Back to Home

Privacy Policy

Effective date: June 20, 2026

This version is no longer in effect.

It was in force until September 7, 2026 and is kept here as a dated record of what was published at the time. For the policy that applies now, see the current version.

Utah Safety Institute, LLC, doing business as Critical Dynamics Risk Management ("CDRisk," "we," "us," or "our"), respects your privacy. This Policy explains what personal information we collect through our website, client portal, and inspection applications, how we use and share it, and the choices and rights you have.

1. Information we collect

Information you provide. When you contact us, request a quote or free assessment, book training, sign up for a program, or create a portal account, we collect details such as your name, business name and role, email address, phone number, mailing address, the contents of your messages, and account credentials. If you purchase a service, our payment processor collects your payment card and billing details (we do not store full card numbers).

Inspection and service data. In the course of providing audits, inspections, and safety programs, we collect facility and equipment information, inspection responses and findings, compliance documentation, signatures, and photographs taken during inspections.

Information collected automatically. When you use our site we collect technical and usage data, including browser and device type, the pages and screens you view, links and buttons you click, scroll depth, time on page, referring sites, search terms used on our site, form interactions (which fields are used and whether a form is completed — not the contents of fields you do not submit), and an approximate location (such as country or region) derived from your IP address. We collect this through privacy-friendly, cookieless first-party analytics. We do not store your IP address in our analytics records and do not use this data to identify you individually. See our Cookie Policy.

Information from third parties. We may receive information from your employer or the organization that engaged us, from carriers or third-party administrators who refer audit work, and from service providers that help us operate.

2. How we use your information

We use personal information to:

  • Provide, perform, and improve our risk audits, inspections, training, and safety programs;
  • Create and administer accounts and the client portal, and authenticate users;
  • Generate inspection reports, certificates, and compliance documentation;
  • Process payments, subscriptions, and bookings;
  • Communicate with you about services, scheduling, support, and account or security notices;
  • Send marketing communications where permitted (you can opt out at any time);
  • Measure and analyze site usage and interactions in aggregate — including with the help of third-party AI tools — to understand performance and improve our marketing and our services;
  • Maintain the security and integrity of our systems and prevent fraud and abuse;
  • Comply with legal, regulatory, and contractual obligations.

We use this information only for our own internal purposes. We do not sell it, and we do not share it for cross-context behavioral advertising.

3. Text messages (SMS)

If you provide your mobile number and opt in, we may send service-related and notification text messages (for example, scheduling, inspection, or portal-message alerts) through our messaging provider. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for help. Mobile opt-in data and consent are not shared with third parties for their own marketing.

4. How we share your information

We do not sell your personal information. We share it only as described here:

  • Service providers (subprocessors) who process information on our behalf under contract, listed below;
  • The organization that engaged us, where inspection or program results are delivered to your employer or client;
  • Legal and safety — to comply with law, respond to lawful requests, enforce our agreements, or protect the rights, safety, and property of any person (including emergency responders in a safety emergency);
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

Service providers we use:

  • Vercel Inc.Website and client portal hosting (privacy policy).
  • Railway Corp.Application and database hosting (privacy policy).
  • Cloudflare, Inc.File, photo, and backup storage (R2), content delivery, and security (privacy policy).
  • ResendEmail delivery, including inbound mail for our mailboxes (privacy policy).
  • Stripe, Inc.Payments and subscriptions (privacy policy).
  • Google LLC (reCAPTCHA)Abuse prevention on our forms; a script font on our signature widget (privacy policy).
  • ExpoMobile push-notification delivery (privacy policy).
  • Anthropic, PBCAI services supporting analysis and product features (privacy policy).

Used only in some circumstances:

  • Sent (sent.dm)SMS and text-message notifications, when your organization enables text notifications (privacy policy).
  • Apple Inc. (iCloud CalDAV)Calendar sync for inspection scheduling, when calendar sync is connected (privacy policy).
  • Google, Microsoft, and Apple sign-inAuthenticating users who choose social sign-in, when you sign in with one of those accounts (privacy policy).

We may use AI services, including Anthropic, PBC ("Claude"), to help analyze usage data and to support features in our Services. Where we do, we provide aggregated or de-identified data wherever possible. If we begin using AI services to process personal information in a way this Policy does not describe, we will update this Policy first.

5. Cookies and tracking

We use strictly necessary cookies to run the site and keep you signed in, and—only with your consent—functional, analytics, and marketing cookies. You can manage your choices any time via the “Cookie Settings” link in our footer. For details, see our Cookie Policy.

6. Data retention

We keep personal information for as long as needed to provide our services, maintain your account, and meet our legal, tax, accounting, insurance, and regulatory obligations. Inspection records and related documentation may be retained for extended periods to meet safety-recordkeeping and contractual requirements. When information is no longer needed, we delete or de-identify it.

7. How we protect your information

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls and authentication, scoped credentials for service providers, and field-level encryption for designated sensitive data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. Your privacy rights

Depending on where you live, you may have the right to request to access, correct, delete, or receive a portable copy of your personal information, and to opt out of marketing and of any “sale” or “sharing” of personal information. You may also withdraw consent where processing is based on consent.

California residents (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect, to delete and correct it, and to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share your personal information for cross-context behavioral advertising. You can manage your analytics choice and submit privacy requests on our Your Privacy Choices page, and we honor opt-out preference signals such as the Global Privacy Control (GPC). We will not discriminate against you for exercising these rights.

Other U.S. states. Residents of states with comprehensive privacy laws have similar rights, including the right to appeal a decision on a request.

To exercise any right, contact us using the details below; we will verify your request before responding. You may use an authorized agent where the law allows.

9. Children's privacy

Our services are intended for businesses and adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us and we will delete it.

10. Third-party links

Our site may link to third-party websites and services we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.

11. U.S.-based processing

We are based in the United States and process information here. If you access our services from outside the United States, you understand your information will be processed in the United States, where data-protection laws may differ from those in your location.

12. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and change the “Effective date” above. For material changes, we will provide additional notice where required, such as by email or a notice in the portal.

13. Contact us

Utah Safety Institute, LLC, Attn: Privacy
d/b/a Critical Dynamics Risk Management
299 S. Main St., Suite 1300
Salt Lake City, UT 84111
Email: info@cdrisk.com
Phone: (844) 4-CDRISK