Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Legal

Privacy Policy

This policy explains what information we collect through the website, enquiries and service delivery, how it is used, stored and shared, and the rights you can exercise.

General

Zhengzhou SheMo Information Technology Co., Ltd. ("we", "us") operates this website (noransom.net) and provides ransomware response and data recovery services under the SheMo Noransom brand. We process personal information and client data in accordance with the Personal Information Protection Law of the PRC (PIPL), the Cybersecurity Law and the Data Security Law.

This policy covers browsing and form submission on this website, as well as information handling during service enquiry, assessment and delivery. We follow the principle of minimum necessity: we collect only what is needed to provide the service, and no personal information unrelated to it.

Please read this policy before using the website or engaging us. If you do not agree with it, please do not submit a form or send samples.

Information we collect

1. Information you provide

  • Contact and enquiry details: organization name, contact name, role, phone number and email submitted by email, phone or instant messaging, together with your description of the incident and technical requirements.
  • Technical material and samples: ransom note text, encrypted sample files, appended extensions, system and database versions, asset and topology descriptions, and log excerpts used for family identification and the recoverability assessment.
  • Information generated during service delivery: system information accessed within the scope you authorize, disk and log images, and operation records from the engagement.

2. Information collected automatically

This is a static website and sets no cookies for cross-site tracking by default. Server and content delivery layers generate ordinary access logs that may include access time, requested page, HTTP status code, IP address and browser user agent, used for security protection, troubleshooting and traffic statistics.

3. What we do not collect

We do not solicit personal information unrelated to ransomware response. We never require images of identity documents, bank account details or payment credentials, and we do not ask for your complete production dataset.

How we use information

We use the information collected only for the following purposes:

  • responding to enquiries and intake: returning calls, replying to email, confirming the situation;
  • family identification and recoverability assessment: analysing samples and ransom notes to determine the variant and viable recovery paths;
  • service delivery: data recovery, incident response, forensics and hardening work, plus the reports and verification checklists delivered;
  • contractual and compliance obligations: contracting, invoicing, and supporting police filings or regulator enquiries at your request;
  • website operation and security: investigating anomalous access, defending against attacks, compiling traffic statistics;
  • service improvement: after de-identification, for summarizing technical methods and internal case study.

We do not use your information for advertising or commercial resale, and we do not process it beyond the purposes above without your consent. If a change of purpose becomes necessary, we will seek your consent again.

Retention and security measures

Retention

  • Enquiry and contact details: retained for the period necessary to handle the enquiry and support follow-up; you may request deletion.
  • Samples and technical material: retained only for the assessment and service period. Working copies are deleted within the period set by contract or mutual agreement after the engagement, and a deletion confirmation can be issued on request.
  • Images and log evidence: retained as agreed for forensic and contractual purposes and deleted at the end of that period. If you require immediate deletion at project close we will comply — we will first explain that this can limit later review and supplementary material for a police filing.
  • Website access logs: retained for a limited period as required for operation and security, then overwritten or deleted.
  • Where law mandates a longer retention period, the statutory requirement applies.

Security measures

  • Client data and samples are held in a controlled environment with access granted on a need basis, limited to engineers on the engagement.
  • Work is performed on read-only images and isolated working copies so original client data is not affected.
  • Transfers use encrypted channels; remote access goes through a controlled channel with an operation log retained.
  • Personnel are bound by confidentiality obligations and lose access when they leave the engagement.

No set of measures can guarantee absolute security. In the event of a personal information breach or similar incident, we will take timely remedial action and fulfil our notification and reporting obligations as required by law.

Sharing and third parties

We do not sell, rent or trade your personal information or client data, and we do not use it for commercial purposes unrelated to this service.

Disclosure may occur only in the following circumstances:

  • With your explicit authorization — for example, providing a report or technical conclusion to an insurer, parent organization or partner you designate;
  • Technical service providers necessary to operate the service: this website uses third-party hosting and content delivery, whose providers may have access to website access logs; if a third-party form service is enabled, form content passes through that provider. We select providers with appropriate qualifications and security capability and constrain their processing scope contractually;
  • Legal requirements: cooperating with investigations and lawful requests from judicial and regulatory authorities;
  • Public safety and vital interests: statutory circumstances such as protecting the life, health or property of you or others.

Use in case studies and articles: the case studies published on this site are illustrative, compiled from typical scenarios and anonymized, and the pages say so. We do not disclose client names, identifiable environment details or business data without written consent.

Cross-border transfer: our services and data processing take place within mainland China. Should a cross-border transfer become necessary, we will obtain your separate consent and complete the procedures required by law.

Your rights

Under the PIPL you have the following rights in respect of the personal information we process:

  • To be informed and to decide: to know the purpose, method and scope of processing, and to restrict or refuse processing of your personal information by others;
  • Access and copy: to access the personal information we hold about you and request a copy;
  • Correction and supplementation: to have inaccurate or incomplete information corrected or completed;
  • Deletion: where the purpose has been achieved, the service has ended, you withdraw consent, or processing was unlawful;
  • Withdrawal of consent: for processing based on consent, at any time; withdrawal does not affect processing already carried out;
  • Explanation: to ask us to explain our personal information handling rules;
  • Rights of close relatives of a deceased person: to exercise access, copy, correction and deletion rights over a deceased natural person's related personal information as provided by law.

To exercise any of these rights, use the channels in the "How to contact us" section below. To protect you, we may need to verify your identity first. We respond within a reasonable period, and where a request cannot lawfully be met we explain why.

How to contact us

If you have questions about this policy, wish to exercise the rights above, or want to raise a complaint about our handling of personal information, contact us using the phone number and email published on the Contact page, noting "privacy policy" so the request is prioritized.

We verify and respond within a reasonable period of receiving a request. If you believe our processing has infringed your lawful rights and we cannot resolve it together, you may also complain to the competent cyberspace administration or public security authorities, or bring proceedings before a people's court as provided by law.

Updates to this policy

We may update this policy in response to changes in law, changes to our services, or improvements in security practice. Updated versions are published on this page and the update date shown at the bottom of the page is revised accordingly.

Where there is a material change to the purpose or method of processing, or to the categories of personal information involved, we will give prominent notice and, where necessary, seek your consent again. We suggest reviewing this page periodically.

This policy was last updated on 11 September 2026.

Updated