Critical Path Group logo CRITICAL PATH GROUP
    • Command
    • Azimuth
  • Methodology
  • Templates
  • Consulting
  • Pricing
  • About
  • Contact

Contents

  • Privacy Policy
  • Terms of Service

Effective Date: May 15, 2026

Privacy Policy

Last updated: May 15, 2026

1. Information We Collect

Critical Path Group, LLC ("Company," "we," "our," or "us") collects information you provide when you create an account, upload financial data, and use our platform. This includes:

  • Account Information: Name, email address, organization name, and password when you register
  • Financial Data: P&L statements, balance sheets, general ledgers, and other financial data contained in uploaded Excel templates
  • Pipeline & Contract Data: Opportunity details, deal values, contract milestones, and related business information you enter
  • Payment Information: Billing details processed securely through Stripe (we do not store credit card numbers)
  • Usage Data: IP addresses, browser type, pages visited, feature usage patterns, and session data collected automatically to improve the platform and ensure security

2. How We Use Your Information

Your data is used to provide the Command dashboard service, generate financial reports, deliver analytics insights, and maintain your account. We do not sell your personal information to third parties.

Azimuth Benchmarking (opt-in only): If you choose to participate, your data is anonymized through a one-way transformation and included in aggregate industry benchmarks. Participation requires your explicit consent, which you can provide during onboarding or at any time from Settings. Anonymized data includes only normalized percentages (margins, utilization rates), industry category, and team size range. Dollar amounts, revenue figures, organization names, and contact information are never included. Anonymized data cannot be traced back to your organization.

AI-Generated Content: The Service uses artificial intelligence to generate executive briefings, analyst commentary, financial health scores, and benchmarking insights. These outputs are derived from your uploaded data and are provided for informational purposes only. AI-Generated Content does not constitute financial, investment, tax, legal, or business advice.

3. Data Retention

We retain your data according to the following schedule:

  • User identity data: Retained while your account is active, plus 30 days after a deletion request
  • Financial data (uploads): Retained while your account is active, plus 30 days after deletion
  • Generated reports: Automatically deleted after 90 days
  • Audit logs: Retained for 1 year, then permanently deleted (PII is redacted from audit log details before storage)
  • Compliance records: Retained for 2 years per regulatory requirements
  • Session data: 24 hours for active sessions, 7 days for refresh tokens

4. Your Rights

You have the right to:

  • Delete your account: Request deletion from Settings. You have a 30-day grace period to cancel. After 30 days, all data is permanently removed.
  • Access your data: View all your uploaded data, reports, and settings through the dashboard. You may request a portable copy of your data via email to [Enable JS to see email].
  • Correct inaccurate data: You can edit your account information from Settings, or request correction of other data via email.
  • Withdraw benchmarking consent: You can withdraw consent at any time from Settings → Azimuth. Withdrawing consent stops future data contributions but does not affect already-anonymized pool data, which is no longer personally identifiable.
  • Manage cookies: You can accept or decline analytics cookies via the banner on this website. You can change your preference at any time by clicking "Cookie Settings" in the footer.
  • Lodge a complaint: You may contact your state's Attorney General or applicable consumer protection agency if you believe we have not honored your rights.

State-Specific Privacy Rights

Residents of the following U.S. states have additional rights under their state's comprehensive consumer privacy law as of 2026-01-01:

Active state laws: California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Indiana (ICDPA), Tennessee (TIPA), Montana (MCDPA), Oregon (OCPA), Texas (TDPSA), Delaware (DPDPA), New Hampshire (NHPA), Nebraska (NDPA), New Jersey (NJDPA), Kentucky (KCDPA), Maryland (MODPA), Minnesota (MCDPA), Rhode Island (RIDTPPA).

Depending on your state of residence, you may have rights to: confirm whether we process your personal data, access your data, correct inaccurate data, delete your data, obtain a portable copy, opt out of "sale" or "sharing" of your data, opt out of targeted advertising, opt out of profiling that produces legal or similarly significant effects, limit use of sensitive personal information, appeal our denial of a privacy request.

How to exercise these rights: Email [Enable JS to see email] with the subject "Privacy Request — [Your State]". We will respond within 45 days (or the timeframe required by your state's law, if shorter). We do not discriminate against you for exercising these rights.

Authorized agents: California residents may designate an authorized agent to exercise rights on their behalf, subject to verification.

5. Data Security

We protect your data with encryption at rest (AES-256) and in transit (TLS 1.3). All access is authenticated via JWT tokens with row-level security enforced at the database level, ensuring that one organization's data can never be accessed by another. Audit logs track all data access for compliance purposes. PII (email addresses, IP addresses) is automatically redacted from audit log detail fields before storage.

6. Third-Party Services (Sub-Processors)

Command by CPG uses the following third-party services to operate the platform. Each provider maintains their own privacy policies and security certifications. We have written processor agreements in place with each vendor, prohibiting use of your data outside the scope of services we contract for.

Tier 1 — Production-Critical Services

  • Neon — PostgreSQL database hosting (data storage)
  • Vercel — Frontend hosting (Next.js production)
  • Railway — Backend hosting (FastAPI production)
  • Cloudflare — DNS, edge optimization, web application firewall, static site hosting
  • Supabase — Authentication and identity management
  • Stripe — Payment processing (we do not store card data)
  • SendGrid (Twilio) — Transactional email delivery and marketing communications

Tier 2 — Operational Support Services

  • Sentry — Error monitoring and performance tracking
  • GitHub (Microsoft) — Source code hosting and continuous integration
  • Google Workspace — Internal email and document collaboration
  • Anthropic — AI inference (Claude API; powers AI Assistant, AI Briefing, AI Chart Summaries, AI Action Plans)
  • Google Analytics — Website usage analytics on this marketing site only (consent-gated; not loaded until you accept cookies; not used in the Command dashboard application)
  • HeyGen — AI avatar video generation for marketing assets only (no customer data sent)
  • Vimeo — Video hosting for public marketing assets only (no customer data hosted)

Tier 3 — Operational Support

  • iPostal1 — Virtual business address for physical mail forwarding

Sub-processor changes: If we add, remove, or substantially change a sub-processor, we will update this list and notify active customers via email at least 30 days in advance, unless an immediate change is required for security or legal reasons.

This list was last updated May 15, 2026.

7. Cookies and Tracking

This website uses Google Analytics to understand visitor behavior. Analytics cookies are not loaded until you consent via the cookie banner. If you decline, no analytics data is collected. You can change your preference at any time by clicking "Cookie Settings" in the footer.

The Command dashboard application does not use analytics cookies.

8. How We Share Your Information

We do not sell your personal information. We may share information only in these circumstances: with the service providers listed above to operate the platform, in response to lawful government requests, in the event of a merger or acquisition (with advance notice to affected users), or with your explicit consent. Anonymized, aggregate benchmarking data may be shared publicly, but it cannot be traced to any individual organization.

9. Universal Opt-Out / Global Privacy Control (GPC)

Several U.S. state privacy laws (including California's CCPA/CPRA) require businesses that "sell" or "share" personal information for cross-context behavioral advertising to honor a universal opt-out signal, such as the Global Privacy Control (GPC) browser signal.

CPG does not "sell" or "share" personal information for advertising purposes. We do not engage in cross-context behavioral advertising, do not exchange personal data with third parties for monetary or advertising consideration, and do not deploy advertising pixels or trackers on this website or in our products. Because we do not engage in any conduct that would be governed by an opt-out signal, we have nothing to opt out of.

If you transmit a Global Privacy Control signal (Sec-GPC: 1 HTTP header) to this website, we honor it as a request to confirm that no in-scope processing is occurring — consistent with the structural absence of "sale" or "share" in our data handling. We will continue to honor the signal if our practices change in the future.

For details on our data-handling posture, see Section 8 (How We Share Your Information) and Section 6 (Sub-Processors). Our internal posture documentation is reviewed at least annually.

10. Automated Decision-Making Technology (ADMT)

Several U.S. state privacy laws require businesses that use automated decision-making technology (ADMT) to make decisions affecting consumers to provide notice, allow opt-out (in some cases), and allow consumers to access information about the decision logic and contest the outcome.

The Command platform's AI features are descriptive and recommendation-only. Our AI Assistant, AI Briefing, AI Chart Summaries, and AI Action Plans analyze your own financial and operational data and present insights to you. They do not make decisions about you that have legal or similarly significant effects on you. Outputs are recommendations — you choose whether to act on them.

Azimuth's peer benchmarking presents quantile bands comparing your firm to a cohort. It does not score you, gate access, or trigger consequential decisions.

If we ever introduce a feature that does qualify as ADMT under any applicable state privacy law (for example, a feature that scores you for credit or lending, or that segments users for differential treatment), we will: (a) update this Privacy Policy with notice of the new feature, (b) describe the categories of decisions involved and the logic at a high level, (c) provide opt-out where required by law, (d) provide a path to contest decisions and request human review.

To request information about any AI-derived output that affected you, or to contest such an output, contact [Enable JS to see email].

11. Contact

For privacy-related inquiries, contact us at:

Critical Path Group, LLC
Email: [Enable JS to see email]
We will respond to your request within 30 days.

Terms of Service

1. Agreement and Acceptance

By accessing or using Critical Path Group's Services, you agree to be bound by these Terms of Service. If you do not agree to these terms, you may not use our Services. We reserve the right to modify these terms at any time. Your continued use of our Services after modifications indicates your acceptance of the updated terms.

2. Description of Services

Critical Path Group provides cloud-based software services for business operations management, planning, and decision-making. Our Services include the Command dashboard, Azimuth Intelligence, templates, and consulting services. The Services are provided on an "as-is" basis and may be updated, modified, or discontinued at any time.

3. User Accounts and Eligibility

You represent and warrant that you are at least 18 years old and have the legal authority to enter into this Agreement. You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to notify us immediately of any unauthorized use of your account.

4. Subscription Plans and Billing

Our Services are offered under various subscription tiers with different features and pricing. All subscriptions are month-to-month unless you select annual billing. You authorize us to charge the payment method you provide on the first day of each billing cycle. We will provide advance notice of any price changes and your continued use of our Services indicates acceptance of the new pricing.

5. Free Trials

We offer a 14-day free trial for new users. You will not be charged during the trial period. To continue using our Services after the trial ends, you must enter a valid payment method and select a paid plan. Your subscription will automatically renew unless you cancel before the trial expires.

6. Acceptable Use Policy

You agree not to use our Services for any illegal or unauthorized purpose. Prohibited activities include:

  • Attempting to gain unauthorized access to our systems or other users' accounts
  • Transmitting malware, viruses, or any malicious code
  • Harassment, discrimination, or abuse of other users
  • Violating intellectual property rights
  • Engaging in any form of fraud or deception
  • Violating applicable laws or regulations

7. User Content and Intellectual Property

You retain ownership of all content you upload to our Services ("User Content"). By uploading User Content, you grant us a non-exclusive, worldwide, royalty-free license to use, modify, and display your content for the purpose of providing our Services. You represent that you own or have the necessary rights to all User Content and that it does not infringe upon any third-party rights.

8. Cancellation and Refunds

You may cancel your subscription at any time from your account settings. Cancellation takes effect at the end of your current billing cycle. We do not offer refunds for partial months or unused portions of your subscription. However, you will retain access to your account through the end of your billing period. All data will be retained according to our privacy policy.

9. Limitation of Liability

To the maximum extent permitted by law, Critical Path Group shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business interruption, even if we have been advised of the possibility of such damages. Our total liability under these terms shall not exceed the amount you have paid us in the 12 months preceding the claim.

10. Warranty Disclaimer

Our Services are provided on an "as-is" and "as-available" basis. We make no warranties, express or implied, regarding the accuracy, reliability, or availability of our Services. To the maximum extent permitted by law, we disclaim all warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

11. Indemnification

You agree to indemnify, defend, and hold harmless Critical Path Group and its officers, directors, employees, and agents from any claims, damages, losses, and expenses (including attorney's fees) arising from your use of our Services, your violation of these terms, or your infringement of any third-party rights.

12. Governing Law and Dispute Resolution

These Terms of Service are governed by the laws of the United States, without regard to its conflicts of law principles. Any disputes arising from or relating to these terms shall be resolved through binding arbitration in accordance with the rules of the American Arbitration Association. You waive any right to a trial by jury or class action proceeding.

CRITICAL PATH GROUP

The shortest path from decision to execution.

Products
  • Command
  • Azimuth
  • Templates
  • Pricing
Company
  • Methodology
  • Consulting
  • About
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Settings

2026 Critical Path Group, LLC. All rights reserved.