Legal

Privacy & Terms

How BdG Advisory handles personal information on this website and in Staff, and the terms for using Staff. Effective 7 October 2026.

The short version

Staff in plain words

  • Staff works for you, on your instructions. Staff is a team of AI agents. You decide what it may access and what it may do, and you review what it produces before relying on it or sending it.
  • We collect what Staff needs to work. That is your account details, what you ask Staff to do, what Staff remembers to help you, and data from the accounts you choose to connect.
  • AI providers process your content. To answer you, Staff sends your content to AI model providers. We use only their paid or API services, whose terms say that content is not used to train their models, or models we run ourselves. We do not sell your personal information, and we do not use your content to train our own models.
  • Connected accounts stay in your control. Staff reads your email, calendar, files or messages only after you authorize it, and only to carry out a task you asked for. You can disconnect at any time.
  • Your data, your choices. You can ask to access, correct, export or delete your data. When you close your account, we delete it, apart from the little we must keep by law.
  • AI can be wrong. Staff's output is not legal, financial, medical or other professional advice. Staff is for adults aged 18 and over.
  • Where you live matters. US law (Colorado) governs these terms, with added sections for the Netherlands and the EU and for Australia. Mandatory consumer and privacy rights where you live still apply.

This summary is for convenience. The Privacy Policy and Terms of Use below are what apply.

Part one

Terms of Use

Effective

These terms are an agreement between you and BdG Advisory, Inc., a Colorado corporation ("BdG Advisory", "we", "our" or "us"). They cover your use of Staff and of our website. Please read them; they include limits on our liability and say which law applies.

Accepting these terms

By creating a Staff account or using Staff, you agree to these terms and confirm you have read the Privacy Policy. If you do not agree, do not use Staff. If you use Staff for an organization, you confirm you are authorized to accept these terms for it, and "you" includes that organization.

Who can use Staff

You must be at least 18 years old and able to form a binding contract. You may not use Staff if you are barred from doing so under the laws that apply to you, including sanctions and export-control laws, or if we have previously closed your account for breaking these terms.

Your account

  • Give us accurate information and keep it up to date.
  • Keep your sign-in details secure and do not share your account. You are responsible for activity on your account.
  • Tell us straight away at info@bdgadvisory.com if you suspect unauthorized access.
  • One person per account, unless your plan says otherwise.

The service

Staff is a team of AI agents that act on your instructions. Depending on what you ask and what you connect, Staff can answer questions, research, draft and organize messages and documents, manage your calendar, prepare posts and carry out other tasks on your behalf.

You stay in charge. Staff acts within the permissions you give it. Where an action affects other people or cannot easily be undone, such as sending a message, accepting an invitation or publishing a post, Staff is designed to ask for your approval first. Some features are early versions; we will label them where we can.

Your content

"Your content" means what you give Staff (instructions, messages, files, and data from connected accounts) and what Staff produces for you (output).

You own your content. As between you and us, you keep all rights in your content, and to the extent we have any rights in the output, we assign them to you. Output may not be unique: Staff may produce similar output for other people.

The license you give us. You grant us a worldwide, non-exclusive, royalty-free license to host, copy, process, transmit and display your content only as needed to operate, secure and support Staff for you, and as described in the Privacy Policy. This includes sending it to the providers that power Staff. The license ends when your content is deleted, except for backup copies until they expire and anything we must keep by law.

Your responsibility. You confirm you have the rights and permissions needed for the content you give Staff, including other people's personal information in your email, calendar and files, and that our use of it under these terms will not break the law or anyone's rights.

Connected accounts

You can connect accounts from other providers, such as email, calendar, files and messaging, so Staff can work in them. By connecting an account, you authorize Staff to access it and act in it within the permissions you grant, to carry out your instructions.

  • Only connect accounts you are entitled to use and authorize. If an account belongs to your employer or another organization, make sure their policies allow you to connect it.
  • You are responsible for the permissions you grant and for reviewing them. You can disconnect an account at any time in Staff or in the provider's own settings.
  • Your use of a connected account remains subject to that provider's terms.

Acceptable use

Do not use Staff, or help anyone else use it, to:

  • break the law or infringe anyone's rights, including privacy and intellectual property rights;
  • send spam, phish, impersonate others, or mislead people about who or what they are dealing with;
  • harass, threaten, defraud or discriminate against anyone, or create content that exploits or harms children;
  • access accounts, data or systems you are not authorized to access;
  • develop weapons, malware or other means of serious harm, or attack, overload or disrupt Staff or any other service;
  • make decisions with legal or similarly significant effects on people, such as about employment, credit, housing or insurance, without appropriate human review;
  • reverse engineer Staff, get around its limits or safeguards, or extract its models, prompts or data, except where the law allows despite this restriction;
  • build a competing product using Staff's output, or resell Staff without our written agreement; or
  • break the usage policies of the model providers that power Staff.

We may investigate suspected misuse and take action, including removing content, limiting features or suspending accounts.

AI output and your review

AI is powerful but imperfect. Please keep these points in mind:

  • Output may be inaccurate. It can be incomplete, out of date, or wrong while sounding confident. It may not reflect your intentions or the facts.
  • It is not professional advice. Staff does not give legal, financial, tax, investment, medical or other professional advice. Consult a qualified professional before acting on matters like these.
  • Review before you rely on it or send it. You are responsible for checking output before using it, relying on it or sharing it with others.
  • Actions you approve are your actions. When Staff acts on your instruction or with your approval, such as sending an email, accepting a meeting or publishing a post, that action is taken on your behalf and you are responsible for it as if you had taken it yourself.

Third-party services

Staff works with services we do not control, including the AI model providers, messaging apps and productivity tools listed in the Privacy Policy. We are not responsible for those services, their availability or their changes. If a provider changes or withdraws its service, a Staff feature that depends on it may change or stop working.

Plans and fees

Staff may be offered on free and paid plans. The features, limits and price of each plan are shown before you choose it.

  • Billing and renewal. Paid plans are billed in advance and renew automatically for the same period until you cancel. We will remind you before an annual renewal. Prices exclude taxes unless shown otherwise.
  • Cancellation. You can cancel at any time by the method shown in your account or by emailing us. Cancellation takes effect at the end of the current billing period, and you keep access until then.
  • Refunds. Fees are non-refundable except where these terms or the law say otherwise. If you are a consumer in the EU, you may have a 14-day right to withdraw from a new paid plan; if you ask us to start the service within that period, you may have to pay for the part already provided.
  • Changes in price. We will give you at least 30 days' notice of a price increase. It applies from your next renewal, and you can cancel before then.
  • Failed payments. If a payment fails, we may move you to a free plan or suspend paid features until it is resolved.
  • Free plans and trials may have limits and may change or end. When a trial ends, it converts to a paid plan only if you chose that when you signed up.

Availability and changes

We work to keep Staff available and reliable, but we do not promise it will be uninterrupted or error-free. We may need maintenance windows, and we may change, add or remove features. If we make a change that materially reduces what a paid plan provides, we will tell you in advance, and you may cancel and receive a prorated refund of fees paid for the period after the change. If we discontinue Staff, we will give you reasonable notice and a chance to export your content.

Intellectual property

Staff, our website, and their software, design, text, graphics and trademarks (including "Staff" and "BdG Advisory") belong to BdG Advisory, Inc. or its licensors. We give you a limited, personal, non-exclusive, non-transferable right to use Staff under these terms. Apart from your content, these terms do not transfer any intellectual property to you.

Feedback

If you send us ideas or suggestions, we may use them without restriction or payment to you. You are never obliged to give feedback.

Website content

The articles, research, opinions, commentary, presentations and other materials on our website are provided for general information only. Nothing on the website is legal, financial, investment, tax, accounting, cybersecurity or other professional advice. While every effort is made to ensure accuracy, we make no warranties about its completeness, accuracy or suitability for a particular purpose, and decisions based on it remain the reader's responsibility.

References to vendors, technologies, products, companies or services are not endorsements unless explicitly stated. Views expressed are the author's at the time of publication and may change without notice.

Disclaimers

To the maximum extent the law allows, Staff and the website are provided "as is" and "as available". We disclaim all warranties not expressly stated in these terms, whether express, implied or statutory, including warranties of merchantability, fitness for a particular purpose, title, non-infringement and accuracy. We do not warrant that output will be accurate, complete or suitable for your purposes.

Nothing in these terms excludes rights you have as a consumer that cannot be excluded by law. See "Governing law and disputes".

Limitation of liability

To the maximum extent the law allows:

  • we are not liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for loss of profits, revenue, data, goodwill or business opportunity, even if we were told they were possible; and
  • our total liability for all claims relating to Staff, the website or these terms is limited to the greater of the fees you paid us for Staff in the 12 months before the event giving rise to the claim, or USD 100.

These limits do not apply to liability that cannot be limited by law, such as for death or personal injury caused by negligence, or for fraud or wilful misconduct.

Indemnity

To the extent the law allows, you will defend and indemnify BdG Advisory against third-party claims, and the resulting losses and reasonable costs, arising from your content, your breach of these terms, your misuse of Staff, or actions taken on your instruction or with your approval. This does not apply to the extent a claim is caused by our own breach or negligence. If you use Staff as a consumer in Australia or the EU, this clause applies only as far as your local law permits.

Suspension and termination

You can stop using Staff and close your account at any time.

We may suspend or close your account, or limit features, if you seriously or repeatedly break these terms, if your use creates risk or harm for others or for Staff, if the law requires it, or if a paid plan remains unpaid. Where reasonable, we will tell you in advance and give you a chance to fix the problem. If we close a paid account without cause, we will refund fees paid for the period after closure.

When an account closes, your right to use Staff ends and we delete your data as described in the Privacy Policy. Sections that by their nature should continue, such as those on intellectual property, disclaimers, limitation of liability, indemnity, and governing law, continue to apply.

Governing law and disputes

These terms are governed by the laws of the State of Colorado, United States, without regard to its conflict-of-laws rules, and by applicable US federal law.

If you have a concern, please contact us first so we can try to resolve it informally; most issues can be resolved this way. If a dispute is not resolved within 30 days, either of us may bring proceedings in the state or federal courts located in Colorado, and both of us consent to their jurisdiction.

Consumer rights where you live are not affected:

  • Australia. Nothing in these terms excludes, restricts or modifies any consumer guarantee, right or remedy under the Australian Consumer Law or other law that cannot lawfully be excluded. Where our liability for failing to meet a consumer guarantee can be limited, it is limited, at our option, to supplying the services again or paying the cost of having them supplied again.
  • Netherlands and the EU. If you are a consumer in the EU, you keep the protection of the mandatory consumer laws of your country of residence, and you may bring proceedings in the courts of the country where you live.
  • Elsewhere, any mandatory consumer protection that applies to you continues to apply.

General

These terms and the Privacy Policy are the whole agreement between you and us about Staff. If a provision is found unenforceable, the rest remains in effect. If we do not enforce a provision, that is not a waiver. You may not transfer these terms without our consent; we may transfer them in connection with a merger, acquisition or sale of assets, provided your rights are not reduced. We are not responsible for delays or failures caused by events beyond our reasonable control. We may send notices to the email address on your account.

Changes to these terms

We may update these terms. If a change is material, we will tell you by email or in Staff at least 30 days before it takes effect, unless it is needed sooner for legal or security reasons. If you do not agree to a change, you can close your account before it takes effect; continuing to use Staff after that means you accept it.

Contact

Questions about these terms go to BdG Advisory, Inc. at info@bdgadvisory.com.

Part two

Privacy Policy

Effective

This policy explains what personal information we collect, why, how we use and share it, and the choices you have. It covers visitors to bdgadvisory.com, people who contact us or engage our advisory services, and everyone who uses Staff.

Privacy is treated with the same seriousness as trust. We handle personal information responsibly, transparently and in line with the privacy laws that apply to us.

Who we are

BdG Advisory provides strategic advisory services, executive insights, research and thought leadership on technology, cybersecurity, artificial intelligence, digital transformation and business strategy. We also build and operate Staff, a service of AI agents that work on your instructions.

The website and Staff are operated by BdG Advisory, Inc., a Colorado corporation ("BdG Advisory", "we", "our" or "us"). We are responsible for your personal information as described here: the "controller" under EU law and the "business" under US state privacy laws.

You can reach us about anything in this policy at info@bdgadvisory.com.

What we collect

Account information

When you sign up for Staff: your name, email address, sign-in details, the plan you are on and your preferences. If you pay for a plan, our payment provider handles your card details; we receive only a confirmation, the last digits and the billing country.

Your conversations and instructions

What you ask Staff to do, the messages you exchange with its agents, the files you share with it, and what it produces for you. If you use voice, we process the recording to understand your request.

Connected-account data

If you connect an account such as email, calendar, files or messages, Staff can access the data in it. We access that data only with your authorization and only to perform a task you asked for, such as summarizing your inbox, drafting a reply or finding a time to meet. We do not browse connected accounts for any other purpose.

Agent memory

To be useful over time, Staff remembers things you tell it or that it learns while helping you, such as your preferences, the people you work with and ongoing tasks. Memory is kept for your account only.

Usage and technical data

How you use Staff (features used, errors, timing, performance), and technical details such as IP address, device and browser type, operating system and approximate location derived from your IP address. We use this to run, secure and improve the service.

Information you give us directly

When you contact us, request information or advisory services, subscribe to updates, download publications, register for events or write to us, you may give us your name, company, job title, email address, telephone number, country or region, and anything in your message. Providing this is voluntary.

Website visits

When you browse our website, certain technical information is collected automatically: IP address, browser type, device type, operating system, pages visited, time spent on pages, referring website, date and time of access, and general location based on IP address. It is generally aggregated and not used to identify individual visitors unless needed for security.

We run our own first-party, server-side analytics to understand aggregate website use, such as page views and referring sources. It uses no cookies and no tracking scripts. Visitor identifiers are derived by hashing technical signals (IP address and browser type) with a weekly-rotating salt and are truncated before storage, so we keep only aggregate counts, not your IP address or anything that identifies you. The weekly salt lets us recognize repeat visits within a week for aggregate return-visitor counts; it rotates every week, so visitors cannot be tracked or re-identified across weeks.

Cookies

Our website uses cookies and similar technologies to work properly and keep it secure, to remember preferences, and to understand how visitors use our content. Staff uses essential cookies and local storage to keep you signed in. Cookies used on this website fall into these categories:

Essential

Required for website functionality and security.

Analytics

Helps us understand website usage and improve content.

Preferences

Remembers user settings where applicable.

Embedded Content

Enables third-party services such as LinkedIn or YouTube content, if present.

Our own analytics, described above, does not use cookies. You can control or disable cookies through your browser settings; some features may not work if you do. Where the law requires it, we ask for your consent before placing non-essential cookies. We honor Global Privacy Control signals as a request to opt out of any sale or sharing of personal information, which we do not do in any case.

How Staff uses AI

Staff's agents are powered by AI models. To respond to you, Staff sends the relevant part of your instructions, conversation, memory and connected-account content to a model provider, which generates a response and returns it to us. Some models run on our own infrastructure; others are run by the providers listed in the table below.

  • We do not sell your personal information, and we do not share it for targeted advertising.
  • We do not use your content to train our own models.

Providers' training and retention

Whether a provider may use content to improve its models depends on the provider and on the tier of its service, so we state it per provider:

  • OpenAI and Anthropic: we use their API services. Under OpenAI's business terms and Anthropic's commercial terms, content sent through the API is not used to train their models by default.
  • Google Gemini: the Gemini API terms distinguish Unpaid Services, where Google may use submitted content to improve its products, including with human review, from Paid Services, where it does not. We send Staff content to Gemini only through Paid Services.
  • Self-hosted models (such as Qwen) run on our own infrastructure, so your content is not sent to the model's developer.
  • Providers may retain content for a limited period for purposes such as abuse monitoring or legal compliance. Their terms can change; their policies are linked in the table below.

Human review

We do not read your conversations or connected-account content, except when you ask us to (for example in a support request), when it is needed to investigate abuse or a security issue, or when the law requires it.

Staff does not make decisions about you that have legal or similarly significant effects. Its agents act on your instructions and on your behalf.

How we use information, and why

We use personal information for these purposes. Where a law such as the GDPR requires a legal basis, it is shown in brackets.

  • To provide Staff: creating your account, carrying out your instructions, remembering context, working in the accounts you connect, and supporting you (performance of our contract with you).
  • To keep Staff and the website secure: preventing fraud, abuse and unauthorized access, and enforcing our terms (legitimate interests; legal obligation where applicable).
  • To improve the service: understanding which features work, fixing errors and measuring performance, using usage data and aggregate statistics rather than the content of your conversations (legitimate interests).
  • To respond to enquiries and deliver advisory services (steps at your request before a contract, performance of a contract, or legitimate interests).
  • To communicate with you: service messages, and updates you asked for. You can unsubscribe from updates at any time (contract for service messages; consent for marketing where the law requires it).
  • To bill paid plans (contract; legal obligation for tax and accounting records).
  • To comply with the law and protect our rights and the rights of others (legal obligation; legitimate interests).

Where we rely on consent, you can withdraw it at any time. Withdrawing does not affect processing that already took place.

Who processes your data

We use service providers to host and run Staff and the website. They act on our instructions under contracts that require them to protect your data and use it only to provide their service to us. The integrations marked "When you connect it" are used only if you choose to connect them.

Service providers and integrations that process personal information
Google Cloud (Google)Privacy termsHosting for the website and Staff: servers, storage, databases and backups.All data described in this policy, stored and processed on our behalf.Used today
Firebase Authentication (Google)Privacy termsSigning in and keeping your account secure.Name, email address, sign-in identifiers, device and IP information.Used today
TelegramPrivacy termsA messaging channel for talking to Staff.Messages, attachments and your Telegram profile identifiers.Used today
LinkedInPrivacy termsPublishing posts you approve to your LinkedIn profile or page.Post drafts you approve, profile identifiers and access tokens.When you connect it
OpenAIPrivacy termsAI models that generate responses and carry out tasks.Your instructions, conversation context and the content a task needs. Sent through the API; not used for training by default under OpenAI's business terms.Used today
AnthropicPrivacy termsAI models (Claude) that generate responses and carry out tasks.Your instructions, conversation context and the content a task needs. Sent through the API; not used for training by default under Anthropic's commercial terms.Used today
Google Gemini (Google)Privacy termsAI models that generate responses and carry out tasks.Your instructions, conversation context and the content a task needs. Sent only through Gemini API Paid Services, under which Google does not use it to improve its products.Used today
Qwen (open-weight models)AI models we run on our own infrastructure.Your instructions, conversation context and the content a task needs. Processed on our own servers; not sent to the model's developer.Used today
Llama (Meta, open-weight models)AI models we may run on our own infrastructure.Your instructions, conversation context and the content a task needs. When self-hosted, not sent to Meta.Planned
Microsoft Teams (Microsoft)Privacy termsTalking to Staff from Teams.Messages, attachments and your Teams identifiers.When you connect it
Microsoft Copilot (Microsoft)Privacy termsTalking to Staff from Copilot.Messages and the context you share with Staff there.When you connect it
ChatGPT (OpenAI)Privacy termsTalking to Staff from ChatGPT.Messages and the context you share with Staff there.When you connect it
Claude (Anthropic)Privacy termsTalking to Staff from the Claude apps.Messages and the context you share with Staff there.When you connect it
iMessage (Apple)Privacy termsTalking to Staff by iMessage.Messages, attachments and your phone number or Apple ID handle.When you connect it
WhatsApp (Meta)Privacy termsTalking to Staff by WhatsApp.Messages, attachments and your phone number and profile name.When you connect it
Outlook and Exchange (Microsoft)Privacy termsReading, drafting, organizing and sending email; managing your calendar and contacts.Email messages and attachments, calendar events, contacts.When you connect it
OneDrive (Microsoft)Privacy termsFinding, reading and organizing your files.Files, folders and their metadata.When you connect it
Gmail (Google)Privacy termsReading, drafting, organizing and sending email.Email messages, attachments and contacts.When you connect it
Google Calendar (Google)Privacy termsReading and managing your calendar.Calendar events, attendees and availability.When you connect it
Google Drive (Google)Privacy termsFinding, reading and organizing your files.Files, folders and their metadata.When you connect it

When you reach Staff through another company's app, such as Teams, Copilot, ChatGPT, Claude, iMessage, WhatsApp or Telegram, that company also processes your messages under its own terms and privacy policy, as part of the service it provides to you. The same applies to the accounts you connect: your email, calendar and file providers keep holding your data under their own terms.

We may also use providers for email delivery, payments, customer support, security monitoring, and professional legal, accounting and compliance services. Before we charge for a plan, we will name our payment provider here.

When we share information

We share personal information only in these cases:

  • With our service providers, as described above.
  • At your direction: when you ask Staff to send an email, share a file, post to LinkedIn or otherwise act toward someone else, we share the content you approved with the recipients you chose.
  • For legal reasons: when required by law, court order or a valid request from a public authority, or when needed to protect the rights, property or safety of our users, the public or us.
  • In a business transfer: if BdG Advisory is involved in a merger, acquisition, financing or sale of assets, personal information may transfer to the new owner, who must honor this policy or tell you before anything changes.
  • With your consent, in any other case.

We never sell personal information to advertisers or data brokers.

International transfers

BdG Advisory operates internationally, and our providers process data in the United States and other countries. Your information may therefore be processed outside the country where you live, including in countries whose data protection laws differ from yours.

Where the law requires it, we protect international transfers with appropriate safeguards, such as the European Commission's Standard Contractual Clauses or a provider's certification under the EU-US Data Privacy Framework. The EU and Australian sections below explain more.

Retention and deletion

  • While your account is open, we keep your account information, conversations and agent memory so Staff can keep helping you. You can ask us to delete specific conversations or memories at any time.
  • When you close your account, we delete your personal information from our active systems within 30 days. Copies in backups are removed as those backups expire, normally within a further 90 days.
  • When you disconnect a connected account, Staff stops accessing it immediately and we revoke the access we held. Copies of its content that Staff kept for a task are deleted within 30 days, unless they became part of a conversation or memory you chose to keep.
  • Enquiries and advisory records are kept as long as reasonably needed to respond, deliver our services and keep business records.
  • What we must keep: we may keep limited information for longer where the law requires it (for example tax and accounting records), or to resolve disputes, prevent fraud and enforce our agreements.

When we no longer need information, we delete it securely or anonymize it so it can no longer identify you.

Security

We use reasonable administrative, organizational and technical safeguards designed to protect personal information against unauthorized access, accidental disclosure, loss, misuse, alteration and destruction. These include encryption in transit, access controls that limit who can reach your data, and restricted handling of the credentials Staff holds for your connected accounts.

No website, service or internet transmission can be guaranteed completely secure. Please keep your sign-in details safe and tell us straight away if you think your account has been compromised.

Your rights and choices

Depending on where you live, you may have the right to:

  • know what personal information we hold about you and get a copy;
  • correct information that is inaccurate;
  • delete your information;
  • receive your information in a portable format;
  • object to, or ask us to restrict, certain processing;
  • withdraw consent you gave earlier;
  • opt out of sale, sharing for targeted advertising, or certain profiling (we do none of these);
  • appeal our decision on your request; and
  • complain to a privacy regulator.

To exercise a right, email info@bdgadvisory.com from the address on your account, or tell us how to reach you. We will verify your identity before acting, and respond within the time the law sets: generally one month in the EU, 30 days in Australia and 45 days under US state laws. We may extend this where the law allows and will tell you if we do. We will not treat you differently for exercising your rights.

You can also disconnect connected accounts, unsubscribe from updates using the link in any message, and close your account at any time.

US state privacy rights

Residents of California, Colorado and other US states with comprehensive privacy laws have the rights described in "Your rights and choices". This section adds what those laws ask us to state.

California (CCPA, as amended by the CPRA)

In the past 12 months we have collected these categories of personal information: identifiers (such as name, email address, IP address and account identifiers); customer records (such as billing details); commercial information (such as the plan you bought); internet or other electronic network activity (such as usage data); approximate geolocation; audio and electronic information (such as messages and voice requests); professional information (such as job title, or details in your connected accounts); and inferences (such as preferences held in agent memory).

We also process sensitive personal information: your account sign-in credentials, and the contents of email, messages and files in accounts you connect. We use it only to provide the service you asked for and for the other purposes the CCPA permits, so the right to limit its use does not apply.

We collect this information from you, from your devices, and from the accounts you connect. We use it for the purposes in "How we use information, and why", disclose it for business purposes to the service providers in "Who processes your data", and keep it as described in "Retention and deletion".

We do not sell or share personal information as the CCPA defines those terms, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. You may use an authorized agent to make a request; we may ask the agent for proof of your authorization and ask you to verify your identity.

Colorado (Colorado Privacy Act)

Colorado residents have the right to access, correct, delete and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in any of those three activities, and we honor universal opt-out signals, such as Global Privacy Control, that Colorado recognizes.

If content you give Staff, or content in an account you connect, includes sensitive data (for example about health or religious beliefs), we process it only to carry out the task you asked for, with the consent you give by connecting that account and giving the instruction.

Appeals. If we decline your request, you can appeal by emailing info@bdgadvisory.com with "Privacy appeal" in the subject line. We will respond within 45 days. If you disagree with the outcome, you can contact the Colorado Attorney General.

Other US states

Residents of other states with comprehensive privacy laws, such as Virginia, Connecticut, Utah, Texas and Oregon, have similar rights, including the right to appeal a refusal to their state attorney general where their law provides for it. Email us to exercise them; we apply the same process and response times.

Netherlands and EU addendum (GDPR)

This addendum applies when the EU General Data Protection Regulation (GDPR) governs our processing, for example when you use Staff or our website from the Netherlands or another EU or EEA country.

Controller. BdG Advisory, Inc. is the controller of your personal information. Contact: info@bdgadvisory.com.

Lawful bases. We rely on the lawful bases shown in "How we use information, and why": performance of our contract with you (Article 6(1)(b)), our legitimate interests in running a secure, working and improving service (Article 6(1)(f)), compliance with legal obligations (Article 6(1)(c)), and your consent where we ask for it (Article 6(1)(a)). Where we rely on legitimate interests, we have weighed them against your rights; you can ask us for details.

Your rights. You have the right of access, rectification, erasure, restriction, data portability and objection (Articles 15 to 21), and the right to withdraw consent at any time. You have an absolute right to object to direct marketing. Staff does not make decisions about you based solely on automated processing that produce legal or similarly significant effects (Article 22).

Providing data. Your name, email address and sign-in details are needed to create an account; without them we cannot provide Staff. Everything else, including connecting accounts, is your choice.

International transfers. We are based in the United States, and our providers process data in the United States and elsewhere. We transfer personal data outside the EEA on the basis of the European Commission's Standard Contractual Clauses, a provider's certification under the EU-US Data Privacy Framework, or another safeguard the GDPR allows. You can ask us for a copy of the relevant safeguards.

Complaints. You can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in the EU country where you live or work, or where you think the infringement took place. We would appreciate the chance to resolve your concern first.

Australia addendum (Privacy Act 1988)

This addendum applies to personal information about individuals in Australia. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Collection. We collect personal information directly from you, or from the accounts you authorize Staff to connect to, and only where it is reasonably necessary for our functions and activities. You can browse our website without telling us who you are; to use Staff you need an account in your name.

Overseas disclosure (APP 8). We disclose personal information to recipients outside Australia: our service providers and model providers in the United States, and in other countries where those providers run their services, including countries in Europe and Asia. Before disclosing, we take reasonable steps, through contracts and provider selection, to ensure those recipients handle your information consistently with the APPs.

Access and correction (APPs 12 and 13). You can ask for access to the personal information we hold about you and ask us to correct it. We respond within 30 days. If we refuse, we will tell you why and how to complain.

Direct marketing. You can opt out of marketing messages at any time using the unsubscribe link or by emailing us.

Complaints. Contact us first at info@bdgadvisory.com; we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

Children

Staff is only for adults aged 18 and over. Our website is intended for business professionals and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

If something goes wrong

If a security incident affects your personal information, we will investigate, contain it and take steps to limit harm. Where the law requires it, we will notify you and the relevant regulators without undue delay. That includes notifying the Dutch Autoriteit Persoonsgegevens within 72 hours where the GDPR requires, the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and the authorities US state laws require.

Changes to this policy

We may update this policy from time to time. The current version is always on this page, with its effective date at the top. If we make a material change, we will tell Staff users by email or in the service before it takes effect.

Contact

Questions, requests and complaints about privacy go to BdG Advisory, Inc. at info@bdgadvisory.com. Website: bdgadvisory.com.