audit rights dpa residency · Privacy Policy
Cardinal Gray policy finding
“ Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of "adequacy" from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Cardinal Gray is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved. Depending on the circumstance, Cardinal Gray also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Cardinal Gray in a manner that does not outweigh your rights and freedoms. Cardinal Gray endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Cardinal Gray and the practices described in this Privacy Statement. Cardinal Gray also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Cardinal Gray has received zero government requests for information. For more information or if you have any questions, please contact us at jack@cardinalgray.com .”
- Document
- Privacy Policy
- Captured
- 2026-07-19
- Location
- Privacy Policy › “Transferring Personal Data to the U.S.”
- Snapshot SHA-256
- 5bf5b913528da36384f5bd5f6eef085a793a5245399154f7992392a5c4b9b119
Informational only, not legal advice. Terms change; verify the source and capture date.