Privacy Policy

Last updated: 02/12/2025

This Privacy Policy explains how NTrigo Ltd. ("NTrigo", "we", "our", or "us") handles information in connection with our website and services.

NTrigo designs its products and services with privacy by design and data minimization as core principles. Our goal is to provide strong cybersecurity protection while collecting as little information as possible.

Scope

This Privacy Policy applies to:

  • Visitors to our website
  • Business customers using NTrigo products and services

This policy does not apply to customer data processed locally within customer environments, which remains under customer control.

No Personal Data Collection by Default

NTrigo does not require individuals to create user accounts, register, or log in in order to use its products.

We do not intentionally collect personal data about end users as part of our core services.

Information We Do Not Collect

NTrigo does not collect or store:

  • Names, email addresses, phone numbers, or physical addresses of end users
  • User accounts or credentials
  • Payment card or financial information
  • Content of emails, messages, files, images, attachments, or communications
  • Website tracking or profiling data
  • Cookies or similar tracking technologies

Minimal Business Information We Do Process

For operational and contractual purposes, NTrigo processes limited business-related information, including:

  • Customer organization name
  • Subscribed packages and service entitlements
  • API keys
  • Aggregated and non-identifying usage statistics
  • Billing status and invoice records

This information is organizational in nature and does not include personal data of end users.

Security Processing and Transient Data Handling

NTrigo products operate in a hybrid SaaS model:

  • The majority of security processing is performed locally within customer environments (on-device or on-prem).
  • For security classification purposes, API requests may include a full URL or URL characteristics only.
  • Such data is processed in real time and immediately discarded.
  • NTrigo does not retain scanned links, attributes, or classification content.
  • Because this data is not stored, NTrigo cannot retrieve historical scanned URLs or content.

Screen Analysis for Phishing Protection

Certain NTrigo applications may request operating system permission to analyze visible screen content for security purposes.

This functionality is used exclusively to detect potentially malicious or phishing URLs that appear on the user’s screen.

The application does not record or store screen recordings or screenshots.

  • A temporary frame may be captured using operating system APIs solely for real-time analysis.
  • Text recognition is performed locally on the device.
  • Only strings matching URL structures are extracted for security classification.
  • No other text, images, messages, files, credentials, or application content are collected, stored, or transmitted.

URL analysis is performed locally whenever possible.

If advanced classification is required, only the isolated URL string may be transmitted securely to NTrigo servers for analysis. No screenshots, surrounding content, or user identifiers are transmitted.

URLs transmitted for analysis are processed in real time and are not stored by NTrigo.

Detected URLs may be stored locally on the user’s device in order to provide a scan history feature. This information remains solely on the user’s device and is not accessible to NTrigo.

Users can delete their scan history at any time directly within the application.

NTrigo does not associate scanned URLs with user identities and does not create user profiles.

Aggregated Usage Metrics

NTrigo may process aggregated, statistical usage data, such as:

  • Request volumes per subscribed package
  • Counts and ratios of security classifications
  • Processing distribution metrics

These metrics are numeric, non-identifying, and cannot be linked to individuals or content.

Website Communications

Our website does not include contact forms or user submissions.

If you contact us directly via email (for example, at security@ntrigo.com), we will use your email address and the information you provide solely to respond to your inquiry. We do not use this information for marketing purposes and do not share it with third parties.

Cookies and Tracking

NTrigo does not use cookies, analytics tools, advertising technologies, or tracking mechanisms on its website or services.

Data Location

Limited service-related information is hosted on Google Cloud Platform (GCP) infrastructure located in the United States.

Stored data is business-related and non-personal in nature.

Data Security

NTrigo implements appropriate technical and organizational measures to protect the limited information it processes, including:

  • Access restrictions based on least privilege
  • Multi-factor authentication
  • Encrypted credential storage
  • Internal access logging and review

Third-Party Service Providers

NTrigo uses a minimal number of third-party infrastructure and service providers. Where applicable, providers are selected based on strong security and compliance practices.

NTrigo does not share customer content or personal data with third parties for advertising or marketing purposes.

GDPR Positioning

To the extent the General Data Protection Regulation (GDPR) applies:

  • NTrigo follows principles of data minimization, purpose limitation, and privacy by design.
  • NTrigo generally acts as a data processor when providing services to business customers.
  • Customers remain responsible for data processed within their own environments.
  • Any data processed by NTrigo is limited, transient, and processed solely on documented customer instructions.

Data Retention

NTrigo does not retain personal data as part of its core cloud services.

URLs transmitted to NTrigo servers for security classification are processed in real time and are not stored.

Certain applications may store detected URLs locally on the user’s device solely to provide a scan history feature. This locally stored information remains under the user’s control and can be deleted at any time from within the application.

Business and operational records are retained only as long as necessary for contractual, legal, or operational purposes.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date.

Contact

If you have questions about this Privacy Policy or NTrigo's privacy practices, please contact:

NTrigo Ltd.
Email: security@ntrigo.com