Privacy Policy
Last updated: June 1, 2025
1. Introduction
NodeSight, Inc. ("NodeSight," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or otherwise interact with us.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide, including: name, email address, company name, job title, and any other information submitted through contact forms or service agreements.
2.2 Automatically Collected Information
When you visit our website, we automatically collect certain information including: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps. We use this information for analytics and to improve our services.
2.3 Tor Traffic Analysis Data
Important: NodeSight's core technology analyzes network traffic metadata at Tor exit relays. We do not capture, store, or process the content of network communications. Our analysis is limited to flow-level metadata: packet sizes, timing patterns, entropy measurements, and protocol-level features. This metadata is processed in real time and is not retained beyond the analytical window unless it triggers a threat alert, in which case forensic metadata (not content) is preserved.
3. How We Use Information
We use collected information to: provide and maintain our services; respond to inquiries and support requests; send service-related communications; improve our products and services; comply with legal obligations; and protect against misuse of our services.
4. Data Retention
Personal information is retained for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Threat alert metadata is retained for the duration specified in your service agreement (typically 90 days for standard plans, customizable for enterprise plans).
5. Data Sharing
We do not sell personal information. We may share information with: service providers who assist in operating our business; law enforcement when required by valid legal process; parties involved in a merger, acquisition, or sale of assets; and with your consent.
6. International Data Transfers
NodeSight operates globally. Information may be transferred to and processed in jurisdictions outside your country of residence. We implement appropriate safeguards for cross-border transfers, including Standard Contractual Clauses (SCCs) where required.
7. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the right to: access your personal data; rectify inaccurate data; request deletion of your data; restrict or object to processing; data portability; and withdraw consent. To exercise these rights, contact privacy@nodesight.ai.
8. Security
We implement technical and organizational measures to protect personal information, including encryption in transit (TLS 1.3) and at rest (AES-256), access controls, audit logging, and regular security assessments.
9. Contact
For privacy-related inquiries: privacy@nodesight.ai
NodeSight, Inc.
Data Protection Officer
Bengaluru, India