Privacy Policy
This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. We aim to be clear and to collect only what we need.
Last updated: July 26, 2026
Overview
AICG, Inc. (“AICG,” “we,” “us,” or “our”) respects your privacy. This policy describes how we handle personal information when you visit our website, submit a form, download a resource, subscribe to communications, or otherwise interact with us. It also describes your rights under the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other US state privacy laws.
For the purposes of the GDPR, AICG, Inc. is the “controller” of personal information collected through this website. You can reach us at legal@aicg.com or at the postal address in the “Questions about this policy?” block at the end of this page.
Scope
This policy applies to personal information we collect through this website and related sales, marketing, and support activities. It does not apply to third-party websites we link to, or to information you provide directly to our product platforms under a separate agreement. Where we process client data as a “processor” on behalf of a customer, that processing is governed by our contract and any applicable Data Processing Addendum (DPA) with that customer, not by this policy. A standard DPA is available to customers and prospective customers on request from legal@aicg.com.
Information we collect
Information you provide
- Contact & lead details - name, business email, company, job title, and the message or interest you share when you submit a form, request a consultation, or download a gated resource such as a whitepaper.
- Communications - the content of emails and other messages you send us, and our correspondence with you.
Information collected automatically
- Usage & device data - IP address, browser type, device and operating system, referring pages, pages viewed, and interaction events, collected through cookies and similar technologies.
- Analytics & advertising identifiers - identifiers set by Google Analytics and the LinkedIn Insight Tag to measure site performance and measure marketing. See our Cookie Policy for specifics.
We do not intentionally collect special categories of data (such as health, biometric, or government-ID numbers) through this website, and we ask that you do not submit them through our forms.
How we use information
- Respond to inquiries and provide the resources or consultations you request.
- Operate, maintain, secure, and improve the website and our content.
- Send you information you asked for and, where permitted, relevant marketing communications you can opt out of at any time.
- Measure and understand website traffic, engagement, and campaign effectiveness.
- Detect, prevent, and address fraud, abuse, and security issues.
- Comply with legal obligations and enforce our terms.
Legal bases for processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Consent - for non-essential cookies and certain marketing communications. You may withdraw consent at any time.
- Legitimate interests - to operate and secure our site, understand how it is used, and pursue business development, balanced against your rights and interests.
- Performance of a contract - to provide something you have requested or to take steps at your request before entering a contract.
- Legal obligation - where we must process information to comply with applicable law.
Cookies & tracking technologies
We use cookies and similar technologies to run the site, remember preferences, and measure performance and marketing. You can control these through your browser and, where offered, our cookie controls. For a full description of the cookies we use - including Google Analytics and the LinkedIn Insight Tag - and how to opt out, see our Cookie Policy. You can also opt out of analytics and advertising tags through our Your Privacy Choices control.
How we share information
We do not sell your personal information for money. We share it only as follows:
- Service providers who process information on our behalf under contract (see below).
- Professional advisors such as auditors and lawyers, where reasonably necessary.
- Legal & safety - to comply with law, respond to lawful requests, or protect the rights, property, and safety of AICG, our users, or others.
- Business transfers - in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
Note that certain advertising and analytics activity may be considered a “sale” or “sharing” under California and other US state laws; see the US state privacy rights section and our Your Privacy Choices control.
Service providers we use
Representative categories and providers include:
- Hosting & infrastructure - Amazon Web Services (AWS Amplify).
- Content management - Sanity (for blog and site content).
- Analytics - Google Analytics.
- Advertising & measurement - LinkedIn.
- Email delivery - SendGrid (and/or comparable email service providers).
- Customer relationship management - OnePageCRM, to manage inquiries and follow-ups.
International data transfers
We are based in the United States, and our service providers may process information in the United States and other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or another lawful transfer mechanism. You may contact us for more information about these safeguards.
EU and UK representative
AICG, Inc. does not have an establishment in the European Economic Area or the United Kingdom. Whether we are required to appoint a representative under Article 27 of the GDPR and Article 27 of the UK GDPR depends on the nature and extent of any offering of goods or services to, or monitoring of the behavior of, individuals located in those regions.
Where a representative is required, we will appoint one and publish their name and contact details in this section, so that individuals in the EEA and the UK can raise privacy matters with a local point of contact in addition to contacting us directly at legal@aicg.com.
Data retention
We keep personal information only for as long as we need it for the purposes described in this policy, after which we delete or anonymize it. Because the right period depends on the type of information and why we hold it, we use the following criteria to decide how long to keep each type:
- Inbound lead and contact records - kept for the duration of our business relationship and for a reasonable period afterward to support follow-up, respond to further inquiries, and meet legal, tax, accounting, and record-keeping obligations.
- Marketing subscriber records - kept until you unsubscribe or ask us to delete them, plus a limited suppression-list period so we can continue to honor your opt-out.
- Website analytics data - kept for the retention period configured in our analytics tools and for the cookie lifetimes described in our Cookie Policy, after which it expires or is aggregated.
- Cookies and similar technologies - retained for the durations listed in our Cookie Policy, which range from the end of your session to a defined number of months or years by cookie.
Where we are required to keep information to comply with a legal obligation, or to establish, exercise, or defend legal claims, we retain it for as long as that obligation or need applies.
Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, or misuse. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Data breach notification
We maintain an incident response process to detect, investigate, and respond to security incidents. In the event of a personal data breach, we will notify affected individuals and the applicable regulators as required by law. This includes, where the GDPR or UK GDPR applies, notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as well as meeting applicable US state breach notification requirements.
Automated decision-making and AI
We do not use website personal information to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR. If this changes, we will update this section and provide the information and safeguards the law requires.
Your rights (GDPR / UK GDPR)
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request erasure of your information.
- Restrict or object to certain processing, including direct marketing.
- Request portability of information you provided to us.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office).
To exercise any of these rights, email us at legal@aicg.com. We may need to verify your identity before responding.
US state privacy rights
California (CCPA/CPRA)
If you are a California resident, you may have the right to know what personal information we collect, use, and disclose; to request deletion or correction of your information; and to opt out of the “sale” or “sharing” of personal information (including certain uses of analytics and advertising cookies for cross-context behavioral advertising). We do not sell personal information for money, and we do not knowingly sell or share the information of minors under 16.
To exercise these rights, email legal@aicg.com, use our Your Privacy Choices control, or adjust your cookie choices as described in our Cookie Policy. We will not discriminate against you for exercising your rights. You may use an authorized agent to submit a request on your behalf.
Other US states
Comprehensive privacy laws in a growing number of states give residents rights that are similar to the California rights above, such as the right to access, correct, and delete personal information, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal information, and certain profiling. Residents with such rights include, depending on your state of residence, residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, and Kentucky, among others. The exact rights and how they apply depend on your state’s law and its effective date.
How to submit a request, timelines, and verification
To exercise any US state privacy right, email us at legal@aicg.com. We will acknowledge and respond to a request within 45 days. Where reasonably necessary, taking into account the complexity and number of requests, we may extend this by an additional 45 days and will let you know if we do.
To protect your information, we may need to verify your identity before we act on a request. We typically do this by asking you to confirm information we already hold, such as the email address and other details associated with your inquiry or subscription. Where an authorized agent submits a request on your behalf, we may ask for proof of authorization and may still ask you to verify your identity directly.
Right to appeal
If we decline to act on your request, you may appeal. To do so, reply to our decision or email legal@aicg.com with “Privacy Request Appeal” in the subject line. We will respond to your appeal within 45 days, or within 60 days where the appeal is complex and we notify you of the extension. If we deny your appeal, you may contact your state Attorney General to raise a concern.
Categories of personal information (CCPA/CPRA disclosure)
The table below summarizes, by category of personal information, the sources we collect it from, the purposes we use it for, the categories of third parties we may disclose it to, and the criteria we use to determine how long we keep it.
| Category | Sources | Purposes | Categories of third parties | Retention criteria |
|---|---|---|---|---|
| Identifiers (name, business email, company, job title, IP address) | Directly from you; automatically from your device and browser | Respond to inquiries, deliver requested resources, marketing, operate and secure the site, comply with law | Service providers (hosting, CMS, analytics, advertising, email, CRM); professional advisors; legal and safety recipients; parties to a business transfer | Duration of the business relationship plus a reasonable period for follow-up and legal, tax, and accounting needs |
| Commercial information (resources downloaded, services inquired about) | Directly from you | Respond to inquiries, marketing, improve our content and services | Service providers (CRM, email); professional advisors | Duration of the business relationship plus a reasonable follow-up period |
| Internet or network activity (browsing, interaction events, referring pages) | Automatically from your device and browser | Measure and improve site performance, security, and marketing | Service providers (analytics, advertising, hosting) | Analytics tool retention settings and the cookie lifetimes in the Cookie Policy |
| Geolocation data (coarse, inferred from IP address) | Automatically from your device and browser | Understand traffic, security, and regional interest | Service providers (analytics, hosting) | Analytics tool retention settings and applicable cookie lifetimes |
| Professional or employment information (job title, company) | Directly from you | Respond to inquiries, qualify and route business development | Service providers (CRM, email); professional advisors | Duration of the business relationship plus a reasonable follow-up period |
| Inferences drawn from the above | Derived by us from the categories above | Understand interest and improve marketing and content relevance | Service providers (CRM, analytics) | Kept with, and for the same period as, the information they are based on |
Sensitive personal information
We do not collect “sensitive personal information” as defined by the CCPA/CPRA through this website, and we ask that you do not submit it through our forms. We do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA/CPRA section 1798.121(a). Because we do not use sensitive personal information for purposes that would trigger the right, we do not offer a separate “Limit the Use of My Sensitive Personal Information” control.
Opt-out preference signals
Our site detects the Global Privacy Control (GPC) signal. When your browser or a browser extension sends GPC, we treat it as a request to opt out and do not load the Google Analytics or LinkedIn Insight Tag technologies for your visit. You can also set your choice directly using our Your Privacy Choices control.
Some browsers also offer a “Do Not Track” setting. Because there is no common industry standard for interpreting Do Not Track, our site does not respond to it; we honor Global Privacy Control instead, as described above.
Children’s privacy
This website is intended for a business audience and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, record the change in the version history below, and, where appropriate, provide additional notice. Your continued use of the site after an update means you accept the revised policy.
Version history
| Date | Summary of changes |
|---|---|
| July 26, 2026 | Added US state privacy rights (with appeals, timelines, and verification), CCPA/CPRA disclosure tables, sensitive personal information, EU/UK representative, opt-out preference signals (Global Privacy Control), data breach notification, automated decision-making and AI, and expanded retention detail. Standardized the address and added this version history. |
| July 11, 2026 | Initial publication of the Privacy Policy. |
More legal documents