Legal & Governance
Last Revised: September 2026 // Document Ref: TVS-LEGAL-2026-09
Corporate Identity & Registry
Registered Entity: ThreatVectorShield
Registered Activity: Digital Transformation Consulting, Web Platform Engineering, Marketing Funnel Optimization & Data Analytics
Headquarters: 51 Rue Levis, 75017 Paris, France
Electronic Correspondence: [email protected]
Telephone: +33 695 382 647
Data Retention & Storage Lifecycle
ThreatVectorShield retains personal contact data (name, email, phone number) submitted through our project intake consoles for the duration necessary to fulfill the stated commercial purpose, plus a statutory archival period of 24 months following the conclusion of the final active engagement.
Project deliverables, technical documentation, and associated digital assets are retained for a minimum of 36 months following final delivery to support warranty obligations and continuity of service. After this period, all client-specific data is irreversibly purged from production and backup systems within 30 calendar days.
Server logs and anonymized analytics data are aggregated and retained for a maximum of 12 months for infrastructure performance benchmarking and security audit purposes. No personally identifiable information is retained within log datasets.
Data Handling & Processing Lifecycle
All personal data processed by ThreatVectorShield is handled in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation) and applicable French data protection legislation enforced by the Commission Nationale de l'Informatique et des Libertés (CNIL).
Collection: Personal data is collected exclusively through voluntary submission via our project intake forms and direct email correspondence. No data is harvested through third-party trackers, cookies, or passive surveillance mechanisms.
Processing: Data is processed solely for client communication, project delivery execution, invoicing, and statutory tax reporting. ThreatVectorShield does not sell, rent, lease, or distribute personal information to unauthorized third-party entities.
Security: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Infrastructure is hosted on ISO 27001-certified EU data centers with redundant backup systems and automated failover protocols.
Third Parties: Where data is shared with essential service providers (e.g., cloud hosting, payment processors), such transfers are governed by formal Data Processing Agreements (DPAs) ensuring equivalent or superior protection standards.
Client Rights & Data Subject Entitlements
Under the GDPR, every data subject interacting with ThreatVectorShield retains the following enforceable rights:
- ✓Right of Access (Art. 15): Request a complete copy of all personal data held by ThreatVectorShield, delivered within 30 calendar days.
- ✓Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data without undue delay.
- ✓Right to Erasure (Art. 17): Request deletion of personal data where no overriding legal obligation requires continued retention.
- ✓Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format for transfer to another controller.
- ✓Right to Object (Art. 21): Object to processing of personal data based on legitimate interests, including direct marketing.
To exercise any of these rights, contact our designated Data Protection Officer at [email protected]. Requests are processed within 30 calendar days in compliance with GDPR timelines.
Terms of Service & Commercial Engagement
All services provided by ThreatVectorShield are governed by explicitly contracted Statements of Work (SOW) executed between the Client and ThreatVectorShield. These Terms of Service establish the baseline framework applicable to every engagement unless superseded by a signed SOW.
Scope & Deliverables: Service scope, deliverables, timelines, and payment schedules are defined in the applicable SOW or proposal document. Any modifications to scope require written agreement from both parties.
Intellectual Property: Upon complete settlement of all commercial invoices, ThreatVectorShield assigns all worldwide intellectual property rights in the client-specific deliverables, source code, design assets, and digital materials to the Client. ThreatVectorShield retains the right to reference the engagement in non-confidential marketing materials unless otherwise agreed.
Payment Terms: Invoices are payable within 14 calendar days of issuance unless otherwise specified in the SOW. Late payments incur a statutory interest rate of 3x the European Central Bank base rate per annum, in accordance with EU Directive 2011/7/EU.
Limitation of Liability: ThreatVectorShield's aggregate liability under any engagement shall not exceed the total commercial value of the applicable SOW. Neither party shall be liable for indirect, consequential, or incidental damages.
Refund & Reimbursement Policy
ThreatVectorShield is committed to transparent commercial practices. The following refund terms apply to all service engagements:
Pre-Delivery Cancellation: If a project is cancelled before any deliverable work has commenced, a full refund of all prepaid amounts will be issued within 14 business days, less any non-recoverable third-party procurement costs documented in the SOW.
Partial Delivery: Where work has been partially completed, the Client will receive a prorated refund reflecting the proportion of undelivered milestones as defined in the applicable SOW. Completed milestones remain billable.
Post-Delivery: Deliverables accepted in writing by the Client are non-refundable. However, ThreatVectorShield provides a 30-day post-launch warranty covering defect resolution for any deliverables that materially deviate from the specifications defined in the SOW.
Retainer Services: Monthly retainer engagements may be terminated with 30 days' written notice. No refund is issued for the current billing period, and all active project deliverables remain the Client's property.
Refund requests should be submitted to [email protected] with the relevant engagement reference number. Requests are evaluated and processed within 10 business days.
Security Audits & Infrastructure Governance
ThreatVectorShield maintains a rigorous information security governance program aligned with ISO/IEC 27001 standards and the NIST Cybersecurity Framework.
Internal Audits: ThreatVectorShield conducts quarterly internal security audits covering access controls, data encryption protocols, vulnerability scanning, and incident response procedures. Audit results are reviewed by senior management and documented in compliance archives.
External Assessments: Annual penetration testing and vulnerability assessments are performed by independent third-party security firms. Critical and high-severity findings are remediated within 30 calendar days of discovery.
Incident Response: A documented incident response plan governs the detection, containment, eradication, and reporting of security incidents. In the event of a personal data breach, affected data subjects and the relevant supervisory authority (CNIL) are notified within 72 hours, in accordance with GDPR Article 33.
Client Audits: Active clients enrolled in enterprise or retainer engagements may request an annual security posture summary report detailing compliance status, audit outcomes, and infrastructure resilience metrics.