Data Privacy & Security Policies
Numberline Security, LLC provides strategic Zero Trust security education and advisory services — helping enterprises make sense of, implement, and operationalize this modern approach to information security. This document outlines our policies regarding data privacy, security practices, and compliance obligations.
Important note: Numberline Security does not operate SaaS applications or host client data on any application servers. Our business is cybersecurity consulting — client data is handled through standard business documents such as spreadsheets, presentations, and reports, and communication is via email and meetings.
Data Privacy Policy
Types of information we collect
CLIENT INFORMATION
- Business contact information (names, titles, email addresses, phone numbers)
- Company information (business name, address, industry sector)
- Technical information about client systems and infrastructure, as disclosed during assessments
- Security assessment findings and recommendations
- Billing and payment information
CONFIDENTIAL CLIENT DATA
- Network diagrams and architecture documentation
- Security policies and procedures
- Vulnerability assessment results
- Incident response documentation
- Risk assessment findings
- Compliance audit materials
How we use information
- Providing cybersecurity advisory services
- Conducting security assessments and audits
- Developing customized security recommendations
- Maintaining ongoing client relationships
- Billing and administrative purposes
- Legal and regulatory compliance
Marketing and promotion
When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to that email. You may opt out of receiving this advertising at app.retention.com/optout.
Information sharing and disclosure
Numberline Security maintains strict confidentiality and does not share client information except:
- With explicit written client consent
- When required by law or legal process
- To protect our legal rights or comply with court orders
- In case of business acquisition, with prior client notification
Data retention
ACTIVE PROJECTS
Engagement + 90 days
COMPLETED PROJECTS
7 years
FINANCIAL RECORDS
7 years
SECURITY ASSESSMENTS
3 years
Security Policy
Numberline Security implements a best-practices information security program tailored to organizations of our size and technology footprint.
Digital security controls
ACCESS CONTROLS
- Multi-factor authentication (MFA) for all sensitive systems
- Role-based access controls
- Regular access reviews and deprovisioning
- Strong password policies
DATA PROTECTION
- Encryption of data at rest
- Encryption of data in transit
- Full disk encryption on all devices
Data Handling Procedures
Given our consulting model, client data is primarily handled through business documents. Our document security procedures cover how documents are created, stored, processed, and analyzed.
CREATION & STORAGE
- All client documents created on encrypted, company-managed devices
- Storage in encrypted, access-controlled cloud repositories
- Version control and audit trails for all documents
- Client-specific folder structures with access restrictions
PROCESSING & ANALYSIS
- Data minimization — only necessary data collected
- Purpose limitation — data used only for stated consulting purposes
- Pseudonymization where possible in reports and presentations
- Secure workstations for data analysis
Client Rights & Requests
Data subject rights
Right to Access
Request copies of personal data we hold.
Right to Rectification
Request correction of inaccurate data.
Right to Erasure
Request deletion of personal data.
Right to Restrict Processing
Limit how we use personal data.
Right to Data Portability
Receive personal data in a portable format.
Right to Object
Object to processing of personal data.
How to exercise these rights
- Submit written requests to info@NumberlineSecurity.com
- Include specific details about your request
- Provide identification verification
Response provided within 30 days.
Feedback and questions
We welcome client feedback on our policies and procedures. Please contact our team with any questions or concerns.