Privacy Policy

Last Updated: February 2026

Information We Collect

We collect information you provide directly to us, including:

Contact Information: Name, email address, company name, and phone number when you contact us or request our services.
Project Information: Technical details about your systems and applications necessary to perform security assessments.
Assessment Data: Vulnerability findings, system configurations, and security test results discovered during engagements.
Communication Records: Correspondence between you and our team related to services.

We do not collect personal information about your end-users or customers unless specifically required for the assessment scope and agreed upon in advance.

How We Use Your Information

We use the information we collect to:

Provide, maintain, and improve our security services
Communicate with you about services, reports, and findings
Send you technical information and security advisories
Respond to your inquiries and support requests
Comply with legal obligations and protect our legal rights
Conduct internal research and analytics to improve our methodologies

We never use client data for marketing purposes without explicit consent, and we never share or sell your information to third parties.

Data Security

We implement robust security measures to protect your information:

Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
Access Control: Strict role-based access controls limit data access to authorized personnel only
Secure Infrastructure: Our systems are hosted in SOC 2 Type II certified data centers
Regular Audits: We conduct regular internal security assessments and third-party penetration tests
Incident Response: We maintain a comprehensive incident response plan and will notify you promptly of any data breach

All client engagement data is stored in isolated, encrypted environments and is never commingled with other client data.

Data Retention

We retain your information as follows:

Project Data: Assessment data, reports, and findings are retained for the period specified in our engagement agreement (typically 1-2 years) unless you request earlier deletion.
Contact Information: Retained for ongoing business relationship purposes until you request removal.
Communication Records: Retained for 3 years for business and legal purposes.

Upon engagement completion or your request, we securely delete all client-specific data using industry-standard secure deletion methods. We will provide written confirmation of data deletion upon request.

Confidentiality

Confidentiality is paramount to our business:

We sign comprehensive Non-Disclosure Agreements (NDAs) before any engagement
All employees undergo background checks and sign confidentiality agreements
Assessment findings are only shared with designated client stakeholders
We never disclose client names or engagement details without explicit written permission
Reports and findings are delivered through secure, encrypted channels only

Our confidentiality obligations survive the termination of any engagement indefinitely unless otherwise agreed.

Your Rights

You have the following rights regarding your personal information:

Access: Request a copy of the personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Deletion: Request deletion of your personal information, subject to legal retention requirements
Portability: Request your data in a portable format
Objection: Object to processing of your personal information

To exercise these rights, contact us at contact@coffsec.com. We will respond to your request within 30 days.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

COFFSec

Email: contact@coffsec.com

We review and update this Privacy Policy periodically. Material changes will be communicated via email to active clients and posted on this page with an updated effective date.

© 2026 COFFSec. All rights reserved.