Privacy Policy

Last Updated: February 14th, 2025

Your privacy is important to us. It is Stern Security’s policy to respect your privacy regarding any information we may collect from you across our domain, sternsecurity.com and other sites we own and operate, including:

  • Velocitysec.com
  • Healthcarebreaches.com

This privacy policy outlines how we collect, use, and safeguard your data when you use our SaaS product and informational websites.

1. Information We Collect

Personal Information

We only ask for personal or company information when we truly need it to provide a service to you. This information may include:

  • Name
  • Email address
  • Company name
  • Phone number
  • Billing information
  • Any other information you choose to provide

Anonymized Data

We collect anonymized data to analyze website traffic and usage patterns. This data helps us understand how companies use our services and improve our offerings. Anonymized data includes, but is not limited to:

  • IP addresses (anonymized)
  • Browser type
  • Operating system
  • Pages visited
  • Time spent on pages
  • Clickstream data

2. How We Collect Information

We collect information by fair and lawful means, with your knowledge and consent. We also let you know why we’re collecting it and how it will be used.

3. How We Use Your Information

(a) We use the information we collect for the following purposes:

  • To provide, operate, and maintain our services
  • To improve, personalize, and expand our services
  • To understand and analyze how you use our services
  • To develop new products, services, features, and functionality
  • To process transactions and manage billing
  • To communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the service, and for marketing and promotional purposes
  • To process your transactions and manage your orders
  • To find and prevent fraud
  • To comply with legal obligations

(b) Purpose of Sharing Third-Party Contact Information

As part of the Velocity risk assessment platform, companies (“Customers”) may request access to security reports of third-parties (“Third-Parties”). In cases where a Third-Party does not respond to such requests, Velocity may share the Third-Party’s designated account contact email address with the requesting Customer to facilitate direct follow-up.

This sharing is intended solely to:

  • Expedite security assessment approvals.
  • Improve communication efficiency between Third-Parties and their Customers.
  • Ensure that security-related inquiries receive prompt attention.

(c) Who Can Access Third-Party Contact Emails

  • Only Customers who have requested access to the Third-Party’s new or existing security report will be able to see the designated security contact email.
  • Third-Party email addresses will not be publicly accessible or shared outside the context of the specific request.
  • Velocity will continue to send automated reminders, but Customers may also use the provided email to follow up independently.

(d) Third-Party Control & Opt-Out Options

Third-Parties can manage their visibility settings and have the following options:

  • Alternative Contact: Third-Parties may designate an alternative contact for security assessments.
  • Email Visibility Preferences: Third-Parties may request that their email not be shared with Customers, but in doing so, they acknowledge that Customers will only be able to contact them via Velocity’s automated reminders.
  • Opt-Out Mechanism: Third-Parties may opt out of email visibility at any time by contacting [[email protected]] or through available settings in Velocity (if applicable).

(e) Compliance & Data Protection Measures

  • Email sharing is conducted in compliance with applicable privacy laws, including GDPR and CCPA, and is limited to business contact information relevant to security assessments.
  • Stern Security does not sell, rent, or otherwise disclose contact information for unrelated purposes.
  • Third-Party contact information is protected through industry-standard security protocols to prevent unauthorized access.

4. Data Retention

We only retain collected information for as long as necessary to provide you with your requested service. What data we store, we’ll protect within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification.

5. Data Sharing

We don’t share any personally identifying information publicly or with third-parties, except when required to by law.

6. External Links

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and practices of these sites, and cannot accept responsibility or liability for their respective privacy policies.

7. Your Rights

You are free to refuse our request for your personal information, with the understanding that we may be unable to provide you with some of your desired services.

8. Changes to This Policy

We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. By using this website, you are agreeing to be bound by the then current version of this policy.

9. Contact Us

For more information about our privacy practices, if you have questions, please contact us through our website or by mail using the details provided below:

Stern Security Inc.

421 N. Harrington St, Suite 340

Raleigh, NC 27603

Your continued use of our website will be regarded as acceptance of our practices around privacy and personal information. If you have any questions about how we handle user data and personal information, feel free to contact us.

Reporting Ethical Concerns
Stern Security is committed to maintaining the highest standards of ethics and integrity. If you have concerns about unethical behavior, security issues, or other compliance matters, please contact us confidentially at [email protected]. Reports may also be made anonymously.