Legal

Privacy Policy

Effective date: 12 July 2026 Last updated: 12 July 2026

This Privacy Policy explains how "Praeven Security" collects, uses, discloses, and retains personal information in connection with the website at praevensecurity.com (the "Site") and related business communications. It also describes the rights available to individuals regarding their personal information and how to exercise them.

This policy covers the Site and pre-engagement business communications only. Personal information and client data processed during a paid engagement (for example, penetration testing, training delivery, or use of PrismVector) are governed by the applicable engagement agreement, statement of work, rules of engagement, and any separate data processing terms, not by this policy.

1. Information we collect

1.1 Information you provide directly

We collect information you submit through forms on the Site or through direct correspondence, including:

Identifiers and contact details: name, business email address, company name, job title, and phone number where provided.

Qualification information: for training requests, approximate number of people to be trained and the compliance driver (for example, SOC 2, CMMC, cyber insurance, or a customer requirement).

Engagement scoping information: for penetration testing, OSINT, or PrismVector requests, information describing the prospective environment, which may include IP ranges, CIDR blocks, approximate host counts, environment type, and testing timelines.

Free-text content: any information you include in a message field or in email correspondence.

Engagement scoping information may describe the configuration of your systems and networks. We treat this information as confidential and use it only to evaluate, scope, and respond to your request. See Section 8.

1.2 Information collected automatically

When you visit the Site, certain information is collected automatically through server logs and analytics tools, including:

Device and connection data: IP address, browser type, operating system, and referring URLs.

Usage data: pages viewed, links selected, and approximate visit duration.

This information is collected through our hosting provider's logs and through the analytics functionality described in Section 5.

1.3 Information from third parties

We may receive limited information from service providers that support the Site, such as spam-prevention or delivery-confirmation data from our forms and email infrastructure. We do not purchase personal information from data brokers.

We do not knowingly collect sensitive personal information as defined under applicable privacy laws (for example, government identifiers, financial account credentials, precise geolocation, or health data) through the Site, and we ask that you not submit such information through our forms.

2. How we use information

We use personal information for the following business purposes:

To respond to inquiries, prepare quotes, and scope potential engagements.

To communicate with you about services you have requested and to manage the pre-engagement relationship.

To operate, maintain, secure, and improve the Site.

To detect, prevent, and respond to fraud, abuse, and security incidents.

To comply with legal obligations and enforce our agreements.

We do not use the information collected through the Site for automated decision-making that produces legal or similarly significant effects, and we do not use it to build advertising profiles.

3. How we share information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws.

We disclose personal information only in the following circumstances:

Service providers and contractors: to vendors that perform functions on our behalf and are contractually limited to using the information for those functions. Our current categories of service providers include website hosting, website analytics, form and email delivery, and spam prevention. [CONFIRM AND NAME SPECIFIC PROVIDERS, e.g., hosting provider, Automattic/Jetpack for analytics, the form plugin vendor, and any CAPTCHA provider.]

Legal and safety: where required to comply with law, respond to lawful requests, or protect the rights, property, or safety of Praeven Security, our clients, or others.

Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to the protections described in this policy.

Where a service provider processes personal information on our behalf, we require by contract that it protect the information and, at the end of the engagement, return or destroy it.

4. Cookies and similar technologies

The Site uses cookies and similar technologies for essential functionality and for the analytics described in Section 5. You can control cookies through your browser settings. Where required, we honor recognized opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out of any sale or sharing of personal information. Because we do not sell or share personal information, no additional opt-out is necessary, but GPC signals are respected as a matter of practice.

5. Analytics

We use [ANALYTICS PROVIDER, e.g., Jetpack Stats by Automattic] to understand aggregate Site usage. This tool collects the usage and device data described in Section 1.2. We use this information only in aggregate to improve the Site and do not use it to identify individual visitors for marketing purposes. For information about the analytics provider's own data practices, see [LINK TO PROVIDER PRIVACY POLICY].

6. Data retention

We retain personal information only as long as necessary for the purposes described in this policy, including to respond to your inquiry, to maintain a record of the business relationship, and to meet legal, accounting, or reporting requirements. Inquiry and scoping information that does not proceed to an engagement is retained for [RETENTION PERIOD, e.g., 24 months] and then deleted or anonymized, unless a longer period is required by law. Engagement records are retained under the terms of the applicable engagement agreement.

7. Data security

We maintain administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature of the information and the risks involved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting personal information, we will notify affected individuals and regulators as required by applicable law.

8. Confidentiality of scoping information

Information describing your systems, networks, or environment that you submit when requesting testing services or PrismVector access is treated as confidential business information. It is accessed only by personnel who need it to evaluate and respond to your request, is not published or shared for any purpose other than responding to you, and is retained under the period stated in Section 6. Any testing engagement that results from your inquiry is conducted only under a separate written agreement and defined rules of engagement.

9. Your privacy rights

Depending on your state of residence, you may have some or all of the following rights regarding your personal information:

Right to know and access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom it was disclosed.

Right to delete personal information we have collected from you, subject to legal exceptions.

Right to correct inaccurate personal information.

Right to opt out of the sale or sharing of personal information. We do not sell or share personal information.

Right to limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information through the Site.

Right to non-discrimination for exercising any of these rights.

How to exercise your rights

To submit a request, contact us at [PRIVACY CONTACT EMAIL]. We will verify your request by confirming information reasonably necessary to establish your identity, and we will respond within the timeframe required by applicable law. You may use an authorized agent to submit a request on your behalf, subject to verification.

Residents of California, and residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and others as those laws take effect), may have additional or differing rights. We honor the rights available to you under the law of your state of residence.

10. Children's privacy

The Site is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it.

11. Third-party links

The Site may contain links to third-party websites. We are not responsible for the privacy practices of those sites, and we encourage you to review their policies.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be indicated clearly. Continued use of the Site after a change indicates acceptance of the updated policy.

13. Contact us

For questions about this policy or to exercise your rights, contact:

Praeven Security - [MAILING ADDRESS OR STATE] privacy@praevensecurity.com

This document is a starting template and does not constitute legal advice. It must be reviewed by qualified privacy counsel and reconciled against your actual data practices before publication.

Prepare. Anticipate. Protect.