PRIVACY NOTICE · EFFECTIVE 05 AUG 2026
Minimal operational data for secure service delivery.
This notice explains what information NBS processes through its sign-in, authenticated console, Control API, audit store, recovery workflow, health endpoints, and documentation surfaces. The service does not use advertising profiles or third-party behavioral analytics on authentication or control surfaces.
1. Scope
This notice applies to information processed when a person or service identity authenticates to NBS, submits a recovery request, views control-plane state, performs an authorized operation, exports an audit record, accesses a public status or documentation page, or interacts with a service health endpoint.
It does not describe the content of bulk object payloads managed by regional data-plane systems. Those payloads are outside the interactive NBS control path and are governed by the policy and ownership assigned to the applicable data space.
NBS is a restricted operational service rather than a public account platform. It does not offer public registration, advertising personalization, consumer profiles, or sale of personal information.
2. Information processed
| Category | Examples | Why it is needed |
|---|---|---|
| Assigned identity | Username, user ID, display name, role, team | Authenticate access and resolve permissions |
| Authentication state | Password outcome, MFA outcome, challenge ID, session creation and expiry | Protect the service and maintain a valid session |
| Operational activity | Action, resource, requested state, settings, change decision | Execute authorized work and preserve accountability |
| Recovery request | Submitted username, case reference, request time | Track recovery without disclosing account existence |
| Request metadata | Request ID, UTC timestamp, response status | Diagnose errors and correlate service events |
| Network abuse signal | Keyed one-way digest of source address | Rate control and security correlation |
| Public page request | Standard web request metadata handled by the HTTPS gateway | Deliver documentation and maintain availability |
Information not placed in the audit store
Passwords, MFA values, clear session cookies, connector secrets, signing keys, and clear source network addresses are not written to the application audit table. Integration pages display aliases and status metadata rather than secret configuration.
3. Purpose of processing
NBS processes operational information only for defined service purposes:
- authenticate assigned identities and prevent unauthorized access;
- resolve and enforce role-based permissions;
- create, validate, and track control-plane resource requests;
- coordinate reliability response, approvals, and access reviews;
- detect abuse, apply bounded sign-in attempts, and investigate security events;
- measure service health and diagnose failures;
- maintain a traceable record of consequential operational actions;
- comply with applicable record-preservation and security obligations defined by the service owner.
Information is not used for advertising, cross-service behavioral profiling, sale, or automated eligibility decisions. Operational alerts and anomaly safeguards may pause a transfer or block a change, but those controls evaluate service state rather than personal characteristics.
4. Cookies and browser storage
Essential session cookie
NBS uses one essential session cookie named nbs_session. It contains an opaque random token and is required for authenticated access. The cookie is marked Secure, HttpOnly, and SameSite=Strict. The corresponding server record stores a hash of the token, user ID, CSRF secret, creation time, expiry, and last-seen time.
Duration
A standard session may remain valid for up to twelve hours. If the user explicitly selects “Keep me signed in on this device,” the session may remain valid for up to thirty days. Sign-out deletes the server record and expires the cookie immediately.
Analytics and advertising
The authentication and console surfaces do not load third-party advertising cookies, behavioral analytics tags, social pixels, or cross-site tracking scripts. Browser storage is not used as a substitute for server authorization.
5. Sources of information
Identity and role attributes originate from the account configuration maintained for the service. Operational inputs are provided by the authenticated actor through the console or Control API. Health and resource state are produced by service components. Request metadata is generated as the HTTPS gateway and application process the transaction.
Recovery requests accept an asserted username but do not confirm whether it matches an active identity. Support validation occurs through the registered account channel, outside the public recovery response.
6. Disclosure and infrastructure providers
Operational information is available only to authorized service roles and infrastructure components that require it to deliver, secure, monitor, or support NBS. Access to the console does not grant access to underlying provider credentials or tenant identifiers.
The integration registry may reference external infrastructure products. A registry entry is operating metadata for a configured connector and is not a statement that the provider sponsors, certifies, or audits NBS. Provider documentation links are supplied for technical reference.
Current public and authenticated pages do not send page-view events to advertising or behavioral analytics services. Infrastructure-level request processing may still involve the hosting and network providers required to deliver the service.
7. Retention
Records are retained only for their operational, security, and accountability purpose. The following defaults apply unless a documented incident hold, legal requirement, or approved exception requires a different period.
| Record | Default retention | Start point | Purpose |
|---|---|---|---|
| Interactive session | 12 hours or 30 days when remembered | Session creation | Authenticated access |
| MFA challenge | 5 minutes or until successful use | Challenge creation | Second-factor verification |
| Recovery case | 90 days after closure | Case closure | Recovery traceability and abuse review |
| Authentication audit | 365 days | Event occurrence | Security review and investigation |
| Control mutation audit | 365 days | Event occurrence | Change traceability |
| Health and status data | 90 days | Measurement time | Availability and incident review |
| Exported evidence | Review-specific | Export creation | Assigned assurance activity |
Deletion from an active store may not immediately remove an item from an encrypted recovery backup. Backup copies follow their own bounded rotation and are not used for ordinary lookup or analytics.
8. Security safeguards
Safeguards include salted password digests, privileged MFA, opaque server-side sessions, CSRF validation, origin checking, role enforcement, bounded request bodies, structured errors, audit trails, restrictive browser security headers, TLS-only access, private application bindings, and controlled release verification.
A one-way keyed digest is used when the service needs to correlate source addresses for abuse prevention. Because the key is retained separately from the audit rows, the digest is not intended to serve as a reversible network identifier.
More detail is available in the Security Center and System Architecture.
9. Access, correction, and restriction requests
Requests concerning assigned identity attributes or operational records must be submitted through the registered support channel for the account. NBS may require identity verification before disclosing or changing information.
Some requests may be limited where a record is required to protect service security, preserve an incident investigation, maintain an audit trail, enforce access controls, or meet an applicable retention requirement. When a correction is appropriate, the service may preserve the original audit event and append a corrective record rather than rewriting history.
Do not submit passwords, MFA values, session cookies, or private keys with a privacy request. A username, request ID, relevant date range, and description of the requested correction are normally sufficient for initial triage.
10. Changes to this notice
This notice is reviewed annually and after material changes to authentication, data categories, retention, tracking, disclosure, or infrastructure processing. Material revisions are recorded below and in the service changelog.
Expanded data categories, cookie behavior, retention, provider disclosure, security safeguards, and request procedures.
Initial publication covering identity, sessions, audit records, and source-address minimization.
Operational