Privacy
Privacy Policy
Effective Date: June 1, 2025 | Last Updated: August 4, 2026
Introduction
ControlSage, Inc. ("ControlSage," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with our compliance and security services for startups and growing companies, including SOC 2, PCI DSS, CMMC, HIPAA, ISO 27001, ISO 42001, and SOX compliance management, audit readiness, risk assessments, and related governance services.
Information We Collect
Personal Information from Clients and Prospects: Name, email address, phone number, job title, company name, professional role and responsibilities, compliance requirements, and communication records including email correspondence, meeting notes, and support requests submitted through our site or contact forms.
Personal Information from Client Personnel: When providing services to our clients, we may process personal information about their employees and users, including identity information (names, email addresses, employee IDs), access information (system access logs, authentication records, privilege assignments), security awareness training completion records, and security incident reports involving personnel.
Technical Information: Website usage data (IP addresses, browser information, pages visited, timestamps), information processed through our compliance management tools and dashboards, and security data such as vulnerability scan results, penetration test findings, and control assessment results.
How We Use Personal Information
Service Delivery: Providing security and compliance consulting services; managing SOC 2, PCI DSS, CMMC, HIPAA, ISO 27001, ISO 42001, and SOX compliance programs; conducting risk assessments, gap analyses, and security reviews; managing third-party audits and certifications; and delivering security awareness training.
Business Operations: Communicating with clients and prospects about our services, processing payments and managing accounts, improving our services and developing new offerings, and maintaining and securing our systems and infrastructure.
Legal and Compliance: Complying with applicable laws and regulations, responding to legal requests and government inquiries, protecting our rights and interests, and investigating security incidents and potential violations.
Information Sharing and Disclosure
Service Providers: We may share personal information with trusted service providers who assist us in delivering our services, including cloud infrastructure providers, compliance management software platforms, payment processors, and other professional service providers. All service providers are contractually required to protect personal information and use it only for the specified purposes.
Client Authorization: When providing services to clients, we may share personal information as directed by our clients and as necessary to deliver contracted services, including coordinating with third-party auditors and assessors (such as C3PAOs, QSAs, and certification bodies) for certification processes, sharing compliance documentation with client stakeholders, and providing security assessment results to authorized personnel.
Legal Requirements: We may disclose personal information when required by law, regulation, or legal process, or when we believe disclosure is necessary to comply with legal obligations, protect the rights, property, or safety of ControlSage, our clients, or others, investigate fraud or security incidents, or respond to government requests.
Business Transfers: In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of the transaction, subject to appropriate confidentiality protections.
Individual Rights and Choices
Access and Correction: Individuals have the right to access their personal information that we process, request correction of inaccurate or incomplete information, and obtain a copy of their personal information in a structured format.
Limitation of Use: Individuals may request that we limit the use of their personal information for specific purposes, subject to legal and contractual obligations.
Deletion: Individuals may request deletion of their personal information, subject to legal retention requirements, ongoing contractual obligations, and legitimate business interests.
Objection and Withdrawal: Individuals may object to certain uses of their personal information and withdraw consent where processing is based on consent.
To exercise these rights, please contact us using the information provided in the "Contact Information" section below.
Data Security
Technical Safeguards: Encryption of data in transit and at rest, multi-factor authentication for system access, regular security assessments and penetration testing, and intrusion detection and monitoring systems.
Administrative Safeguards: Security awareness training for all personnel, background checks for employees with access to personal information, documented incident response procedures, and regular review and update of security policies.
Physical Safeguards: Secure data centers with restricted access, environmental controls and monitoring, and secure disposal of physical media.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations and regulatory requirements, resolve disputes and enforce agreements, and maintain business records and continuity. Specific retention periods vary based on the type of information and applicable legal requirements. Upon expiration of retention periods, we securely delete or anonymize personal information.
International Data Transfers
As a U.S.-based company providing services globally, we may transfer personal information internationally. We ensure adequate protection for such transfers through standard contractual clauses, adequacy decisions by relevant authorities, and other appropriate safeguards as required by law.
Third-Party Links and Services
Our website and services may contain links to third-party websites and integrate with third-party services. This Privacy Policy does not apply to such third parties. We encourage individuals to review the privacy policies of any third-party services they use.
Children's Privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.
Dispute Resolution
ControlSage aims to resolve privacy complaints directly and promptly. If you do not receive a timely response to a privacy concern, or if your complaint is not satisfactorily addressed, you may escalate the matter as described in this section, including through applicable regulatory bodies. Where legally required, unresolved complaints may be referred to an independent dispute resolution provider or resolved through binding arbitration. ControlSage is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable laws. We will post the updated policy on our website and indicate the effective date of changes. For material changes, we may provide additional notice as appropriate.
Contact Information
For questions about this Privacy Policy, to exercise your rights, or to submit a privacy complaint, please contact us:
ControlSage, Inc.
Privacy Officer
Email: privacy@controlsage.com