PRIVACY POLICY

Last Updated and Effective Date: March 16, 2026

 


Privacy Policy

Last Updated: March 2026

At N2M, we prioritize operational integrity and data security. This policy explains how we handle information collected through N2Mco.com and our professional advisory engagements.

1. Information We Collect

We limit data collection to what is necessary for our business relationships:

  • Direct Information: Name, professional email, company, and job title provided via contact forms.

  • Engagement Data: Information shared during IT Due Diligence, cybersecurity assessments, or fractional leadership engagements.

  • Technical Data: IP addresses and basic website usage metrics to optimize site performance.

2. Our Role as a Service Provider

In the context of M&A and IT Due Diligence, N2M often acts as a Service Provider (or Data Processor).

  • Target Data: We process technical and operational data from target companies solely to fulfill our contractual advisory obligations.

  • Data Rooms: When accessing third-party Virtual Data Rooms (VDRs), we adhere to the specific security and retention protocols of the platform provider and the selling entity.

3. How We Use Your Data

We use data to drive measurable results and project efficiency:

  • Service Delivery: Conducting technical assessments and M&A advisory.

  • Communication: Sending project updates or relevant industry insights.

  • Security: Protecting our systems and your information from unauthorized access.

4. Data Sharing & Disclosure

We do not sell your data. We only share information with:

  • Vetted Partners: Specialized vendors (e.g., secure hosting, data analysis tools) required to fulfill our services.

  • Legal Necessity: If required by law or to protect the rights of N2M and our clients.

5. Security Standards

As cybersecurity advisors, we apply “battle-tested” standards to our own operations:

  • Encryption: Data is encrypted in transit and at rest.

  • Access Control: We use strict role-based access to ensure sensitive information is only handled by necessary personnel.

  • Minimization: We purge data that no longer serves a documented business purpose once an engagement is closed.

6. Regional Rights (CCPA/GDPR)

Depending on your location, you have the right to:

  • Access & Correction: Request a copy of your data or ask us to fix inaccuracies.

  • Deletion: Request that we remove your personal data from our systems.

  • Opt-Out: Unsubscribe from any communications at any time.

7. Contact Us

For any privacy-related inquiries, please contact: Email: privacy@n2mco.com