Privacy

Welcome to Nucleaus™!

Nucleaus, LLC and its affiliates (collectively “Nucleaus”, “we” and “us”) respect your privacy. We offer services that enable businesses to perform cybersecurity testing.

This Privacy Policy describes the types of Personal Data we collect through our payments, products and services (“Services”) and via our online presence, which include our main website at Nucleaus.com, as well as services that we enable Internet users to access (our “Sites”). This policy also describes how we use Personal Data, with whom we share it, your rights and choices, and how you can contact us about our privacy practices. This policy does not apply to third-party websites, products, or services, even if they link to our Services or Sites, and you should consider the privacy practices of those third-parties carefully.

1. Overview
Nucleaus obtains Personal Data about you from various sources to provide our Services and to manage our Sites. “You” may be a visitor to one of our websites, or a user of one or more of our Services (“User” or “Nucleaus User”).

2. Personal Data We Collect and Personal Data that we collect about you.
Personal Data is any information that relates to an identified or identifiable individual. The Personal Data that you provide directly to us through our Sites will be apparent from the context in which you provide the data. In particular:

  • When you register for a Nucleaus account we collect your full name, email address, and account log-in credentials.
  • When you fill-in our online form to contact our sales team, we collect your full name, work email, country, and anything else you tell us about your project, needs and timeline.
  • When you order online, we collect your email address, payment card number, CVC code and expiration date.
  • When you respond to Nucleaus emails or surveys we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we will collect the phone number you use to call Nucleaus. If you contact us by phone as a Nucleaus User, we may collect additional information in order to verify your identity.
  • If you are a Nucleaus User, you will provide your contact details, such as name, postal address, telephone number, and email address. As part of your business relationship with us, we may also receive other information about you, such as government identifiers associated with you and your organization (such as your tax number or Employer Identification Number).
  • If you are a Nucleaus User, when you make payments or conduct transactions through a Nucleaus’s website or application, we will receive your transaction information. The information that we collect will include payment method information (such as credit or debit card number, or bank account information), purchase amount, date of purchase, and payment method. Different payment methods may require the collection of different categories of information. Nucleaus will determine the payment methods that it enables you to use, and the payment method information that we collect will depend upon the payment method that you choose to use from the list of available payment methods that are offered to you by Nucleaus.
  • When we conduct fraud monitoring, prevention and detection activities, we may also receive Personal Data about you from our business partners, financial service providers, identity verification services, and publicly available sources (e.g., name, address, phone number, country), as necessary to confirm your identity and prevent fraud. Our fraud monitoring, detection and prevention services may use technology that helps us assess the risk associated with an attempted transaction that is enabled on a Nucleaus website or the application that collects information.

You may also choose to submit information to us via other methods, including: (i) in response to marketing or other communications, (ii) through social media or online forums, (iii) through participation in an offer, program or promotion, (iv) in connection with an actual or potential business relationship with us, or (v) by giving us your business card or contact details at trade shows or other events.

3. Information that we collect automatically on our Sites.
Our Sites use cookies and other technologies to function effectively. These technologies record information about your use of our Sites, including, but not limited to:

Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the language version of the Sites you are visiting;

Usage data, such as time spent on the Sites, pages visited, links clicked, language preferences, and the pages that led or referred you to our Sites.

We also may collect information about your online activities on websites and connected devices over time and across third-party websites, devices, apps and other online features and services. We use various analytics on our Sites to help us analyze Your use of our Sites and diagnose technical issues.

4. How We Use Personal Data
A. Our products and services.
We rely upon a number of legal grounds to ensure that our use of your Personal Data is compliant with applicable law. We use Personal Data to facilitate the business relationships we have with our Users, to comply with our financial regulatory and other legal obligations, and to pursue our legitimate business interests. We also use Personal Data to complete our payment transactions.

B. Marketing and events-related communications.
We may send you email marketing communications about Nucleaus products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with the consent requirements that are imposed by applicable law. When we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and, with your permission, include you on our marketing information campaigns.

C. Interest-based advertising.
When you visit our Sites or online services, both we and certain third parties collect information about your online activities over time and across different sites to provide you with advertising about products and services tailored to your individual interests (this type of advertising is called “interest-based advertising”). These third parties may place or recognize a unique cookie or other technology on your browser (including the use of pixel tags). Where required by applicable law, we will obtain your consent prior to processing of your information for the purpose of interest-based advertising.

You may see our ads on other websites or mobile apps. Ad networks allow us to target our messaging to users based on a range of factors, including demographic data, users’ inferred interests and browsing context (for example, the time and date of your visit to our Sites, the pages that you viewed, and the links that you clicked on). This technology also helps us track the effectiveness of our marketing efforts and understand if you have seen one of our advertisements.

We may work with various advertising networks. To learn how to opt out of behavioral advertising delivered by Network Advertising Initiative member companies, please visit the Network Advertising Initiative and Digital Advertising Alliance. You may download the AppChoices app to opt out in mobile apps. If you opt out from interest-based advertising, you may see advertising that is not relevant to you. At present, there is no industry standard for recognizing Do Not Track browser signals, so we do not respond to them.

4. How We Disclose Personal Data.
Nucleaus does not sell or rent Personal Data to marketers or unaffiliated third parties. We share your Personal Data with trusted entities, as outlined below.

A. Nucleaus. We share Personal Data with other Nucleaus entities in order to provide our Services and for internal administration purposes.

B. Service providers. We share Personal Data with a limited number of our service providers. We have service providers that provide services on our behalf, such as identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services. These service providers may need to access Personal Data to perform their services. We authorize such service providers to use or disclose the Personal Data only as necessary to perform services on our behalf or comply with legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are primarily located in the United States of America.

C. Business partners. We share Personal Data with third party business partners only when this is necessary to provide our Services to our Users.

D. Corporate transactions. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Data with third parties for the purpose of facilitating and completing the transaction.

E. Compliance and harm prevention. We share Personal Data as we believe necessary: (i) to comply with applicable law; (ii) to enforce our contractual rights; (iii) to protect the rights, privacy, safety and property of Nucleaus, you or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities.

5. Your Rights and Choices.

You have choices regarding our use and disclosure of your Personal Data:

  • Opting out of receiving electronic communications from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.
  • How you can see or change your account Personal Data. If You would like to review, correct, or update Personal Data that You have previously disclosed to us, You may do so by signing in to your Nucleaus account or by contacting us.
  • Your data protection rights. Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:
    • The right to request confirmation of whether Nucleaus processes Personal Data relating to you, and if so, to request a copy of that Personal Data;
    • The right to request that Nucleaus rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
    • The right to request that Nucleaus erase your Personal Data in certain circumstances provided by law;
    • The right to request that Nucleaus restrict the use of your Personal Data in certain circumstances, such as while Nucleaus considers another request that you have submitted (including a request that Nucleaus make an update to your Personal Data); and
    • The right to request that we export to another company, where technically feasible, your Personal Data that we hold in order to provide Services to you.
    • Where the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time. You may also have the right to object to the processing of your Personal Data on grounds relating to your particular situation.
  • In order to exercise your data protection rights, you may contact Nucleaus as described in the Contact Us section below. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the applicable data protection authority.
  • For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.

6. Nucleaus global privacy practices
We store and process the information that we collect in the United States in accordance with this Privacy Statement (our subprocessors may store and process data outside the United States). However, we understand that we have users from different countries and regions with different privacy expectations, and we try to meet those needs even when the United States does not have the same privacy framework as other countries.

We provide the same standard of privacy protection — as described in this Privacy Statement — to all our users around the world, regardless of their country of origin or location, and we are proud of the levels of notice, choice, accountability, security, data integrity, access, and recourse we provide. We have appointed a Privacy Counsel and we work hard to comply with the applicable data privacy laws wherever we do business, and our Privacy Counsel also acts as our Data Protection Officer, part of a cross-functional team that oversees our privacy compliance efforts. Additionally, if our vendors or affiliates have access to User Personal Information, they must sign agreements that require them to comply with our privacy policies and with applicable data privacy laws.

In particular:

  • Nucleaus™ provides clear methods of unambiguous, informed consent at the time of data collection, when we do collect your personal data using consent as a basis.
  • We collect only the minimum amount of personal data necessary for our purposes, unless you choose to provide more. We encourage you to only give us the amount of data you are comfortable sharing.
  • We offer you simple methods of accessing, correcting, or deleting the User Personal Information we have collected.
  • We provide our users notice, choice, accountability, security, and access, and we limit the purpose for processing. We also provide our users a method of recourse and enforcement. These are the Privacy Shield Principles, but they are also just good practices.

Cross-border data transfers

For cross-border data transfers from the European Union (EU) and the European Economic Area (EEA), Nucleaus™ adheres to the Privacy Shield Framework. You may view our entry in the Privacy Shield List.

In addition to providing our users methods of unambiguous, informed consent and control over their data, we participate in and comply with the Privacy Shield framework, and we are committed to subject any Personal Information we receive from the EU and EEA to the Privacy Shield Principles. In addition, we continue to participate in the Safe Harbor Framework for Swiss data transfers to the US. 

7. Security and Retention.

We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data within our organization against unauthorized access, destruction, loss, alteration or misuse. Your Personal Data is only accessible to a limited number of personnel who need access to the information to perform their duties. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.

If you are a Nucleaus User, we retain your Personal Data as long as we are providing the Services to you. We retain Personal Data after we cease providing Services to you, even if you close your Nucleaus account, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Data to comply with our tax, accounting, and financial reporting obligations, where we are required to retain the data by our contractual commitments to our financial partners. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.

8. Use by Minors.
The Services are not directed to individuals under the age of thirteen (13), and we request that they not provide Personal Data through the Services.

9. Updates To this Privacy Policy and Notifications.
We may change this Privacy Policy from time to time to reflect new services, changes in our Personal Data practices or relevant laws. The “Last updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes are effective when we post the revised Privacy Policy on the Services. We may provide you with disclosures and alerts regarding the Privacy Policy or Personal Data collected by posting them on our website and, if you are a User, by contacting you through your Nucleaus Dashboard, email address and/or the physical address listed in your Nucleaus account.

10. Links To Other Websites.
The Services may provide the ability to connect to other websites. These websites may operate independently from us and may have their own privacy notices or policies, which we strongly suggest you review. If any linked website is not owned or controlled by us, we are not responsible for its content, any use of the website or the privacy practices of the operator of the website.

11. Jurisdiction-specific Provisions.
California residents. If you are a California resident, then, subject to certain limits under California law, you may ask us to provide you with (i) a list of certain categories of Personal Data we have disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year; and (ii) the identity of those third parties. To make this request, California residents may contact us as specified in the Contact Us section below.

12. Contact Us
If You have any questions or complaints about this Privacy Policy, please contact us electronically or send physical mail to:

Nucleaus, LLC
1079 Woodland Church Rd.
Wake Forest NC 27587
Attention: Nucleaus Legal