Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · cardinalgray.com

Cardinal Gray

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-19
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

13 verified findings4 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: subprocessors data sharing

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
1
low
1/1
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Cardinal Gray's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 13 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 13 citationsLast captured 2026-07-19
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Data retention

Specifies where personal data is stored (Cardinal Gray servers and third-party cloud database services in the United States), states that service data is retained for the duration of the customer relationship plus a subsequent period for operational analysis and archival purposes, and states that prospect data is retained until it no longer has business value and is purged — defining retention periods and purposes for different data categories.

" Your personal data is stored by Cardinal Gray on its servers and on the servers of the cloud-based database management services that Cardinal Gray engages, located in the United States. Cardinal Gray retains service data for the duration o..."
📍 Privacy Policy › “Data Storage and Retention”Jump to exact text →
plan language
Audit rights / DPA / residency

Discloses that data is processed in the United States, acknowledges the absence of an adequacy finding, and states that Cardinal Gray provides appropriate safeguards through binding standard data protection clauses enforceable by data subjects — establishes the cross-border transfer mechanism and residency/DPA compliance procedure.

" Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the Un..."
📍 Privacy Policy › “Transferring Personal Data to the U.S.”Jump to exact text →
Conflicting provisions (1)
  • Clause A states that users should contact the internal data protection officer for questions, concerns, and to exercise privacy rights, while Clause B directs users to email jack@cardinalgray.com for questions or complaints concerning personal data processing.

    " Cardinal Gray is headquartered in New York, New York in the United States. Cardinal Gray has appointed an internal data protection officer for you to contact if you have any questions or concerns about Cardinal Gray's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cardinal Gray's data protection officer:"
    "If for some reason access is denied, Cardinal Gray will provide an explanation as to why access has been denied. For questions or complaints concerning the processing of your personal data, you can email us at jack@cardinalgray.com . Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority."
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 13
Severity
Surface
Document
Tier
Subprocessors & data sharing
High
" The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events. We do not otherwise reveal your personal data to non-Cardinal Gray persons or businesses for their independent use unless: (1) you request or authorize it; (2) it's in connection with Cardinal Gray-hosted and Cardinal Gray co-sponsored conferences; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes."
Privacy Policy › “Sharing Information with Third Parties”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes that personal information is stored in third-party hosted databases in the United States where those parties are restricted to cloud storage and retrieval only; enumerates the limited circumstances under which Cardinal Gray will disclose personal data to non-Cardinal Gray parties (authorization, connection with a transaction, legal requirement, etc.) — protective restriction on third-party data sharing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn)."
Privacy Policy › “Work Phone Number”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States the purposes for which collected personal information is used (service delivery), explicitly prohibits selling personal information to anyone, restricts sharing to third parties that facilitate service delivery only, and discloses that additional data may be received from third parties such as professional networking sites — user-favorable restriction on sale and broad third-party sharing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We do not knowingly attempt to solicit or receive information from children."
Privacy Policy › “Children's Data”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts the company from knowingly soliciting or receiving information from children, establishing a prohibition on collecting children's personal data.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Cardinal Gray Incorporated is a Delaware C Corporation. We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes Cardinal Gray's policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies."
Privacy Policy › “Introduction”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Introduces Cardinal Gray's commitment to describing its personal data collection and use policies, acknowledges an ongoing responsibility to update the Privacy Notice as practices change, and frames the document's scope for the reader.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Cardinal Gray collects personal information about its website visitors and customers. This information is generally limited to:"
Privacy Policy › “How We Collect and Use Your Personal Information”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Introduces the categories of personal information collected by Cardinal Gray about website visitors and customers, establishing the scope of the collection described in subsequent segments.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" As is true of most other websites, Cardinal Gray's website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system, and other usage information about the use of Cardinal Gray's website, including a history of the pages you view. We use this information to help us design our site to better suit our users' needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences. Cardinal Gray has a legitimate interest in understanding how members, customers and potential customers use its website. This assists Cardinal Gray with providing more relevant products and services, with communicating value to our sponsors and corporate members, and with providing appropriate staffing to meet member and customer needs."
Privacy Policy › “Use of the Cardinal Gray Website”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Discloses that the website automatically collects technical and usage data (IP addresses, location, browser type, operating system, page history) and states the purposes for which that data is used, namely site design improvement and server diagnostics — establishes collection scope and purpose limitation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:"
Privacy Policy › “Questions, Concerns, or Complaints”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Establishes the procedure for users to contact the company to exercise rights or raise concerns, directing them to the contact details that follow.

AI-generated interpretation, not legal advice.

Data retention
High
" Your personal data is stored by Cardinal Gray on its servers and on the servers of the cloud-based database management services that Cardinal Gray engages, located in the United States. Cardinal Gray retains service data for the duration of the customer's business relationship with Cardinal Gray and for a period of time thereafter, to analyze the data for Cardinal Gray's own operations, and for historical and archiving purposes associated with Cardinal Gray's services. Cardinal Gray retains prospect data until such time as it no longer has business value and is purged from Cardinal Gray systems. All personal data that Cardinal Gray controls may be deleted upon verified request from Data Subjects or their authorized agents. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at jack@cardinalgray.com ."
Privacy Policy › “Data Storage and Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Specifies where personal data is stored (Cardinal Gray servers and third-party cloud database services in the United States), states that service data is retained for the duration of the customer relationship plus a subsequent period for operational analysis and archival purposes, and states that prospect data is retained until it no longer has business value and is purged — defining retention periods and purposes for different data categories.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Cardinal Gray is headquartered in New York, New York in the United States. Cardinal Gray has appointed an internal data protection officer for you to contact if you have any questions or concerns about Cardinal Gray's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cardinal Gray's data protection officer:"
Privacy Policy › “Data Protection Officer”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that Cardinal Gray has appointed an internal data protection officer and directs individuals who wish to exercise privacy rights or raise concerns about personal data policies to contact that officer, establishing a procedural mechanism for rights exercise.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of "adequacy" from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Cardinal Gray is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved. Depending on the circumstance, Cardinal Gray also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Cardinal Gray in a manner that does not outweigh your rights and freedoms. Cardinal Gray endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Cardinal Gray and the practices described in this Privacy Statement. Cardinal Gray also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Cardinal Gray has received zero government requests for information. For more information or if you have any questions, please contact us at jack@cardinalgray.com ."
Privacy Policy › “Transferring Personal Data to the U.S.”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Discloses that data is processed in the United States, acknowledges the absence of an adequacy finding, and states that Cardinal Gray provides appropriate safeguards through binding standard data protection clauses enforceable by data subjects — establishes the cross-border transfer mechanism and residency/DPA compliance procedure.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" The European Union's General Data Protection Regulation (GDPR) and other countries' privacy laws provide certain rights for data subjects. Data Subject rights under GDPR include the following:"
Privacy Policy › “Data Subject Rights”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the source of data subject rights (general data protection regulation and other countries' privacy laws) and introduces the list of rights that follow, framing the legal basis for subsequent right-granting segments.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" This Privacy Notice is intended to provide you with information about what personal data Cardinal Gray collects about you and how it is used. If you wish to confirm that Cardinal Gray is processing your personal data, or to have access to the personal data Cardinal Gray may have about you, please contact us. You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Cardinal Gray might have received the data from Cardinal Gray; what the source of the information was (if you didn't provide it directly to Cardinal Gray); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Cardinal Gray if it is inaccurate. You may request that Cardinal Gray erase that data or cease processing it, subject to certain exceptions. You may also request that Cardinal Gray cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Cardinal Gray processes your personal data. When technically feasible, Cardinal Gray will—at your request—provide your personal data to you. Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Cardinal Gray will provide you with a date when the information will be provided. "
Privacy Policy › “Rights related to automated decision making including profiling”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes the procedure by which individuals may confirm processing, access their personal data, and request information about processing purposes, data categories, recipients, and data sources — establishing a practical mechanism for exercising data subject rights.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
"If for some reason access is denied, Cardinal Gray will provide an explanation as to why access has been denied. For questions or complaints concerning the processing of your personal data, you can email us at jack@cardinalgray.com . Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority."
Privacy Policy › “Rights related to automated decision making including profiling”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that Cardinal Gray will provide an explanation when access is denied, directs individuals with questions or complaints to a contact email, and informs those in the European Union of recourse to the European Data Protection Supervisor or a national data protection authority — establishes complaint and redress procedures.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Cardinal Gray's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Cardinal Gray's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Cardinal Gray's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Cardinal Gray requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Cardinal Gray's published policies yet.

What the policies actually cover

0 topics

None of Cardinal Gray's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

13
clauses
3
patterns
3
stances
privacy sharing · 3
privacy sharingHIGHPrivacy Policy › “Work Phone Number”

The clause permits sale of personal data or information.

We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industr...
Open source citation
privacy sharingMEDIUMPrivacy Policy › “Work Phone Number”

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industr...
Open source citation
privacy sharingMEDIUMPrivacy Policy › “Sharing Information with Third Parties”

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events....
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH2
All applicable tierssubprocessors data sharingconditionalMEDIUM1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 19, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn).
Open timeline citation
Jul 19, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on privacy data use

We use this information to provide prospects and customers with services. We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services. From time to time, Cardinal Gray receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third party website (e.g. LinkedIn).
Open timeline citation
Jul 19, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events. We do not otherwise reveal your personal data to non-Cardinal Gray persons or businesses for their independent use unless: (1) you request or authorize it; (2) it's in connection with Cardinal Gray-hosted and Cardinal Gray co-sponsored conferences; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

13 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Cardinal Gray's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Cardinal Gray's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Cardinal Gray's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.