Ultegrity.ai

Privacy Policy

ultegrity.ai

Effective Date: February 22, 2026

Marc J. Weinstein PLLC (the "Firm," "we," "us," or "our"), doing business as Ultegrity, operates the website located at ultegrity.ai (the "Site"), the AI Risk Assessment tool made available through the Site (the "Assessment Tool"), and the AI Compliance Intelligence feed (the "Intelligence Feed"). This Privacy Policy describes how we collect, use, retain, and protect information in connection with the Site and its features.

By accessing the Site or using any of its features, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree to this Privacy Policy, do not access the Site or use any of its features.

1. Information We Collect

We collect the following categories of information:

Contact Information. When you request a Report from the Assessment Tool, we collect your name, professional title, organization name, and organizational email address (collectively, your "Contact Information"). We do not accept personal email addresses for Report delivery.

Assessment Responses. When you answer one or more of the questions in the Assessment Tool, we collect your responses. These responses, together with the AI Risk Score and risk tier classifications generated from them, are collectively referred to as your "Assessment Data." Your Assessment Data is transmitted to the Firm regardless of whether you subsequently provide Contact Information. If you provide Contact Information and request a Report, your Assessment Data is also used to produce and deliver your Report.

Report. If you provide Contact Information, your Assessment Data is used to generate an AI Risk Assessment Report tailored to your responses (the "Report"). The Report is a document assembled by the Assessment Tool that contains your Assessment Data together with content selected from the Firm's proprietary content framework based on your Assessment Data. While the underlying content framework, including questions, response blocks, scoring methodology, tier narratives, domain summaries, recommendations, and the selection and arrangement of resources, is the intellectual property of the Firm, the specific combination of content assembled for your organization constitutes a unique document. Because the particular selection and arrangement of content in a Report can be used to derive or reconstruct your Assessment Data, the Firm treats each Report with the same confidentiality afforded to Assessment Data under Section 5 of this Privacy Policy.

Marketing Preference. If you choose to opt in to receive communications from the Firm, we record that preference.

Automatically Collected Information. When you visit the Site, including when you browse the Intelligence Feed or the Reference Library, we may automatically collect limited technical information, including pages viewed, time spent on the Site, and general geographic region. This information is collected through privacy-respecting analytics that do not use cookies and do not track individual users across websites. We do not collect device identifiers, IP addresses for tracking purposes, or browser fingerprints.

Information We Do Not Collect Through the Intelligence Feed. The Intelligence Feed is a read-only feature. We do not collect any personal information from users who browse the Intelligence Feed. No account, login, or identifying information is required to view Intelligence Feed content.

2. How We Use Your Information

We use the information we collect for the following purposes:

To generate and deliver your Report. Your Assessment Data is used to calculate your AI Risk Score, assemble your Report tailored to your responses, and deliver the Report to you via immediate download and email. Your Contact Information is used to address and deliver the Report.

For the Firm's internal records. We retain a copy of your Assessment Data for the Firm's internal purposes. If you provide Contact Information, we retain your Contact Information together with your Assessment Data for business development and internal reference purposes. If you do not provide Contact Information, the Assessment Data the Firm receives cannot be associated with any individual or organization.

To send you your Report. We send a single transactional email to the email address included in your Contact Information, containing your Report as an attachment. This email is a fulfillment of the service you requested and is not a marketing communication.

To send marketing communications, if you opt in. If you affirmatively opt in to receive communications from the Firm, we will use the email address included in your Contact Information to send you information about AI governance developments, resources, and advisory services. You may opt out of marketing communications at any time by following the unsubscribe instructions included in each communication or by contacting us directly.

For aggregated analysis. We may use Assessment Data in aggregated, de-identified form that cannot reasonably be used to identify any individual or organization. This aggregated data may be used for research, thought leadership, conference presentations, or informational publications.

To operate and improve the Site. We use automatically collected technical information to understand how visitors use the Site, to maintain and improve Site performance, and to inform decisions about Site content and features.

3. How We Process and Store Your Information

When you complete the Assessment Tool, your Assessment Data is processed in real time by a serverless function and transmitted to the Firm. If you subsequently provide Contact Information and request a Report, a second serverless function generates your Report, triggers the delivery emails, and transmits a copy of your Report, your Assessment Data, and your Contact Information to the Firm. Neither your Assessment Data nor your Contact Information is stored in any database on the Site's servers. After processing is complete, no copy of your Assessment Data or Contact Information persists on the web server.

The Firm retains Assessment Data and, where provided, Contact Information in the Firm's internal systems, subject to the retention period described in Section 12. Assessment Data received without Contact Information cannot be associated with any individual or organization.

The Intelligence Feed processes publicly available third-party content using artificial intelligence to generate summaries. This processing does not involve any user data. No personal information is transmitted to or collected by the AI summarization service in connection with the Intelligence Feed.

4. How We Share Your Information

We do not sell, rent, or trade your Contact Information or Assessment Data to third parties.

We may share your information in the following limited circumstances:

Service Providers. We use third-party service providers to host the Site, to send transactional and marketing emails on our behalf, and to generate AI summaries for the Intelligence Feed. These service providers process information solely on our instructions and for the purposes described in this Privacy Policy. Our current service providers include Vercel (hosting), Resend (email delivery), and Anthropic (AI summarization for the Intelligence Feed). The AI summarization service processes only publicly available third-party content and does not receive any user personal information.

Legal Requirements. We may disclose your Contact Information or Assessment Data if required to do so by law, legal process, or court order, or if we believe in good faith that such disclosure is necessary to comply with applicable law, respond to a subpoena or court order, or protect the rights, property, or safety of the Firm or others.

Aggregated, De-Identified Data. We may share aggregated, de-identified Assessment Data that cannot reasonably be used to identify any individual or organization, as described in Section 2 above.

5. Confidentiality

We treat your Assessment Data and your Report as confidential to the extent that either can be associated with an identified individual or organization. Your Assessment Data consist of your responses to the assessment, score, and classifications generated from your responses. Your Report is the particular combination of content assembled based on your Assessment Data. Taken together, these reveal information about your organization's AI governance practices. The Firm will not disclose Assessment Data or Reports that can be associated with your organization to third parties without your consent, except as described in Section 4 above. Assessment Data received by the Firm without Contact Information cannot be associated with any individual or organization and is not subject to this confidentiality commitment.

We treat your Contact Information as confidential and will not disclose it to third parties without your consent, except as described in Section 4 above.

This confidentiality commitment does not apply to the underlying content framework of the Assessment Tool, including the questions, response block text, scoring methodology, tier narratives, domain summaries, recommendations, and the selection and arrangement of resources, which are the intellectual property of the Firm and may appear in Reports generated for other users. This confidentiality commitment is a contractual obligation and does not create or imply any evidentiary privilege. For additional information, please refer to the Terms of Use.

6. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect the Contact Information and Assessment Data we collect and maintain. The Site is served over encrypted HTTPS connections. Assessment Data is processed in serverless functions that do not persist data after processing. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee the absolute security of your information.

7. Your Rights and Choices

Access and Deletion. You may request access to or deletion of the Contact Information we hold about you by contacting us at the address below. Upon receiving a verified request, we will provide or delete the requested information within a reasonable timeframe, subject to any legal obligations requiring retention.

Marketing Opt-Out. If you have opted in to receive marketing communications, you may opt out at any time by following the unsubscribe instructions in any marketing email or by contacting us directly. Opting out of marketing communications does not affect the delivery of your Report or the transactional email associated with it.

8. Cookies and Tracking Technologies

The Site uses privacy-respecting analytics that do not rely on cookies, do not track users across websites, and do not collect personally identifiable information. We do not use advertising cookies, social media tracking pixels, or any third-party tracking technologies. If our analytics practices change, we will update this Privacy Policy accordingly.

9. Children's Privacy

The Site and its features are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.

10. International Data Transfers

The Site is hosted in the United States. If you are accessing the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States. By using the Site and providing your information, you consent to such transfer, storage, and processing. If you are located in the European Economic Area, the United Kingdom, or Switzerland, we will take appropriate steps to ensure that your personal data receives an adequate level of protection in accordance with applicable law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be effective upon posting of the revised Privacy Policy on the Site with an updated effective date. Your continued use of the Site following the posting of changes constitutes your acceptance of such changes. We encourage you to review this Privacy Policy periodically.

12. Data Retention

Assessment Data that is processed on the web server is not retained on the server after processing. The Firm retains Assessment Data and, where provided, Contact Information in the Firm's internal systems for a period of three (3) years from the date the assessment was completed, after which identified Assessment Data will be deleted unless you request earlier deletion. Assessment Data received without Contact Information cannot be associated with any individual or organization. Aggregated or de-identified Assessment Data may be retained indefinitely.

13. Contact Information

If you have questions about this Privacy Policy, wish to exercise any of your rights described above, or wish to request access to or deletion of your Contact Information, please contact:

Marc J. Weinstein PLLC
info@ultegrity.ai