handling procedures, and federal regulations including the FAR and DFARS privacy clauses.
02 / DATA COLLECTION
Information We Collect
We collect information in the following categories:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Name, title, organization, security clearance level | You directly |
| Contact Data | Email address, phone number, mailing address | You directly |
| Technical Data | IP address, browser type, device identifiers, access logs | Automated collection |
| Usage Data | Pages visited, time on site, referral source, click paths | Automated collection |
| Communications Data | Briefing requests, inquiry messages, correspondence | You directly |
| Contractual Data | Procurement details, contract identifiers, clearance verifications | You or your organization |
We do not collect sensitive categories of personal data (such as biometric data, health data, or financial account details) through our website. Any sensitive data collected in the context of government contracts is handled pursuant to applicable federal regulations and contract-specific data handling plans.
03 / DATA USE
How We Use Information
We use your information for the following purposes:
- To respond to briefing requests, inquiries, and procurement processes
- To verify eligibility and security clearance status for classified briefings
- To fulfill contractual obligations under government and commercial contracts
- To improve and optimize our website and digital presence
- To send relevant communications about NSIGNIS capabilities, events, and publications only with your consent
- To comply with legal obligations, export control regulations, and government reporting requirements
- To detect, investigate, and prevent security incidents and fraudulent activity
- To enforce our terms and protect the rights of NSIGNIS and our clients
We never use your personal data to train, fine-tune, or otherwise improve our AI models without your explicit written consent and the approval of any relevant contracting authority.
05 / RETENTION
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, and to resolve disputes. Specific retention periods are:
| Data Type | Retention Period | Basis |
|---|---|---|
| Website inquiry records | 3 years from last contact | Legitimate interest |
| Contract-related data | 7 years post-contract | Legal obligation (FAR) |
| Security logs | 2 years | Security / legal obligation |
| Marketing consent records | Until consent withdrawn + 1 year | Consent |
| Classified / CUI data | Per applicable contract / NARA schedule | Federal regulation |
06 / SECURITY
Security
NSIGNIS implements a layered security program commensurate with our position as a defense technology provider. Our controls include:
- End-to-end encryption for all data in transit (TLS 1.3 minimum) and data at rest (AES-256)
- Zero-trust network architecture with continuous identity verification
- High-authorized cloud infrastructure for all government-related data
- Certified processes for CUI handling
- Continuous security monitoring, intrusion detection, and automated incident response
- Annual third-party penetration testing audits
- Personnel background screening and security clearance verification
Despite these measures, no system can guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
07 / YOUR RIGHTS
Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data, subject to legal and contractual retention requirements
- Restriction: Request that we restrict processing of your data in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact our Legal Desk at [email protected].
We will respond within 30 days. Some rights may be limited where data is processed under government contracts or where legal obligations require retention.
09 / INTERNATIONAL
International Data Transfers
NSIGNIS is headquartered in Sofia,Bulgaria. If you are located outside the U.S., please be aware that information you provide may be transferred to and processed in the United States or other jurisdictions in which we or our service providers operate.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on one or more of the following transfer mechanisms:
- European Commission Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreements (IDTAs)
- Adequacy decisions where applicable
- Derogations under Article 49 GDPR for defense and national security purposes where applicable
Certain data processed under U.S. contracts may be subject to export control restrictions. Such data is handled exclusively within authorized jurisdictions by cleared personnel.
10 / CHILDREN
Children's Privacy
Our website and services are directed exclusively to professionals operating in the defense, intelligence, and national security sectors. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has submitted personal information to us, we will promptly delete such information. If you believe we have inadvertently collected information from a minor, please contact us at [email protected].
11 / UPDATES
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify affected individuals directly.
We encourage you to review this policy periodically. Your continued use of our website after the effective date of any changes constitutes your acceptance of the updated policy.
12 / CONTACT
Contact Us
For questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Legal Desk:
Legal Desk