Legal & Compliance

Privacy Policyfor Norvex Assurance

This Privacy Policy explains how Norvex Assurance collects, uses, shares, and protects your personal information when you visit our website or engage our compliance and audit services.

Last UpdatedJuly 16, 2026
Section 01

Who We Are

Norvex Assurance ("we", "our", "us") is a compliance and audit firm helping businesses achieve and maintain global security and regulatory certifications. Our services include SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, ISO 42001, HITRUST, and US Tax compliance — delivered to organisations across the US, UK, India, and international markets.

We act as a data controller when determining how and why we process your personal information. Where we use third-party platforms and tools to deliver our services, those providers may act as data processors under our direction and are bound by appropriate data protection agreements.

Section 02

Information We Collect

Contact and Business Information

When you engage with us, submit an inquiry, or contract our services, we collect your name, business email address, phone number, company name, and job title.

Project and Audit Information

In the course of delivering compliance and audit services — including SOC 2 assessments, ISO 27001 gap analyses, HIPAA readiness reviews, GDPR audits, and PCI DSS assessments — we may collect business documentation, system architecture details, security control evidence, and operational information relevant to your audit scope.

Technical Data

When you visit our website at norvexassurance.com, we may collect device identifiers, IP addresses, browser type, and usage data through standard web analytics tools and cookies.

Sensitive or Regulated Data

In limited circumstances — for example, during HIPAA compliance engagements for healthcare clients or GDPR assessments for organisations handling personal data — we may review or process data categories that are regulated under applicable privacy laws. This is done only to the extent required by the scope of engagement and with appropriate safeguards in place.

Section 03

Why We Process Your Information

We process your information for the following purposes:

  • Service delivery: To provide audit, compliance, and advisory services you have contracted us for — including SOC 2 readiness and certification, ISO 27001 implementation, HIPAA compliance programmes, GDPR framework development, PCI DSS assessments, ISO 42001 AI governance, and US tax compliance support. Processing for this purpose is necessary for the performance of our contract with you.
  • Legal and regulatory compliance: To meet our own obligations under applicable laws, including financial record-keeping, professional standards, and anti-fraud requirements.
  • Legitimate business interests: To improve our service quality, manage client relationships, conduct internal reporting, and maintain the security and integrity of our systems.
  • Consent-based processing: Where we send you communications about our services, updates, or relevant compliance topics, we do so with your consent where required by applicable law. You may withdraw consent at any time.
Section 04

How We Share Your Information

We do not sell or rent your personal information to any third party.

We may share your information with:

  • Service providers and technology partners: Platforms we use to deliver our services — including cloud infrastructure providers, CRM systems, audit tooling, and document management platforms — operate under strict data processing agreements with us. These include providers such as AWS, Microsoft Azure, Google Cloud, Okta, and similar platforms that form part of our technical environment.
  • Regulatory bodies and legal authorities: Where we are required by law, court order, or regulatory instruction to disclose information, we will do so in compliance with applicable legal obligations.
  • Certification and accreditation bodies: Where the delivery of a certification service — such as SOC 2 or PCI DSS — involves submission to or review by an accreditation body or independent auditor, relevant information may be shared with those bodies as part of the certification process.
  • Affiliated entities: Where we work with affiliated professionals or partner firms to deliver specific services, information is shared only to the extent necessary and under appropriate confidentiality obligations.
Section 05

International Data Transfers

Norvex Assurance serves clients globally and may process or store data across different countries. Where personal data is transferred across borders — for example between India, the US, UK, and other jurisdictions — we ensure those transfers are protected through legally recognised mechanisms including Standard Contractual Clauses, adequacy decisions where applicable, and any additional safeguards required by the laws of the relevant jurisdiction.

Section 06

Data Retention

We retain your information for as long as is necessary to:

  • Fulfil the purposes described in this policy
  • Meet our contractual obligations to you
  • Comply with applicable legal, tax, and regulatory record-keeping requirements — which vary by jurisdiction and service type
  • Address any disputes or enforce our agreements

When information is no longer needed for these purposes, it is securely deleted or anonymised.

Section 07

How We Protect Your Information

We implement appropriate technical and organisational security measures to protect your information against unauthorised access, loss, or disclosure. These include encryption of data in transit and at rest, access controls and authentication requirements, and security practices aligned with the same frameworks we help our clients implement — including ISO 27001, SOC 2, and AICPA audit standards.

Section 08

Your Rights

Depending on your country of residence, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information where no longer required
  • Restrict or object to certain types of processing
  • Request a copy of your data in a portable format
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your relevant data protection authority

To exercise any of these rights, please contact us at support@norvexassurance.com. Please specify your request clearly and indicate your country of residence so we can apply the correct legal framework to your request.

Section 09

Cookies and Website Tracking

Our website uses cookies and similar tracking technologies for:

  • Site functionality — to ensure the website operates correctly
  • Analytics — to understand how visitors use our site and improve the experience

You can manage or disable cookies through your browser settings at any time. Disabling certain cookies may affect the functionality of the website.

Section 11

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or operational practices. When we do, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

Questions about your data?

Our team is here to help with privacy requests, data subject enquiries, and any questions about how we handle your information.