NCSC AI Toolkit · Privacy Back to unlock

Privacy and data practices

What the NCSC AI Toolkit collects, how long it keeps it, and how to request deletion. Last updated 2026-06-10.

What we collect

Legacy audit reports (April through June 2026). An earlier version of the toolkit let you generate a signed PDF audit of a vendor agreement, which stored the pasted text and the AI's output. That feature has been removed. Reports created during that window are retained so the /verify page can still confirm them: workshop and bypass reports carry no email; annual reports are linked to the requester's email. No new audit reports are created.

What we don't do

Retention

Your rights

Regardless of jurisdiction, you can request: (a) a copy of the data we hold on you, (b) deletion of your lead, any readiness snapshot tied to your email, and any associated legacy audit reports, (c) correction of inaccurate information, (d) revocation of any active access link.

Email joseph.colarusso@charterts.com from the email address on file. Joe processes requests manually; expect a 5-business-day turnaround. Deletion is irreversible.

EU / California / New York residents

GDPR (EU), CCPA (California), and NY SHIELD Act recognize the rights above and add procedural requirements. The data we collect under Path B is processed with your explicit consent at submission. Withdraw consent anytime by emailing the address above.

Security

Contact

Joseph Colarusso · Charter Technology Solutions · joseph.colarusso@charterts.com · 866-399-3230