Nuaj Company Inc. ("Nuaj", "we", "us") explains here what personal information we collect, why, how long we keep it, and the rights you have over it.
One policy, every product. It applies to NuajProtect, NuajLens, and Nexaplane, to the Nuaj websites at nuaj.com and their product pages, to the download portal at download.nuaj.com, and to our support and billing communications.
The products differ enormously in what they send us — one runs a hosted control plane, one sends us nothing at all after you download it, and one sends a licence check. What Each Product Sends Us below states that per product, and it is the section to read first: everything else in this Policy is qualified by it.
Where you run a product on your own infrastructure, see Self-Hosted Deployments — the split of responsibility is different.
This Policy forms part of, and should be read with, the Master Terms and the End User License Agreement for the product you use.
Contact
Nuaj Company Inc.
8250 Lawson Rd., Suite 201
Milton, Ontario L9T 5C6
Canada
Privacy enquiries and rights requests: privacy@nuaj.com
General and legal enquiries: legal@nuaj.com
Where Nuaj offers its products. Nuaj is established in Canada and offers its products in Canada and the United States. It does not target, market to, or solicit customers in the European Economic Area or the United Kingdom, and has not appointed a representative under Article 27 of the European Union General Data Protection Regulation. Should Nuaj begin offering its products to customers there, it will appoint and name that representative in this section before doing so.
This is a statement about who Nuaj sells to, not about how it treats data: the protections described in this Policy and in the Data Processing Agreement — including the Article 28 processing terms, the security measures, and the seventy-two-hour breach notification — apply to every customer, wherever they are.
What Each Product Sends Us
| Product | What reaches Nuaj at runtime | Nuaj's role |
|---|---|---|
| NuajProtect | Operational and security telemetry from enrolled endpoints, through the hosted control plane, continuously | Processor for the Customer; Controller of account, billing and security data |
| NuajLens | Nothing. No scan target, no finding, and no asset inventory ever leaves your network | Controller only of the download-access request and the portal's server logs |
| Nexaplane | A licence-validation request only | Controller of that request; not a processor in your tenants' chain |
NuajProtect
NuajProtect enrols endpoints to a hosted control plane, and those endpoints report continuously. Everything in Information We Collect applies to it in full, and it is the only product for which Nuaj processes operational data on your behalf. The Data Processing Agreement governs that processing.
NuajLens
NuajLens is downloaded, self-hosted, and has no licence key and no runtime contact with Nuaj. Once you have the software, nothing about your use of it reaches us: not the assets you register, not the targets you scan, not the findings, not a version check, not a heartbeat. We could not tell you whether a given copy is running.
We state that as a commitment rather than leaving it as an absence, because it is what we have built and it will not be changed silently: if a future version of NuajLens contacts Nuaj for any reason, this Policy will say so before that version is released.
What we do hold is what you gave us to obtain the software: the access request to download.nuaj.com — the requesting organization, the contact name and email address, and what you told us about your intended use — and the portal's own server logs (IP address, user agent, what was downloaded, when). We keep the contact address so that we can reach you about a security update, because with no runtime channel it is the only route we have to you.
Nexaplane
Nexaplane contacts Nuaj for licence validation only. That request carries the installation identifier, the licence or organization identifier, the software version, the time of the request, and the source IP address it arrives from. An IP address is personal data in some jurisdictions, which is why the request is enumerated here rather than described as carrying nothing.
No tenant data, no traffic data, no configuration, and no personal data belonging to your tenants is sent to Nuaj. Nuaj processes the validation request as an independent Controller for licence administration, on the basis of its legitimate interest in verifying that the software it licenses is licensed — it does not make Nuaj a processor or sub-processor of your tenants' data.
Where Nexaplane bills your tenants, it does so through your payment provider accounts. Those payments do not pass through Nuaj, and the payment processors involved are yours rather than Nuaj's sub-processors.
Information We Collect
This section is written by activity, not by product. The activities below are what generate personal information, and they are stable: a product performs some subset of them, and a new product adds a row to the table above rather than a new kind of collection here.
What follows therefore describes the maximum. Read it against What Each Product Sends Us: only the activities listed there for your product apply to you. Account, acceptance, support, billing, and website records arise from dealing with Nuaj at all; every other entry arises only where your product performs that activity.
Account information. Your name, email address, the organization you belong to, your role, and the account you belong to. Provided by you or by the administrator who invited you.
Authentication and session records. Password hashes (never the password itself), multi-factor enrolment data, session tokens, sign-in times, and the IP addresses sessions are used from. We do not store your password.
Agreement acceptance records. For each agreement you accept: the accepting account, the date and time, the source IP address, the agreement version, and a cryptographic hash of the exact text accepted.
Download-portal access requests. Where you request access to download.nuaj.com: the requesting organization, the contact name and email address, what you told us about your intended use, and the portal's server logs. Where a product has no runtime contact with Nuaj, this is the only record Nuaj holds of anyone using it.
Licence-validation requests. Where a product validates its licence with Nuaj — the table above states which products do: the installation identifier, the licence or organization identifier, the software version, the time, and the source IP address.
Operational and security telemetry — where a product enrols endpoints to a hosted control plane. From protected endpoints: attack observations, block and drop counts, traffic volumes and rates, device health, software versions, and configuration state. Each endpoint also reports its own identity so the dashboard can show you the device you deployed: its hostname, the addresses configured on its interfaces — which for a router or bridge includes private, internal ones — and the public address its traffic leaves from. This describes network activity, not the content of communications. We do not collect packet payloads, and we do not collect your application, system, or security logs.
Diagnostic captures — where a product enrols endpoints to a hosted control plane. To investigate a fault, an authorized Nuaj operator may request a capture from an enrolled endpoint. A capture is limited to the product's own service log and the kernel message buffer, is requested deliberately rather than taken automatically, is capped in size, is held only for the support interaction, and is not written to durable storage. Kernel messages may incidentally contain device and address identifiers.
Support communications. What you send us when you contact support, and our replies.
Billing information. Where a paid subscription applies: plan, billing contact, invoices, and payment status. Card details are handled by our payment processor and are not stored by Nuaj.
Website and product usage. Standard server logs (IP address, user agent, requested page, timestamp) kept for security and for diagnosing faults.
Why We Use It, and On What Basis
We process the information above to:
- provide, operate, secure, and support the products — necessary to perform our contract with you;
- grant and administer access to the download portal, and reach you about a security update affecting software you downloaded — contract performance, and our legitimate interest in the security of the software we distribute;
- verify that software we license is licensed — our legitimate interest in the integrity of our own licensing;
- authenticate you and protect accounts from unauthorized access — our legitimate interest in security, and a legal obligation in some jurisdictions;
- detect, investigate, and mitigate threats against you and against the network — our legitimate interest, and the substance of the product itself;
- bill for the service and keep accounting records — contract performance and legal obligation;
- send service messages about your account, such as the welcome message, security notices, and alerts you have configured — contract performance;
- meet legal, regulatory, and law-enforcement obligations.
We do not sell personal information, and we do not use it for advertising.
Marketing email, if we ever send it, is separate: it goes only to people who have asked for it, and every such message carries an unsubscribe link. Service messages about your account are not marketing and are not subject to unsubscribe.
Community Threat Intelligence
Where a product includes an optional community threat-intelligence capability — today the Nuaj Threat Exchange, in the products the table above marks as reporting telemetry — enabling it transmits limited technical indicators derived from attacks observed by your deployment: attacking IP addresses, targeted ports and protocols, threat categories, timestamps, and anonymous reporter counts.
No log content, no packet payloads, and no identifiers of your users or endpoints are transmitted. An attacking IP address may constitute personal information in some jurisdictions; we process it on the basis of our legitimate interest, and that of every other participant, in defending against the attack it is conducting.
This capability can be disabled at any time in the server settings without affecting other functionality.
Sharing
We share personal information only with:
- Service providers who process it on our behalf under written terms — hosting, email delivery, payment processing, and error monitoring — and only as needed to perform those services;
- Professional advisers, such as auditors and legal counsel, under duties of confidentiality;
- Authorities, where we are legally required to disclose, and only to the extent required;
- A successor entity, in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Sub-processors
The service providers that may process personal information on Nuaj's behalf are:
| Provider | Purpose | Location |
|---|---|---|
| Halton Data Center Inc. | Colocation and cloud infrastructure for the hosted service | Milton, Ontario, Canada |
| Stripe | Payment processing and billing | United States / Ireland |
| PayPal | Alternative payment processing | United States / Luxembourg |
| Google (Workspace) | Outbound email delivery for service messages | United States |
| VoIP.ms | SMS delivery for multi-factor authentication codes | Canada |
The hosted service runs from a facility in Milton, Ontario operated by Halton Data Center Inc., a separate company in which Nuaj holds a 70% interest. We name the relationship rather than listing the company on its own, because a shared owner means this provider is not independent of us and you should be able to weigh that. It also means data residency and physical access are within our control rather than a landlord's. Your account and operational data are held in Canada.
We will update this list before adding a new sub-processor that processes personal information. To be notified of changes, write to privacy@nuaj.com.
International Transfers
Nuaj operates from Canada. All Nuaj services are hosted in Canada unless otherwise indicated — and where anything is hosted elsewhere, it is named: in the sub-processor table above, in Annex III of the Data Processing Agreement, or on your own order.
Today there is one hosting region, Milton, Ontario, and every customer's account and operational data is held there. Should Nuaj operate a hosted service from an additional region, the region is recorded on the affected customer's order and named in Annex III, moving a customer between regions is a material change notified in advance, and a new region is introduced through the 30-day sub-processor notice and objection process in the Data Processing Agreement.
Some sub-processors listed above operate outside Canada — payment processing and outbound email are handled by providers in the United States and the European Union. This means billing contact details and the content of service emails we send you are processed outside Canada. SMS delivery is handled in Canada.
Where information is transferred out of a jurisdiction whose law restricts such transfers, we rely on the mechanisms that law provides, including the European Commission's Standard Contractual Clauses where applicable.
Retention
Account information is retained while the account is active. After an account is closed, we retain what is needed for legal, accounting, tax, and security purposes, and delete or anonymize the remainder.
Agreement acceptance records are retained for as long as necessary to establish the terms in force between us, which will typically extend beyond the life of the account.
Operational and security telemetry is retained on a rolling window appropriate to its purpose; aggregate and statistical data that no longer identifies a person may be retained indefinitely.
Threat indicators contributed to the community exchange are aggregated with other submissions and are not tied to your deployment.
Security
We protect personal information with encryption in transit, encryption of credentials at rest, role-based access control, multi-factor authentication, audit logging, and least-privilege administrative access. No system can be guaranteed absolutely secure; the End User License Agreement sets out the limits of our liability.
Security Breach Notification
If a breach of our security safeguards involves your personal information and creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, as required by Canadian federal privacy law. Where the EU or UK General Data Protection Regulation applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where that regulation requires it.
Our notification will describe what happened, what information was involved, what we are doing about it, and what you can do to reduce your risk. We keep a record of breaches of security safeguards as the law requires.
For a self-hosted deployment, the operational data is on your systems and you are the controller of it: notification obligations for a breach of your own systems rest with you. Nuaj will support your investigation on request.
Your Rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- delete information, subject to our legal retention obligations;
- port information you provided to us, in a structured, machine-readable form;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent, without affecting processing already carried out.
To exercise any of these, contact privacy@nuaj.com. We will respond within the period required by applicable law, and we may need to verify your identity first.
If your account was created by an organization's administrator, some requests may be directed to that organization, which controls the account.
You may also complain to a supervisory authority: in Canada, the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d'accès à l'information; in the United States, your state Attorney General.
United States State Privacy Rights
This section applies to residents of United States states with a consumer privacy law, including California, Virginia, Colorado, Connecticut, Texas, and Utah. It describes Nuaj's own processing. Where Nuaj processes personal information on behalf of a business customer — the operational data in a Nuaj hosted service, which the table in What Each Product Sends Us identifies — that customer directs the processing and requests should go to them; Nuaj acts as a service provider or processor under Annex IV of the Data Processing Agreement, and will assist them in answering you.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, we receive no consideration of any kind for personal information, and we run no advertising, remarketing, or profiling. There is therefore nothing for an opt-out to switch off — but if that ever changes, this Policy will say so before it does and an opt-out will be published with it.
We do not collect sensitive personal information as those laws define it, we do not use it to infer characteristics, and the products are not designed to process it.
What we collect about you, in the categories these laws use
| Category | What it is here | Where it comes from | Why | Who we disclose it to |
|---|---|---|---|---|
| Identifiers | Name, business email, organization, account and installation identifiers, IP address | You, your administrator, your deployment | Operate and secure the service, authenticate you, bill you | Hosting, email, payment and SMS providers, as service providers |
| Commercial information | Plan, subscription, invoices, payment status | You, your payment | Billing and accounting | Payment providers, as service providers |
| Internet or network activity | Server logs, dashboard usage, download-portal requests, network telemetry from enrolled endpoints | Your use, your deployment | Operate, secure, support, and report | Hosting provider, as a service provider |
| Professional information | Your role and the organization you act for | You or your administrator | Access control and support | — |
We do not collect biometric information, precise geolocation, government identifiers, financial account numbers, health information, or information about your personal or household activity — and none of the products is designed to.
Retention is described in Retention above. We keep each category for as long as that section states and no longer, other than where the law requires us to keep it.
Your rights
Subject to verification and to the exceptions the applicable law provides, you may:
- know what personal information we have collected about you, the categories of sources, the purposes, and the categories of recipients;
- access a copy of it, and port it in a portable, machine-readable form;
- correct inaccurate information;
- delete it;
- opt out of any sale, sharing, or targeted advertising — none of which we do;
- limit the use of sensitive personal information — which we do not collect;
- not be discriminated against for exercising any of these rights. We do not deny service, change prices, or reduce quality because you made a request.
How to exercise them. Write to privacy@nuaj.com. We respond within forty-five (45) days, extendable once by a further forty-five days where the request is complex, and we will tell you if we need the extension. We may need to verify your identity, and we will ask only for what verification requires.
Authorised agents. An agent may make a request on your behalf with written authorisation from you; we may ask you to confirm it directly.
Appeals. If we refuse a request, you may appeal by writing to legal@nuaj.com within forty-five days, stating why. We will respond in writing within forty-five days with our decision and our reasons, and — where we still refuse — how to complain to your state Attorney General. This applies wherever you live, not only in the states that require an appeal process.
California "Shine the Light". We do not disclose personal information to third parties for their own direct marketing purposes.
Opt-out preference signals. The nuaj.com website loads its one analytics tool only after you accept it on the banner; nothing is loaded and no analytics cookie is set unless you choose to accept. A Global Privacy Control signal from your browser is honoured as a refusal, and there is nothing else to opt out of.
Self-Hosted Deployments
Where you run a Nuaj product on your own infrastructure, you are the controller of the operational data it collects, and that data stays on your systems.
What still reaches Nuaj is only what What Each Product Sends Us lists for that product: at most, what is needed to license, support, and bill the deployment, plus any threat indicators the deployment chooses to contribute to the community exchange. For some products it is nothing at all.
Self-hosting therefore changes Nuaj's role, not merely the volume of what it holds. Where a product sends Nuaj no operational data, Nuaj is not a processor or sub-processor of anything that product produces, and there is no processing for a Data Processing Agreement to govern. Where a product sends only a licence-validation request, Nuaj receives that request as an independent Controller of its own licensing records — not as a processor in your customers' chain.
Where Nuaj does act as a processor for you, the Data Processing Agreement governs that processing; it is published alongside this Policy and applies without signature. Where you use a product to deliver a service to your own customers, that Agreement's provider mode describes how the three-party chain works.
Cookies and Similar Technologies
A Nuaj product console — whether Nuaj hosts it or you run it yourself — uses strictly necessary cookies and local browser storage to keep you signed in and to remember interface preferences such as theme and language. It does not use advertising or cross-site tracking cookies, and it does not embed third-party analytics that profile you. A console you host yourself sends nothing to Nuaj by doing any of this.
The nuaj.com website uses one optional measurement tool, Google Analytics, to count visits and see which pages are read. It is off until you accept it: nothing is loaded and no analytics cookie is set unless you choose Accept on the banner, and your choice is remembered in your own browser's local storage rather than sent to us. IP addresses are truncated before Google records them. We run no advertising, remarketing, or session-replay tags, and we do not sell or share website data for advertising. To change your mind, clear this site's data in your browser and the banner will ask again.
This document and every other Nuaj legal document are served as self-contained pages, at nuaj.com and in each product: they load no fonts, scripts, or other assets from third-party servers, so reading one discloses nothing about you to anyone but Nuaj.
Children
The Nuaj products are business products and are not directed to children. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction.
Changes to This Policy
We may update this Policy. When we do, we revise the version identifier shown at the top of this page and, where the change is material, we notify account holders through the service or by email before it takes effect.
Language
This Policy was drafted in the English language, and the English version is the sole authoritative version. Any translation is provided for convenience only. Les parties ont expressément demandé et convenu que le présent document soit rédigé en langue anglaise.