01 / OVERVIEW

Overview

NSIGNIS LTD ("NSIGNIS," "we," "our," or "us") is committed to protecting the privacy and security of information entrusted to us by our clients, partners, and website visitors. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you interact with our website at nsignis.com, our products, or our services.

Given the nature of our work; providing artificial intelligence solutions for defense, security and business sector, we operate under heightened data governance standards. All data handling practices are designed to comply with applicable U.S. federal regulations, the EU General Data Protection Regulation (GDPR), and applicable export control requirements.

This policy applies to information collected through our public-facing website and marketing activities. Operational data processed under government contracts is governed by the applicable contract terms, classified data handling procedures, and federal regulations including the FAR and DFARS privacy clauses.

02 / DATA COLLECTION

Information We Collect

We collect information in the following categories:

Category Examples Source
Identity Data Name, title, organization, security clearance level You directly
Contact Data Email address, phone number, mailing address You directly
Technical Data IP address, browser type, device identifiers, access logs Automated collection
Usage Data Pages visited, time on site, referral source, click paths Automated collection
Communications Data Briefing requests, inquiry messages, correspondence You directly
Contractual Data Procurement details, contract identifiers, clearance verifications You or your organization

We do not collect sensitive categories of personal data (such as biometric data, health data, or financial account details) through our website. Any sensitive data collected in the context of government contracts is handled pursuant to applicable federal regulations and contract-specific data handling plans.

03 / DATA USE

How We Use Information

We use your information for the following purposes:

  • To respond to briefing requests, inquiries, and procurement processes
  • To verify eligibility and security clearance status for classified briefings
  • To fulfill contractual obligations under government and commercial contracts
  • To improve and optimize our website and digital presence
  • To send relevant communications about NSIGNIS capabilities, events, and publications only with your consent
  • To comply with legal obligations, export control regulations, and government reporting requirements
  • To detect, investigate, and prevent security incidents and fraudulent activity
  • To enforce our terms and protect the rights of NSIGNIS and our clients

We never use your personal data to train, fine-tune, or otherwise improve our AI models without your explicit written consent and the approval of any relevant contracting authority.

04 / DISCLOSURE

Information Sharing

NSIGNIS does not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:

  • Service providers: Vetted third-party vendors who assist with IT infrastructure, secure communications, and business operations, all bound by data processing agreements and security requirements
  • Government clients and contracting authorities: As required by applicable contracts or task orders
  • Legal obligations: When required by law, regulation, court order, or lawful government request — including requests from national security or law enforcement authorities
  • Business transfers: In connection with a merger, acquisition, or sale of assets, subject to the same privacy commitments
  • With your consent: For any other purpose disclosed at the time of collection

All third-party service providers with access to personal data are subject to confidentiality obligations and security requirements commensurate with the sensitivity of the data handled.

05 / RETENTION

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, and to resolve disputes. Specific retention periods are:

Data Type Retention Period Basis
Website inquiry records 3 years from last contact Legitimate interest
Contract-related data 7 years post-contract Legal obligation (FAR)
Security logs 2 years Security / legal obligation
Marketing consent records Until consent withdrawn + 1 year Consent
Classified / CUI data Per applicable contract / NARA schedule Federal regulation

06 / SECURITY

Security

NSIGNIS implements a layered security program commensurate with our position as a defense technology provider. Our controls include:

  • End-to-end encryption for all data in transit (TLS 1.3 minimum) and data at rest (AES-256)
  • Zero-trust network architecture with continuous identity verification
  • High-authorized cloud infrastructure for all government-related data
  • Certified processes for CUI handling
  • Continuous security monitoring, intrusion detection, and automated incident response
  • Annual third-party penetration testing audits
  • Personnel background screening and security clearance verification

Despite these measures, no system can guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.

07 / YOUR RIGHTS

Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data, subject to legal and contractual retention requirements
  • Restriction: Request that we restrict processing of your data in certain circumstances
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests or for direct marketing
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact our Legal Desk at [email protected].
We will respond within 30 days. Some rights may be limited where data is processed under government contracts or where legal obligations require retention.

08 / COOKIES

Cookies & Tracking Technologies

Our website uses a minimal set of cookies and similar technologies. We do not use third-party advertising trackers or behavioral profiling tools.

Type Purpose Duration
Strictly Necessary Session management, security tokens, CSRF protection Session
Functional User preferences (e.g., language, region) 1 year
Analytics Anonymized page view counts and performance metrics (self-hosted) 90 days

You may configure your browser to refuse all cookies or to alert you when cookies are being sent. Disabling cookies may affect the functionality of certain features of our site. EU/UK visitors may be presented with a cookie consent banner upon first visit.

09 / INTERNATIONAL

International Data Transfers

NSIGNIS is headquartered in Sofia,Bulgaria. If you are located outside the U.S., please be aware that information you provide may be transferred to and processed in the United States or other jurisdictions in which we or our service providers operate.

For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on one or more of the following transfer mechanisms:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreements (IDTAs)
  • Adequacy decisions where applicable
  • Derogations under Article 49 GDPR for defense and national security purposes where applicable

Certain data processed under U.S. contracts may be subject to export control restrictions. Such data is handled exclusively within authorized jurisdictions by cleared personnel.

10 / CHILDREN

Children's Privacy

Our website and services are directed exclusively to professionals operating in the defense, intelligence, and national security sectors. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that a minor has submitted personal information to us, we will promptly delete such information. If you believe we have inadvertently collected information from a minor, please contact us at [email protected].

11 / UPDATES

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required by law, notify affected individuals directly.

We encourage you to review this policy periodically. Your continued use of our website after the effective date of any changes constitutes your acceptance of the updated policy.

12 / CONTACT

Contact Us

For questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Legal Desk:

Legal Desk

Encrypted Contact PGP Key ID: B0CAFA68
Response Time Within 30 business days of receipt