Privacy Policy
Last updated: [DATE] — Effective: [DATE]
Template notice: this page is a starting structure, not finished legal text. Have it reviewed and completed by qualified legal counsel before publishing — especially the sections on data collected via the contact form, the GRC Health Check tools, and any analytics or cookies you add. Replace every bracketed placeholder before launch.
1. Who We Are
The Kimberg Institute of Governance, Risk and Compliance ("the Institute," "we," "us") operates this website at [DOMAIN]. This policy explains what information we collect, why, and how it's handled.
2. Information We Collect
- Contact form submissions — name, work email, organization, and any message content you provide.
- Discovery call bookings — information you provide through our scheduling tool (Calendly), governed additionally by Calendly's privacy policy.
- 25-Point SME GRC Health Check responses — your self-reported answers and resulting score. [Clarify here whether responses are stored, and if so, where and for how long.]
- Site analytics — [name your analytics tool once added, e.g., Plausible or Google Analytics] collects aggregate usage data such as pages visited and general location.
3. How We Use Information
- To respond to inquiries and schedule discovery calls.
- To prepare proposals and deliver contracted GRC Health Check and advisory engagements.
- To send the Weekly GRC Intelligence Brief, only to those who opt in.
- To improve this website and our services.
We do not sell personal information. We do not share it with third parties except service providers who help us operate (e.g., Calendly, email/newsletter tools, form-handling services) and as required by law.
4. Client Engagement Data
Information shared during a paid engagement (Health Check responses, documents, interview notes) is governed by the confidentiality terms of the signed Proposal & Statement of Work, not this website policy. [Cross-reference your engagement contract's confidentiality clause here.]
5. Cookies
[Describe any cookies used by your analytics tool, the Calendly widget, or session/functional cookies. Provide an opt-out mechanism if required in your jurisdiction, e.g., under GDPR or PIPEDA.]
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or request deletion of your personal information. Contact us at [PRIVACY CONTACT EMAIL] to make a request.
7. Data Retention
[State how long contact form and discovery call data is retained, and your retention policy for client engagement files — the Client Delivery SOP specifies a 7-year retention for engagement files; confirm whether that applies here too.]
8. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
9. Contact
Questions about this policy: [PRIVACY CONTACT EMAIL].