Dr. Nolyn Johnson LLC · Effective Date: May 20, 2026 · www.drnolyn.com
Dr. Nolyn Johnson LLC takes data security seriously. As a cybersecurity consulting firm, we hold ourselves to a high standard in protecting the personal, organizational, and confidential information entrusted to us by clients, website visitors, Academy participants, and partners.
This Policy applies to all data collected, processed, or stored in connection with:
Tier 1
Confidential
Client security assessments, risk registers, incident response plans, contractual data. Highest protection controls.
Tier 2
Internal
Business operational data, staff information, financial records. Standard access controls and encryption.
Tier 3
Public
Marketing content, published books, publicly available website content. Minimal restrictions.
Encryption
Access Controls
Endpoint Security
Step 1
Detection
Affected systems isolated. Escalated to principal within 1 hour.
Step 2
Assessment
Scope and impact assessed within 24 hours.
Step 3
Notification
Affected individuals notified within 72 hours per TN law and GDPR Art. 33.
Step 4
Remediation
Root cause analysis and corrective actions within 30 days.
We do not store credit card numbers, bank account information, or payment credentials on our systems. All payment processing is handled by PCI-DSS compliant third-party processors (Stripe and/or PayPal). The Company never has access to full payment card numbers.
This Policy is reviewed annually and updated as needed. The current version is always available at www.drnolyn.com/data-security. Last reviewed: May 20, 2026.
Security Contact — Dr. Nolyn Johnson LLC
5865 Ridgeway Center Parkway, Suite 300, Memphis, TN 38120
1-844-DRNOLYN (1-844-376-6596)
njohnson@drnolyn.com
For responsible disclosure of security vulnerabilities, email with subject line "Security Disclosure" and allow 30 days for investigation before public disclosure.