ThreatVectorShield // Systems Operational
SLA: < 2 Hours |
Home / Legal
Compliance Framework

Legal & Governance

Last Revised: September 2026 // Document Ref: TVS-LEGAL-2026-09

01

Corporate Identity & Registry

Registered Entity: ThreatVectorShield

Registered Activity: Digital Transformation Consulting, Web Platform Engineering, Marketing Funnel Optimization & Data Analytics

Headquarters: 51 Rue Levis, 75017 Paris, France

Electronic Correspondence: [email protected]

Telephone: +33 695 382 647

02

Data Retention & Storage Lifecycle

ThreatVectorShield retains personal contact data (name, email, phone number) submitted through our project intake consoles for the duration necessary to fulfill the stated commercial purpose, plus a statutory archival period of 24 months following the conclusion of the final active engagement.

Project deliverables, technical documentation, and associated digital assets are retained for a minimum of 36 months following final delivery to support warranty obligations and continuity of service. After this period, all client-specific data is irreversibly purged from production and backup systems within 30 calendar days.

Server logs and anonymized analytics data are aggregated and retained for a maximum of 12 months for infrastructure performance benchmarking and security audit purposes. No personally identifiable information is retained within log datasets.

Contact Data: 24 months post-engagement Project Assets: 36 months post-delivery Server Logs: 12 months aggregated
03

Data Handling & Processing Lifecycle

All personal data processed by ThreatVectorShield is handled in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation) and applicable French data protection legislation enforced by the Commission Nationale de l'Informatique et des Libertés (CNIL).

Collection: Personal data is collected exclusively through voluntary submission via our project intake forms and direct email correspondence. No data is harvested through third-party trackers, cookies, or passive surveillance mechanisms.

Processing: Data is processed solely for client communication, project delivery execution, invoicing, and statutory tax reporting. ThreatVectorShield does not sell, rent, lease, or distribute personal information to unauthorized third-party entities.

Security: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Infrastructure is hosted on ISO 27001-certified EU data centers with redundant backup systems and automated failover protocols.

Third Parties: Where data is shared with essential service providers (e.g., cloud hosting, payment processors), such transfers are governed by formal Data Processing Agreements (DPAs) ensuring equivalent or superior protection standards.

04

Client Rights & Data Subject Entitlements

Under the GDPR, every data subject interacting with ThreatVectorShield retains the following enforceable rights:

  • ✓Right of Access (Art. 15): Request a complete copy of all personal data held by ThreatVectorShield, delivered within 30 calendar days.
  • ✓Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data without undue delay.
  • ✓Right to Erasure (Art. 17): Request deletion of personal data where no overriding legal obligation requires continued retention.
  • ✓Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format for transfer to another controller.
  • ✓Right to Object (Art. 21): Object to processing of personal data based on legitimate interests, including direct marketing.

To exercise any of these rights, contact our designated Data Protection Officer at [email protected]. Requests are processed within 30 calendar days in compliance with GDPR timelines.

05

Terms of Service & Commercial Engagement

All services provided by ThreatVectorShield are governed by explicitly contracted Statements of Work (SOW) executed between the Client and ThreatVectorShield. These Terms of Service establish the baseline framework applicable to every engagement unless superseded by a signed SOW.

Scope & Deliverables: Service scope, deliverables, timelines, and payment schedules are defined in the applicable SOW or proposal document. Any modifications to scope require written agreement from both parties.

Intellectual Property: Upon complete settlement of all commercial invoices, ThreatVectorShield assigns all worldwide intellectual property rights in the client-specific deliverables, source code, design assets, and digital materials to the Client. ThreatVectorShield retains the right to reference the engagement in non-confidential marketing materials unless otherwise agreed.

Payment Terms: Invoices are payable within 14 calendar days of issuance unless otherwise specified in the SOW. Late payments incur a statutory interest rate of 3x the European Central Bank base rate per annum, in accordance with EU Directive 2011/7/EU.

Limitation of Liability: ThreatVectorShield's aggregate liability under any engagement shall not exceed the total commercial value of the applicable SOW. Neither party shall be liable for indirect, consequential, or incidental damages.

06

Cookie Policy

ThreatVectorShield employs only strictly necessary cookies required for the technical operation of our web platform. No advertising, tracking, or third-party analytics cookies are deployed.

Session Cookies: Essential cookies are used to maintain session state, preserve user preferences (such as cookie consent acknowledgment), and ensure secure form submissions. These cookies are stored in your browser's local storage and expire upon browser session termination or manual clearance.

Consent: A cookie consent banner is presented on your first visit. Acknowledging this banner stores a single persistent consent flag (cookie_accepted) in your browser's local storage. No cookies are set prior to your explicit acknowledgment.

You may manage or delete stored cookies at any time through your browser settings. Declining cookies may limit certain platform functionalities.

07

Refund & Reimbursement Policy

ThreatVectorShield is committed to transparent commercial practices. The following refund terms apply to all service engagements:

Pre-Delivery Cancellation: If a project is cancelled before any deliverable work has commenced, a full refund of all prepaid amounts will be issued within 14 business days, less any non-recoverable third-party procurement costs documented in the SOW.

Partial Delivery: Where work has been partially completed, the Client will receive a prorated refund reflecting the proportion of undelivered milestones as defined in the applicable SOW. Completed milestones remain billable.

Post-Delivery: Deliverables accepted in writing by the Client are non-refundable. However, ThreatVectorShield provides a 30-day post-launch warranty covering defect resolution for any deliverables that materially deviate from the specifications defined in the SOW.

Retainer Services: Monthly retainer engagements may be terminated with 30 days' written notice. No refund is issued for the current billing period, and all active project deliverables remain the Client's property.

Refund requests should be submitted to [email protected] with the relevant engagement reference number. Requests are evaluated and processed within 10 business days.

08

Security Audits & Infrastructure Governance

ThreatVectorShield maintains a rigorous information security governance program aligned with ISO/IEC 27001 standards and the NIST Cybersecurity Framework.

Internal Audits: ThreatVectorShield conducts quarterly internal security audits covering access controls, data encryption protocols, vulnerability scanning, and incident response procedures. Audit results are reviewed by senior management and documented in compliance archives.

External Assessments: Annual penetration testing and vulnerability assessments are performed by independent third-party security firms. Critical and high-severity findings are remediated within 30 calendar days of discovery.

Incident Response: A documented incident response plan governs the detection, containment, eradication, and reporting of security incidents. In the event of a personal data breach, affected data subjects and the relevant supervisory authority (CNIL) are notified within 72 hours, in accordance with GDPR Article 33.

Client Audits: Active clients enrolled in enterprise or retainer engagements may request an annual security posture summary report detailing compliance status, audit outcomes, and infrastructure resilience metrics.