Skip to main content
Platform Review
PricingSign in
Cardinal Gray assessment

Cardinal Gray procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Cardinal Gray
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown Cardinal Gray is headquartered in New York, New York in the United States. Cardinal Gray has appointed an internal data protection officer for you to contact if you have any questions or concerns about Cardinal Gray's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cardinal Gray's data protection officer:Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown The European Union's General Data Protection Regulation (GDPR) and other countries' privacy laws provide certain rights for data subjects. Data Subject rights under GDPR include the following:Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown This Privacy Notice is intended to provide you with information about what personal data Cardinal Gray collects about you and how it is used. If you wish to confirm that Cardinal Gray is processing your personal data, or to have access to the personal data Cardinal Gray may have about you, please contact us. You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Cardinal Gray might have received the data from Cardinal Gray; what the source of the information was (if you didn't provide it directly to Cardinal Gray); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Cardinal Gray if it is inaccurate. You may request that Cardinal Gray erase that data or cease processing it, subject to certain exceptions. You may also request that Cardinal Gray cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Cardinal Gray processes your personal data. When technically feasible, Cardinal Gray will—at your request—provide your personal data to you. Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Cardinal Gray will provide you with a date when the information will be provided. Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Cardinal Gray has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Cardinal Gray's services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of "adequacy" from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Cardinal Gray is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved. Depending on the circumstance, Cardinal Gray also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Cardinal Gray in a manner that does not outweigh your rights and freedoms. Cardinal Gray endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Cardinal Gray and the practices described in this Privacy Statement. Cardinal Gray also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Cardinal Gray has received zero government requests for information. For more information or if you have any questions, please contact us at jack@cardinalgray.com .Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknownIf for some reason access is denied, Cardinal Gray will provide an explanation as to why access has been denied. For questions or complaints concerning the processing of your personal data, you can email us at jack@cardinalgray.com . Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown Your personal data is stored by Cardinal Gray on its servers and on the servers of the cloud-based database management services that Cardinal Gray engages, located in the United States. Cardinal Gray retains service data for the duration of the customer's business relationship with Cardinal Gray and for a period of time thereafter, to analyze the data for Cardinal Gray's own operations, and for historical and archiving purposes associated with Cardinal Gray's services. Cardinal Gray retains prospect data until such time as it no longer has business value and is purged from Cardinal Gray systems. All personal data that Cardinal Gray controls may be deleted upon verified request from Data Subjects or their authorized agents. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at jack@cardinalgray.com .Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium The personal information Cardinal Gray collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Cardinal Gray engages third parties to send information to you, including information about our products, services, and events. We do not otherwise reveal your personal data to non-Cardinal Gray persons or businesses for their independent use unless: (1) you request or authorize it; (2) it's in connection with Cardinal Gray-hosted and Cardinal Gray co-sponsored conferences; (3) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (5) to address emergencies or acts of God; or (6) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.Captured 2026-07-19Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.