Privacy Policy
Version 1, effective September 22, 2026.
Privacy Policy
Effective September 22, 2026 · Version 1 · https://cardinaltraining.io/privacy
On this page
- 1. Information we collect
- 2. How we use information
- 3. Analytics, cookies, and crash reporting
- 4. AIA CES reporting
- 5. Disclosures of Personal Information
- 6. How long we keep information
- 7. Security
- 8. Additional Information for California Residents
- 9. Additional Information for Residents of the EEA, United Kingdom, or Switzerland
- 10. Children
- 11. Mobile app permissions
- 12. Changes to this policy
- 13. Contact
- Cardinal Assistant
Cardinal Glass Industries, Inc. ("Cardinal," "we," "us") operates the Cardinal Training continuing education platform at cardinaltraining.io (the "Site") and the Cardinal AIA mobile app for iOS and Android (the "App"). Together they are the "Service." This policy explains what personal information we collect through the Service, how we use and share it, and the choices you have.
Cardinal is headquartered at 775 Prairie Center Drive, Eden Prairie, Minnesota 55344, USA. The Service is operated from the United States.
1. Information we collect
Information you give us
- Account information. First and last name, email address, and password. Optionally, phone number, company name, mailing address, job title, professional bio, LinkedIn URL, time zone, and a profile photo.
- AIA membership information. Whether you are a member of the American Institute of Architects (AIA) and, if so, your eight-digit AIA member number. You may add or change this in your profile, but it is locked once a certificate has been issued on it.
- Live event responses. When you respond to a live event invitation: your RSVP, meal preference, dietary restrictions, and any reason you give for declining. If someone invites you by email before you have an account, we hold your name and email address for the invitation.
- Certificate claim forms. For live events, the completion form asks for your name, AIA membership status and member number, and optionally phone and address. It also asks whether you want Cardinal marketing email and a copy of your certificate by email.
- Instructor profile. If you are a Cardinal instructor: photo, bio, credentials, presenter title, and a signature image that appears on certificates you present. If you do not upload a signature, we generate one from your typed name.
- Notes, searches, and support. Notes you attach to course videos, your search history in the App, and anything you send through the contact form or a support ticket.
Information collected automatically
- Learning activity. Enrollments, course progress, pages viewed in PDF courses, video watch position and percentage watched, playback events (play, pause, seek, quality changes), test attempts, answers, scores, time taken, certificates issued and downloaded, and live event attendance confirmations.
- Device and log data. IP address, browser and device type, operating system and app version, device model, the pages and screens you visit, timestamps, and error reports. When you sign in, we record the session and an approximate location (city, region, country) derived from your IP address using a MaxMind GeoLite2 database stored on our servers. We do not collect GPS location and we discard latitude and longitude.
- Security events. Failed sign-in attempts, rate-limit violations, blocked IP addresses, and administrative actions taken on your account, kept for audit purposes.
- Email engagement. Whether emails we send you are delivered, opened, or clicked, and whether they bounce. Our email providers report this to us.
- Push notification tokens. If you allow notifications in the App, a device token from Apple, Google, or Expo so we can deliver them.
- Analytics data. Described in Section 3.
Information from others
Cardinal administrators may add you as an attendee at a live event using the name and email you gave at the event. A colleague or host may invite you to a live event by email.
2. How we use information
We (and our service providers acting on our behalf) use personal information to:
- create and secure your account, verify your email address, deliver two factor codes, and detect fraud and abuse;
- deliver courses, track your progress, score tests, and issue and verify certificates;
- report course completions to AIA Continuing Education System (CES) for AIA members, as described in Section 4;
- manage live event invitations, RSVPs, catering needs, reminders, calendar files, and attendance records;
- send transactional email and push notifications about your account, courses, tests, certificates, and events;
- send Cardinal marketing email only if you opted in, which you can withdraw at any time;
- respond to support requests and accessibility requests;
- operate and improve the Service, measure which courses and features are used, and fix errors;
- support Cardinal's business, including letting Cardinal sales representatives see which professionals and firms use Cardinal Training (Section 5);
- meet legal, regulatory, and AIA provider obligations, and enforce our Terms of Use.
We do not use your personal information to train artificial intelligence models.
3. Analytics, cookies, and crash reporting
Google Analytics 4 and Google Tag Manager (Site)
We use Google Analytics 4 (GA4), loaded through Google Tag Manager, to understand how the Site is used. GA4 receives events such as page views, sign ups, course starts and completions, test submissions, certificate issuance, event RSVPs, and searches, along with a pseudonymous cookie identifier and a hashed user identifier that Google cannot reverse to your account. Google receives your IP address in the network request and, under GA4's default settings, uses it only to derive coarse location before discarding it.
Firebase Analytics (App)
The App uses Firebase Analytics, which feeds the same GA4 property, to record screen views and the same learning events as the Site. Advertising identifier (IDFA and Android Advertising ID) collection is disabled, so the App does not track you across other companies' apps or websites and does not show an Apple App Tracking Transparency prompt.
Your analytics choices
- Cookie banner (Site). We use Cookiebot to record your choice. If you are in the European Economic Area, United Kingdom, or Switzerland, analytics cookies stay off until you opt in. Everywhere else, analytics is on by default and you may opt out from the banner or the cookie settings link in the footer. We honor the Global Privacy Control browser signal as an opt out.
- App settings. You can turn analytics on or off in the App's privacy settings at any time.
- Browser add-on. You may also install Google's Analytics opt-out browser add-on.
- Erasure. If you delete your account, we ask Google to delete the analytics data associated with your hashed identifier.
First-party analytics
Independently of Google, the Service keeps its own record of the same learning events, plus PDF page views and video playback events, in our database. Administrators and Cardinal instructors use this to see enrollment, completion, and engagement for the courses they manage, and to help you when you contact support.
Crash and error reporting
The Site and App send error reports to Sentry so we can find and fix bugs. Reports include the error, device and app version, and the identifier of the signed-in user. The App may also capture a masked replay of the screens leading up to a crash.
Cookies we set
A representative list of the cookies we use is below. However, this list is subject to change and may be incomplete or inaccurate.
| Cookie | Purpose | Duration |
|---|---|---|
| Session and XSRF-TOKEN | Keep you signed in and protect forms from forgery. Strictly necessary. | Expire after 8 hours of inactivity |
| remember_web | Keeps you signed in if you choose "Remember me". Strictly necessary. | 5 years |
| CookieConsent | Stores your cookie choice (Cookiebot). | 12 months |
| _ga, _ga_* | Google Analytics 4 visitor and session identifiers. Set only with consent where required. | Up to 2 years |
We also use Google reCAPTCHA v3 on sign in, registration, contact, RSVP, and certificate forms to block bots. reCAPTCHA is subject to the Google Privacy Policy and Terms of Service.
4. AIA CES reporting
Cardinal is an AIA CES Approved Provider (Provider Number 10121105). If you are an AIA member with a member number on file and you complete a course and pass its test, or confirm attendance at a live event, a Cardinal administrator submits your completion to AIA CES. The file uploaded to AIA contains only the AIA course number, session code, your AIA member number, and the completion date. It does not contain your name or email address. Submission is done manually by Cardinal staff through AIA's provider portal, not by an automated feed, so it can take several weeks to appear in your AIA transcript.
If you are not an AIA member, or you have not entered a member number, nothing is reported to AIA. You still receive a certificate that you may submit to your state licensing board yourself.
5. Disclosures of Personal Information
We may disclose your personal information to the following types of organizations or persons:
- AIA. Course number, session code, member number, and completion date for AIA members, as described in Section 4. If an event is cancelled, AIA is notified by email.
- Service providers. Companies that process data on our behalf under contract and only for our purposes: DigitalOcean (hosting and file storage), Bunny.net (video delivery), Brevo and Resend (email delivery and engagement reporting), Expo, Google Firebase, and Apple (push notifications), Google (Analytics, Tag Manager, reCAPTCHA), Cookiebot (consent management), Sentry (error reporting), MaxMind (IP geolocation database, used on our servers), Coconut (video transcoding, if enabled), and OpenStreetMap Nominatim (venue address lookup for events, no personal data).
- Within Cardinal. Cardinal administrators and the instructors assigned to your courses can see your profile and learning activity. Cardinal Glass sales representatives may see which professionals and firms use Cardinal Training, including your name, company, contact details, and the courses you have completed, so they can follow up about Cardinal products. They do not receive your test answers or AIA member number.
- Certificate verification. Anyone holding a certificate number or scanning the QR code on a certificate can confirm, after passing a CAPTCHA, the recipient name, course title, credits, issue date, instructor, provider details, revocation status, and a masked form of the AIA member number. This lets employers and licensing boards confirm a certificate is genuine.
- Legal and safety. When required by law, subpoena, or government request, or to protect the rights, property, or safety of Cardinal, our users, or the public.
- Business transfers. If Cardinal sells or transfers the Service or a related business, personal information may transfer with it, subject to this policy.
6. How long we keep information
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the information, whether we can achieve those purposes through other means, and the applicable legal requirements.
7. Security
We use administrative, technical, and physical measures to protect your personal information from loss, theft, and unauthorized use, disclosure, or modification. Please be aware that no data transmission over the Internet is 100% secure. While we strive to protect your personal information, we cannot ensure or warrant the security of any information you transmit to us and you do so at your own risk.
8. Additional Information for California Residents
By simply accessing the Service, the following applies. If you create an account or interact with us in other ways (e.g., by filling out forms on the Site or in the App), please continue reading below to learn more about the personal information we collect, and how we use and disclose such information.
| Categories of personal information to be collected *No sensitive personal information is collected **None of this personal information is “sold” or “shared,” as those terms are defined by the CCPA. | Identifiers, such as your IP address, browser and device type, and cookie identifiers associated with the means by which you access the Service |
| The purposes for which the above categories of personal information are collected and used | Providing the Service and ensuring that our content is presented to you in the most effective manner Analytics regarding use of the Service, as described in Section 3 above Developing, updating, and improving the Service To help maintain the safety, security, and integrity of the Service Preventing and detecting fraud, security breaches, and other unlawful activities in connection with the Service Enforcing our agreements and complying with our legal or regulatory obligations |
| The criteria used by us to determine the period for which the personal information will be retained | Cardinal will retain the personal information it collects and uses so long as it has a legitimate business need to do so, or as required by law (e.g., for tax, legal, accounting or other purposes), whichever is the longer. |
To learn more about our practices in connection with the collection, processing, and disclosure of personal information relating to California consumers, continue to read below.
CALIFORNIA PRIVACY POLICY
Personal Information We Collect and Disclose
As defined by the CCPA, “personal information” includes any information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. For the purposes of the CCPA and this section, personal information does not include certain regulated information, such as protected health information that is collected by a covered entity or business associate governed by the Health Insurance Portability and Accountability Act, or public information.
In the past 12 months, Cardinal has collected the following categories of personal information from consumers and disclosed such information to the following categories of third parties for the business or commercial purposes described below.
| CATEGORIES OF PERSONAL INFORMATION | ||
|---|---|---|
| Categories of PI Collected | Examples | Categories of Third Parties to Whom Disclosed |
| Identifiers | A real name, email address, postal address, telephone number, account username, Internet Protocol address, or other similar identifiers | Our service providers, such as IT systems providers and our marketing and advertising vendors AIA, as described elsewhere in this policy Our professional advisors and affiliates for business purposes |
| Commercial information | Records of courses enrolled in, completed, or considered, test attempts and scores, certificates issued, live event attendance, and similar learning activity | Our service providers, such as IT systems providers and our marketing and advertising vendors AIA, as described elsewhere in this policy Our professional advisors and affiliates for business purposes |
| Internet or other similar network activity | Browsing details, search history, information about your interaction with the Site and App, including pages and screens visited, video playback events, timestamps, and other similar session data | Our service providers, such as IT systems providers and our marketing and advertising vendors |
| Personal information types listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) | A name, address, telephone number, email address | Our service providers, such as IT systems providers and our marketing and advertising vendors |
| Professional or employment-related information | Job title, company name, professional credentials, AIA membership status and member number | Our service providers, such as IT systems providers and our marketing and advertising vendors AIA, as described elsewhere in this policy Our professional advisors and affiliates for business purposes |
From time to time, Cardinal may be required to disclose your information to governmental authorities for the purpose of complying with applicable laws and regulations or in response to legal process. We may also disclose your personal information to third parties in connection with the sale of our business or assets, or any merger or similar corporate matter, when your personal information is part of the assets involved in such transaction.
Applicable Retention Periods
For each category of personal information identified above, we will retain your personal information only for as long as necessary to fulfill your requests or the purposes for which it was obtained, as set forth in this section. The criteria used to determine our retention periods include (i) to fulfill the purpose for which the information was collected, (ii) for as long as we have an ongoing relationship with you, and (iii) as required by a legal obligation to which we are subject.
How We Collect Your Information
Cardinal collects the categories of personal information listed above from the following sources:
- Direct collection: We collect information directly from you when you choose to provide it to us, such as when you create an account, update your profile, enroll in courses, respond to live event invitations, submit certificate claim forms, opt in to marketing email, or contact us through a support ticket or the contact form on the Site.
- Indirect and technology-based collection: We also collect certain information from you indirectly when you visit, use, or navigate the Site or the App. Cardinal collects certain identifiers (such as IP addresses) and internet and similar network activity (such as learning activity, device and log data, and analytics data) from you indirectly using cookies and similar tracking technologies, as described in Section 3.
- Third-party collection: Cardinal administrators may add you as a live event attendee using the name and email you provided at the event, and a colleague or host may invite you to a live event by email.
Use of Personal Information
- We collect and use your personal information for the following business or commercial purposes:
- Creating and securing your account, verifying your email address, delivering two-factor codes, and detecting fraud and abuse.
- Delivering courses, tracking your progress, scoring tests, issuing and verifying certificates, and managing live event invitations, RSVPs, catering needs, reminders, and attendance records.
- Reporting course completions to AIA Continuing Education System (CES) for AIA members, as described in Section 4.
- Sending transactional email and push notifications about your account, courses, tests, certificates, and events, and responding to support and accessibility requests.
- Sending Cardinal marketing email only if you opted in, which you can withdraw at any time.
- Operating and improving the Service, measuring which courses and features are used, and fixing errors.
- Supporting Cardinal’s business, including letting Cardinal sales representatives see which professionals and firms use Cardinal Training, as described in Section 5.
- Meeting legal, regulatory, and AIA provider obligations, and enforcing our Terms of Use.
Sensitive Personal Information
Cardinal does not collect “sensitive personal information” (as defined by the CCPA) for the purposes of inferring characteristics about California consumers. Accordingly, Cardinal treats any such information as “personal information” consistent with applicable provisions of the CCPA.
Sale or Sharing of Personal Information
In the past 12 months, Cardinal has not “sold” any categories of personal information or “shared” any such information for the purposes of cross-context behavioral advertising. Likewise, Cardinal does not have actual knowledge of any sales or sharing of personal information regarding minors under 16 years of age.
Your Rights Under the CCPA
The CCPA provides California residents with the rights discussed below. For convenience, and as required by the CCPA, we explain how you can exercise those rights, to the extent they are applicable.
- Right to Request Information. You have the right to request that we disclose certain information about our collection and use of your personal information during the past twelve (12) months. Specifically, you may request that we disclose:
- The categories of personal information we collected about you;
- The categories of sources for the personal information we collected about you;
- The business and commercial purposes for collecting your personal information;
- The categories of third parties to whom we disclose your personal information;
- The specific pieces of personal information we collected about you; and
- If we disclosed your personal information for a business purpose, the categories of personal information received by each category of third party.
- Right to Data Portability. You have the right to request that we provide copies of the specific pieces of personal information we collected about you. If a verifiable consumer request is made, and subject to any exceptions or limitations under the CCPA, we will take steps to deliver the personal information to you either by mail or electronically. If we provide the information to you electronically, it will be in a portable and readily useable format, to the extent technically feasible. Consistent with the CCPA and our interest in the security of your personal information, we will describe but may not provide copies of certain personal information we may receive from you (e.g., driver’s license number, other government-issued identification number, financial account number, health or medical identification number, account password, or security questions or answers) in response to a CCPA request, to the extent any of those items are in our possession.
- Right to Request Deletion. You have the right to request that we delete personal information we collected from you, subject to any exceptions or limitations under the CCPA.
- Right to Correct Inaccurate Information. If we maintain inaccurate personal information about you, you have the right to request that we correct that inaccurate personal information, taking into account the nature of the personal information and the purposes of the processing of the personal information.
- Right to Opt-Out. Consumers in California have the right to opt-out of (a) the sale of personal information, or (b) the sharing of their personal information for the purposes of cross-context behavioral advertising (as defined in the CCPA). Because Cardinal does not “sell” or “share” personal information, these rights are not available.
Exercising Your Rights
To exercise the rights described above, you—or someone authorized to act on your behalf—must submit a verifiable consumer request to us by sending an e-mail to privacy@cardinaltraining.io with the subject line: “CCPA Request” or calling us at
+1 (952) 935-1722. Your request must include your name, e-mail address, mailing address, phone number, the nature of your inquiry and the context in which we may have received your information. If you are an agent submitting a request on behalf of a consumer, we may request that you submit a signed permission from the consumer authorizing you to make the request. In order to protect the privacy and data security of consumers, the verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative of such consumer; and
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
As indicated above, please be aware that the CCPA provides certain limitations and exceptions to the foregoing rights, which may result in us denying or limiting our response to your request. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request. We may also request that you provide additional information if needed to verify your identity or authority to make the request. We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you or the consumer on whose behalf you are making the request.
Response Timing and Format
The CCPA requires us to respond to a verifiable consumer request within forty-five (45) days of its receipt; however, we may extend that period by an additional 45 days. If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response via e-mail. Any disclosures we provide will only cover the 12-month period preceding the receipt of the verifiable consumer request, provided that you may request disclosure beyond the 12-month period as permitted by the CCPA. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select the format of our response; the format will be readily useable and should allow you to transmit the information from one entity to another. We will not charge a fee to process or respond to a verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing the request.
Our Commitment Not to Discriminate
Consistent with the CCPA, we will not discriminate against you for exercising any of your CCPA rights by:
- Denying you services or products.
- Charging you different prices or rates for services or products, including through granting discounts or other benefits, or imposing penalties.
- Providing you a different level or quality of services or products.
- Suggesting that you may receive a different price or rate for services or a different level or quality of services or products.
Data Sharing for Direct Marketing Purposes
California Civil Code § 1798.83 (California’s Shine the Light Act) further permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. Cardinal does not share personal information with third parties for their own direct marketing purposes. If you have questions, please contact us as described in Section 13.
9. Additional Information for Residents of the EEA, United Kingdom, or Switzerland
The European Union’s General Data Protection Regulation and the United Kingdom’s and Switzerland’s versions of the same (collectively, referred to as the “GDPR”) afford certain rights to individuals in the European Economic Area or Switzerland, Gibraltar, United Kingdom and similar, as applicable (collectively, referred to as “Europe”). If you are in Europe, you have the following rights. Note, however, that not all rights apply in all circumstances.
- Right of access: subject to certain exceptions, you have the right of access to your personal information that we hold. If you are requesting access to your data in order to protect the rights of others, we may require you to validate your identity before we can release that information to you.
- Right to rectify your personal information: if you discover that the information we hold about you is inaccurate or incomplete, you have the right to have this information rectified (i.e., corrected).
- Right to be forgotten: you may ask us to delete information we hold about you in certain circumstances. This right is not absolute, and it may not be possible for us to delete the information we hold about you, for example, if we have an ongoing contractual relationship or are required to retain information to comply with our legal obligations.
- Right to restriction of processing: in some cases, you may have the right to have the processing of your personal information restricted. For example, where you contest the accuracy of your personal information, its use may be restricted until the accuracy is verified.
- Right to object to processing: you may object to the processing of your personal information (including profiling) when it is based upon our legitimate interests. You may also object to the processing of your personal information for the purposes of direct marketing and for the purposes of statistical analysis.
- Right to data portability: you have the right to receive, move, copy, or transfer your personal information to another controller when we are processing your personal information based on consent or on a contract and the processing is carried out by automated means.
With regard to the personal information collected through the Service, Cardinal is typically the “data controller” under the GDPR. If you wish to exercise one of the rights discussed above, you may do so by submitting a written request to privacy@cardinaltraining.io with the subject line, “GDPR Request.” This is normally free, unless the request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or decline to respond. Once we have received your request, we will review it and contact you within thirty (30) days of receipt of your request, will notify you of any delay in processing your request and, in any event, will respond to the request within three (3) months. Please note that we may need to request specific information from you to help us confirm your identity. If you are located in Europe and have a concern about our processing of your data, you may have the right to make a complaint to the appropriate data protection authority in your jurisdiction of residence.
Where Cardinal processes personal information of employees or other authorized users of its customers in connection with the Service, Cardinal acts as a data processor on behalf of the customer (who is the data controller). In such cases, individuals should direct any GDPR rights requests (including access, rectification, erasure, and data portability) to their employer. Cardinal will assist the customer in responding to such requests as required by the GDPR and our data processing agreements.
We will process different types of information under different lawful bases under the GDPR depending on the nature of the information and your relationship with us. The following table describes how we plan to use your personal information and our lawful basis for doing so. We may process your personal information on more than one basis depending on the specific purpose for which we have collected or are otherwise using your information. If the lawful basis is your consent, you have the right to withdraw your consent. Please note, we do not engage in automated decision-making.
| To manage our relationship with you in connection with the Service, including: Delivering courses, tracking your progress, scoring tests, and issuing certificates Responding to inquiries and providing support Managing live event invitations, RSVPs, and attendance Notifying you about changes to the Service or this policy Reporting course completions to AIA CES for AIA members | Account information (name, email, password, phone, company, address, job title) AIA membership information Live event responses and certificate claim forms | Necessary for our legitimate interests (to manage our business relationships and administer our operations including through the keeping of appropriate records) Necessary for performance of a contract Necessary to comply with legal obligations |
| To administer and protect our business and the Service, including: Defending and advancing legal claims Enforcing our Terms of Use Ensuring effective security for the Service Conducting Service maintenance and fixing errors Identifying and addressing security risks and unlawful activity | Account information Device and log data Security events Analytics data | Necessary for our legitimate interests (running our business, facilitating administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise) Necessary to comply with legal obligations Necessary for performance of a contract |
| To support and promote Cardinal’s business, including measuring which courses and features are used, improving the Service, sending marketing email (with your consent), and letting Cardinal sales representatives see which professionals and firms use Cardinal Training | Account information Learning activity Email engagement Analytics data | Necessary for our legitimate interests (to enhance our services, improve our marketing strategies and develop our business) With your consent |
If we transfer personal information from the EEA, Switzerland, or UK to the United States or any other country, we will implement appropriate legal mechanisms to ensure an adequate level of personal data protection consistent with the GDPR’s requirements. For example, if the recipient country has not received an Adequacy Decision from the European Commission (such as the United States), we will rely on Standard Contractual Clauses (SCC) that have been approved by the European Commission as the lawful mechanisms for such transfers. Further, we will enter into appropriate data processing agreements with all non-EU (sub)processors that contain SCCs and define data protection standards to be employed by each (sub)processor.
10. Children
The Service is intended for working professionals. It is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.
11. Mobile app permissions
The App asks for camera and photo library access only when you choose to set a profile photo, notification permission for course, test, certificate, and event alerts, and storage to keep downloaded course videos inside the App's private storage for offline viewing. You can revoke any permission in your device settings.
12. Changes to this policy
We will post any revised policy on the Site and in the App with a new effective date. For material changes we will email account holders or show an in-product notice before the change takes effect. Continued use after the effective date means you accept the revised policy.
13. Contact
Cardinal Glass Industries, Inc.
Attn: Cardinal Training Privacy
775 Prairie Center Drive, Eden Prairie, MN 55344, USA
privacy@cardinaltraining.io
+1 (952) 935-1722
Cardinal Assistant
The Cardinal Assistant is an in-platform question and answer feature that helps you find information in our training and product documentation. When you use it, we store the questions you ask and the answers you receive so you can return to them, and so we can review the quality and safety of the feature.
Assistant conversations are retained for 90 days and are then permanently deleted. During that window they are reviewable by Cardinal Training administrators, who may read a conversation to investigate a quality or safety concern. Every such review is recorded in our internal audit log. Aggregate, anonymous statistics about the topics people ask about are kept for longer and contain no question text and nothing identifying you.
Your questions are sent to third-party AI providers under contract to process them on our behalf. Those providers are not permitted to use your questions to train their models. You can request a copy of your assistant conversations, or ask us to delete them, using the same requests described elsewhere in this policy.
Questions about this document or how we handle your data? Our team is happy to help.
Contact Our Team