Privacy Policy

Last updated: May 12, 2026

This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service, and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.


A note on what this Policy covers — and what it does not

This Privacy Policy describes how Promontory CX, LLC handles Personal Data about You when You are a website visitor, prospect, client representative, or platform user.

When We are engaged by a client to deliver consulting services or operate the Discern platform on the client's behalf, we may process information about the client's customers, survey respondents, or research participants. In those circumstances We act as a processor on the client's behalf, and the handling of that data is governed by the contractual relationship between Us and the client — including a separate Data Processing Agreement — not by this Privacy Policy. If You believe a Promontory CX client holds information about You and You have a question about that data, please contact the client directly.


Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for You to access our Service or parts of our Service.

Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.

Company (referred to as either "the Company," "We," "Us," or "Our" in this Privacy Policy) refers to Promontory CX, LLC, 418 Broadway STE N, Albany, NY 12207, USA.

Cookies are small files that are placed on Your computer, mobile device, or any other device by a website, containing details of Your browsing history on that website among its many uses.

Country refers to: New York, United States.

Device means any device that can access the Service, such as a computer, mobile phone, or digital tablet.

Discern means the AI-powered Customer Experience assessment platform operated by Promontory CX.

Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.

Service refers, collectively, to the Website and the Discern platform.

Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used. A list of Service Providers (also referred to as "subprocessors") that handle client data in connection with the Discern platform is maintained separately as the Discern Subprocessor List and is available on request.

Subprocessor means a Service Provider engaged by the Company to process Personal Data in connection with the Discern platform on behalf of a client.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Website refers to Promontory CX, accessible from https://promontorycx.com.

You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.


Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number (where You choose to provide it)
  • Company affiliation, job title, and role (where You choose to provide it)
  • Other information You voluntarily submit through contact forms, account registration, or direct communications with Us

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers, and other diagnostic data.

We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.

Information We Process on Behalf of Clients (Processor Role)

Separately from the Personal Data described above, when the Company is engaged by a client to deliver consulting services or operate the Discern platform on the client's behalf, the Company may process Personal Data about the client's customers, survey respondents, or research participants. The Company processes this data as a processor on the client's behalf, on the client's documented instructions, for the purpose of delivering the engaged services.

The handling of this client-controlled data is governed by the contractual relationship between the Company and the client (including the Data Processing Agreement and Discern Security Brief), not by this Privacy Policy.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:

  • Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
  • Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).

Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.

Where required by law, we use non-essential cookies (such as analytics, advertising, and remarketing cookies) only with Your consent. You can withdraw or change Your consent at any time using Our cookie preferences tool (if available) or through Your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

We use both Session and Persistent Cookies for the purposes set out below:

Necessary / Essential Cookies

  • Type: Session Cookies
  • Administered by: Us
  • Purpose: These Cookies are essential to provide You with services available through the Service and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.

Cookies Policy / Notice Acceptance Cookies

  • Type: Persistent Cookies
  • Administered by: Us
  • Purpose: These Cookies identify if users have accepted the use of cookies on the Website.

Functionality Cookies

  • Type: Persistent Cookies
  • Administered by: Us
  • Purpose: These Cookies allow Us to remember choices You make when You use the Service, such as remembering Your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter Your preferences every time You use the Service.

The Discern platform itself does not use third-party analytics, advertising trackers, or behavioral profiling cookies. Authentication uses standard session cookies necessary for the platform to function.

For more information about the cookies we use and Your choices regarding cookies, please contact Us.


Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service.
  • To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
  • For the performance of a contract: the development, compliance, and undertaking of any contract You have entered into with Us, including the delivery of services and the provision of platform access.
  • To contact You: to contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities, products, or contracted services, including security updates, when necessary or reasonable for their implementation.
  • To respond to Your inquiries and requests: to attend and manage Your requests to Us.
  • For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
  • For limited marketing communications: We may, where We have a lawful basis to do so, send You information about Our services that may be of interest to You. You may opt out of marketing communications at any time by following the unsubscribe link in any such message or by contacting Us. We do not sell Your Personal Data and We do not share Your Personal Data with third parties for those third parties' own marketing purposes.
  • For business operations and improvement: identifying usage trends, evaluating and improving Our Service and the user experience, and conducting general business administration.

We may share Your Personal Data in the following situations:

  • With Service Providers: We may share Your Personal Data with Service Providers (including Subprocessors of the Discern platform) to perform services on Our behalf. Service Providers are contractually obligated to protect the confidentiality of the Personal Data We share with them and to use it only as We direct.
  • For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
  • With Affiliates: We may share Your Personal Data with Our affiliates, in which case We will require those affiliates to honor this Privacy Policy. Affiliates include any parent company, subsidiaries, joint venture partners, or other companies that We control or that are under common control with Us. As of the effective date of this Policy, the Company does not have such affiliates.
  • For legal requirements: As described under "Disclosure of Your Personal Data" below.
  • With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Where possible, We apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods ("up to") and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose.

Account Information

  • User accounts: retained for the duration of Your account relationship plus up to 24 months after account closure to handle any post-termination issues or resolve disputes.

Customer Support Data

  • Support tickets and correspondence: up to 24 months from the date of ticket closure to resolve follow-up inquiries, track service quality, and defend against potential legal claims.
  • Chat transcripts: up to 24 months for quality assurance and staff training purposes.

Usage Data

  • Website analytics data (cookies, IP addresses, device identifiers): up to 24 months from the date of collection, which allows Us to analyze trends while respecting privacy principles.
  • Server logs (IP addresses, access times): up to 24 months for security monitoring and troubleshooting purposes.

Usage Data is retained in accordance with the retention periods described above, and may be retained longer only where necessary for security, fraud prevention, or legal compliance.

Data processed in Our capacity as a processor on behalf of clients is retained for the period specified in the applicable client engagement and Data Processing Agreement, not under the periods set out in this Section.

We may retain Personal Data beyond the periods stated above for the following reasons:

  • Legal obligation: We are required by law to retain specific data (e.g., financial records for tax authorities).
  • Legal claims: Data is necessary to establish, exercise, or defend legal claims.
  • Your explicit request: You ask Us to retain specific information.
  • Technical limitations: Data exists in backup systems that are scheduled for routine deletion.

You may request information about how long We will retain Your Personal Data by contacting Us.

When retention periods expire, We securely delete or anonymize Personal Data according to the following procedures:

  • Deletion: Personal Data is removed from Our systems and no longer actively processed.
  • Backup retention: Residual copies may remain in encrypted backups for a limited period consistent with our backup retention schedule and are not restored except where necessary for security, disaster recovery, or legal compliance.
  • Anonymization: In some cases, We convert Personal Data into anonymous statistical data that cannot be linked back to You. This anonymized data may be retained indefinitely for research and analytics.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of Your jurisdiction.

Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards and supplementary measures where appropriate, including the use of European Commission Standard Contractual Clauses where applicable. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy, and no transfer of Your Personal Data will take place to an organization or country unless there are adequate controls in place, including the security of Your data and other Personal Data.


Delete Your Personal Data

You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.

Our Service may give You the ability to delete certain information about You from within the Service.

You may update, amend, or delete Your information at any time by signing in to Your Account, if You have one, and visiting the account settings section that allows You to manage Your Personal Data. You may also contact Us to request access to, correct, or delete any Personal Data that You have provided to Us.

Please note, however, that We may need to retain certain information when We have a legal obligation or lawful basis to do so.


Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

Other Legal Requirements

The Company may disclose Your Personal Data in the good-faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of Your Personal Data is important to Us. We implement reasonable technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, and destruction, including:

  • Encryption of data at rest and in transit
  • Authentication and access control on platform systems
  • Confidentiality obligations on personnel and Service Providers
  • Documented incident response procedures

For Personal Data processed in connection with the Discern platform, additional security detail is described in the Discern Security Brief, which is available on request.

No method of transmission over the Internet or method of electronic storage is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee absolute security.


Your Privacy Rights

Depending on Your jurisdiction, You may have specific rights with respect to Your Personal Data. To exercise any of the rights described below, contact Us using the information in the "Contact Us" section. We will respond within the time periods required by applicable law. We may need to verify Your identity before fulfilling certain requests.

California Residents (CCPA / CPRA)

If You are a California resident, You have specific rights under the California Consumer Privacy Act and California Privacy Rights Act (collectively, "CCPA/CPRA"), including:

  • Right to know what Personal Data We have collected about You and how We have used and disclosed it
  • Right to access a portable copy of Your Personal Data
  • Right to delete Personal Data, subject to legal exceptions
  • Right to correct inaccurate Personal Data We hold about You
  • Right to opt out of "sale" or "sharing" of Personal Data
  • Right to limit the use or disclosure of sensitive Personal Data, where We use such data for purposes that require an opt-out
  • Right to non-discrimination for exercising Your privacy rights

We do not "sell" or "share" Personal Data as those terms are defined under CCPA/CPRA. We do not use sensitive Personal Data for purposes that require an opt-out.

You may submit CCPA/CPRA requests to Us at the email address in the "Contact Us" section. You may also designate an authorized agent to make a request on Your behalf, subject to verification.

Other US State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other US states that have enacted comprehensive privacy laws may have rights similar to those described above for California residents, including the rights of access, correction, deletion, and the right to opt out of certain processing activities. Specific rights vary by state. To exercise these rights, contact Us using the information in the "Contact Us" section.

EU, UK, and Swiss Residents (GDPR / UK GDPR)

If You are located in the European Economic Area, the United Kingdom, or Switzerland, You have rights under the GDPR, UK GDPR, or Swiss data protection law, as applicable, including:

  • Right of access to Your Personal Data
  • Right to rectification of inaccurate Personal Data
  • Right to erasure ("right to be forgotten"), subject to legal exceptions
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on Our legitimate interests or for direct marketing
  • Right to withdraw consent at any time, where processing is based on consent
  • Right to lodge a complaint with Your local data protection supervisory authority

The legal bases on which We process Your Personal Data are typically:

  • Performance of a contract (when You engage Us or We are providing services)
  • Legitimate interests (for general business operations, including business development and improvement of our services)
  • Consent (where required by law and where We have requested consent)
  • Legal obligation (to comply with applicable law)

Children's Privacy

Our Service does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.

If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.


Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.


Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.

We will let You know via email and/or a prominent notice on Our Service prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.


Contact Us

If You have any questions about this Privacy Policy, or wish to exercise any of the rights described in this Policy, You can contact Us:


© 2026 Promontory CX

Consultant-grade CX assessments, in days.