Legal
Privacy Notice
Last updated: 11 August 2026 · Effective: 11 August 2026
1. Who we are and how to contact us
“NjoKey”, “we”, “us” and “our” mean the NjoKey contracting provider identified in the relevant Order Form. Until a registered company is identified on this page, customers must rely on the provider identity and business address stated in their Order Form. We do not present NjoKey as a registered company where no such registration has been confirmed.
- Website: njokey.com
- Privacy enquiries and rights requests: privacy@njokey.com
- Security reports: security@njokey.com
- Contractual enquiries: legal@njokey.com
A customer is normally the controller of personal data it places in NjoKey or causes NjoKey to collect about its workers. NjoKey normally acts as that customer’s processor. NjoKey acts as a controller for its own website, prospects, account administration, billing, security, service analytics, legal compliance and business records.
2. Who this notice concerns
This notice may apply to:
- website visitors, prospects and people who book a demo or contact sales;
- customer owners, administrators, billing contacts and authorised users;
- employees, contractors and other workers whose organisation uses NjoKey;
- people whose identities, accounts, devices or work events appear in connected systems;
- suppliers, advisers, partners and people who contact support or report a vulnerability.
If your employer or another organisation provided your data, that organisation must give you appropriate privacy information and establish its own lawful basis. Questions about an employer’s policy, monitoring decision or use of a finding should normally be directed to that employer first.
3. Personal data we may process
Website, sales and communications data
- name, work email, company, job role and contact details;
- demo time, notes, product interests, industry, headcount, countries and requirements;
- messages, support requests, feedback and records of our communications;
- IP address, browser, device type, referral page, timestamps and security logs;
- cookie or similar technology data where those technologies are deployed.
Account, commercial and billing data
- organisation and workspace details, account identifiers, roles and permissions;
- plan, employee or seat count, billing cycle, quotation and subscription status;
- billing address, tax information and Stripe customer, session and subscription references;
- authentication, sign-in, SSO, MFA, session and administrative activity records.
Payment card details are collected by Stripe. NjoKey does not intend to receive or store complete payment-card numbers or card security codes.
Workforce, identity and integration data
- name, work contact details, worker identifier, employment status and start or end dates;
- department, manager, group, role, normal work country and approved locations;
- directory accounts, group memberships, authentication state and joiner, mover or leaver events;
- records imported from customer-authorised identity, HR, SSO, SCIM or other integrations.
Device and endpoint data
- device identity, owner, manufacturer, model, serial or hardware identifiers;
- operating system, installed applications, local accounts and administrator status;
- encryption, firewall, antivirus, malware protection, patch and update status;
- network, VPN and connectivity signals, component health and last check-in;
- policies, observations, evidence freshness, findings, exceptions and remediation results;
- remote support or management session metadata and command or action audit records.
Location policy data
Where a customer enables a defined location policy check, NjoKey may process GPS-derived location, IP-derived location, network or wireless signals, country, region, accuracy, timestamp, verification outcome and supporting anti-spoofing signals. NjoKey is designed for checks at defined work events or policy moments, not continuous personal movement tracking. Actual customer configuration may affect what is collected.
Compass and generated data
- prompts, questions, instructions and feedback submitted to Compass;
- selected organisation, policy, workforce, device, finding and evidence context;
- Compass responses, drafts, explanations, citations, confidence information and action plans;
- approvals, rejections, execution results and audit events associated with an action.
4. How we obtain personal data
We obtain data:
- directly from you when you browse, enquire, buy, configure or use NjoKey;
- from a customer that creates accounts, imports records or installs the endpoint software;
- from customer-authorised identity, HR, directory, device, support and communication systems;
- from the NjoKey endpoint components installed on managed devices;
- from Stripe and other providers involved in payment, hosting, security or communications;
- automatically through service logs and strictly necessary technologies.
5. Purposes and lawful bases
| Purpose | Typical lawful basis when NjoKey is controller |
|---|---|
| Responding to enquiries, demos and requested proposals | Steps before a contract; legitimate interests |
| Creating accounts, providing subscriptions, support and billing | Contract; legitimate interests |
| Operating, securing, troubleshooting and improving the service | Legitimate interests; legal obligation where applicable |
| Preventing fraud, misuse and unauthorised access | Legitimate interests; legal obligation where applicable |
| Keeping financial, contractual and audit records | Contract; legal obligation; legitimate interests |
| Sending requested product updates or B2B marketing | Consent where required; legitimate interests, subject to objection and PECR |
| Handling legal claims and regulatory requests | Legal obligation; legitimate interests |
When NjoKey acts as processor, the customer determines the purpose and lawful basis and NjoKey processes data on documented instructions. A customer must not assume that employee consent is always the appropriate lawful basis merely because a NjoKey screen or workflow asks for acknowledgement or permission.
6. AI processing through Compass
Compass uses Anthropic’s commercial Claude API. To answer a request, NjoKey may send Anthropic the prompt and only the organisation context selected or retrieved as relevant to that request. This may include personal data where the customer’s instruction or use case requires it. Customers should avoid placing special-category data, criminal-offence data, secrets or unrelated personal information in prompts unless specifically agreed and legally justified.
Under Anthropic’s published standard commercial API position, API inputs and outputs are generally deleted from Anthropic systems within 30 days, subject to exceptions stated by Anthropic, unless NjoKey obtains and applies an eligible zero-data-retention agreement. NjoKey does not claim zero retention unless confirmed in the relevant Order Form or DPA.
Compass output may be incomplete, inaccurate or inappropriate. Material employment, disciplinary, access, security, legal, tax or compliance decisions must be reviewed by an authorised human. NjoKey does not use Compass as the sole basis for a decision that produces legal or similarly significant effects about an individual.
7. How we share personal data
We may share personal data with:
- the customer and its authorised administrators, reviewers and connected systems;
- Anthropic for Compass processing;
- Stripe for checkout, subscriptions, payment and fraud prevention;
- cloud hosting, database, email, observability, security and customer-support providers;
- professional advisers, auditors, insurers and prospective investors or acquirers under confidentiality;
- courts, regulators, law enforcement or other parties where required or permitted by law.
We do not sell personal data. We do not share personal data for third-party behavioural advertising. A current subprocessor list and the applicable DPA may be requested from privacy@njokey.com.
8. International transfers
Some providers may process data outside the United Kingdom. Where UK data-protection law restricts a transfer, we use an available adequacy regulation or appropriate safeguards, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where appropriate. Contact privacy@njokey.com for information about relevant safeguards.
9. Retention
We keep personal data only for as long as reasonably necessary for the relevant purpose, contractual commitment, customer instruction and legal requirement. Customer-configured retention settings and the DPA govern customer content. Unless a different period is documented, our current intended guide is:
- unsuccessful sales enquiries and demo records: up to 24 months after the last meaningful interaction;
- marketing preferences and suppression records: while needed to honour the preference;
- account and service records: for the subscription and a reasonable closure period;
- security and authentication logs: normally up to 12 months, longer when investigating an incident;
- billing, tax and contract records: normally six years after the relevant financial period or contract;
- customer content after termination: export and deletion according to the Customer Agreement and DPA;
- Anthropic API inputs and outputs: subject to the arrangement described in section 6.
We may preserve limited records for legal claims, fraud prevention, security incidents, backup integrity or a legal hold. Backups are isolated and expire through scheduled rotation.
10. Security
We use technical and organisational measures appropriate to the risk, including access controls, tenant separation, encryption in transit, credential controls, logging, least-privilege service access and incident procedures. Endpoint commands are intended to be authorised, device-bound, time-limited and audited. No service can be guaranteed completely secure, and customers remain responsible for their accounts, devices, administrators and lawful configuration.
Please report suspected vulnerabilities or unauthorised access to security@njokey.com. Do not include unnecessary personal data or exploit a vulnerability beyond what is reasonably necessary to demonstrate it.
11. Cookies and similar technologies
We may use technologies that are strictly necessary for security, sessions, checkout, preferences and core website operation. We will request consent before using non-essential analytics or advertising technologies where the law requires it. Browser controls may block technologies, but blocking necessary storage may prevent parts of the service from working.
12. Your data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data; object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. Rights are not absolute and exemptions may apply.
Email privacy@njokey.com. We may need to verify your identity and clarify the request. If NjoKey processes the data only for a customer, we may refer the request to that customer. In the UK, you may complain to the Information Commissioner’s Office at ico.org.uk, but we would appreciate the opportunity to address the concern first.
13. Children
NjoKey is a business service and is not directed to children. Customers must not deploy NjoKey to monitor children or process children’s data without prior written agreement, an appropriate risk assessment and a lawful, transparent implementation.
14. Changes to this notice
We may update this notice as the product, providers or law changes. We will publish the new date and provide additional notice where a change materially affects individuals. Earlier versions may be requested from legal@njokey.com.