Legal
Privacy Policy
Last updated: October 2, 2026
This Privacy Policy describes how NGC Risk LLC (“NGC Risk,” “we,” “us”) collects and uses information through ngcrisk.com (the “Website”) and when you contact us about our services.
1. What this policy covers
This policy covers visitors to the Website, people who contact us or book a call, and our business contacts. It does not cover information we handle for a client during an engagement. That information is governed by the agreement with that client. It also does not cover The Wardroom platform, which has its own privacy policy at wardroom.app.
2. Information we collect
- Contact form submissions: your name, email address, company, the topic you choose, and your message.
- Bookings: the details you give when you book a call through our Microsoft Outlook booking page, such as your name, email address, and meeting notes.
- Correspondence: emails and other messages you send us, and notes from our calls with you.
- Technical data: IP address, browser and device type, pages requested, and timestamps, which our hosting provider records automatically to deliver and protect the Website.
The Website does not use analytics, advertising, or tracking cookies. See our Cookie Policy for details.
3. How we use information
We use this information to reply to your enquiry, schedule and hold meetings, provide our services, keep the Website secure, and comply with legal obligations. If you ask about The Wardroom closed beta, we use your details to contact you about it. We do not sell personal information, and we do not use it for third-party advertising.
4. Service providers
We share information only with the providers that run parts of the Website and our business, and only as needed:
- Cloudflare: Website hosting, DNS, and security.
- Web3Forms: delivers contact form submissions to our inbox.
- Microsoft 365: email, calendar, and the Outlook booking page.
Each provider is bound by its own data protection terms. We may also disclose information when the law requires it.
The Website links to LinkedIn and Substack. When you follow those links, those companies’ own privacy policies apply.
5. How long we keep information
We keep enquiries and correspondence for as long as they are useful for following up or for an ongoing business relationship, and delete them on request. Information tied to a client engagement is kept as the engagement agreement requires.
6. Your rights
You can ask to see, correct, or delete the personal information we hold about you by emailing us at the address below. We will respond within a reasonable time and may need to confirm your identity first.
California residents: you have the right to know what personal information we collect, to request its deletion, and to opt out of its sale or sharing. NGC Risk does not sell or share personal information as California law defines those terms, so there is nothing to opt out of.
7. Where information is processed
NGC Risk is based in the United States, and information you send us is processed in the United States. Our providers may process it in other countries under their own data protection terms.
8. Children
The Website is meant for businesses and is not directed to children under 13. We do not knowingly collect their personal information, and we will delete it if we learn we have.
9. Security
We use reasonable technical and organizational measures to protect information, including encryption in transit. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Changes and contact
We may update this policy from time to time. Changes take effect when posted here, and we will revise the “Last updated” date above.
Questions or requests about this policy: privacy [at] ngcrisk [dot] com
