LEGAL & COMPLIANCE

Privacy Policy

Effective Date: October 1, 2026Last Revised: October 1, 2026

1. Introduction & Scope

Commitment to Data Privacy & Transparency

This Privacy Policy outlines how Netrocos LLC ("Netrocos", "we", "us", or "our") collects, utilizes, processes, and safeguards personal and commercial data when you visit netrocos.com (the "Site"), submit inquiries, or access our proprietary Client Portal and software engineering capabilities (collectively, the "Services"). Netrocos acts as the Data Controller with respect to personal data submitted directly through our website, contact forms, and client authentication systems. For software engineering engagements where we architect, deploy, or interface with client-managed databases or third-party cloud environments, our data processing obligations are governed by executed Statements of Work (SOW) and applicable Data Processing Agreements (DPAs). By accessing our Site or utilizing our Services, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with our policies and practices, your choice is to not use our Services.

2. Information We Collect

Direct Submissions, Portal Credentials & System Telemetry

We collect information that identifies, relates to, or could reasonably be linked with you through the following channels: • Project Inquiries & Technical Briefs: When you submit an assessment, contact message, or engineering brief through our inquiry pipeline, we collect your full name, business email address, organization name, technical requirements, estimated project budget, project timeline, and any project documentation or architectural specifications you voluntarily supply. • Client Portal Authentication & Operations: Authorized client personnel provisioned access to our proprietary Client Portal provide professional contact details, secure authentication credentials (which are stored exclusively utilizing salted, one-way cryptographic hashes), and project collaboration notes or feedback. • Automated Network Telemetry & Diagnostic Data: When you access our website or authenticated services, our cloud infrastructure and edge network servers automatically log standard network and diagnostic request metadata. This data may include your Internet Protocol (IP) address, approximate geographic location (at country and regional level), browser user-agent and version, operating system, device characteristics, referring URLs, pages accessed, and request timestamps. This technical information is collected to preserve system availability, enforce rate limits, prevent unauthorized intrusions, and defend against denial-of-service (DDoS) attempts. • Zero Data Sales & Sensitive Characteristics: We do not sell your personal data, we do not share your information for cross-context behavioral advertising, and we do not collect or process sensitive personal information (such as government identification numbers, financial account PINs, biometric identifiers, or health records).

3. How We Use Information

Service Delivery, Account Authentication & Operational Security

We process collected information strictly for legitimate commercial, operational, and security purposes, anchored upon appropriate legal bases: • Engineering Scoping & Contract Performance (GDPR Art. 6(1)(b)): Evaluating your technical requirements, preparing architectural proposals, scoping Statements of Work, communicating deliverable milestones, and executing software engineering agreements. • Client Portal Provisioning & Identity Verification (GDPR Art. 6(1)(b)): Authenticating authorized users, provisioning access to project tracking dashboards, managing deliverables, and granting access to staging environments and technical documentation. • Operational Security & Threat Mitigation (GDPR Art. 6(1)(f)): Preserving the security and operational resilience of our platforms, analyzing traffic anomalies, enforcing edge rate limiting, mitigating malicious bot vectors, and protecting our distributed systems and network infrastructure against unauthorized access or disruption. • Legal, Statutory & Regulatory Compliance (GDPR Art. 6(1)(c)): Enforcing our contractual terms, fulfilling corporate tax and accounting obligations, and complying with applicable statutory, regulatory, or judicial mandates.

4. Third-Party Infrastructure & Subprocessors

Enterprise Edge, Storage & Payment Service Providers

To deliver enterprise-grade performance, high-availability edge delivery, and secure commercial transactions, Netrocos contracts with vetted third-party service providers and subprocessors: • Cloudflare, Inc.: Provides enterprise cloud routing, global content delivery (CDN), DDoS mitigation, web application firewalls (WAF), SSL/TLS transport encryption, and secure managed cloud infrastructure. • Stripe, Inc.: Handles commercial payment processing, billing instrumentation, and transaction settlement. Netrocos does not process, store, or transmit raw credit card numbers or security CVV codes on its internal servers; all billing transactions comply with Level 1 PCI-DSS standards managed directly by Stripe. • Transactional Communications Infrastructure: Cloud email dispatch services utilized to deliver cryptographic portal invitation tokens, account security notices, and milestone dispatch alerts. Each third-party subprocessor is bound by data protection agreements requiring technical and organizational security controls that meet or exceed applicable statutory data privacy benchmarks.

5. Data Retention & Security Safeguards

System Isolation & Cryptographic Protection

We implement industry-standard technical and organizational security measures engineered to protect your information against unauthorized access, destruction, loss, or alteration: • Data Minimization & Retention: We retain personal information and project inquiries only for as long as necessary to fulfill the operational purposes for which it was gathered, conduct active engineering engagements, resolve disputes, and satisfy statutory tax and legal recordkeeping mandates. • Cryptographic & Transport Protections: All web communications and API interactions are strictly encrypted in transit utilizing modern Transport Layer Security (TLS 1.3). User credentials and authentication states are protected utilizing salted, one-way cryptographic hashing and secure session tokens. • Administrative Access Controls: Access to inbound leads, contact messages, and client deliverables is strictly restricted to authorized engineering personnel subject to multi-factor authentication and role-based access controls (RBAC). • Security Disclaimer: While we maintain comprehensive physical, electronic, and procedural defenses, no method of transmission over the Internet or electronic storage mechanism is completely impenetrable. Netrocos cannot warrant or guarantee absolute invulnerability against all possible security threats or zero-day exploits.

6. Your Privacy Rights & Choices

Global Privacy Rights, CCPA/CPRA & GDPR Compliance

Depending upon your jurisdiction (including the European Economic Area under GDPR, the United Kingdom under UK GDPR, and California under CCPA/CPRA), you may hold the following statutory rights regarding your personal information: • Right of Access & Portability: You may request confirmation of whether we process your personal data, obtain a copy of such data, and receive it in a structured, commonly used, and machine-readable format. • Right to Rectification: You may request the correction or completion of inaccurate or outdated personal and business details. • Right to Erasure ('Right to be Forgotten'): You may request the deletion of your personal data from our active systems, subject to our legal obligations to retain corporate, financial, or tax records. • Right to Restriction & Objection: You have the right to object to or request restrictions upon the processing of your data under certain statutory circumstances. • Right to Non-Discrimination: We will never discriminate, deny services, charge differing rates, or alter service quality because you exercised any statutory privacy right. To exercise any of these rights, submit a written request to our Data Privacy Desk at privacy@netrocos.com. To safeguard client confidentiality, we verify the requester's identity prior to processing any data access or erasure request. We respond to all verified inquiries within statutory timeframes (typically within thirty (30) days for GDPR or forty-five (45) days for CCPA).

7. Cookies & Session Storage

Essential Technical Cookies Only

Netrocos maintains a strict data minimization stance: we do not utilize invasive cross-site advertising cookies, behavioral retargeting pixels, or third-party marketing trackers. • Essential Technical Cookies: We employ only strictly necessary first-party session cookies and security tokens. These essential cookies are required to authenticate authorized Client Portal sessions, validate anti-forgery (CSRF) tokens, enforce rate limits, and maintain routing stability across our distributed edge infrastructure. • Browser Controls: You may configure your browser to decline or block cookies; however, doing so will impede your ability to authenticate and access protected features within the Netrocos Client Portal.

8. Privacy Inquiries & Contact

Data Rights & Protection Officer

If you have inquiries, concerns, or requests regarding this Privacy Policy, our data protection practices, or our compliance with applicable privacy regulations, please contact our Legal & Privacy Administration: Netrocos LLC Attention: Legal & Data Privacy Desk Email: privacy@netrocos.com Website: https://netrocos.com/privacy We are committed to resolving inquiries regarding your privacy and our handling of your personal information in a prompt, transparent manner.