LEGAL
OUR COMMITMENTS
Kennedy Risk Group works with regulated enterprises, financial institutions, and boards. The standards below shape every product decision, vendor selection, and data practice described in this policy.
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
All client data, including risk register content, is encrypted using industry-standard TLS and AES-256.
Risk data, financial figures, and organizational content you enter remain yours. Export or deletion available on request.
Internal access to client data is restricted to authorized personnel with a documented business need.
ON THIS PAGE
This Privacy Policy explains how Kennedy Risk Group, LLC ("Kennedy Risk Group," "KRG," "we," "our," or "us") collects, uses, discloses, and safeguards information when you visit kennedyriskgroup.com, engage our advisory services, or use the Risk Command Center platform (collectively, the "Services").
We are the controller of the personal information we collect about visitors and prospects. For client data entered into Risk Command Center on behalf of an organization, KRG acts as a processor and our customer is the controller.
This policy applies to:
It does not cover information practices of third-party services that you connect to the Services, or information your employer or organization processes about you outside of KRG.
We do not knowingly collect special categories of personal data, government identifiers, or biometric data.
We do not use client risk data to train third-party AI models or for any purpose other than delivering the Services.
Where the EU or UK GDPR applies, we rely on the following legal bases:
We share information only as described below. We do not sell personal information.
We work with a small set of vetted vendors to deliver the Services. Categories include cloud hosting and database infrastructure, authentication, transactional email, analytics, payment processing, customer support tooling, and AI inference providers used to power specific platform features. A current list of material subprocessors is available on request to contact@kennedyriskgroup.com.
We are based in the United States and may process information in the U.S. and other countries where our service providers operate. When we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organizational measures.
We retain personal information for as long as needed to provide the Services, satisfy legal, accounting, and reporting requirements, resolve disputes, and enforce our agreements. Typical retention windows:
You may request earlier deletion subject to the limitations described in Section 11.
We maintain a defense-in-depth security program that includes:
No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you and, where required, regulators in accordance with applicable law.
Subject to applicable law, you may have the right to:
To exercise any of these rights, email contact@kennedyriskgroup.com. We will verify your request and respond within the timeframes required by applicable law. If you use the platform through your employer, please direct rights requests to your organization first.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws may have additional rights, including the right to know, delete, correct, and opt out of certain types of processing. We do not sell personal information and do not engage in cross-context behavioral advertising or profiling that produces legal or similarly significant effects. To submit a request or appeal a decision, contact contact@kennedyriskgroup.com.
If you are located in the UK or EEA, you have the rights described in Section 11 under the UK GDPR and EU GDPR. You also have the right to lodge a complaint with your local supervisory authority. We will cooperate with regulators where required.
We use a limited set of cookies and similar technologies to keep you signed in, remember preferences, measure site performance, and understand how the Services are used. Categories:
You can manage cookies through your browser settings. Blocking some cookies may affect your experience.
Certain features of the Risk Command Center use AI to suggest risk categories, draft mitigations, generate board summaries, and surface anomalies. Inputs you provide to these features are processed by vetted model providers under contractual restrictions that prohibit using your content to train their general models. AI-generated content is for decision support only and should be reviewed by a qualified human before being relied upon.
The Services are designed for business use and are not directed to individuals under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
Our Services may link to third-party websites and tools we do not control. This Privacy Policy does not apply to those services. We encourage you to review their privacy notices before providing any information.
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date and, where appropriate, notify you by email or in-product notice. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
For privacy questions, rights requests, or concerns about this policy, contact:
Kennedy Risk Group, LLC Attn: Privacy Email: contact@kennedyriskgroup.com
We respond to verified requests within the timeframes required by applicable law and aim to acknowledge all inquiries within five business days.
Review our terms of service and usage policies.
Enterprise risk management advisory and platform.
Questions about our privacy practices? Reach out.