top of page

NKCyberTech Privacy Policy

Effective date: September 19, 2026

1. Who We Are

NKCyberTech provides cybersecurity, privacy, governance, risk, compliance, audit-readiness, and professional training services. In this Policy, “NKCyberTech,” “we,” “us,” and “our” refer to the business operating the NKCyberTech website and services.

Privacy questions and requests may be sent to info@nkcybertech.com. Please do not include passwords, authentication codes, payment-card details, health information, or other highly sensitive information in an ordinary email.

2. Information We Collect

Information you provide
• Contact and professional information, such as name, business email address, telephone number, job title, employer, and location.
• Inquiry and engagement information, including consultation requests, training interests, project requirements, communications, proposals, contracts, and support requests.
• Assessment information you choose to submit through questionnaires, readiness tools, scoping forms, or similar resources.
• Billing and transaction information needed to issue invoices, process payments, maintain records, and prevent fraud. Payment-card information may be handled directly by a payment processor rather than stored by NKCyberTech.
• Event, webinar, or training registration information and attendance records.
• Job applicant, contractor, vendor, or business-partner information when relevant to a relationship with NKCyberTech.

Information collected automatically
When you use our website, we and our service providers may collect device and usage information such as IP address, browser type, operating system, referring pages, pages viewed, approximate location derived from IP address, date and time of access, device identifiers, cookie identifiers, and interaction data. We use this information to operate, secure, troubleshoot, measure, and improve the website and, where permitted, to assess advertising performance.

Client service data
NKCyberTech does not require clients to provide personally identifiable information when anonymized, redacted, aggregated, masked, or synthetic evidence will reasonably meet the engagement purpose. During an engagement, clients may provide business records, technical evidence, system information, personnel records, vendor information, security findings, audit evidence, or other information. Clients are responsible for minimizing that information and ensuring they are authorized to provide it. If personal information is necessary, NKCyberTech processes it only for the engagement, related administration, legal obligations, security, and other purposes authorized by the client or permitted by law.

Information we ask you not to send
Do not submit sensitive PII or regulated data through the public website, ordinary email, booking forms, or assessment tools. Unless we specifically request it through an approved secure channel for an authorized engagement, do not send passwords, private encryption keys, production credentials, full payment-card numbers, government identifiers, medical records, protected health information, biometric data, precise financial information, or unnecessary personal information. If unsolicited sensitive information is received, we may securely delete, return, redact, or restrict it when reasonably practicable and legally permitted.

3. How We Use Personal Information

• Respond to inquiries, schedule consultations, prepare proposals, register participants, and deliver services or training.
• Administer client, vendor, partner, contractor, and business relationships.
• Operate, maintain, personalize, troubleshoot, and improve our website, assessment tools, and services.
• Authenticate users, protect accounts and systems, detect misuse, prevent fraud, investigate incidents, and maintain security logs.
• Process invoices and payments and maintain tax, accounting, and business records.
• Send operational messages and, with consent where required, marketing communications. You may unsubscribe from promotional email at any time.
• Measure website and campaign performance and understand how visitors find and use our services.
• Comply with law, lawful requests, professional obligations, insurance requirements, dispute-resolution needs, and the establishment, exercise, or defence of legal claims.

4. Legal Grounds and Consent

We rely on consent where required. Depending on the context and applicable law, we may also process personal information to perform a contract or take requested pre-contractual steps, comply with legal obligations, protect vital or security interests, or pursue legitimate business interests that are not overridden by an individual’s rights. Consent may be withdrawn, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not affect processing already lawfully completed.

5. Cookies, Analytics and Advertising
Our website and service providers may use cookies, pixels, tags, local storage, and similar technologies. These technologies may be necessary for site operation and security, or may support preferences, analytics, and advertising measurement. Where required, non-essential technologies are used only after consent. Browser controls may block or delete cookies, but some website features may not function correctly.

Third-party analytics or advertising providers, including Google services where enabled, may receive device and usage information under their own terms and privacy notices. NKCyberTech does not control how an independent third party uses information for its own purposes. Available advertising and cookie choices depend on the technology, browser, device, and jurisdiction.

6. When We Disclose Information
We do not sell personal information for money. We may disclose information only as reasonably necessary in the following circumstances:
• Service providers that support hosting, website operation, communications, scheduling, customer relationship management, analytics, advertising measurement, document collaboration, security, payment processing, accounting, and professional services.
• Auditors, certification bodies, penetration-testing providers, legal counsel, insurers, and other specialists when authorized for an engagement or reasonably necessary for professional, legal, or risk-management purposes.
• Government, regulatory, law-enforcement, judicial, or other parties when required by law or when we reasonably believe disclosure is necessary to protect rights, safety, security, or property.
• A prospective or completed corporate transaction, such as financing, reorganization, merger, sale, or transfer of assets, subject to appropriate confidentiality and legal safeguards.
• Other recipients when you direct us to disclose information or provide valid consent.

7. Cross-Border Processing
NKCyberTech and its service providers may process information in Canada, the United States, and other countries where they operate. Information processed outside your province, state, or country may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement, or national-security authorities under lawful process. Where required, we use contractual, organizational, and technical measures intended to support lawful transfers. You may contact us for information about applicable transfer safeguards, subject to legal and confidentiality restrictions.

8. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide services, maintain business and security records, comply with legal, tax, accounting, insurance, and professional obligations, enforce agreements, and resolve disputes. Retention periods vary according to the type and sensitivity of the information, the engagement, legal requirements, limitation periods, and security needs. Information may remain in backups or archives until deleted in the ordinary course, subject to access restrictions. We may retain de-identified or aggregated information where it cannot reasonably be used to identify an individual.

9. Security
We use administrative, technical, and physical safeguards designed to protect personal information in a manner appropriate to its sensitivity and the risks involved. These may include access controls, authentication, encryption where appropriate, secure configuration, logging, vendor review, confidentiality obligations, backup controls, and incident-response procedures.

No internet transmission, cloud service, email system, or storage method is completely secure. Accordingly, we cannot guarantee absolute security, uninterrupted availability, or that unauthorized access will never occur. Individuals should use approved secure channels, protect their credentials, and promptly notify us of suspected misuse. Where required by applicable law, we will assess and provide breach notifications to affected individuals and regulators.

10. Your Rights and Choices
Depending on where you live and subject to legal exceptions, you may have rights to request access to personal information, obtain information about its use and disclosure, correct inaccurate information, withdraw consent, object to or restrict certain processing, request deletion, receive portable data, or complain to a privacy regulator. You may also opt out of promotional email by using the unsubscribe mechanism or contacting us.

To submit a request, email info@nkcybertech.com and describe the request. We may verify identity and authority before responding. We may decline, limit, or charge a permitted fee for a request where allowed by law, including when information is protected by privilege, confidentiality duties, security restrictions, another person’s rights, or record-retention requirements. We will explain a refusal where required.

11. Children
Our website and services are intended for organizations and adults and are not directed to children under 16. We do not knowingly collect personal information from children through the website without authorization required by law. If you believe a child has provided personal information, contact us so we can assess and take appropriate action.

12. Third-Party Websites and Platforms
Our website may link to third-party websites, social platforms, scheduling tools, payment services, training platforms, or other services. Their privacy practices are governed by their own notices and terms. A link or integration does not mean NKCyberTech controls or accepts responsibility for the third party’s privacy, security, content, or availability. Review the third party’s notices before providing information.

13. Confidentiality and Professional Services
A public privacy policy is not a substitute for a confidentiality agreement, data processing agreement, statement of work, business associate agreement, or other engagement-specific terms. Where a signed agreement conflicts with this Policy regarding client service data, the signed agreement controls to the extent permitted by law. NKCyberTech may preserve evidence, security logs, communications, and records when reasonably necessary to investigate suspected misconduct, respond to incidents, meet legal obligations, or establish, exercise, or defend legal claims.

14. Changes to This Policy
We may update this Policy to reflect changes in law, technology, services, or business practices. The updated version will be posted with a revised effective date. If required by law, we will provide additional notice or obtain consent for material changes. Continued use of the website after an update does not replace consent where consent is legally required.

15. Contact and Complaints
Questions, privacy requests, and complaints may be sent to:
NKCyberTech
Email: info@nkcybertech.com
Website: https://www.nkcybertech.com

We will review complaints and respond as required by applicable law. You may also have the right to contact the privacy or data-protection regulator in your jurisdiction.

16. Interpretation and Legal Effect
This Policy is intended to provide transparency and to support compliance with applicable privacy and data-protection laws. It does not waive legal rights, create warranties, guarantee outcomes, or limit obligations that cannot lawfully be limited. If any provision is unenforceable, the remaining provisions continue to apply to the extent permitted by law.

bottom of page