Privacy Policy
Last Updated: June 2026
ERG Leadership Alliance, LLC (the "Company") respects the privacy of users of its website, www.ergleadershipalliance.com, and the services provided therein (the "Site"). This privacy policy explains what information is gathered, how it is used, and how long it is kept.
Use of Information
As a general policy, no personally identifiable information, such as your name, address, or email address, is automatically collected from your visit to the Site. However, certain non-personal information is recorded by the standard operation of the Company's internet servers, including browser type, operating system, and IP address, in order to enhance your online experience.
The Site's mailing lists, downloads, registration forms, and surveys may request contact information such as your name, work email address, and organizational affiliation. Information submitted will be used only as necessary for our legitimate business interests, including the improvement of our products, services, and the content of the Site. Personally identifiable information is never sold or leased to any third party.
With your permission, we may use your contact information to send you information about our company and services. You may opt out of receiving future communications as described in the Choice/Opt-Out section below.
The Company does not store any credit card information. Payment processing is handled exclusively by Stripe, Inc. (a PCI DSS Level 1 certified processor), and ELA has no access to payment card data.
Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law. Our standard retention periods are:
- Member names and work email addresses: retained for the duration of your active membership plus 2 years following expiration or last account activity.
- Certification and training records: retained for 7 years from the date of certification or activity.
- Billing and transaction records: retained for 7 years from the date of the transaction, as required by applicable tax law.
- Marketing and email communications: retained until you opt out, or for 3 years of inactivity.
For our complete data retention schedule, see ELA's Data Retention & Deletion Policy, available upon request at [email protected].
Third-Party Data Processors
ELA uses the following third-party service providers ("processors") to deliver its services. Each processor is bound by contractual data protection obligations consistent with applicable law:
| Processor | Purpose | Location |
|---|---|---|
| Kajabi, LLC | Platform hosting, content delivery, membership management, user authentication, and bulk member email marketing (CAN-SPAM compliant) | United States |
| Google LLC | Internal file storage and collaboration (Google Drive/Workspace) | United States |
| Zoom Video Communications, Inc. | Virtual event and training delivery | United States |
| Intuit Inc. (QuickBooks) | Financial recordkeeping and invoicing | United States |
| Zoho Corporation | CRM, person-to-person client and prospect correspondence, contact management | United States |
| Newfold Digital (Bluehost) | Public website hosting and corporate email management (all ELA accounts except info@) | United States |
| GoDaddy / Microsoft Outlook | Email management for [email protected] | United States |
| Stripe, Inc. | Payment card processing (optional; via Kajabi) | United States |
GDPR Compliance
For individuals in the UK, the EEA, Switzerland, or other regions that require a lawful basis for processing personal data (such as under GDPR Article 6), ELA's legal bases for collecting and processing personal data are:
- Performance of a contract — where processing is necessary to perform our obligations under a membership or service agreement.
- Consent — where you have given your consent to receive communications or for a specific processing activity.
- Legitimate Interests — where processing is in our legitimate business interests (for example, to provide platform access, improve our services, or ensure platform security), and those interests are not overridden by your rights and freedoms.
- Legal Requirement — where we are required to process your data by applicable law or regulation.
ELA operates its member platform on servers located in the United States. For EU/UK data subjects, ELA ensures that appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable. For more information, contact [email protected].
Your Rights & Access to Your Information
You have the following rights regarding your personal data held by ELA. To exercise any right, email [email protected] with the relevant subject line:
- Right to Access: Request a copy of the personal data ELA holds about you. Email with subject line: "Personal Information Review Request."
- Right to Rectification: Request correction of inaccurate or incomplete personal data. Email with subject line: "Personal Information Correction Request."
- Right to Erasure (Right to be Forgotten): Request deletion of your personal data or user account. Email with subject line: "Delete My Information" or "Delete Account."
- Right to Restriction: Request that we limit processing of your personal data in certain circumstances.
- Right to Data Portability: Request that we provide your personal data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests, including for direct marketing purposes. To opt out of marketing communications, follow the unsubscribe link in any email or contact us at [email protected].
We will respond to all rights requests within 30 days. There is no charge for reasonable requests. We may ask you to verify your identity before processing your request.
Right to Lodge a Complaint
If you are located in the EU or UK and believe ELA has not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the relevant data protection supervisory authority:
- UK residents: Information Commissioner's Office (ICO) — ico.org.uk
- EU residents: The supervisory authority in your country of residence or place of work.
We encourage you to contact us first at [email protected] so we can attempt to resolve your concern directly.
US State Privacy Rights
ELA has assessed its applicability under US state comprehensive privacy laws. Based on ELA's current revenue, member data volume, and data practices (including the fact that ELA does not sell or share personal information), ELA does not currently meet the applicability thresholds of any major US state consumer privacy law, including the California Consumer Privacy Act (CCPA/CPRA).
Regardless of applicable law, ELA honors the following rights for all members and website visitors in any US state: the right to know what data we hold about you, the right to request deletion of your data, and the right to opt out of marketing communications. To exercise any of these rights, contact [email protected].
International Members — APAC, Canada & Latin America
ELA serves members and clients in Australia, New Zealand, Canada, Brazil, Mexico, and is expanding into additional international markets. ELA has assessed its obligations under applicable privacy laws in each of these regions and complies with the core requirements of the Australian Privacy Principles (APPs), New Zealand Privacy Act 2020, Canada's PIPEDA and Quebec Law 25, Brazil's LGPD, and Mexico's LFPDPPP.
ELA's data practices — including limited data collection (names and work email addresses only), no sale or sharing of personal data, strong security measures, and comprehensive data subject rights — satisfy the core requirements of these frameworks. A full International Privacy Compliance Assessment is available upon request from [email protected].
To exercise data rights under any international privacy law (including ARCO rights under Mexican law, access and correction rights under Australian Privacy Act, rights under LGPD, or rights under the NZ Privacy Act), please contact [email protected]. ELA will respond within the timeframe required by the applicable law.
By registering as a member of ERG Leadership Alliance and accepting these Terms, you acknowledge that ERG Leadership Alliance's Privacy Policy (available at ergleadershipalliance.com/privacy-policy) serves as ELA's Privacy Notice (Aviso de Privacidad) for purposes of Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). You consent to the transfer of your personal data (name and work email address) to ERG Leadership Alliance's technology providers in the United States of America, including Kajabi LLC, Google LLC, and Zoho Corporation, for the purposes of providing membership platform access, training, certifications, and related services. You have the right to exercise your ARCO rights (Access, Rectification, Cancellation, and Opposition) and to revoke this consent at any time by contacting [email protected]. ELA will process your request within 20 business days, as required by applicable law.
Español: Al registrarse como miembro de ERG Leadership Alliance y aceptar estos Términos, usted reconoce que la Política de Privacidad de ELA (disponible en ergleadershipalliance.com/privacy-policy) sirve como el Aviso de Privacidad de ELA para los efectos de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). Usted consiente la transferencia de sus datos personales (nombre y dirección de correo electrónico profesional) a los proveedores de tecnología de ERG Leadership Alliance ubicados en los Estados Unidos de América, incluyendo Kajabi LLC, Google LLC y Zoho Corporation, con el fin de proporcionarle acceso a la plataforma de membresía, capacitación, certificaciones y servicios relacionados. Usted tiene derecho a ejercer sus derechos ARCO (Acceso, Rectificación, Cancelación y Oposición) y a revocar este consentimiento en cualquier momento comunicándose con [email protected]. ELA procesará su solicitud dentro de los 20 días hábiles siguientes a su recepción, según lo exige la ley aplicable.
By registering as a member of ERG Leadership Alliance and accepting these Terms, you consent to the collection and transfer of your personal information (including your name and work email address) to ERG Leadership Alliance's technology service providers located in the United States of America, including Kajabi LLC, Google LLC, and Zoho Corporation. This transfer is necessary to provide you with access to the ERG Leadership Alliance membership platform, training content, certifications, and related services. ELA's US-based providers are bound by data protection agreements requiring them to protect your information in a manner consistent with Brazilian law. You may withdraw this consent at any time by contacting [email protected], with the understanding that withdrawal will result in the closure of your ELA account and deletion of your personal information.
Português: Ao se registrar como membro da ERG Leadership Alliance e aceitar estes Termos, você consente com a coleta e transferência de suas informações pessoais (incluindo seu nome e endereço de e-mail profissional) para os provedores de serviços de tecnologia da ERG Leadership Alliance localizados nos Estados Unidos da América, incluindo Kajabi LLC, Google LLC e Zoho Corporation. Essa transferência é necessária para fornecer acesso à plataforma de membros da ERG Leadership Alliance, ao conteúdo de treinamento, certificações e serviços relacionados. Os provedores dos EUA da ELA estão vinculados a acordos de proteção de dados que exigem a proteção de suas informações de forma consistente com a lei brasileira. Você pode retirar este consentimento a qualquer momento entrando em contato com [email protected], ciente de que a retirada resultará no encerramento de sua conta ELA e na exclusão de suas informações pessoais.
Use of Cookies
Cookies are small text files placed on your device when you visit the Site. ELA's website uses cookies primarily for platform functionality (such as maintaining your login session) and for analytics purposes (to understand how visitors use the Site). Some cookies may be set by third-party providers, including Kajabi, whose cookie practices are governed by their own privacy policy.
Most browsers are initially set to accept cookies. You can configure your browser to refuse all cookies or to alert you when a cookie is being sent. Note that disabling cookies may affect the functionality of the Site or your ability to log in to your member account.
Children Under 16
ELA's services are directed at working professionals and are not intended for individuals under 16 years of age. If ELA discovers that a child under 16 has provided personally identifiable information, we will delete that information promptly. If you believe a child under 16 has submitted information to ELA, please contact [email protected].
Security
ELA takes the security of your personal data seriously. We have implemented technical, administrative, and organizational measures to protect your information from unauthorized access, disclosure, alteration, or destruction. These include multi-factor authentication on all administrative accounts, SSL/TLS encryption for all data in transit, and contractual security obligations with our third-party processors.
ELA's member platform is hosted by Kajabi, LLC, which maintains geo-redundant, encrypted data storage and a comprehensive information security program. More detail on ELA's security practices is available in our Information Security Statement, available upon request at [email protected].
Please be aware that no data transmission over the Internet can be guaranteed 100% secure. While we take significant steps to protect your information, we cannot warrant the absolute security of any information you transmit via the Internet.
Links to External Sites
The Company is not responsible for the privacy practices or content of third-party websites that may be linked to the Site. We encourage you to review each website's privacy policy before disclosing any personal information.
Transfer of Information Across National Borders
ELA operates on servers located in the United States. If you are located outside the United States, please be aware that information you provide may be transferred to, stored, and processed in the United States. For EU and UK residents, we ensure that appropriate contractual safeguards (including Standard Contractual Clauses) are in place with our third-party processors.
Data Incident and Breach Response Policy and Plan
Effective July 2025
1. Purpose
This document outlines the policy and procedures of ERG Leadership Alliance, LLC for responding to personal data incidents and breaches. It is designed to ensure swift, appropriate, and compliant action in the event of a data incident, and to safeguard the rights and interests of all affected parties.
2. Scope
This policy applies to all employees, contractors, associates, and partners who process or manage personal data on behalf of ERG Leadership Alliance, LLC. It covers incidents involving electronic, paper-based, or verbal data disclosures.
3. Policy Overview
ERG Leadership Alliance, LLC is committed to protecting personal data in accordance with applicable data protection laws, including the UK GDPR, the EU GDPR, and the Massachusetts Data Security Law (M.G.L. c. 93H). In the event of a personal data breach, we follow a seven-step response framework to assess, contain, and manage the incident.
4. Definition of a Personal Data Breach
A personal data breach is a security incident that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
5. Data Incident and Breach Response Plan
Step 1 — Remain Calm and Begin Documentation: Start a breach log immediately. Record key details: what happened, when, who discovered it, and any immediate actions taken.
Step 2 — Start the 72-Hour Clock: The clock starts from the point of discovery. Determine whether the breach meets the threshold for regulatory reporting. Reporting to relevant authorities must occur within 72 hours if required.
Step 3 — Establish the Facts: Investigate to understand what data was affected, how it happened, who is impacted, and the timeline of events.
Step 4 — Contain the Breach: Take immediate steps to stop further data loss or exposure. Recall or secure emails; retrieve or remotely wipe lost devices; change passwords or revoke access where appropriate.
Step 5 — Assess the Risk: Evaluate potential harm to individuals (identity theft, financial loss, emotional distress, reputational damage) and determine the level of impact and likelihood of harm.
Step 6 — Protect Affected Individuals: If appropriate, notify affected individuals with a clear explanation of what happened, steps they should take to protect themselves, and support being offered by ELA.
Step 7 — Report the Breach (if necessary): If reportable, notify relevant regulatory authorities. For UK matters, notify the ICO using the official reporting form. For Massachusetts matters, notify the Massachusetts Attorney General's Office (mass.gov/ago) and affected Massachusetts residents as required by M.G.L. c. 93H.
6. Ongoing Responsibilities
Review and Learn: After every breach, review the incident and update internal procedures to reduce the risk of recurrence. Training: All staff and contractors acknowledge ELA's security and data handling requirements annually. Policy Review: This document is reviewed annually and after any reportable breach.
7. Contact for Reporting
All data incidents must be reported immediately to the Data Protection Lead:
Name: Maureen Cidzik
Email: [email protected]
Phone: 617.843.5517
Contact Information
For questions about this privacy policy, to exercise your data rights, or to report a concern:
ERG Leadership Alliance, LLC
30 Chestnut Street, Westborough, MA 01581
Email: [email protected]
Phone: 617.843.5517
Website: ergleadershipalliance.com
For EU residents with unresolved concerns: You may also contact the relevant EU data protection authority in your country of residence.
Your Acceptance of These Terms
By using the Site, you accept the policies set forth in this Privacy Policy. If you do not agree to this policy, please do not use the Site. This policy may be revised from time to time; the 'Last Updated' date at the top of this page reflects the most recent revision. Continued use of the Site following any update constitutes your acceptance of the revised policy.