Privacy Policy

Last updated: [DATE] · Keystone, a product of Next Generation Technologies, Inc. ("NGT", "we", "us").

⚠️ DRAFT TEMPLATE — not yet legal advice. This page is a starting skeleton and must be reviewed and finalized by qualified legal counsel before publication. Bracketed […] items need real values.

1. Scope

This policy describes how NGT collects, uses, and protects information when you use the Keystonegovernance, risk & compliance platform (the "Service"). It covers (a) account data we collect about users, and (b) customer content that your organization enters into the Service.

2. Information we collect

  • Account information — name, work email, organization/workspace, role, and authentication data (hashed password, multi-factor enrollment).
  • Customer content — the GRC records you enter (risks, assets, vendors, policies, incidents, documents, etc.). This belongs to your organization; we process it on your behalf.
  • Usage & security logs — IP address, browser/user-agent, timestamps, and audit-trail events, retained for security and troubleshooting.
  • Cookies — a single session cookie used to keep you signed in. We do not use third-party advertising or tracking cookies.

3. How we use information

To provide and secure the Service, authenticate users, maintain audit trails, communicate service-related notices, and meet legal obligations. We do not sell personal information, and we do not use your customer content to train AI models.

4. Sub-processors & sharing

We share data only with vetted service providers strictly to operate the Service. Current sub-processors include: Cloudflare (network/TLS), Resend (transactional email), and Microsoft Azure OpenAI (the optional, opt-in assistant). [Confirm full list + DPAs.] We may disclose information if required by law.

5. The AI assistant

When enabled, the assistant is read-only and scoped to your current workspace. Prompts may be sent to the configured AI provider to generate a response; they are not used to train the provider's models. [Confirm provider data-handling terms.]

6. Data security

We apply layered controls including TLS in transit, encryption at rest [confirm], role-based access control, tenant isolation, multi-factor authentication, login throttling, append-only audit logging, and session idle-lock. No system is perfectly secure; see our Terms for warranty limitations.

7. Data retention

Customer content is retained for the life of your subscription and deleted within [N] days of account termination, except where retention is legally required. Security logs are retained for [N]. [Set periods with counsel; banks often require ≥1 year.]

8. Your rights & data ownership

Your organization owns its customer content. Account holders may access and correct their information in Profile. To request export or deletion, contact us at [email]. Depending on your jurisdiction, you may have additional rights (e.g., GLBA, state privacy laws). [Review.]

9. International transfers

[State where data is hosted and any cross-border transfer safeguards.]

10. Changes

We may update this policy; material changes will be posted here with a new "Last updated" date.

11. Contact

Next Generation Technologies, Inc. — [mailing address] · [privacy email].

Terms of Use · Back to sign in

Keystone by Next Generation Technologies, Inc. · Privacy · Terms · verify controls before relying on output.