Nuaj Company Inc. (“Nuaj”, “we”, “us”) provides NuajProtect. This Policy explains what personal information we collect, why, how long we keep it, and the rights you have over it.
It applies to the NuajProtect hosted service, the Nuaj websites at nuaj.com and their product pages, and our support and billing communications. Where you run NuajProtect on your own infrastructure, see Self-Hosted Deployments below — the split of responsibility is different.
This Policy forms part of, and should be read with, the End User License Agreement and the Terms of Service.
Contact
Nuaj Company Inc.
8250 Lawson Rd., Suite 201
Milton, Ontario L9T 5C6
Canada
Privacy enquiries and rights requests: privacy@nuaj.com
General and legal enquiries: legal@nuaj.com
Information We Collect
Account information. Your name, email address, the organization you belong to, your role, and the account you belong to. Provided by you or by the administrator who invited you.
Authentication and session records. Password hashes (never the password itself), multi-factor enrolment data, session tokens, sign-in times, and the IP addresses sessions are used from. We do not store your password.
Agreement acceptance records. For each agreement you accept: the accepting account, the date and time, the source IP address, the agreement version, and a cryptographic hash of the exact text accepted.
Operational and security telemetry. From protected endpoints: attack observations, block and drop counts, traffic volumes and rates, device health, software versions, and configuration state. Each endpoint also reports its own identity so the dashboard can show you the device you deployed: its hostname, the addresses configured on its interfaces — which for a router or bridge includes private, internal ones — and the public address its traffic leaves from. This describes network activity, not the content of communications. We do not collect packet payloads, and we do not collect your application, system, or security logs.
Diagnostic captures. To investigate a fault, an authorized Nuaj operator may request a capture from a protected endpoint. A capture is limited to NuajProtect’s own service log and the kernel message buffer, is requested deliberately rather than taken automatically, is capped in size, is held only for the support interaction, and is not written to durable storage. Kernel messages may incidentally contain device and address identifiers.
Support communications. What you send us when you contact support, and our replies.
Billing information. Where a paid subscription applies: plan, billing contact, invoices, and payment status. Card details are handled by our payment processor and are not stored by Nuaj.
Website and product usage. Standard server logs (IP address, user agent, requested page, timestamp) kept for security and for diagnosing faults.
Why We Use It, and On What Basis
We process the information above to:
- provide, operate, secure, and support the service — necessary to perform our contract with you;
- authenticate you and protect accounts from unauthorized access — our legitimate interest in security, and a legal obligation in some jurisdictions;
- detect, investigate, and mitigate threats against you and against the network — our legitimate interest, and the substance of the product itself;
- bill for the service and keep accounting records — contract performance and legal obligation;
- send service messages about your account, such as the welcome message, security notices, and alerts you have configured — contract performance;
- meet legal, regulatory, and law-enforcement obligations.
We do not sell personal information, and we do not use it for advertising.
Marketing email, if we ever send it, is separate: it goes only to people who have asked for it, and every such message carries an unsubscribe link. Service messages about your account are not marketing and are not subject to unsubscribe.
Community Threat Intelligence
NuajProtect includes an optional community threat-intelligence capability (the Nuaj Threat Exchange). When enabled, it transmits limited technical indicators derived from attacks observed by your deployment: attacking IP addresses, targeted ports and protocols, threat categories, timestamps, and anonymous reporter counts.
No log content, no packet payloads, and no identifiers of your users or endpoints are transmitted. An attacking IP address may constitute personal information in some jurisdictions; we process it on the basis of our legitimate interest, and that of every other participant, in defending against the attack it is conducting.
This capability can be disabled at any time in the server settings without affecting other functionality.
Sharing
We share personal information only with:
- Service providers who process it on our behalf under written terms — hosting, email delivery, payment processing, and error monitoring — and only as needed to perform those services;
- Professional advisers, such as auditors and legal counsel, under duties of confidentiality;
- Authorities, where we are legally required to disclose, and only to the extent required;
- A successor entity, in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Sub-processors
The service providers that may process personal information on Nuaj’s behalf are:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and billing | United States / Ireland |
| PayPal | Alternative payment processing | United States / Luxembourg |
| Google (Workspace) | Outbound email delivery for service messages | United States |
| VoIP.ms | SMS delivery for multi-factor authentication codes | Canada |
Nuaj operates the hosted service from its own facility in Milton, Ontario; hosting is not sub-contracted.
We will update this list before adding a new sub-processor that processes personal information. To be notified of changes, write to privacy@nuaj.com.
International Transfers
Nuaj operates from Canada, and the hosted service runs from a Canadian facility. Your account and operational data are held in Canada.
Some sub-processors listed above operate outside Canada — payment processing and outbound email are handled by providers in the United States and the European Union. This means billing contact details and the content of service emails we send you are processed outside Canada. SMS delivery is handled in Canada.
Where information is transferred out of a jurisdiction whose law restricts such transfers, we rely on the mechanisms that law provides, including the European Commission’s Standard Contractual Clauses where applicable.
Retention
Account information is retained while the account is active. After an account is closed, we retain what is needed for legal, accounting, tax, and security purposes, and delete or anonymize the remainder.
Agreement acceptance records are retained for as long as necessary to establish the terms in force between us, which will typically extend beyond the life of the account.
Operational and security telemetry is retained on a rolling window appropriate to its purpose; aggregate and statistical data that no longer identifies a person may be retained indefinitely.
Threat indicators contributed to the community exchange are aggregated with other submissions and are not tied to your deployment.
Security
We protect personal information with encryption in transit, encryption of credentials at rest, role-based access control, multi-factor authentication, audit logging, and least-privilege administrative access. No system can be guaranteed absolutely secure; the End User License Agreement sets out the limits of our liability.
Security Breach Notification
If a breach of our security safeguards involves your personal information and creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, as required by Canadian federal privacy law. Where the EU or UK General Data Protection Regulation applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where that regulation requires it.
Our notification will describe what happened, what information was involved, what we are doing about it, and what you can do to reduce your risk. We keep a record of breaches of security safeguards as the law requires.
For a self-hosted deployment, the operational data is on your systems and you are the controller of it: notification obligations for a breach of your own systems rest with you. Nuaj will support your investigation on request.
Your Rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- delete information, subject to our legal retention obligations;
- port information you provided to us, in a structured, machine-readable form;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent, without affecting processing already carried out.
To exercise any of these, contact privacy@nuaj.com. We will respond within the period required by applicable law, and we may need to verify your identity first.
If your account was created by an organization’s administrator, some requests may be directed to that organization, which controls the account.
You may also complain to a supervisory authority: in Canada, the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’accès à l’information; in the EU or UK, your national data protection authority.
Self-Hosted Deployments
Where you run NuajProtect on your own infrastructure, you are the controller of the operational data your deployment collects, and it stays on your systems — Nuaj does not receive it.
In that arrangement Nuaj processes only: the information needed to license, support, and bill your deployment, and the threat indicators your deployment chooses to contribute to the community exchange. Where Nuaj acts as a processor for you, the Data Processing Agreement governs that processing; it is published alongside this Policy and applies without signature.
Cookies and Similar Technologies
The NuajProtect dashboard uses strictly necessary cookies and local browser storage to keep you signed in and to remember interface preferences such as theme and language. It does not use advertising or cross-site tracking cookies, and it does not embed third-party analytics that profile you.
The nuaj.com website uses one optional measurement tool, Google Analytics, to count visits and see which pages are read. It is off until you accept it: nothing is loaded and no analytics cookie is set unless you choose Accept on the banner, and your choice is remembered in your own browser’s local storage rather than sent to us. IP addresses are truncated before Google records them. We run no advertising, remarketing, or session-replay tags, and we do not sell or share website data for advertising. To change your mind, clear this site’s data in your browser and the banner will ask again.
This document, the End User License Agreement, and the Terms of Service are served as self-contained pages: they load no fonts, scripts, or other assets from third-party servers, so reading them discloses nothing about you to anyone but Nuaj.
Children
NuajProtect is a business product and is not directed to children. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction.
Changes to This Policy
We may update this Policy. When we do, we revise the version identifier shown at the top of this page and, where the change is material, we notify account holders through the service or by email before it takes effect.
Language
This Policy was drafted in the English language, and the English version is the sole authoritative version. Any translation is provided for convenience only. Les parties ont expressément demandé et convenu que le présent document soit rédigé en langue anglaise.