Priority Governance
Legal

Privacy Policy

prioritygovernance.com | Site · Effective August 2, 2026 | Last updated September 1, 2026

This Privacy Policy explains how Priority Governance collects, uses, discloses, retains, and protects personal information when you visit prioritygovernance.com; submit the free AI Governance QuickScan; purchase or download the AI Governance Starter Kit; book or participate in an AI Governance QuickStart Workshop; subscribe to or use Control Center; communicate with us; or otherwise use our website and related services (collectively, the “Services”).

Priority Governance is operated from Colorado, United States. In this Policy, “Priority Governance,” “we,” “us,” and “our” refer to the operator of prioritygovernance.com. This Policy does not apply to the independent practices of third-party websites or services.

1. Notice at collection

The following table summarizes the categories of personal information we may collect, why we collect them, and the types of recipients to which they may be disclosed for business purposes. The categories listed describe our practices during the 12 months preceding this Policy and the information we expect to continue collecting.

CategoryExamplesPrimary purposesBusiness-purpose recipients
Identifiers and contact informationName, email address, organization, website, role, billing contact, transaction and verification identifiersVerify submissions; provide results; process purchases; deliver downloads; schedule and provide Workshops; support and communicateHosting, database, email, payment, scheduling, file-delivery, video-meeting, security, and professional-service providers
Organization and professional informationIndustry, organization-size band, buyer market, role, participant role, business triggerScore and contextualize the QuickScan; prepare Workshop materials; provide and improve ServicesThe providers and authorized personnel needed to deliver the Services
Assessment and governance informationAnswers to 21 questions, “Not sure” flags, trigger selections, Readiness Level, pillar results, recommendations, high-level pre-work, decisions, action owners, evidence referencesGenerate results; facilitate the Workshop; prepare requested outputs; support the organization; improve the ServicesAuthorized personnel and service providers supporting the requested Service
Commercial and transaction informationProduct purchased, amount, discount, tax, payment status, transaction identifier, download status, booking and support historyProcess and document orders; provide access; prevent fraud; support purchasers; maintain accounting and legal recordsPayment, tax, accounting, email, file-delivery, hosting, database, and professional-service providers
Internet and technical informationRaw IP addresses in provider logs; pseudonymous IP-derived identifier in the application database; browser, device, pages, timestamps, request headers, delivery events, and diagnostic informationDeliver, secure, troubleshoot, verify, and protect the ServicesHosting, network, database, email, payment, file-delivery, and security providers
Control Center governance informationOrganization profile and size band, roles and titles, AI tools and environments in use, information categories, existing policies and restrictions, governance priorities, approval responsibilities, governance decisions, approvals and typed signatures, review schedules, activation progress, and guidance-request metadataConfigure and operate Control Center for the organization; record and maintain its governance decisions and approved baseline; support, secure, and improve the serviceHosting, database, email, and security providers; authorized personnel; and, where the optional guidance layer is enabled, an AI provider
Communications and Workshop contentEmails, support requests, questionnaire answers, participant details, session notes, corrections, feedback, and testimonial permissionsRespond; provide and improve Services; prepare deliverables; maintain preferences and recordsAuthorized personnel, communications and meeting providers, and professional advisors as needed

We do not sell personal information and do not share personal information for cross-context behavioral advertising. See Section 13.

2. Information you provide through the QuickScan

When you submit the QuickScan, we collect:

Organization name and website.

Industry and organization-size band.

Respondent name, email address, and role or title. All three are optional.

Selections indicating whether the organization sells into regulated, enterprise, or public-sector markets.

Multiple-choice answers to 21 assessment questions, including “Not sure” selections.

Selections describing what prompted the scan.

Your choices about contact concerning your results, related products or services, and a possible future testimonial request.

Records showing the Terms, Privacy Policy, methodology, consent, and other versions associated with the submission.

The QuickScan has no substantive free-text assessment field and does not accept document uploads.

3. Email address handling

The QuickScan may be completed without providing an email address. If you choose to provide one, it must be in a valid email format. We do not restrict the address to a business or organizational domain, and we do not reject free or personal email domains.

We do not currently send a verification link or code for the QuickScan, and completing the QuickScan does not trigger an automated email. If we introduce email verification, we will process the email address, verification status, send and verification timestamps, provider message identifier, delivery or bounce status, and related security metadata, and this policy will be updated before that happens.

Any verification or service message would be transactional. Providing an email address alone does not enroll you in marketing communications.

4. Purchase, payment, and download information

When you purchase a Starter Kit, Workshop, or another paid Service, we or our providers may collect:

Purchaser and billing contact information.

Organization name and email address.

Product, price, discount, tax, currency, payment status, and transaction identifiers.

Billing address or tax-location information when required.

Order confirmation, delivery, download-link, download-status, and support records.

Fraud, chargeback, refund, and dispute information.

Payment-card and bank-account information is collected and processed by the payment provider. Priority Governance does not need to store full payment-card or bank-account numbers in its application database. We may receive limited payment details, such as payment type, last four digits, expiration information, billing country, transaction identifier, and payment status, as provided by the processor.

5. Workshop and scheduling information

When you book, prepare for, or participate in a Workshop, we may collect:

Participant names, email addresses, roles, and organization.

Scheduling details, time zone, meeting link, attendance, reminders, and rescheduling history.

The organization’s QuickScan results and selected priorities.

High-level pre-session questionnaire responses, business trigger, target outcome, approved-tool names, policy or inventory status, deadlines, and advisor involvement.

Decisions, action items, owners, due dates, limitations, evidence references, corrections, and requested deliverables.

Communications, feedback, and support requests.

The standard Workshop does not require sensitive customer, employee, health, financial, credential, contract, source-code, production-log, privileged, or regulated records. Describe data categories and workflows rather than providing the underlying data.

Priority Governance does not record a Workshop unless recording is disclosed in advance and authorized as required. If a Workshop is recorded under a separate agreement, we will provide additional notice concerning the recording, purpose, access, and retention.

6. Information collected automatically

Our application database stores submission timestamps, record metadata, consent and methodology versions, and a pseudonymous one-way identifier derived from the submitting device’s IP address. The application submission record does not store the raw IP address. We use the IP-derived identifier for security, abuse prevention, submission integrity, rate limiting, and troubleshooting.

Our hosting, network, database, email, payment, scheduling, file-delivery, video-meeting, and security providers may process technical information in operational logs, such as raw IP address, browser or device type, requested pages, timestamps, referrer information, request headers, payment or delivery events, and diagnostic or security information. Their handling and retention depend on our configurations, their services, and applicable law.

7. Information we do not request through the QuickScan

Do not submit passwords, credentials, access tokens, Social Security numbers, government identifiers, payment-card or bank information, protected health information, children’s personal information, sensitive employee or customer records, privileged communications, confidential contracts, restricted source code, production logs, trade secrets, security vulnerabilities, or third-party information you are not authorized to disclose.

The QuickScan does not provide user accounts and does not collect account passwords. Paid Services may use purchase confirmations, download links, scheduling links, or provider-hosted pages rather than a Priority Governance user account.

8. How we use information

We use personal information to:

Check the format of an email address, where one is provided, and associate it with a submission.

Receive, process, score, and display QuickScan results.

Generate the Policy Starter Outline and question-level recommendations.

Process orders, payments, discounts, taxes, refunds, disputes, and accounting records.

Deliver downloadable products and provide delivery support.

Schedule, prepare for, facilitate, document, and follow up on Workshops.

Create requested Decision Logs, 30-Day Roadmaps, Leadership Summaries, and related outputs.

Communicate about results or related products and services when requested or permitted.

Send transactional, service, security, legal, purchase, booking, and delivery communications.

Ask whether you would like to provide feedback or a testimonial when separately permitted.

Operate, maintain, troubleshoot, secure, and prevent misuse of the Services.

Maintain records of consent, Terms acceptance, policy versions, submissions, orders, licenses, requests, and communications.

Improve the QuickScan, scoring methodology, content, products, Workshops, and user experience.

Create aggregated or de-identified internal insights intended not to identify a respondent or organization.

Enforce our agreements, resolve disputes, comply with law, and protect rights, safety, and security.

9. Automated scoring and AI-model use

QuickScan scoring and generation of the on-screen Readiness Level, pillar results, and Policy Starter Outline are deterministic and based on selected answers. No external AI model currently receives or processes QuickScan submissions for scoring or generation.

Control Center works the same way. The governance options its Governance Guidance Assistant presents — the outcome each option produces, the conditions attached to it, and who approves it — are generated deterministically from the organization’s own configuration. An optional AI layer may be used only to improve the wording of options that already exist; it is off by default, it is not currently enabled, and it does not select, change, or approve any governance outcome. Section 25 describes what that layer receives when it is enabled.

We do not use QuickScan submissions, purchaser information, Workshop inputs, Control Center governance records, activation information, guidance requests, or customer-specific deliverables to train a public AI model.

Priority Governance may use software-assisted drafting and editing tools to create or maintain its general, non-customer-specific content. If we later use an external AI provider to process identifiable customer submissions or Workshop content, we will evaluate the provider, update this Policy, and provide any notice or choice required before that processing begins.

The QuickScan does not make employment, credit, housing, insurance, education, healthcare, legal, or similarly consequential decisions about individuals. Its score is an informational, organization-level self-assessment result.

10. Legal bases for international users

Where a law such as the EU or UK GDPR requires a legal basis, we rely on one or more of the following, depending on the processing:

Contract: to provide a QuickScan you request, process a purchase, deliver a product, schedule or provide a Workshop, and support the applicable Service.

Consent: for optional marketing contact, a testimonial request, or another activity for which we specifically request consent. You may withdraw consent prospectively.

Legitimate interests: to secure and improve the Services, prevent fraud and abuse, maintain business records, communicate with organizational users, understand service performance, and establish or defend legal claims, balanced against affected rights.

Legal obligation: to comply with tax, accounting, law-enforcement, court, regulatory, and other legal requirements.

We do not use consent as the basis for necessary transactional processing when another basis applies.

11. How we disclose information

We disclose personal information only as described in this Policy:

Service providers: Providers that host, store, transmit, authenticate, secure, process payments, deliver email or files, schedule meetings, provide video conferencing, calculate tax, support accounting, or otherwise support the Services. Current core infrastructure includes Supabase for the submission database and administrative authentication and Vercel for application hosting and delivery. A transactional email provider may support service communications. Paid Services may add payment, scheduling, file-delivery, and video-meeting providers.

AI provider for the optional guidance layer: The Governance Guidance Assistant in Control Center can operate entirely without an AI provider, and does so today. Where the optional wording layer is enabled, a third-party AI provider processes the structured governance metadata described in Section 25 in order to return re-worded option text. The provider currently configured for that layer is Anthropic. The layer is off by default and is not currently enabled; if we change the provider or enable the layer for a customer, we will update this Policy and tell the customer that a model may re-word option text.

Authorized personnel and contractors: People who need information to provide a requested Service, prepare deliverables, support users, maintain the system, or protect the Services.

Professional advisors: Attorneys, accountants, auditors, insurers, consultants, and other advisors subject to appropriate duties of confidentiality.

Legal and safety purposes: When we reasonably believe disclosure is required by law or necessary to protect rights, investigate fraud or misuse, enforce agreements, respond to lawful requests, or protect safety and security.

Business transactions: In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law.

At your direction: When you direct, authorize, or request the disclosure.

We require service providers to process information for the services they provide to us, subject to contractual and legal obligations appropriate to their role.

12. Third-party pages and services

A checkout, payment, scheduling, video-meeting, or file-delivery page may be operated by a third party. That provider may collect information directly under its own privacy policy in addition to processing information for Priority Governance. Review the provider’s notices when using its page.

Priority Governance is not responsible for the independent practices of a third-party website that is not acting as our service provider.

13. Sale, targeted advertising, analytics, and cookies

Priority Governance does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not currently use advertising cookies, advertising pixels, or third-party targeted-advertising analytics on the QuickScan.

The site uses strictly necessary technologies and limited operational logs required to deliver, secure, verify, sell, and support the Services. A third-party checkout, scheduling, or video-meeting page may use necessary or optional technologies under that provider’s policy and settings.

If we introduce nonessential analytics, advertising technologies, or cookies, we will update this Policy and provide any notice, consent mechanism, Global Privacy Control response, or opt-out required before activation.

14. Communications and choices

You may receive transactional, purchase, download, booking, Workshop, service, security, or legal communications necessary to provide an interaction you requested.

We may contact you about your results or related Priority Governance products and services when you request or permit that contact or when another lawful basis allows an appropriate business communication. Marketing messages will identify the sender and provide a working unsubscribe method and other information required by applicable law.

You may opt out of marketing by using the unsubscribe method, replying with your request, or emailing support@prioritygovernance.com. We will process the request within the period required by law. Opting out of marketing does not stop necessary transactional or legal communications.

Permission to request a testimonial does not authorize publication. We obtain separate approval before publishing an identifiable testimonial, organization name, logo, quotation, score, or case study.

15. Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, considering the Service requested, relationship duration, security needs, legal obligations, dispute periods, and whether information can be de-identified. In general:

QuickScan submissions and generated outputs: Retained while needed to provide and support results, maintain submission and consent records, improve the Services, and support related customer interactions, then deleted or de-identified unless a dispute, security matter, legal obligation, or active customer relationship requires longer retention.

Email-verification data: We do not currently send verification messages, so no verification tokens or codes are generated. If email verification is introduced, tokens or codes will be short-lived and will be invalidated, deleted, or rendered unusable after verification or expiration, and verification status and related evidence may remain with the submission and consent record.

Purchase and license records: Retained for the period needed to provide access and support, establish the license, prevent fraud, handle refunds or chargebacks, and satisfy tax, accounting, contract, and legal requirements.

Workshop inputs and customer-specific deliverables: Retained while needed to prepare, deliver, correct, and support the Workshop and maintain appropriate business records, then deleted or de-identified unless the customer requests continued retention, the parties agree otherwise, or law or a dispute requires longer retention.

Control Center governance records: Governance decisions, the AI inventory and environment records, roles, information categories, rules, actions and risks, exceptions, evidence references, review records, approvals, and approved baselines are an organization’s governance history, and they are the longest-lived Control Center information. They are retained for the subscription and for the period stated in the applicable order or agreement, then deleted, or deleted earlier on the organization’s written request, subject to the exceptions and residual-copy limits described in this Policy.

Control Center event and usage metadata: Governance event records and guidance-request usage records are operational metadata with a shorter life than governance records, and they are kept separately from them. The retention period applied to governance event telemetry is 90 days. Deleting this metadata does not remove the governance records it relates to: an approved decision survives the record of the request that helped produce it. Deletion under these periods is carried out by Priority Governance and is not necessarily immediate at the moment a period ends.

Communications and preferences: Retained while needed to respond, provide Services, document requests and opt-outs, and maintain business records.

Security and operational logs: Retained according to security needs, system configurations, provider practices, and legal requirements.

Backups: Residual copies may remain for a limited period until overwritten or expired through the ordinary backup cycle.

De-identified or aggregated information: May be retained for research, measurement, security, and service improvement when it is not reasonably linkable to a respondent or organization.

Counsel and Priority Governance will periodically review retention criteria and operational deletion schedules.

16. Privacy requests available to everyone

Regardless of where you live, you may request:

Access to personal information associated with you.

Correction of inaccurate personal information.

Deletion of personal information.

A copy of information you provided in a reasonably portable format.

Withdrawal of optional contact permission.

Objection to or restriction of certain processing where applicable.

Submit a request to support@prioritygovernance.com, preferably from the email address used for the QuickScan or purchase. Because the site may not use a customer account, we may request information reasonably necessary to verify the request and protect the organization and other individuals.

We may deny or limit a request when an applicable exception permits or requires us to protect other people, maintain security, prevent fraud, comply with law, preserve tax or transaction records, establish or defend legal claims, or retain information validly de-identified. We will respond within the period required by applicable law.

If applicable law provides a right to appeal, you may appeal by replying to our decision or emailing the same address with “Privacy Appeal” in the subject line.

17. Jurisdiction-specific rights

Depending on your location and whether a law applies to Priority Governance’s activities, you may have additional rights concerning access, correction, deletion, portability, objection, restriction, withdrawal of consent, appeal, or opting out of sale, targeted advertising, sharing, or certain profiling.

Residents of Colorado and California may have rights described by their respective privacy laws when the law applies. Individuals in the European Economic Area or United Kingdom may also have the right to lodge a complaint with the data-protection authority in their location.

We do not discriminate against a person for exercising an applicable privacy right. Sale and targeted-advertising opt-outs are not currently needed for our stated practices because we do not engage in those activities. If our practices change, we will provide the required opt-out methods and recognize applicable browser-based preference signals.

18. Deletion mechanics

The administrative system supports deletion of QuickScan submissions from the active database. Deleting information from the active database may not immediately remove residual copies from security logs, transaction records, email records, legal records, completed deliverables, or backups. Those copies are handled through their applicable retention cycles and legal exceptions.

Where feasible and legally permitted, we will instruct relevant service providers to delete or return information covered by a valid request.

19. Security

We use administrative, technical, and organizational safeguards designed to protect personal information. Current measures include server-side submission processing, restricted administrative access, default-deny public database access, administrator email allowlisting, data minimization, and an IP-derived pseudonymous security identifier rather than storage of raw IP addresses in application submission records.

Control Center records are scoped to a single organization on every read and write. Administrative access is limited to allowlisted Priority Governance personnel, and a client completes activation through a time-limited, revocable link rather than a user account. The application also limits what a Control Center record may contain, as described in Sections 23 and 25.

Additional paid-service providers are selected and configured based on the functions they perform. No method of transmission, payment, meeting, download, storage, or security is completely secure, and we cannot guarantee absolute security.

20. International access and transfers

Priority Governance operates from the United States. Our providers may process information in the United States and other locations where they operate. If you access the Services from outside the United States, your information may be transferred to a country whose data-protection laws differ from those in your location.

Where legally required, we will use an approved transfer mechanism or other recognized safeguard. Contact us for additional information about an applicable transfer mechanism.

21. Children

The Services are intended for adults acting in a business or organizational capacity and are not directed to children. You must be at least 18 to submit the QuickScan, purchase a Service, or participate as the booking customer. We do not knowingly collect personal information from children. If you believe a child submitted personal information, contact support@prioritygovernance.com so we can investigate and take appropriate action.

22. Information for Fractional and professional-services clients

If your organization engages Priority Governance for the ongoing Fractional AI Governance service described in the Terms, we collect and maintain additional information needed to provide that service under the separately signed services agreement. This information may include:

Client organization and contact information, including the named Internal Governance Liaison and Leadership Sponsor and other participants your organization designates.

Meeting, scheduling, and attendance information for the kickoff and recurring governance check-ins.

The governance records we maintain for your organization, which may include an AI-tool inventory, use-case register, vendor-review notes, a decision log, an action-and-risk register, an exceptions or incident record, a review schedule, and links or references to evidence your organization identifies.

Decisions, action items, owners, and due dates recorded during the engagement.

Communications, service and support records, feedback, and, where separately permitted, testimonial approvals.

Contract and billing records for the engagement, such as the signed agreement, invoices, payment status, and related transaction identifiers, handled as described in Section 4.

The Fractional service is designed to operate on governance-level information — descriptions of tools, workflows, data categories, decisions, and controls — rather than on your underlying sensitive operational data. Consistent with Sections 5 and 7 and the applicable services agreement, we do not require you to submit sensitive customer, employee, health, financial, credential, contract, source-code, production-log, privileged, or regulated records to receive the normal service. When a specific situation must be discussed, describe the data category and workflow rather than providing the underlying records.

As set out in the services agreement, your organization owns the organization-specific governance records populated for it, and Priority Governance retains its methods, frameworks, templates, and scoring logic. We use engagement information to provide, coordinate, document, and support the service and to maintain appropriate business records, and we retain it as described in Section 15 and the signed agreement.

Control Center is included while Fractional AI Governance is active, and it is the working surface for the engagement. Where your organization’s governance records are maintained in Control Center, Sections 23 through 26 also apply to them.

23. Control Center and Guided Activation information

Control Center is a subscription service in which an organization keeps its AI-governance records with Priority Governance. A subscription begins with Guided Activation, the structured process that configures Control Center around the organization. This Section and Sections 24 through 26 describe the information involved; the Terms of Service describe the service itself.

Guided Activation collects:

Organization information — the organization’s name and legal name, its approximate size or size band, its industry or practice type, and the governance priorities it states in its own words.

Roles — the job functions the organization’s AI rules apply to, and whether each is in use. These are the organization’s own roles, not Priority Governance accounts.

AI tools and environments — the AI tools and services in use, the vendor, how each is used today, whether the account is organization-managed or personal, the plan or workspace label, who administers it, restrictions already in place, and whether the AI is embedded in software the organization already uses.

Information categories — the categories of information the organization handles, in its own labels and definitions, and which of them are in use.

Activities — the kinds of AI use the organization wants to govern.

Existing policies and practices — whether a written AI policy exists and where it is kept, what staff have been told, tools or uses already prohibited or restricted, whether an approval process exists, and who approves new tools and exceptions.

Approval responsibilities and governance contacts — the governance owner, the Internal Governance Liaison, the approver and exception-approver roles, an escalation contact, and the chosen review cadence, including names and titles where the organization provides them.

Governance decisions — the questions the organization decides, the options presented, the option selected, any note the organization adds, the outcome and conditions proposed, who approved it, and the rule the approved decision produced.

Review scheduling and activation progress — what is scheduled for review and when, which parts of activation are complete, which questions are still with Priority Governance, and when the activation was started, submitted, reviewed, and approved.

Control Center records the information the organization provides. It does not inspect the organization’s systems, accounts, devices, networks, documents, or AI activity to gather or verify that information, and it does not determine whether information legally qualifies as privileged, confidential, or subject to any regulatory category. The organization and its own advisors make those determinations; Control Center records and operationalizes them.

Control Center is designed to hold governance information about an organization’s AI use rather than the material being governed. It does not collect prompts entered into AI tools, model responses, document or file contents, client matter contents, privileged communications, email or message contents, browsing history, raw web addresses, screenshots, clipboard contents, keystrokes, passwords, credentials, or API keys. There is no field for that information, and a record carrying one is rejected by the application. Consistent with Sections 5 and 7, describe the category of information and the workflow rather than providing the underlying records.

Two activation fields — the organization’s stated governance priorities and the restrictions it already has in place — are free-text boxes completed by the organization in its own words, because a governance program has to reflect what an organization actually does. Each carries guidance not to include sensitive material and the length is limited, but what is typed into them is stored as entered.

24. Control Center approval evidence and activation links

When a person approves a governance decision or completes organization sign-off, Control Center records the approver’s name and title, the organization name, the statement approved, a typed signature, and the date and time. That record is the organization’s evidence of its own approval, and it is kept as approved rather than rewritten afterwards.

Where technical evidence is retained with an approval, it is limited to browser information and a one-way identifier derived from the submitting device’s IP address. Consistent with Section 6, the raw IP address is not stored in the approval record.

Activation may be completed with Priority Governance directly or through a link issued to the organization. Only a one-way hash of the link’s token is stored, never the token itself, so the stored record cannot be used to reconstruct a working link. A link expires after a set period, can be revoked at any time, and closes automatically once the organization has completed approval, so it cannot be used afterwards to change what was approved.

Because the token forms part of the link address, it may appear in ordinary web-server, hosting, or infrastructure request logs and in the browser history of anyone who opens it, in the same way as any other web address. Storing only a hash protects the stored record; it does not make the link itself secret. Treat an activation link as private: send it only to people authorized to complete activation for the organization, and ask us to revoke it if it is misdirected.

25. Governance Guidance Assistant and guidance-usage records

Control Center includes a Governance Guidance Assistant that explains the options available at a governance question. As described in Section 9, the options themselves are generated deterministically. An optional AI layer may be used only to improve the wording of options that already exist. It is off by default and is not currently enabled. Where it is enabled, the third-party AI provider identified in Section 11 processes the information described below.

What that layer receives is structured governance metadata: the organization type and size band, the organization’s stated governance priorities, the role, the AI environment with its posture and whether it has been approved, the information category, the activity, restrictions the organization has already recorded, related governance decisions already made expressed in plain language, and the governance question itself.

Control Center is designed to use structured governance metadata for guidance rather than the underlying documents, prompts, or client matter content being governed. It is designed not to send prompts entered into other AI tools, model responses, document or file contents, client matter contents, privileged communications, email or message contents, raw web addresses, browsing history, screenshots, clipboard contents, keystrokes, passwords, credentials, or API keys. The fields a guidance request may carry are enumerated in the application, and a request carrying anything else is rejected before it is sent.

Two of the permitted fields — the organization’s stated governance priorities and the restrictions it already has in place — are written by the organization in its own words. If sensitive material is typed into one of them, it would form part of the metadata sent while the AI layer is enabled. That is why those fields carry guidance against it, and why this is described as a designed limit on what the service sends rather than a guarantee about what a person types.

Control Center keeps an internal record of guidance requests so we can operate the service and understand what it costs to run. Each record contains only: the organization and, where there is one, the activation it belongs to; the question key, which identifies which governance question was asked and never its wording; the date and time; whether the request was answered deterministically or with the AI layer; the model name; input and output token counts; an estimated cost; how long the request took; and whether it succeeded.

These records contain no prompts, no model output, no option or guidance text, no document or matter contents, and no privileged communications. We use them for service operation, performance, reliability, cost management, and product improvement. The estimated cost is an internal planning figure calculated from published vendor rates; it is not an amount charged to anyone, it is not a price, and it is not shown to customers.

26. Workplace and staff information in Control Center

Control Center records how an organization governs AI use: the roles its rules apply to, the policies and restrictions it has set, who approves what, the decisions and exceptions it has made, and the review schedule. It records governance about roles and named responsibilities. It does not monitor devices, read documents, messages, or prompts, capture browsing history, or track an individual’s activity inside an AI tool.

Where governance information identifies an individual — a governance owner, an Internal Governance Liaison, an approver, or a person named in a decision or an exception — Priority Governance processes that information to provide the service to the organization and to maintain its governance records.

Priority Governance provides transparent product and privacy information, including this Policy, so that an organization can explain to its people what Control Center holds and why. The organization determines its own employment and privacy notice obligations, what it tells its staff, whether it is authorized to deploy any workplace control it chooses to adopt, and when to seek specialist or legal advice on those questions. We will provide the product information needed to support that; we do not make those determinations for the organization.

27. Changes to this Policy

We may update this Policy to reflect changes in our Services, providers, practices, or legal obligations. We will post the revised Policy with a new effective date. If a change materially expands how we use previously collected personal information, we will provide additional notice or obtain consent when required. We will not quietly repurpose previously collected information for a materially incompatible purpose.

28. Contact

Questions, privacy requests, appeals, or concerns may be sent to support@prioritygovernance.com.

Priority Governance operates from Colorado, United States.