Terms of Service
Version: 2026-06-08-v2 · Effective 24.3.2026
Guiding Principle
NoData computes access, not permissions. We orchestrate governance but never access, store, or process customer data, and never hold customer keys. All diagnosis, enforcement, encryption, and proof are performed in the customer's environment only.
1. Service Definition
NoData provides an Information Access Processor — a system that computes who may see what, for people, applications, and AI, across the customer's data, files, and systems. It comprises: the Capsule (an agent installed in the customer's environment), the Courier console (orchestration and policy), reversible field- and file-level encryption, per-identity access grants with time / view-count / restriction controls, and signed, hash-chained decision receipts.
All enforcement and key custody run in the customer's environment. NoData orchestrates — but never accesses, stores, processes, or executes on the customer's source code, business data, or personal information (PII), and never holds the customer's encryption keys.
2. Customer Responsibility
The customer is responsible for:
- Installing and running the Capsule and the executor in their own environment
- Holding and safeguarding their own encryption keys
- Backing up data before applying encryption or policy changes
- Verifying that policy is enforced as intended
- Retaining reports, receipts, and evidence
NoData orchestrates governance and provides the tooling — it does not make direct changes to the customer's systems and does not hold the customer's keys.
3. Information NoData Stores
NoData stores a minimal audit log for legal proof purposes:
- User ID (if registered), session ID
- Action timestamps
- Action types (scan, grant, policy, encrypt, proof, export)
- Proof hashes (SHA-256) — cannot be reversed to data
- Terms of service consents
Retention period: 7 years (Israeli Income Tax Ordinance + SOC 2 CC7.4 requirement).
4. Information NoData Does NOT Store
NoData does NOT store under any circumstances:
- Customer source code
- Table names, field names, or schemas
- Scanned PII values or business data
- Scan report contents (stored in customer's browser only)
- Credentials, encryption keys, or passwords
- Content of messages, files, or media sent through communication tools
5. Encrypted Communication Tools
Communication tools (chat, secure channel, rooms, report box) operate with end-to-end encryption (E2E).
NoData cannot read, decrypt, or access sent content. Content is encrypted in the sender's browser and decrypted only in the receiver's browser.
Messages are auto-deleted per TTL settings. Only delivery proof (HMAC) remains — not the content.
6. Signed Receipts & Proof
Every governed access decision is recorded as a signed, hash-chained receipt containing proof hashes only — never customer data.
NoData verifies the integrity of the receipt chain (from genesis) — not the underlying data. The processor's decision count and the receipts are independently verifiable.
Receipts do not constitute SOC 2 certification. SOC 2 Type II compliance requires external audit by a qualified auditor.
7. Limitation of Liability
NoData provides the service "AS IS". NoData is not liable for:
- Damage caused by running the Capsule / executor in the customer's environment
- Data loss due to improper use of tools
- Failure to meet SOC or other regulatory requirements
- Temporary or permanent service interruption
NoData's total liability is limited to the amount paid in the last 12 months.
8. Governing Law
These terms are governed by the laws of the State of Israel. Exclusive jurisdiction is granted to the courts of Tel Aviv-Jaffa.
NoData — Information Access Processor
We compute access, not permissions.
nodatacapsule.com