Skip to main content

Legal

Privacy Policy

Last updated: August 23, 2026

Information we collect

When you contact us through our forms, email, or scheduled calls, we collect the information you provide — typically your name, work email, optional phone number, organization, role, organization type, business trigger, desired timeline, source attribution, consent, and any optional description you submit.

When you use Enterprise Trust Score™ — SOC 2 Deal Readiness, your assessment answers stay in your browser until you choose to unlock the full report. At that point, we collect your name, work email, company, role, team size, primary customer segment, assessment responses, decision-readiness response, readiness and deal-pressure scores, engagement-fit classification, recommended path, and consent choices so we can generate and deliver the report and respond appropriately. Historical version 1 and version 2 reports remain supported under their original assessment logic.

When you use Enterprise Trust Score™ — AI Governance Readiness, your structured assessment answers stay in your browser until you choose to unlock the full report. At that point, we collect your name, work email, company, role, optional company or LinkedIn URL, urgency, desired outcome, assessment responses, generated score and findings, attribution and consent choices so we can generate and deliver the report, protect the service and route appropriate follow-up.

The AI Governance Readiness assessment does not need confidential system content. Do not enter passwords, credentials, API keys, access tokens, customer records, detailed vulnerabilities, confidential architecture or sensitive production data.

We also collect limited attribution data associated with an assessment visit, such as source, medium, campaign, content, term, the referring site and path, and the landing path. We use bounded fields and do not intentionally place your name, email, company, or assessment answers in analytics events or attribution URLs.

When you visit ektreasure.com, our hosting provider (Vercel) automatically logs technical request data — IP address, user-agent, and request paths — used solely for operating the site and protecting it against abuse.

How we use your information

We use the information you submit to respond to your inquiry, prepare scoped proposals, and stay in touch about an active engagement. We do not sell or rent your information.

SOC 2 Deal Readiness assessment submissions are used to generate and deliver your requested report and PDF, calculate directional readiness and enterprise deal-pressure scores, classify engagement fit, recommend an appropriate path, route lead and sales follow-up, detect abuse, and improve the assessment. Optional marketing messages are sent only when you select the separate marketing checkbox.

AI Governance Readiness assessment submissions are used to calculate a deterministic readiness score and maturity band, identify the top three gaps, generate evidence-readiness and agentic-control indications, build an answer-linked 30-day action plan, deliver the requested report and route appropriate follow-up. The result is a readiness diagnostic, not certification, regulatory approval, an audit opinion, legal advice or a claim of formal framework conformity.

If we send you a written proposal or marketing follow-up, we'll always identify ourselves clearly and include an opt-out path.

Cookies and analytics

This site does not use third-party advertising cookies. Vercel may set strictly-necessary cookies required to serve the site and protect against abuse.

If you allow analytics, Google Analytics 4 measures page views and bounded events such as assessment starts and completion, preliminary score bands, report requests, recommended paths, consultation-form progress, downloads and outbound calls to action. Microsoft Clarity may also be enabled to help us understand aggregate page interaction; contact and assessment surfaces are masked. Clarity and GoHighLevel tracking are not initialized on the AI Governance Readiness assessment, and no third-party analytics scripts run on its private bearer-link report page. Analytics does not load before your affirmative choice, and you can change that choice using the Analytics preferences link in the footer.

Analytics events are designed not to include your name, email address, company name, phone number, raw assessment answers, exact scores, report contents, free-form messages, or URL query strings. Advertising storage, Google Signals and ad personalization are disabled.

For the AI Governance Readiness assessment, analytics may include only a bounded maturity tier and boolean indications that agentic AI, multi-agent use or high-risk autonomy was detected. Raw answers, contact details, exact AI scores and generated report contents are not included in analytics events.

Third parties

Consulting intake forms submit first to EK Treasure's internal /api/contact route hosted by Vercel. The route validates and limits the request before securely creating or updating the related contact in GoHighLevel, which is used for sales workflow and opportunity management. The existing Brevo business-inbox notification remains a backup while the CRM integration is verified. Provider credentials remain server-side. The form includes the fields you submit, bounded source, service-interest and campaign attribution, and your consent choice; it does not ask for passwords, access tokens, detailed vulnerabilities, or confidential evidence. A Web3Forms fallback remains available in the application but is not the primary production contact processor.

Assessment submissions are processed on Vercel. Upstash Redis provides distributed rate limiting. Brevo is the configured transactional email processor for customer report delivery, contact-form delivery and internal sales notification. The report PDF is generated by EK Treasure's application on demand. A Resend fallback exists in the code but is not configured in production.

The AI Governance Readiness assessment also uses Upstash Redis for a 30-day token-backed report snapshot. The snapshot contains the generated report, the name and company it was prepared for, and Triage and Diagnostic links; it does not contain the raw assessment answers. Only a SHA-256 digest of the random report-view token is used as the Redis key.

When you unlock an AI Governance report, EK Treasure creates or updates a limited GoHighLevel contact for the requested business follow-up. The direct integration sends your name, work email, company, a fixed assessment source, and controlled tags for assessment version, lead grade, final maturity band, urgency, desired outcome, marketing-consent state and recognized campaign channels. It does not send raw assessment answers, question paths, exact scores, findings, report contents, private report links, referrer paths, optional company or LinkedIn URLs, or free-form technical information.

If an AI-specific CRM webhook is configured, EK Treasure may send the submitted contact, structured assessment and generated result to that business system for requested follow-up. The optional AI server-analytics webhook receives only the completion event, maturity tier and three bounded AI risk flags—not a lead identifier, lead classification, contact details or raw answers. Generic webhook destinations must be explicitly allowlisted.

Enterprise Trust Triage for AI Governance may use the configured GoHighLevel booking calendar; when no external booking URL is configured, the application uses the internal AI Governance-focused Enterprise Trust Triage contact route. Hot-lead and server-analytics webhooks remain optional integration points.

Google may process consented, privacy-limited website analytics. Microsoft may process consented interaction analytics only when Clarity is configured. GoHighLevel may process form-submission, sales-follow-up and consented external-tracking data. Google Search Console ownership verification does not itself track visitors. We do not share contact or assessment data with advertising networks. Providers receive only the information needed for hosting, rate limiting, requested report delivery, business follow-up, consented analytics and service protection.

Where we engage subprocessors for delivering services under a signed agreement (for example, a compliance-automation vendor supporting a SOC 2 or ISO 27001 readiness engagement), they are bound by the data-protection terms of that agreement, not by this page.

Retention and safeguards

Unqualified contact inquiries are retained while we respond, determine whether follow-up is appropriate and maintain a reasonable record of the interaction; records with no continuing business or legal purpose are reviewed for deletion.

SOC 2 Deal Readiness submissions and generated reports are retained while needed to deliver the requested report, protect the service, support the related readiness conversation and maintain an appropriate record of the request. EK Treasure has not yet finalized a fixed deletion schedule for unqualified inquiries or SOC 2 assessment submissions; until it does, these records are reviewed by purpose and deleted or de-identified when no longer needed.

The token-backed AI Governance report snapshot expires automatically 30 days after it is created. That snapshot does not store raw assessment answers. The 30-day period applies to the personalized report view, not to separate contact, consent, email-delivery or CRM records that may be retained under the inquiry, commercial-opportunity, legal and opt-out purposes described here.

Active commercial opportunities are retained while evaluation, proposal and reasonable follow-up remain active. Client, contract, invoicing and service records are retained for the engagement and for applicable legal, tax, insurance, dispute-management and professional-record obligations.

Consent records are retained as needed to demonstrate and apply the choices you made. Minimal suppression or opt-out records may be retained for as long as needed to ensure we continue to honour an unsubscribe or do-not-contact request.

We use access controls, transport encryption, rate limiting, validation, restricted integration credentials, and other administrative and technical safeguards appropriate to the sensitivity of the information.

Your choices

You can withdraw optional marketing consent or request access, correction, or deletion of personal information you've sent us by emailing info@ektreasure.com. We may need to verify your identity before fulfilling a request and will respond within the time required by applicable law.

Contact

Questions about this policy or your data should go to info@ektreasure.com. EK Treasure Inc. is headquartered in Toronto, Canada.

Request Enterprise Trust Triage if you need any clarification.