Trust & Privacy

How we handle your data.

This page is maintained by Continuity Insight to answer common privacy and security questions. It describes current practices and is not an independent certification.

Last updated: July 2026

What we collect

We collect only what's needed to deliver the service: the information you provide when you request an assessment or brief (company, role, contact details), the operational inputs you submit into our tools, and standard technical logs (IP address, browser type, page views) used to operate and improve the platform.

We do not require or collect payment card information; where transactions occur, they are processed by a third-party processor and no card data is stored on our systems.

How we use it

Your data is used to deliver the service you requested — running an assessment, generating a brief, following up on a request. We use aggregated, de-identified information to improve the platform's models and outputs.

We do not sell your data. We do not share your operational inputs with other clients. We do not use client data to train third-party models.

Security practices

Current controls in place:

  • Traffic to the platform is encrypted in transit using TLS.
  • Access to production systems is restricted to authorized personnel.
  • Credentials and secrets are stored in a managed secret store, not in source code.
  • Third-party infrastructure providers are chosen for their published security posture.

These are current operational practices, not certifications. We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI compliance.

Data retention

Assessment inputs and generated outputs are retained for the duration of the engagement plus a reasonable operational window to support follow-up. You may request deletion of your data at any time (see contact below).

Contact and communication records may be retained longer where needed to maintain the business relationship or meet legal obligations.

Subprocessors and third parties

We rely on a small number of infrastructure and email service providers to operate the platform. We select vendors who publish their own security and privacy practices, and we limit what we share with them to what's necessary to deliver the service.

A current list of subprocessors is available on request via the contact below.

Your rights

You can request access to, correction of, or deletion of the personal information we hold about you. To exercise these rights, contact us using the details below and we will respond within a reasonable timeframe.

Reporting a security issue

If you believe you've found a security vulnerability, please contact us at the address below with a clear description and, if possible, steps to reproduce. We take reports seriously and will investigate promptly. Please do not publicly disclose an issue until we've had a reasonable opportunity to respond.

Shared responsibility

Security is a shared responsibility. Continuity Insight is responsible for the platform, its infrastructure, and the controls described above. Clients are responsible for how they distribute credentials, what data they submit into the tools, and their own internal handling of any outputs and reports.

Contact

Privacy, security, or data-handling questions: privacy@continuityinsight.com

General inquiries: see the About page.