Skip to content
Noxys

Privacy Policy

Last updated: 23 March 2026

1. Data Controller

Noxys Security SAS ("Noxys", "we", "us") is the data controller for personal data collected through this website (noxys.eu) and the Noxys platform (app.noxys.cloud).

Contact: [email protected]

2. Data We Collect

2.1 Website (noxys.eu)

  • Contact details you submit through our forms: work email address, and — where the form asks for them — full name, company and job role (demo requests, webinar registrations, Shadow AI Score results, team invitations)
  • Language preference (stored locally in your browser, never transmitted)
  • Standard web server logs (IP address, user agent, timestamps) via Cloudflare
  • Form submissions are recorded in our CRM (Attio) so our team can follow up on your request. See our sub-processor list for details.

This website currently loads no analytics or marketing trackers: no third-party cookies, no tracking pixels, no advertising or statistical profiling. A consent banner is nevertheless provided so your choice is recorded before any such tracker could be enabled; you can change it at any time from the cookie preferences page.

2.2 Noxys Platform (app.noxys.cloud)

  • Account information (name, email, organization)
  • AI usage metadata (platform names, timestamps, department, risk classifications)
  • PII detection alerts (classification type only — never the actual sensitive data)
  • SHA-256 content hashes (irreversible, cannot be used to reconstruct original content)

Privacy by design: The Noxys browser extension processes prompt content entirely locally. Raw prompt text is never transmitted to our servers. Only hashes, metadata, and classifications are sent. This is a hard architectural constraint, not a policy commitment.

3. Legal Basis for Processing

We process personal data under the following GDPR legal bases:

  • Contract performance (Art. 6(1)(b)) — to provide the Noxys service
  • Legitimate interest (Art. 6(1)(f)) — to improve our service and ensure security
  • Consent (Art. 6(1)(a)) — for marketing communications (opt-in only)

4. Data Storage and Transfers

Noxys platform data — account information, AI usage metadata, classifications and audit evidence — is stored exclusively in European Union datacenters, on European infrastructure providers. Noxys uses no US hyperscaler: no AWS, no GCP, no Azure.

Two limited exceptions apply, and neither touches platform data. This marketing website (noxys.eu) is delivered through Cloudflare's CDN: Cloudflare, Inc. is a US-incorporated company and processes connection logs (IP address, user agent) at its European edge. Contact details submitted through our forms are processed in our CRM (Attio), in the EU and the United Kingdom — a country covered by a European Commission adequacy decision. Both transfers are governed by Article 28 data processing agreements and, where required, Standard Contractual Clauses. For Enterprise and Sovereign customers, on-premises and private VPC deployments remove even these dependencies.

5. Data Retention

  • Discovery tier: limited retention window, set out in the Order Form
  • Enterprise plan: retention window set out in the Order Form
  • Sovereign plan: custom retention period

Raw prompt content is never stored at any tier — only hashes, metadata and classifications. After the retention period, that metadata is permanently and irreversibly deleted. Account data is retained for the duration of the contract plus 30 days.

6. Your Rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Eraseyour data ("right to be forgotten", Art. 17)
  • Restrict processing (Art. 18)
  • Port your data to another provider (Art. 20)
  • Object to processing (Art. 21)

To exercise any of these rights, contact us at{" "} [email protected]. We will respond within 30 days.

7. Sub-processors

We use a minimal set of sub-processors, each bound by a data processing agreement compliant with GDPR Article 28. The current list — including each sub-processor's purpose and the location of processing — is published on our Trust Center.

8. Security

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS 1.3), encryption at rest, access controls, and regular security assessments.

9. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email to registered users. The "Last updated" date at the top reflects the most recent revision.

10. Contact

For questions about this privacy policy or our data practices, contact us at:{" "} [email protected]

You also have the right to lodge a complaint with your local data protection authority (DPA).