LEGAL

Privacy Policy

OUR COMMITMENTS

Privacy principles we operate by

Kennedy Risk Group works with regulated enterprises, financial institutions, and boards. The standards below shape every product decision, vendor selection, and data practice described in this policy.

We do not sell your data

We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.

Encrypted in transit and at rest

All client data, including risk register content, is encrypted using industry-standard TLS and AES-256.

You own your data

Risk data, financial figures, and organizational content you enter remain yours. Export or deletion available on request.

Least-privilege access

Internal access to client data is restricted to authorized personnel with a documented business need.

ON THIS PAGE

1. Overview

This Privacy Policy explains how Kennedy Risk Group, LLC ("Kennedy Risk Group," "KRG," "we," "our," or "us") collects, uses, discloses, and safeguards information when you visit kennedyriskgroup.com, engage our advisory services, or use the Risk Command Center platform (collectively, the "Services").

We are the controller of the personal information we collect about visitors and prospects. For client data entered into Risk Command Center on behalf of an organization, KRG acts as a processor and our customer is the controller.

2. Scope & Applicability

This policy applies to:

It does not cover information practices of third-party services that you connect to the Services, or information your employer or organization processes about you outside of KRG.

3. Information We Collect

Information you provide

Information collected automatically

Information from third parties

We do not knowingly collect special categories of personal data, government identifiers, or biometric data.

4. How We Use Information

We do not use client risk data to train third-party AI models or for any purpose other than delivering the Services.

5. Legal Bases for Processing

Where the EU or UK GDPR applies, we rely on the following legal bases:

6. How We Share Information

We share information only as described below. We do not sell personal information.

7. Subprocessors & Vendors

We work with a small set of vetted vendors to deliver the Services. Categories include cloud hosting and database infrastructure, authentication, transactional email, analytics, payment processing, customer support tooling, and AI inference providers used to power specific platform features. A current list of material subprocessors is available on request to contact@kennedyriskgroup.com.

8. International Data Transfers

We are based in the United States and may process information in the U.S. and other countries where our service providers operate. When we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organizational measures.

9. Data Retention

We retain personal information for as long as needed to provide the Services, satisfy legal, accounting, and reporting requirements, resolve disputes, and enforce our agreements. Typical retention windows:

You may request earlier deletion subject to the limitations described in Section 11.

10. Security

We maintain a defense-in-depth security program that includes:

No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you and, where required, regulators in accordance with applicable law.

11. Your Rights & Choices

Subject to applicable law, you may have the right to:

To exercise any of these rights, email contact@kennedyriskgroup.com. We will verify your request and respond within the timeframes required by applicable law. If you use the platform through your employer, please direct rights requests to your organization first.

12. U.S. State Privacy Rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, and opt out of certain types of processing. We do not sell personal information and do not engage in cross-context behavioral advertising or profiling that produces legal or similarly significant effects. To submit a request or appeal a decision, contact contact@kennedyriskgroup.com.

13. UK & EEA Rights (GDPR)

If you are located in the UK or EEA, you have the rights described in Section 11 under the UK GDPR and EU GDPR. You also have the right to lodge a complaint with your local supervisory authority. We will cooperate with regulators where required.

14. Cookies & Tracking

We use a limited set of cookies and similar technologies to keep you signed in, remember preferences, measure site performance, and understand how the Services are used. Categories:

You can manage cookies through your browser settings. Blocking some cookies may affect your experience.

15. AI Features

Certain features of the Risk Command Center use AI to suggest risk categories, draft mitigations, generate board summaries, and surface anomalies. Inputs you provide to these features are processed by vetted model providers under contractual restrictions that prohibit using your content to train their general models. AI-generated content is for decision support only and should be reviewed by a qualified human before being relied upon.

16. Children's Privacy

The Services are designed for business use and are not directed to individuals under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

17. Third-Party Links

Our Services may link to third-party websites and tools we do not control. This Privacy Policy does not apply to those services. We encourage you to review their privacy notices before providing any information.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date and, where appropriate, notify you by email or in-product notice. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

19. Contact Us

For privacy questions, rights requests, or concerns about this policy, contact:

Kennedy Risk Group, LLC Attn: Privacy Email: contact@kennedyriskgroup.com

We respond to verified requests within the timeframes required by applicable law and aim to acknowledge all inquiries within five business days.

Review our terms of service and usage policies.

Enterprise risk management advisory and platform.

Questions about our privacy practices? Reach out.