Cardinal Gray
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Describes that personal information is stored in third-party hosted databases in the United States where those parties are restricted to cloud storage and retrieval only; enumerates the limited circumstances under which Cardinal Gray will disclose personal data to non-Cardinal Gray parties (authorization, connection with a transaction, legal requirement, etc.) — protective restriction on third-party data sharing.
States the purposes for which collected personal information is used (service delivery), explicitly prohibits selling personal information to anyone, restricts sharing to third parties that facilitate service delivery only, and discloses that additional data may be received from third parties such as professional networking sites — user-favorable restriction on sale and broad third-party sharing.
Restricts the company from knowingly soliciting or receiving information from children, establishing a prohibition on collecting children's personal data.
How to read this page: Overall risk rates what Cardinal Gray's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 13 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 13 citationsLast captured 2026-07-19
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Specifies where personal data is stored (Cardinal Gray servers and third-party cloud database services in the United States), states that service data is retained for the duration of the customer relationship plus a subsequent period for operational analysis and archival purposes, and states that prospect data is retained until it no longer has business value and is purged — defining retention periods and purposes for different data categories.
" Your personal data is stored by Cardinal Gray on its servers and on the servers of the cloud-based database management services that Cardinal Gray engages, located in the United States. Cardinal Gray retains service data for the duration o..."
Discloses that data is processed in the United States, acknowledges the absence of an adequacy finding, and states that Cardinal Gray provides appropriate safeguards through binding standard data protection clauses enforceable by data subjects — establishes the cross-border transfer mechanism and residency/DPA compliance procedure.
" Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the Un..."
Clause A states that users should contact the internal data protection officer for questions, concerns, and to exercise privacy rights, while Clause B directs users to email jack@cardinalgray.com for questions or complaints concerning personal data processing.
" Cardinal Gray is headquartered in New York, New York in the United States. Cardinal Gray has appointed an internal data protection officer for you to contact if you have any questions or concerns about Cardinal Gray's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cardinal Gray's data protection officer:"
"If for some reason access is denied, Cardinal Gray will provide an explanation as to why access has been denied. For questions or complaints concerning the processing of your personal data, you can email us at jack@cardinalgray.com . Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events. We do not otherwise reveal your personal data to non-Cardinal Gray persons or businesses for their independent use unless: (1) you request or authorize it; (2) it's in connection with Cardinal Gray-hosted and Cardinal Gray co-sponsored conferences; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes."
Describes that personal information is stored in third-party hosted databases in the United States where those parties are restricted to cloud storage and retrieval only; enumerates the limited circumstances under which Cardinal Gray will disclose personal data to non-Cardinal Gray parties (authorization, connection with a transaction, legal requirement, etc.) — protective restriction on third-party data sharing.
AI-generated interpretation, not legal advice.
" We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn)."
States the purposes for which collected personal information is used (service delivery), explicitly prohibits selling personal information to anyone, restricts sharing to third parties that facilitate service delivery only, and discloses that additional data may be received from third parties such as professional networking sites — user-favorable restriction on sale and broad third-party sharing.
AI-generated interpretation, not legal advice.
" We do not knowingly attempt to solicit or receive information from children."
Restricts the company from knowingly soliciting or receiving information from children, establishing a prohibition on collecting children's personal data.
AI-generated interpretation, not legal advice.
" Cardinal Gray Incorporated is a Delaware C Corporation. We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes Cardinal Gray's policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies."
Introduces Cardinal Gray's commitment to describing its personal data collection and use policies, acknowledges an ongoing responsibility to update the Privacy Notice as practices change, and frames the document's scope for the reader.
AI-generated interpretation, not legal advice.
" Cardinal Gray collects personal information about its website visitors and customers. This information is generally limited to:"
Introduces the categories of personal information collected by Cardinal Gray about website visitors and customers, establishing the scope of the collection described in subsequent segments.
AI-generated interpretation, not legal advice.
" As is true of most other websites, Cardinal Gray's website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system, and other usage information about the use of Cardinal Gray's website, including a history of the pages you view. We use this information to help us design our site to better suit our users' needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences. Cardinal Gray has a legitimate interest in understanding how members, customers and potential customers use its website. This assists Cardinal Gray with providing more relevant products and services, with communicating value to our sponsors and corporate members, and with providing appropriate staffing to meet member and customer needs."
Discloses that the website automatically collects technical and usage data (IP addresses, location, browser type, operating system, page history) and states the purposes for which that data is used, namely site design improvement and server diagnostics — establishes collection scope and purpose limitation.
AI-generated interpretation, not legal advice.
" If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:"
Establishes the procedure for users to contact the company to exercise rights or raise concerns, directing them to the contact details that follow.
AI-generated interpretation, not legal advice.
" Your personal data is stored by Cardinal Gray on its servers and on the servers of the cloud-based database management services that Cardinal Gray engages, located in the United States. Cardinal Gray retains service data for the duration of the customer's business relationship with Cardinal Gray and for a period of time thereafter, to analyze the data for Cardinal Gray's own operations, and for historical and archiving purposes associated with Cardinal Gray's services. Cardinal Gray retains prospect data until such time as it no longer has business value and is purged from Cardinal Gray systems. All personal data that Cardinal Gray controls may be deleted upon verified request from Data Subjects or their authorized agents. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at jack@cardinalgray.com ."
Specifies where personal data is stored (Cardinal Gray servers and third-party cloud database services in the United States), states that service data is retained for the duration of the customer relationship plus a subsequent period for operational analysis and archival purposes, and states that prospect data is retained until it no longer has business value and is purged — defining retention periods and purposes for different data categories.
AI-generated interpretation, not legal advice.
" Cardinal Gray is headquartered in New York, New York in the United States. Cardinal Gray has appointed an internal data protection officer for you to contact if you have any questions or concerns about Cardinal Gray's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cardinal Gray's data protection officer:"
States that Cardinal Gray has appointed an internal data protection officer and directs individuals who wish to exercise privacy rights or raise concerns about personal data policies to contact that officer, establishing a procedural mechanism for rights exercise.
AI-generated interpretation, not legal advice.
" Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of "adequacy" from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Cardinal Gray is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved. Depending on the circumstance, Cardinal Gray also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Cardinal Gray in a manner that does not outweigh your rights and freedoms. Cardinal Gray endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Cardinal Gray and the practices described in this Privacy Statement. Cardinal Gray also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Cardinal Gray has received zero government requests for information. For more information or if you have any questions, please contact us at jack@cardinalgray.com ."
Discloses that data is processed in the United States, acknowledges the absence of an adequacy finding, and states that Cardinal Gray provides appropriate safeguards through binding standard data protection clauses enforceable by data subjects — establishes the cross-border transfer mechanism and residency/DPA compliance procedure.
AI-generated interpretation, not legal advice.
" The European Union's General Data Protection Regulation (GDPR) and other countries' privacy laws provide certain rights for data subjects. Data Subject rights under GDPR include the following:"
Defines the source of data subject rights (general data protection regulation and other countries' privacy laws) and introduces the list of rights that follow, framing the legal basis for subsequent right-granting segments.
AI-generated interpretation, not legal advice.
" This Privacy Notice is intended to provide you with information about what personal data Cardinal Gray collects about you and how it is used. If you wish to confirm that Cardinal Gray is processing your personal data, or to have access to the personal data Cardinal Gray may have about you, please contact us. You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Cardinal Gray might have received the data from Cardinal Gray; what the source of the information was (if you didn't provide it directly to Cardinal Gray); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Cardinal Gray if it is inaccurate. You may request that Cardinal Gray erase that data or cease processing it, subject to certain exceptions. You may also request that Cardinal Gray cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Cardinal Gray processes your personal data. When technically feasible, Cardinal Gray will—at your request—provide your personal data to you. Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Cardinal Gray will provide you with a date when the information will be provided. "
Describes the procedure by which individuals may confirm processing, access their personal data, and request information about processing purposes, data categories, recipients, and data sources — establishing a practical mechanism for exercising data subject rights.
AI-generated interpretation, not legal advice.
"If for some reason access is denied, Cardinal Gray will provide an explanation as to why access has been denied. For questions or complaints concerning the processing of your personal data, you can email us at jack@cardinalgray.com . Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority."
States that Cardinal Gray will provide an explanation when access is denied, directs individuals with questions or complaints to a contact email, and informs those in the European Union of recourse to the European Data Protection Supervisor or a national data protection authority — establishes complaint and redress procedures.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Cardinal Gray's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Cardinal Gray's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Cardinal Gray's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Cardinal Gray requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Cardinal Gray's published policies yet.
What the policies actually cover
0 topicsNone of Cardinal Gray's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industr...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industr...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events....”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | privacy data use | worsens | HIGH | 2 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on privacy data use
“We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn).”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn).”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events. We do not otherwise reveal your personal data to non-Cardinal Gray persons or businesses for their independent use unless: (1) you request or authorize it; (2) it's in connection with Cardinal Gray-hosted and Cardinal Gray co-sponsored conferences; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
13 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Cardinal Gray's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Cardinal Gray's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Cardinal Gray's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.