AI Audit for Companies

Privacy Policy

Scope. This document applies to the websites aiauditforcompanies.com and srjconsultingservices.com, and to all products and services offered through them — including the SRJ AI Audit Platform — each owned and operated by SRJ Consulting & Services LLC (“SRJ,” “we,” “us,” or “our”). References in this document to the “Site” or to srjconsultingservices.com include aiauditforcompanies.com.

SRJ Consulting & Services LLC (“SRJ,” “we,” “us,” “our”) respects your privacy. This Privacy Policy (“Policy”) explains what Personal Information we collect, how we use and share it, how long we keep it, the choices and rights you have, and how to contact us. This Policy applies to srjconsultingservices.com, our newsletter, our downloadable publications and worksheets, our on-demand press kit, and any related pages, tools, and communications (collectively, the “Website”). By using the Website or providing information to us, you agree to the practices described in this Policy.

1. Relationship to our other legal documents

This Policy is a companion to our Terms of Use and Disclaimer. Each is incorporated into this Policy by reference. Capitalized terms not defined here have the meanings given to them in the Terms of Use.

2. Who we are

SRJ Consulting & Services LLC is a Texas limited liability company with its principal place of business at 13054 Cinderella Lane, Frisco, TX 75035-5194 United States, United States. SRJ is the “controller” of Personal Information collected through the Website under applicable European and United Kingdom law, and the “business” that collects Personal Information under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA/CPRA”). Our contact information appears in Section 36.

3. Scope of this Policy

This Policy covers Personal Information that SRJ collects through the Website, our newsletter, our contact forms, our scheduling tools, our secure file upload facility, our downloadable worksheets and books, our on-demand press kit, and any direct communication with SRJ. This Policy does not apply to: (a) websites, tools, or services operated by third parties, even if linked from the Website, which are subject to their own privacy policies; (b) Personal Information you provide directly to a third-party vendor whose service you access from the Website (for example, Amazon for book purchases or Beehiiv for newsletter subscription management); or (c) Personal Information that SRJ handles under a signed engagement agreement, which is governed by that agreement.

4. Key definitions

5. Personal Information we collect

5.1 Information you provide to us

We collect Personal Information you provide directly, including when you:

5.2 Information collected automatically

When you visit the Website, SRJ and its Service Providers automatically collect certain technical information, which may include your IP address, browser type and version, device type, operating system, screen resolution, language preference, time zone, referring website, pages viewed, links clicked, search terms entered on the Website, session duration, mouse movements and clicks (via Microsoft Clarity, if you consent), and the dates and times of your visits. This information is used for analytics, site performance, security, fraud prevention, and abuse detection.

5.3 Information from third parties

We may receive limited information from third parties, including: (a) our Service Providers who help us operate the Website (for example, hosting logs and error reports); (b) analytics platforms that aggregate visitor behavior; (c) our newsletter platform Beehiiv, which reports subscription events and email engagement metrics; and (d) publicly available sources, such as LinkedIn profiles or company websites, which may be consulted for context in preparing an engagement.

6. Categories of Personal Information collected (CCPA/CPRA disclosure)

For purposes of the CCPA/CPRA, in the preceding twelve months SRJ has collected the following categories of Personal Information:

We do not collect Sensitive Personal Information as defined by the CCPA/CPRA in the ordinary course of Website use. If you voluntarily provide Sensitive Personal Information in a message to us, we will treat it consistent with this Policy and applicable law.

7. Sources of Personal Information

We collect Personal Information from the following sources: (a) directly from you, when you interact with the Website; (b) automatically, through cookies, tracking technologies, and server logs; (c) from Service Providers that assist us in operating the Website; (d) from publicly available sources, as described in Section 5.3; and (e) from third parties who refer you to us or introduce us with your consent.

8. How we use Personal Information (business and commercial purposes)

We use Personal Information for the following business and commercial purposes:

9. Legal bases for processing (EEA, UK, and Swiss residents)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your Personal Information on the following legal bases under the General Data Protection Regulation and the UK GDPR:

10. How we share Personal Information

We do not sell your Personal Information, and we do not share your Personal Information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We disclose Personal Information only in the following circumstances:

SMS opt-in data carve-out. No mobile information or SMS opt-in data is shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are excluded from all sharing categories above and will not be sold, rented, shared, or transferred to any third party for any purpose other than to deliver the text messages you have consented to receive.

11. Third-party Service Providers

The Website relies on the following categories of Service Providers, each of which processes Personal Information only under contract, only for the purposes we authorize, and only as necessary to provide their service. This list is representative, not exhaustive, and may change:

Each Service Provider processes information under its own privacy policy. We select Service Providers we consider reputable and require contractual privacy and security protections.

12. Cookies and similar technologies

The Website uses cookies, pixels, local storage, and similar technologies. Cookies are managed through the Complianz consent management platform, which classifies cookies into these categories:

The Complianz banner appears on your first visit and lets you accept all, reject non-essential, or customize per category. You can withdraw or change your consent at any time through the cookie preferences link at the footer of the Website or by visiting Opt-Out Preferences. You can also control cookies through your browser settings; disabling cookies may limit some features.

13. Global Privacy Control and Do Not Track

The Website respects the Global Privacy Control (GPC) browser signal, an opt-out preference signal recognized under the CCPA/CPRA. When our systems detect a valid GPC signal from your browser, we treat that signal as a request to opt out of the sale or sharing of Personal Information for cross-context behavioral advertising. Because we do not sell Personal Information or share it for cross-context behavioral advertising in any event, the practical effect is that we honor your GPC preference on arrival.

Because there is no consistent industry standard for responding to the older “Do Not Track” browser signal, the Website does not currently respond to that signal differently.

14. Newsletter and email communications

If you subscribe to our newsletter, we collect your email address and any name you provide, and we deliver newsletter content through Beehiiv. Every newsletter email identifies itself as commercial, contains our physical postal address, and provides a functioning unsubscribe link. You may opt out at any time by clicking the unsubscribe link in any newsletter email or by emailing info@srjconsultingservices.com with “unsubscribe” in the subject line. Unsubscribing from the newsletter does not affect other communications related to services you have specifically requested. We comply with the CAN-SPAM Act of 2003.

15. SMS text messaging and A2P 10DLC compliance

The WPForms contact form (form ID 196) offers an optional SMS-consent checkbox. If you check that box and provide your phone number, you consent to receive SMS text messages from SRJ related to your inquiry. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out; reply HELP for help. Contact us at info@srjconsultingservices.com or by telephone for support.

SRJ’s SMS program is registered as a compliant A2P 10DLC campaign with U.S. wireless carriers. Consent to receive text messages is not a condition of any purchase, service, or communication. Mobile information and SMS opt-in data are not shared with third parties or affiliates for marketing or promotional purposes and are not sold, rented, or transferred to any third party for any purpose other than to deliver the messages you have consented to receive.

16. Website analytics and session recording

SRJ uses Google Analytics 4 (measurement ID G-WWP3BSKN5N) to understand aggregate Website use and Microsoft Clarity (project ID wxtqd3ud7i) to view session recordings and heatmaps that help us diagnose usability issues. Both tools are gated behind the Complianz consent banner under the “Statistics” category and do not run until you provide consent. Session recordings are masked by default to reduce collection of typed input; we do not intentionally record passwords, credit-card numbers, or other sensitive fields. Microsoft Clarity retains session data on its own schedule described at Microsoft Clarity FAQ. You can opt out of both tools by rejecting the “Statistics” category in the consent banner or by using a browser extension that blocks tracking.

17. Book worksheet gate and the functional cookie

Downloadable worksheets that accompany our books are gated behind a lightweight email-verification step: you enter an email address, we send a one-time confirmation email with a signed unlock link, and clicking the link sets a first-party functional cookie named “srj_worksheet_access” that remembers the unlock for 10 years, path /, SameSite Lax. The cookie contains only a numeric marker; no email address, name, or identifying content is stored inside the cookie. The email address you enter is used solely for delivery of the confirmation email and is not enrolled in the newsletter or any marketing automation unless you separately opt in. You can clear the cookie at any time through your browser.

18. AI use in our operations

SRJ advises executives on the disciplined, accountable use of artificial intelligence. Consistent with that work, we use AI tools in our own operations, including in the production of written content, editorial support, research, analysis, and graphics across the Website, our newsletter, our books, and related publications. Every piece of content is reviewed, edited, and approved by Stephen R. Jordan before publication. Please see our Disclaimer for further detail.

19. How we do NOT use your Personal Information with artificial intelligence

Because we advise on responsible AI, we hold ourselves to a specific commitment about your Personal Information and artificial intelligence:

20. Data retention

We retain Personal Information only for as long as necessary to fulfill the purposes described in this Policy, to maintain reasonable business records, and to comply with legal obligations. Retention periods vary by category:

When Personal Information is no longer required, we take reasonable steps to delete or de-identify it.

21. Data security

We take reasonable administrative, technical, and organizational measures to protect Personal Information transmitted to and held by us. These measures include: TLS encryption in transit for all Website traffic (HTTPS enforced by HSTS); the Sucuri web application firewall filtering inbound traffic; Cloudflare Turnstile bot protection on the contact form; strong administrator authentication with multi-factor authentication; role-based access control; monthly patch and update cycles for the WordPress core, theme, and plugins; regular backups; and a small, deliberate plugin footprint to limit attack surface.

Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You provide information to us at your own risk. You are responsible for maintaining the security of any account credentials you use to access services related to the Website.

22. Data breach notification

If SRJ becomes aware of a breach of security that compromises the confidentiality, integrity, or availability of your Personal Information, we will investigate promptly, take reasonable steps to contain and remediate the incident, and notify affected individuals and applicable regulators as required by law. Notifications may be delivered by email, by prominent notice on the Website, or by other means reasonably designed to reach affected individuals.

23. Children’s privacy

The Website and our services are directed to business professionals, not children. We do not knowingly collect Personal Information from children under 13, and we do not knowingly market to children or teenagers. If you believe a child under 13 has provided Personal Information to us, please contact us at info@srjconsultingservices.com and we will take reasonable steps to delete the information. We comply with the Children’s Online Privacy Protection Act (COPPA).

24. Your privacy choices and rights

Subject to applicable law and to identity verification, you have the following choices with respect to your Personal Information:

The specific rights available to you depend on your state or country of residence, as described in Sections 25 through 27.

25. California residents: CCPA and CPRA rights

If you are a California resident, the CCPA/CPRA gives you the following rights:

To exercise any of these rights, contact us using the details in Section 36. We will verify your identity before responding. We will respond within the timeframes required by law (generally 45 days, with a possible 45-day extension). If we deny a request, you may appeal by replying to our response.

Notice of financial incentives. SRJ does not offer any financial incentive tied to the collection, retention, sale, or sharing of Personal Information.

26. Other U.S. state privacy rights

Depending on your state of residence, you may have additional rights under the following state privacy laws:

Depending on your state, these rights generally include the right to confirm processing and access your Personal Information, the right to correct inaccurate Personal Information, the right to delete Personal Information, the right to obtain a portable copy of your Personal Information, the right to opt out of targeted advertising, sale of Personal Information, and certain profiling, and the right to appeal our denial of a request. As stated above, SRJ does not sell Personal Information and does not use it for targeted advertising or profiling that produces legal or similarly significant effects. To exercise any right, contact us using the details in Section 36.

27. EEA, UK, and Swiss residents: GDPR rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:

To exercise these rights, contact us using the details in Section 36. We will respond within one month, subject to statutory extensions where the request is complex.

28. International data transfers

SRJ is based in the United States, and our Service Providers may process Personal Information in the United States or in other jurisdictions. If you access the Website from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and in other countries where our Service Providers operate, and that data-protection laws in those countries may differ from those in your jurisdiction.

Where required for transfers of personal data out of the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss-U.S. Data Privacy Framework, as applicable. You may request more information about these safeguards by contacting us.

29. Automated decision-making and profiling

SRJ does not make decisions that produce legal or similarly significant effects on you by solely automated means, and does not engage in automated profiling of individuals for purposes that produce such effects. The Website uses automated analytics and heatmaps to understand aggregate visitor behavior, but these do not produce individualized decisions about you.

30. How to exercise your rights

To exercise any right described in Sections 24 through 27, please send a request to info@srjconsultingservices.com with a clear subject line such as “Privacy Rights Request.” Please include: (a) your full name; (b) the email address, phone number, or account identifier associated with your Personal Information; (c) the state or country in which you reside; (d) a clear statement of the right you are exercising and, where relevant, the Personal Information at issue; and (e) any additional information needed to verify your identity.

We will use the information you provide to verify your identity. If we cannot verify your identity to a level of certainty appropriate to the sensitivity of the information or the risk of harm from unauthorized disclosure, we may decline to fulfill your request and will explain why. We respond as promptly as we can, in any event within the timeframes required by applicable law.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We require the agent to provide a signed authorization or a valid power of attorney, and we may require you to verify your identity directly and to confirm to us that you have authorized the agent to submit the request.

31. Appeals

If we decline a privacy rights request in whole or in part, you may appeal our decision by replying to our response within 60 days of receipt, or by sending a new email to info@srjconsultingservices.com with the subject line “Privacy Rights Appeal.” We will review the appeal and respond within the timeframe required by applicable law (generally 45 days). If your appeal is denied, you may submit a complaint to your state attorney general or, if applicable, your data-protection supervisory authority.

32. Non-discrimination

We will not deny you goods or services, charge you different prices, provide a different level or quality of service, or retaliate against you for exercising a privacy right described in this Policy.

33. Sale of business, mergers, and acquisitions

If SRJ enters into a merger, acquisition, financing, reorganization, bankruptcy, receivership, or sale of some or all of its assets, Personal Information may be part of the transferred assets. Any acquirer will be required to honor the commitments in this Policy with respect to Personal Information collected before the transfer, and material changes to privacy practices going forward will be notified to affected individuals.

34. Links to other websites

The Website may contain links to third-party websites, including Amazon (for book purchases), Beehiiv (for newsletter subscription management), LinkedIn (for professional profile), YouTube (for embedded video), and other services referenced in our content. We are not responsible for the privacy practices or content of any third-party website. We encourage you to review the privacy policy of any third-party website you visit.

35. Changes to this Policy

We may update this Policy from time to time. When we do, we will update the “last updated” date at the top of this Policy and post the revised Policy on the Website. If we make material changes, we will provide reasonable notice, which may include a banner on the Website, an email to subscribers, or another reasonable method. Your continued use of the Website after the effective date of the revised Policy constitutes your acceptance of the revised Policy. If you do not agree, your only remedy is to stop using the Website and to unsubscribe from any communications you had previously requested.

36. Contact and privacy inquiries

Questions, comments, requests, or complaints regarding this Policy or our privacy practices may be directed to:

SRJ Consulting & Services LLC
Attn: Privacy Officer
13054 Cinderella Lane
Frisco, TX 75035-5194 United States
United States
Email: info@srjconsultingservices.com

Dispute resolution for matters arising from this Policy is governed by the arbitration and venue provisions in Sections 18 and 20 of the Terms of Use (JAMS binding arbitration; venue: Collin County, Texas; governing law: Texas).