Overview & Scope
SignalGround is an RF spectrum intelligence platform operated by New Vision Security LLC (“New Vision Security,” “we,” “us,” or “our”). This Privacy Policy applies to the SignalGround web application accessed at app.signalground.app, the marketing site at signalground.net, and any related services we provide (collectively, the “Service”).
The Service is built around publicly available FCC Universal Licensing System (ULS) data, which is not personal data in itself. We collect a small amount of information from users of the Service in order to authenticate access, deliver requested features, secure the platform against abuse, and meet our contractual and legal obligations.
Information We Collect
We collect the following categories of information:
Account & Authentication Information
| Category | Examples | Source |
|---|---|---|
| Access codes & SKUs | SignalGround access codes (e.g. SG-V4XE-ENT), SKU/tier assignments | Provided by us at provisioning |
| Tenant identifiers | Microsoft Azure tenant ID for marketplace customers | Microsoft Marketplace at subscription creation |
| Contact information | Business email address, organization name REVIEW: legal — confirm fields collected at signup | Provided by you or your organization |
Usage & Diagnostic Information
- Server access logs (IP address, request timestamps, endpoint paths, response codes) retained for security monitoring and debugging
- Application telemetry (query timings, feature usage counts) used to improve performance and reliability
- Authentication events (successful and failed sign-ins, code redemptions)
Communications
- Messages you send to laura@newvisionsecurity.com or other support addresses
- Any voluntary feedback or feature requests submitted through the Service
FCC Public Records (not personal data of users)
The Service surfaces records from the FCC Universal Licensing System, which is a public record. Those records may include licensee names, addresses, callsigns, and other regulatory information that is itself published by the FCC. We do not treat FCC-published licensee information as “personal data” you have shared with us, because that information was already public when we ingested it.
Information We Do Not Collect
- We do not collect Social Security numbers, government ID numbers, or financial account numbers
- We do not collect payment card data directly — payments flow through Microsoft Marketplace or other processors
- We do not use third-party advertising or behavioral tracking pixels REVIEW: legal — confirm no ad pixels are embedded anywhere
How We Use Information
We use the information described above to:
- Authenticate access to the Service and enforce subscription entitlements
- Deliver the features you request (queries, reports, memos, exports)
- Detect, investigate, and prevent abuse, fraud, and security incidents
- Diagnose performance and reliability issues
- Communicate with you about your account, the Service, security alerts, and material changes
- Meet our contractual and legal obligations REVIEW: legal — confirm legal bases and add jurisdiction-specific bases where required
We do not use your information to train third-party machine learning models. REVIEW: legal — confirm and add scope around any Azure OpenAI features used for in-product summarization
Data Retention
We retain information only as long as necessary to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements.
| Category | Retention |
|---|---|
| Account & authentication records | REVIEW: legal — specify retention (e.g. life of subscription + 90 days) |
| Server access logs | REVIEW: legal — specify retention (commonly 30–90 days) |
| Application telemetry | REVIEW: legal — specify retention |
| Support communications | REVIEW: legal — specify retention |
| FCC public records | Refreshed daily from FCC source; not user-specific |
Data Security
We protect the Service with controls including:
- Encryption in transit (TLS) for all client connections
- Encryption at rest for the application database (Azure SQL)
- Secrets stored in Azure Key Vault with managed identity access
- Private network endpoints for database and cache services
- Role-separated database accounts (read-only API service account)
- Continuous monitoring of authentication events and unusual access patterns
No system is perfectly secure. If we become aware of a security incident that materially affects your information, we will notify you and any regulators required by applicable law in a timely manner. REVIEW: legal — specify breach-notification timeline (e.g. 72 hours under GDPR)
Your Rights & Choices
Depending on where you are located, you may have rights to:
- Request access to the information we hold about you
- Request correction of inaccurate information
- Request deletion of your information, subject to legal retention obligations
- Request a portable copy of information you provided to us
- Object to or restrict certain processing
- Withdraw consent where processing relies on consent
To exercise any of these rights, contact us at laura@newvisionsecurity.com. We will respond within the timeframe required by applicable law. REVIEW: legal — add verification process and response-time commitments
California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights regarding your personal information.
Categories of personal information we collect
In the past twelve months, we have collected the following statutory categories: identifiers (email, account codes), commercial information (subscription tier), internet or network activity (server logs), and professional information (organization name). REVIEW: legal — verify category list matches actual practice
Categories disclosed for a business purpose
We disclose the categories above to the service providers identified in Section 4 strictly for the business purposes described there.
“Do Not Sell or Share My Personal Information”
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. REVIEW: legal — confirm and update if any future change
Right to non-discrimination
You will not receive discriminatory treatment for exercising any of your CCPA rights.
European Economic Area (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (or equivalent local law) gives you additional rights.
Data controller
The data controller is New Vision Security LLC, College Park, Georgia, United States. REVIEW: legal — appoint an EU representative if required by Article 27
Lawful bases for processing
- Contract: processing necessary to deliver the Service to you
- Legitimate interests: security monitoring, fraud prevention, product improvement
- Legal obligation: where required by applicable law
- Consent: where you have provided it, you may withdraw at any time
REVIEW: legal — confirm bases match actual practice
International transfers
Information may be transferred to the United States. We rely on Standard Contractual Clauses or equivalent mechanisms where required. REVIEW: legal — identify specific transfer mechanism in use with each subprocessor
Right to lodge a complaint
You have the right to lodge a complaint with your local supervisory authority.
Children’s Privacy
The Service is intended for business and professional use and is not directed to children under 16. We do not knowingly collect information from children. If you believe a child has provided us information, please contact us and we will delete it.
International Data Transfers
The Service is hosted in the United States (Microsoft Azure, Central US region). If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you understand that your information will be transferred to and processed in the United States, subject to the protections described in this Privacy Policy and applicable law. REVIEW: legal — add Standard Contractual Clauses reference if needed
Cookies & Local Storage
The Service uses browser session storage to maintain your authentication state during a session. This information is stored locally in your browser and is not transmitted to third parties.
We do not use cookies or local storage for advertising, behavioral tracking, or cross-site profiling. REVIEW: legal — confirm and update if analytics or marketing cookies are added later
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify active subscribers by email or in-product notice.
Contact Us
Questions about this Privacy Policy or our handling of your information:
College Park, Georgia, United States
Email: laura@newvisionsecurity.com
UEI: NQ7DY8MADL23 · CAGE: 5AAG0
REVIEW: legal — consider establishing a dedicated privacy@ alias and adding postal address