Data Defenders LLC — Protecting Your Most Valuable Business Asset

Legal · Version 1.1 · Last updated April 2026

Privacy Policy

How Data Defenders collects, uses, stores, and protects personal information — and your rights regarding that information.

1. Who We Are

Data Defenders, LLC ("Data Defenders", "we", "our", or "us") is a Delaware-based cybersecurity and AI risk consulting firm. Our website is datadefenders.ai.

This Privacy Policy explains how we collect, use, store, and protect personal information submitted through our website and NIST AI RMF Snapshot tool, and describes your rights.

2. Information We Collect

We collect information you voluntarily provide through our contact forms and Snapshot tool, including name, corporate email, organization, role, and self-assessment responses. We do not collect payment card data (handled by our checkout processor), government IDs, health data, or other sensitive personal data through our website.

3. Lawful Basis for Processing (GDPR)

For individuals in the EU or UK, we process personal data on the following lawful bases under GDPR Article 6: consent, contract performance, and legitimate interests (responding to inquiries, delivering requested materials).

4. How We Use Your Information

Information is used solely to respond to inquiries, deliver requested reports and materials, and — if you have opted in — send occasional email updates.

5. Email Communications

Marketing emails include an unsubscribe link. Transactional emails (such as your Snapshot PDF) are sent as fulfillment of a requested service and are not subject to marketing opt-out.

6. Data Storage, Security and Retention

Data is stored in a secured PostgreSQL database hosted by Railway (US-based). Railway encrypts data at rest; we use parameterized queries, rate limiting, input sanitization, and access controls at the application layer. We retain assessment records for two years plus regulatory retention obligations. You may request deletion at any time via contact-us@datadefenders.ai.

7. International Data Transfers

Data Defenders is based in the United States. Transfers from the EU/UK rely on Standard Contractual Clauses (SCCs) as the lawful transfer mechanism.

8. Your Rights

You have rights of access, correction, deletion, portability, restriction, and objection. Contact contact-us@datadefenders.ai to exercise them. We respond within 30 days.

9. California Residents — CCPA / CPRA

California residents have additional rights to know, delete, correct, opt out of sale/sharing, and non-discrimination. Contact us at contact-us@datadefenders.ai or +1 720-739-1583. We respond within 45 days.

10. Data Breach Notification

In the event of a breach affecting your personal information, we will notify affected individuals and applicable regulators within the timeframes required by law.

11. GDPR — Supervisory Authority

EU/UK residents have the right to lodge a complaint with their local supervisory authority. We encourage you to contact us first.

12. Third-Party Services

Railway (hosting), our email delivery provider, and our checkout processor process data only as instructed. We do not share data with any other third parties.

13. Cookies and Tracking

The website does not use tracking cookies, third-party analytics, advertising cookies, or cross-site tracking. No Google Analytics, no Meta Pixel.

14. Children Privacy

Our services are for business professionals. We do not knowingly collect information from individuals under 18.

15. Changes to This Policy

Material changes will be indicated by updating the version and date at the top of this page.

Questions?

Contact us for any privacy question, correction, or deletion request.

contact-us@datadefenders.ai · +1 720-739-1583

Talk to Us Directly

Free 25-minute consultation. Bring your questions.

Schedule the consultation Ask a question +1 720-739-1583

©2026 Data Defenders, LLC · Home · Privacy · FAQ

AI Governance · Fractional CISO · Cyber Programs · GRC