01Introduction & Scope
Consultex is the AI-powered management consulting platform that blends human expertise with the power of AI — a model we call Fused Intelligence™. We respect your privacy and are committed to protecting personal information that you share with us or that we collect through your use of our Site and Services.
This Privacy Policy explains:
- The categories of personal information we collect and how we collect it;
- The purposes for which we use that information;
- The parties with whom we share it;
- Your rights and choices regarding your information; and
- How we protect it and how long we keep it.
This policy applies to information collected through the Site, the Consultex Platform, our applications, sales and marketing interactions, customer support, and any other channel where we present this notice. It does not apply to third-party websites or services that we link to but do not operate.
Business contracts. When Consultex acts as a service provider, processor, or business associate on behalf of a customer (for example, processing Customer Employee Data inside the Platform), our use of that data is also governed by the contract with that customer — including the Terms of Service, the EU Data Protection Addendum where applicable, and any Business Associate Agreement under HIPAA. In those cases, please refer first to the customer’s own privacy notice for how the data was collected.
02Information We Collect
Information you provide directly
We collect information you give us when you:
- Contact us or request a demo — name, business email, phone, company name, role, and the details of your inquiry;
- Subscribe to our newsletter or content — email address and any preferences you share;
- Register for the Platform — account credentials, business details, billing information, and the data you ask Robi® to analyze on your behalf;
- Apply for a job — résumé content, cover letter, contact details, work history, and anything else you choose to send;
- Attend an event or webinar — registration information and event participation data; or
- Communicate with our team — the contents of those communications, including support tickets and feedback.
Information collected automatically
When you visit the Site or use the Platform, we and our service providers automatically collect:
- Device and browser data — IP address, browser type and version, operating system, device identifiers, screen resolution, and language preference;
- Usage data — pages visited, time spent, links clicked, referring URLs, search terms, and how you interact with the Platform;
- Cookies and similar technologies — see Section 5 for details; and
- Approximate location — derived from IP address, used to localize content and prevent fraud.
Information from third parties
We may receive information about you from:
- Service providers — payment processors, identity-verification vendors, and analytics partners (e.g., aggregated usage and conversion data);
- Marketing & data partners — for prospect research, account-based marketing, and to enrich the contact information you give us;
- Public sources — LinkedIn or other professional networks where you have made information public;
- Our customers — when a customer asks us to process Customer Employee Data on its behalf inside the Platform.
Sensitive information
We do not request sensitive personal information (e.g., government IDs, financial account details beyond what’s necessary to process payments, racial or ethnic origin, health information outside an active BAA, etc.) through general Site forms. Please do not submit sensitive information unless we have asked you to do so under a written agreement. If you are a healthcare client and need to process Protected Health Information, see the HIPAA Policy.
03How We Use Information
We use the personal information we collect for the following purposes:
- Provide and operate the Services — including account creation, authentication, billing, customer support, and the agentic-execution features delivered by Robi®;
- Improve and develop the Services — including platform analytics, feature development, model performance, and quality assurance;
- Communicate with you — including responses to inquiries, transactional messages (e.g., invoices, security alerts), product updates, and — if you opt in — marketing emails;
- Personalize your experience — including content recommendations and tailored Site behavior;
- Marketing and advertising — including outreach to prospects, measurement of marketing campaigns, and remarketing where permitted by law;
- Hiring and recruitment — including evaluating job applications and onboarding new hires;
- Security, fraud, and abuse prevention — including monitoring for suspicious activity, enforcing our Terms of Service, and protecting our customers and ourselves;
- Legal compliance — including responding to lawful requests from public authorities, exercising or defending legal claims, and complying with our obligations under applicable law;
- With your consent — for any other purpose disclosed at the time of collection.
Where required by applicable law, we will rely on a lawful basis to process your personal information, including (a) performance of a contract with you; (b) compliance with a legal obligation; (c) our legitimate interests (balanced against your rights); or (d) your consent.
04How We Share Information
We share personal information only as described below. We do not sell personal information for monetary consideration.
Vendors and contractors that perform services on our behalf — including cloud infrastructure (Microsoft Azure), email and communications providers, payment processors, analytics platforms, customer-support tools, and security vendors. These parties are bound by written agreements that limit their use of personal information to providing services to us.
If you use the Platform as an authorized user of a customer organization, we may share information about your use with that customer’s administrators in line with the customer’s instructions and contract.
We may share information with our parent, subsidiary, or affiliated entities for the purposes described in this policy. In the event of a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, personal information may be transferred as part of the transaction.
We may disclose information when we believe in good faith that disclosure is required by law, regulation, court order, or other legal process; to protect the rights, property, or safety of Consultex, our customers, or others; to investigate fraud or security incidents; or to enforce our agreements.
Any other sharing that we describe at the point of collection and that you authorize.
Aggregated and de-identified data. We may share aggregated or de-identified information that cannot reasonably be used to identify you for any purpose permitted by law.
05Cookies & Tracking
We and our service providers use cookies, web beacons, pixels, and similar technologies to operate and improve the Site and the Services. These technologies fall into the following categories:
Required for core Site functions — including authentication, session management, security, and load balancing. These cannot be disabled.
Help us understand how visitors use the Site so we can improve it. We use aggregated and de-identified data wherever possible.
Remember your preferences (e.g., language, region) and personalize the experience.
Used (where permitted by law) to measure marketing campaigns and serve relevant content on this Site and third-party sites.
Your choices. Most browsers let you refuse cookies or alert you when cookies are being sent. If you decline cookies, some portions of the Site may not function as intended. You can also opt out of certain marketing cookies through industry tools (e.g., the Digital Advertising Alliance, the European Interactive Digital Advertising Alliance), or by adjusting your settings in our cookie banner where available.
We honor browser-based opt-out signals such as Global Privacy Control (GPC) where required by law.
06Data Retention
We retain personal information only as long as needed for the purposes described in this policy, to comply with legal and tax obligations, to resolve disputes, and to enforce our agreements. When we no longer need information, we delete or de-identify it, subject to our backup and disaster-recovery cycles.
Some specific retention rules:
- Customer Employee Data — if a customer cancels its account or becomes inactive due to past-due amounts, we may delete Customer Employee Data after a period of 2 months, per the Terms of Service.
- Marketing prospects — retained until you unsubscribe or, where required, for the period prescribed by applicable law.
- HIPAA records — maintained for at least six (6) years per the HIPAA Policy.
- Financial records — retained for the period required by tax, accounting, and audit obligations.
07Your Privacy Rights
Depending on where you live, you may have rights under applicable privacy laws — including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and similar laws in other US states (Virginia, Colorado, Connecticut, Utah, and others). These rights generally include:
- Access — request a copy of the personal information we hold about you;
- Correction — request that we correct inaccurate or incomplete information;
- Deletion — request that we delete certain personal information;
- Portability — receive a copy of your information in a structured, machine-readable format;
- Restriction or objection — ask us to limit our processing or object to processing based on our legitimate interests;
- Opt-out of sale or sharing for cross-context behavioral advertising — even though Consultex does not sell personal information, you may exercise this right by submitting a request;
- Withdraw consent — where processing is based on consent, you may withdraw it at any time;
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
To exercise these rights, email legal@consultexai.com with the subject line “Privacy Rights Request.” We will verify your identity before fulfilling the request and respond within the timeframe required by applicable law.
EU/UK residents (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described above and the right to lodge a complaint with your local supervisory authority. Consultex’s legal basis for processing varies by activity and is described in Section 3.
California residents (CCPA/CPRA)
California residents have the rights to know, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information. We do not sell personal information and have not done so in the preceding 12 months. We do not knowingly use or disclose sensitive personal information beyond the purposes permitted by law.
You may designate an authorized agent to make a request on your behalf. We may require verification of the agent’s authority.
08International Transfers
Consultex is headquartered in the United States and our infrastructure runs on Microsoft Azure across multiple regions. When you use our Site or Services, your information may be transferred to, processed, and stored in countries other than your country of residence, including the United States.
Where required, we rely on appropriate safeguards for cross-border transfers — including the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and the EU-US Data Privacy Framework (where applicable). Business customers with EU/UK data-protection obligations should request our EU Data Protection Addendum by emailing legal@consultexai.com.
09Children’s Privacy
The Site and Services are intended for business use and are not directed to children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected information from a child under 13, please contact legal@consultexai.com and we will take prompt steps to delete it.
10Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our security program includes:
- SOC 2 Type II independent audit (AICPA Trust Services Criteria);
- AES-256 encryption at rest and TLS 1.3 encryption in transit;
- Role-based access control (RBAC) and zero-trust architecture;
- Automated PII redaction for AI model interactions;
- Multi-tenancy isolation between customer environments; and
- Continuous monitoring, logging, and audit trails.
For the full security posture, see the Security page. No method of transmission or storage is 100% secure — while we work hard to protect your information, we cannot guarantee absolute security.
11Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other reasons. The “Last updated” date at the top of this page indicates when the policy was last revised. For material changes, we will provide additional notice (for example, by email to account holders or a prominent notice on the Site). Your continued use of the Site or Services after the effective date of any update constitutes your acceptance of the revised policy.
12Contact Us
If you have questions, concerns, or requests about this Privacy Policy or our privacy practices, please contact us at:
- Email — legal@consultexai.com (privacy requests, EU DPA & SCCs)
- General support — support@consultexai.com
- Security & vulnerability reports — security@consultexai.com
- Phone — (866) 261-6030 (Monday–Friday, 9am–5pm)
EU/UK residents may also contact our representative or local supervisory authority. Customers under a Business Associate Agreement should refer to the HIPAA Policy for additional procedures specific to Protected Health Information.