Privacy Policy
1. Introduction
NORTH AVENUE - CYBER RISK ADVISORS LLC (“North Avenue,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with NorthAvenue.ai (the “Website”) and related communications and services.
The Website is primarily intended for businesses and business professionals in the United States, although it may be accessible to visitors in other countries. By using the Website, you acknowledge the practices described in this Privacy Policy.
The Website is a static, informational site. It does not operate a server-side contact-form processing system, customer account system, or database for storing form submissions. Information described in this Policy is collected either automatically as part of ordinary Website hosting and delivery, or separately, when you choose to email us directly, as described below.
2. Information We Collect
2.1 Information You Provide by Email
The Website’s contact form is not connected to a server-side database or backend system. Clicking “Send” opens a pre-addressed email in your own email application; the Website itself does not transmit, receive, or store any information you enter into that form. Information is sent to us only if you choose to send that email yourself.
If you email us, whether by sending the pre-filled draft generated by the contact form or by contacting us directly, the message may include:
- Your name and contact information, such as your email address;
- Your company name;
- The contents of your message, including the reason for your inquiry or consultation request; and
- Any other information you choose to include.
We handle information received this way in the same manner as other business correspondence, in accordance with this Privacy Policy.
Please do not submit confidential, sensitive, or security-related information by email to us. In particular, do not send passwords, authentication credentials, security keys, detailed vulnerability information, regulated data, or other information that you would not want transmitted by ordinary email.
2.2 Information Collected Automatically
When you visit the Website, certain technical information may be collected automatically by our hosting, content-delivery, security, and analytics services. This may include:
- IP address;
- Browser and device information;
- User agent information;
- Requested URL;
- Referring URL;
- Date and time of requests;
- Approximate geographic information derived from an IP address;
- Website performance information; and
- Security or diagnostic information.
We use a content delivery network along with associated hosting, security, and web application firewall (WAF) services. Depending on the services enabled and their configuration, these providers may process request metadata and security-event information, including information associated with WAF, bot-management, firewall, DDoS protection, and other security functions.
We use Cloudflare Web Analytics, a privacy-focused analytics service that does not rely on cookies or persistent identifiers to measure Website usage. We do not use advertising-oriented analytics tools or cross-site tracking technologies.
2.3 Information from Other Sources
We may receive information from third parties when appropriate for our business purposes, such as professional contacts, referral sources, publicly available business information, or service providers.
We will handle such information in accordance with applicable law and this Privacy Policy.
3. How We Use Information
We may use information we receive by email, or automatically collect through the Website as described in Section 2.2, to:
- Operate, maintain, secure, and improve the Website;
- Respond to inquiries and consultation requests;
- Communicate with you about your request or an existing business relationship;
- Evaluate and provide professional services;
- Prevent, detect, investigate, and respond to security incidents, fraud, abuse, or other unlawful activity;
- Maintain business, accounting, administrative, and legal records;
- Comply with applicable legal obligations;
- Enforce our agreements and protect our legal rights;
- Understand Website usage and performance through analytics and related technical information; and
- Otherwise use information for purposes disclosed at the time of collection or with your consent where required.
4. Cookies and Similar Technologies
The Website is a static site. Serving static files in this way does not itself set cookies, and the Website does not use server-side application code that would set cookies.
Our analytics service operates without cookies or persistent client-side identifiers.
In limited circumstances, our content delivery and security provider’s own protective features on our custom domain, such as bot mitigation or firewall challenges, may set a security-related cookie to recognize that a visitor has passed a security check. This is a function of that provider’s network rather than something configured by the Website’s own code.
The Website’s own front-end code does not set cookies for visitors browsing the Website.
If this changes, for example if we add features that require cookies or similar technologies for visitors, we will update this section accordingly.
Browser settings may allow you to control cookies generally, although disabling certain technologies could affect how security challenges or Website functionality operate.
5. How We Disclose Information
We may disclose information in the following circumstances.
5.1 Service Providers
We may disclose information to vendors and service providers that help us operate the Website and our business, including providers of:
- Hosting and content delivery;
- Website source code and content hosting;
- Cybersecurity and security monitoring;
- Web application firewall and related security services;
- Analytics;
- Email and communications;
- Information technology;
- Professional services; and
- Other business-support functions.
These providers may process information on our behalf and are expected to use it only for authorized purposes and in accordance with applicable contractual and legal requirements. Because the Website does not operate its own contact-form backend, this section primarily concerns our general business operations, such as our business email host, rather than Website-submitted form data.
5.2 Professional and Business Relationships
Where appropriate, we may share information with clients, prospective clients, contractors, advisors, or other business counterparties as necessary to provide services or conduct legitimate business activities.
5.3 Legal and Security Requirements
We may disclose information when reasonably necessary to:
- Comply with applicable law, regulation, legal process, or governmental requests;
- Protect our rights, property, or safety;
- Protect the rights, property, or safety of others;
- Investigate suspected wrongdoing, fraud, abuse, or security incidents;
- Detect or prevent unauthorized access or other threats; or
- Protect the security and integrity of our systems, Website, clients, and users.
5.4 Business Transactions
Information may be disclosed as part of an actual or contemplated merger, acquisition, financing, sale of assets, restructuring, reorganization, or similar business transaction, subject to applicable confidentiality and legal requirements.
5.5 With Your Direction or Consent
We may disclose information when you direct us to do so or otherwise provide consent where consent is required.
6. Artificial Intelligence and Automated Technologies
North Avenue may use artificial intelligence, machine-learning systems, or other automated technologies internally or as part of future business services.
Where such technologies are used, we intend to apply appropriate contractual, technical, and organizational safeguards based on the nature and sensitivity of the information involved.
Based on the Website's current configuration, NorthAvenue.ai does not include a public AI chatbot or other public AI submission feature. If this changes, we will update the Website and this Privacy Policy as appropriate.
Information submitted through the Website's contact form should not be assumed to receive special protections associated with a secure client portal, encrypted document exchange, or other dedicated security environment.
7. Client Information and Confidential Business Data
North Avenue provides cybersecurity and cyber-risk advisory services. Information received from clients in the course of providing professional services may be subject to contractual confidentiality obligations, engagement terms, professional obligations, and other protections in addition to this Privacy Policy.
Clients and prospective clients should not submit confidential, proprietary, regulated, or security-sensitive information through the Website's general contact form unless North Avenue has expressly instructed them to do so through an approved secure process.
The Website’s contact form is intended for initial communications and business inquiries. It is not intended to serve as a secure mechanism for submitting sensitive security information, incident details, credentials, vulnerability data, or other confidential technical information.
8. Data Retention
We retain information we receive by email or automatically collect through the Website for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- Provide requested services;
- Respond to inquiries;
- Maintain business and transaction records;
- Resolve disputes;
- Enforce agreements;
- Comply with legal, tax, accounting, or regulatory obligations;
- Protect our systems and business; and
- Establish, exercise, or defend legal claims.
Retention periods may vary depending on the type of information, the context in which it was collected, applicable contractual obligations, and legal or regulatory requirements.
Information may also remain in backups, archives, or other systems for periods consistent with our technical and business practices.
9. Data Security
We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
Security measures may include, as appropriate:
- Access controls;
- Network and application security;
- Authentication and authorization controls;
- Encryption;
- Security monitoring;
- Logging and incident detection;
- Security services provided by third-party vendors; and
- Administrative and organizational safeguards.
No method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, while we take reasonable measures to protect information, we cannot guarantee absolute security.
10. Your Privacy Rights and Choices
Depending on where you live and the laws that apply to you, you may have certain rights regarding your personal information.
These rights may include, where applicable:
- The right to request access to personal information we maintain about you;
- The right to request correction of inaccurate personal information;
- The right to request deletion of certain personal information;
- The right to request a copy of certain personal information;
- The right to object to or restrict certain processing;
- The right to withdraw consent where processing is based on consent; and
- Other rights provided by applicable privacy law.
To make a privacy-related request, contact us at privacy@northavenue.ai.
We may need to verify your identity before completing certain requests. We will respond to valid requests in accordance with applicable law.
If a request is denied, where required by applicable law we will explain the reason for the denial and any available appeal process.
North Avenue does not sell personal information in the ordinary course of its business.
11. Do Not Track and Global Privacy Controls
Browsers and devices may offer privacy controls such as Do Not Track (“DNT”) or Global Privacy Control (“GPC”).
The effect of these signals can vary depending on the technology, browser, service, and applicable law.
Where required by applicable law, we will process recognized privacy signals in accordance with applicable requirements.
12. Third-Party Websites and Services
The Website may contain links to third-party websites, applications, or services.
North Avenue is not responsible for the privacy practices, security, content, or policies of third parties.
Your interactions with third-party websites or services are governed by their own terms and privacy policies. We encourage you to review those policies before providing personal information to third parties.
13. Children’s Privacy
The Website is intended for business and professional audiences and is not directed to children.
We do not knowingly collect personal information from children through the Website.
If you believe that a child has provided personal information to us, please contact us at privacy@northavenue.ai so that we can evaluate the situation and take appropriate action.
14. International Visitors
North Avenue is based in the United States, and the Website is primarily intended for U.S. businesses and business professionals.
Visitors from other countries may nevertheless access the Website and submit information to us.
If you access the Website from outside the United States, your information may be processed in the United States or in other jurisdictions where North Avenue or its service providers operate.
Depending on your location and applicable law, those jurisdictions may provide different privacy protections than the laws of your home jurisdiction.
Where applicable law requires additional safeguards for international transfers of personal information, we will seek to implement appropriate mechanisms.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, technology, services, legal requirements, or other circumstances.
When we make changes, we will update the “Last Updated” date at the beginning of this Privacy Policy.
For material changes, we may also provide additional notice through the Website or other appropriate means.
Your continued use of the Website after an updated Privacy Policy becomes effective constitutes your acknowledgment of the updated policy to the extent permitted by applicable law.
16. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or North Avenue’s privacy practices, please contact us:
NORTH AVENUE - CYBER RISK ADVISORS LLC
Attn: Privacy Inquiries
Rockville, Maryland, United States
Email: privacy@northavenue.ai
Website: NorthAvenue.ai