Legal
Privacy Policy
Effective: May 27, 2025 · Veridian Risk & Resilience Group, LLC
1. Who We Are
Veridian Risk & Resilience Group, LLC (“Veridian,” “we,” “our”) is an operational risk and resilience consulting firm based in Central Florida. We operate the website at veridianriskgroup.org and the Veridian Risk Platform (the “Platform”). You may contact us at director@veridianriskgroup.org or by phone at (407) 470-5992.
2. Information We Collect
We collect information you provide directly when you:
- ·Submit a consultation request (name, company, phone, email, industry, and notes you choose to include)
- ·Log in to the client platform (email address and password)
- ·Contact us by phone or email
We may also collect standard server log data automatically, including IP addresses, browser type, referring URLs, and page views. This data is used to maintain security, monitor system performance, and detect abuse. We do not sell this data.
3. How We Use Your Information
We use the information we collect to:
- ·Respond to consultation requests and schedule discovery calls
- ·Deliver contracted consulting services to your organization
- ·Maintain your client account and provide access to the Platform
- ·Send service-related communications (reports, follow-ups, compliance reminders)
- ·Maintain an audit trail for security and compliance purposes
- ·Improve the website and Platform experience
We do not use your contact information for unsolicited marketing. We will not add you to mass email lists without your explicit consent.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We may share information only in these limited circumstances:
- ·Service providers: We use Supabase (database), Resend (email delivery), and Vercel (hosting). These providers process data only as needed to deliver their services and are contractually bound to protect it.
- ·Legal compliance: If required by law, court order, or to protect the rights and safety of our clients or the public.
- ·Business transition: If Veridian is acquired or merged, your information may transfer to the successor entity under the same privacy commitments.
5. Data Retention
Consultation request data is retained for 3 years to support follow-up and engagement history. Client account and engagement data is retained for the duration of the service relationship plus 5 years for compliance documentation purposes. Audit logs are retained indefinitely as an immutable record. You may request deletion of your personal data at any time by contacting us — subject to our legal and compliance obligations.
6. Security
We implement industry-standard security measures including encrypted data transmission (TLS), server-side access controls, Row Level Security on our database, and audit logging of all data operations. Client platform access requires authenticated login. No security system is perfectly impenetrable — if you believe your data has been compromised, please contact us immediately.
7. Cookies & Tracking
Our public website does not currently use advertising cookies or third-party tracking pixels. The client platform uses session cookies necessary for authentication. We may add analytics tools (such as Google Analytics) in the future, at which point this policy will be updated and a cookie notice displayed.
8. Your Rights
Regardless of your location, you may request to:
- ·Access the personal data we hold about you
- ·Correct inaccurate personal data
- ·Delete your personal data (subject to legal retention obligations)
- ·Receive a portable copy of your data
- ·Opt out of any marketing communications
To exercise these rights, email director@veridianriskgroup.org with “Privacy Request” in the subject line. We will respond within 30 days.
9. Children
Our website and services are directed to business professionals. We do not knowingly collect personal information from individuals under 18 years of age. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this policy periodically. When we do, we will revise the effective date at the top of this page. Material changes that affect how we use your data will be communicated directly to affected clients via email. Your continued use of our website or services after changes are posted constitutes acceptance of the updated policy.
11. Contact
For any questions about this Privacy Policy or how we handle your data: