Free Agentic AI Security Workshop Map your footprint, identify your highest-risk gaps, and leave with a customized security summary. Book a Workshop→
Start assessment
LEGAL
LAST UPDATED SEPTEMBER 10, 2025

Data Privacy & Security Policies

Numberline Security, LLC provides strategic Zero Trust security education and advisory services — helping enterprises make sense of, implement, and operationalize this modern approach to information security. This document outlines our policies regarding data privacy, security practices, and compliance obligations.

Important note: Numberline Security does not operate SaaS applications or host client data on any application servers. Our business is cybersecurity consulting — client data is handled through standard business documents such as spreadsheets, presentations, and reports, and communication is via email and meetings.

01

Data Privacy Policy

Types of information we collect

CLIENT INFORMATION

  • Business contact information (names, titles, email addresses, phone numbers)
  • Company information (business name, address, industry sector)
  • Technical information about client systems and infrastructure, as disclosed during assessments
  • Security assessment findings and recommendations
  • Billing and payment information

CONFIDENTIAL CLIENT DATA

  • Network diagrams and architecture documentation
  • Security policies and procedures
  • Vulnerability assessment results
  • Incident response documentation
  • Risk assessment findings
  • Compliance audit materials

How we use information

  • Providing cybersecurity advisory services
  • Conducting security assessments and audits
  • Developing customized security recommendations
  • Maintaining ongoing client relationships
  • Billing and administrative purposes
  • Legal and regulatory compliance

Marketing and promotion

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to that email. You may opt out of receiving this advertising at app.retention.com/optout.

Information sharing and disclosure

Numberline Security maintains strict confidentiality and does not share client information except:

  • With explicit written client consent
  • When required by law or legal process
  • To protect our legal rights or comply with court orders
  • In case of business acquisition, with prior client notification

Data retention

ACTIVE PROJECTS

Engagement + 90 days

COMPLETED PROJECTS

7 years

FINANCIAL RECORDS

7 years

SECURITY ASSESSMENTS

3 years

02

Security Policy

Numberline Security implements a best-practices information security program tailored to organizations of our size and technology footprint.

Digital security controls

ACCESS CONTROLS

  • Multi-factor authentication (MFA) for all sensitive systems
  • Role-based access controls
  • Regular access reviews and deprovisioning
  • Strong password policies

DATA PROTECTION

  • Encryption of data at rest
  • Encryption of data in transit
  • Full disk encryption on all devices
03

Data Handling Procedures

Given our consulting model, client data is primarily handled through business documents. Our document security procedures cover how documents are created, stored, processed, and analyzed.

CREATION & STORAGE

  • All client documents created on encrypted, company-managed devices
  • Storage in encrypted, access-controlled cloud repositories
  • Version control and audit trails for all documents
  • Client-specific folder structures with access restrictions

PROCESSING & ANALYSIS

  • Data minimization — only necessary data collected
  • Purpose limitation — data used only for stated consulting purposes
  • Pseudonymization where possible in reports and presentations
  • Secure workstations for data analysis
04

Client Rights & Requests

Data subject rights

Right to Access

Request copies of personal data we hold.

Right to Rectification

Request correction of inaccurate data.

Right to Erasure

Request deletion of personal data.

Right to Restrict Processing

Limit how we use personal data.

Right to Data Portability

Receive personal data in a portable format.

Right to Object

Object to processing of personal data.

How to exercise these rights

  • Submit written requests to info@NumberlineSecurity.com
  • Include specific details about your request
  • Provide identification verification

Response provided within 30 days.

Feedback and questions

We welcome client feedback on our policies and procedures. Please contact our team with any questions or concerns.

info@NumberlineSecurity.com