Compliance Architects LLC (hereinafter, “CA”) is a specialized management consulting firm delivering quality, compliance and regulatory consulting services for our clients. We respect our third-party contractors and business partners and are committed to protecting your privacy and maintaining the security of your personal information. We treat personal data in accordance with applicable international, federal, state, and local data protection laws. CA is committed to being a good steward of this information and will take all the necessary steps to ensure that this information is protected. The purpose of this data privacy policy is to inform you of the personal data we may collect, how we use it, and how we protect it. If you have any questions or concerns about this privacy policy or about the controls in place to protect your personal data, please contact us at privacy@compliancearchitects.com.
This data privacy protection policy only applies to independent contractors, third-party companies, and/or other independent entities that perform work on behalf of CA for our client companies. Other CA privacy and data protection policies may be in effect for other situations, as appropriate.
CA collects and retains certain personal, and sensitive personal data (by which we mean either a special category of personal data or data relating to criminal convictions and offences, as permitted under applicable laws) that you have provided to us, about you. This data may be encrypted and/or password-protected before being saved on our systems.
The personal data and information collected may include, but are not limited to, the following information you may have provided to us:
Sensitive personal data collected that you may have provided to us may include:
This information will be collected by CA in several ways through multiple channels while working with our organization and over the duration of relationship with you:
To meet a variety of legal obligations, minimize operational risk, and ensure we work with qualified and reputable third parties at our client sites and with our clients, CA must collect and process information about you for normal staff contracting purposes. CA will not exploit this data in any way, nor will we sell or provide this data to any third party for commercial gain. The information we hold, and process will be used for our management and administrative use only. We will keep and use it to enable us to run the business and manage our relationship with you effectively, lawfully and appropriately, during your capability and skills screening, affiliation and contracting process, while you are working for us, at the time when your contract ends and after you have left. This includes using your personal data to enable us to comply with our contract with you, to comply with any legal requirements, pursue our legitimate interests and protect or defend our legal position in the event of legal proceedings. If you do not provide this data, we may be unable in some circumstances to comply with our legal or contractual obligations and we will tell you about the implications of that decision. Your willingness to contract with CA constitutes your explicit acceptance of this Data Protection and Privacy Policy, and your acknowledgement of your notice of, and considerations of the implications of, these provisions. Some of the key processing activities may include:
Monitoring for security purposes
We have implemented industry standard security measures to help us to keep our systems and business safe and secure. The security measures implemented for the processing of personal data either routinely or occasionally (as appropriate), includes, but is not limited to:
This processing is necessary for the purposes of the legitimate interests pursued by us to keep our business data and your personal data secure and confidential and in some cases to protect or defend our legal rights.
Monitoring for productivity, engagement, and performance
Business Intelligence and Analytics: We may use workplace analytics tools to monitor at the individual and aggregate level, as permitted under applicable laws, your level of engagement and key performance indicators of the services CA provides to its clients. The data we receive may be used for understanding the productivity of the team or function you are a member of and other performance indicators, such as accuracy of processing, and ultimately to serve our clients better. It is our legitimate business interest to conduct such analysis, gather business intelligence and manage productivity and performance.
Monitoring Through Email Analytics: We may use email analytics tools in order to understand the ability of our contractors across the company to come together in engaging on different projects, as permitted under applicable laws The data we receive through email analytics may be used to monitor engagement and collaboration patterns of employees and contractors, based on various parameters, such as team members they work with and projects they work on. It is our legitimate business interest to conduct such analysis to help improve employee and contractor productivity.
We may also send targeted and relevant emails to employees and contractors to effectively distribute organizational information and leadership messages. In order to assess the effectiveness of organizational information and leadership messages we may gather metrics, such email open rate, read rate and time spent on reading such emails, to understand and improve our staff’s engagement with such emails.
In the future, if we intend to process your personal data for a purpose other than that mentioned above, we will update this policy accordingly.
We may use carefully selected third parties to carry out certain activities to help us to run our business (such as payment processing, cloud service providers, IT support vendors, etc.), to facilitate your travel and expense (corporate card vendors, travel and immigration vendors), to carry out background verification (background verification agencies) and to facilitate audits (third-party auditors) and for other business critical purposes.
We have implemented industry standard security measures to keep your personal data secure and confidential, including and not limited to:
We transfer personal data to clients that maintain international business operations for the purposes described above. We may also transfer personal data to their or our third-party service providers outside of the US as described above. Your personal data may be stored in databases located outside of the US. The database may be controlled by an administrative staff located outside the US and can be accessed electronically.
Where we transfer personal data outside of US we either transfer personal data to countries that provide an adequate level of protection equivalent to what is stated within this policy, or, we have appropriate safeguards in place. Appropriate safeguards to cover these transfers are in the form of standard contractual/data protection clauses.
Where we transfer personal data outside the US we have covered these transfers by entering into standard contractual clauses in alignment with provisions mandated for privacy by the European Commission. If you would like more information on the any of the data transfer mechanisms on which we rely please contact us at privacy@compliancearchitects.com.
We store personal data in line with legal, regulatory, financial and best-practice business requirements. To ensure your availability, fit and capabilities for consulting work, your personal data will be collected, stored and processed by us before, during and after you are engaged with us. At your request, we will securely delete/destroy your records and related documents containing your personal data as soon as practicable and in line with our data retention policies, and any legal or regulatory requirements.
If you have expressed an interest in working for us in the future (e.g., under a temporary, contract or full-time arrangement) we will retain relevant records and documents containing your personal data, for future engagement-related opportunities. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at privacy@compliancearchitects.com
You have a right to:
To exercise the rights outlined above in respect of your personal data, you may submit a data subject request privacy@compliancearchitects.com
This privacy notice was updated by CA in January of 2023. To ensure you understand our current privacy practices, you are asked to review this Privacy Policy at least annually to understand your rights and participation under this policy.
The most senior executive of CA is the controller of data for the purposes of applicable legal and regulatory requirements and expectations in all jurisdictions. For more information about CA, please visit our website at https://compliancearchitects.com. This policy will always be located at the following CA website address: privacy@compliancearchitects.com
Thank you for your ongoing trust and relationship with Compliance Architects LLC.
© 2009-2025 Compliance Architects Holdings LLC – used by permission. All copyrights, trademarks and other intellectual property are the property of Compliance Architects Holdings LLC and are used by permission.