Privacy Policy

Effective date: September 29, 2026

Azimuth Consulting, LLC ("Azimuth," "we," "us," or "our") operates the Organizational Health Snapshot and Organizational Health Discovery Brief. This policy explains how information is processed when an adult uses these services in a business or organizational capacity.

Azimuth primarily offers the services in the United States. Virtual and subscription-based services may also be available outside the United States where Azimuth offers them and applicable law and provider terms permit. Availability outside the United States is not an offer in every jurisdiction and does not guarantee local storage or processing.

Information we process

The services process:

  • Your first and last name, email address, role or level, organization, organization size, sector, declared assessment perspective, department or group when applicable, observation period, and the organizational situation you describe.

  • Twenty-eight ratings, guided coaching responses, corrections, evidence summaries, and consent choices.

  • A generated two-page Snapshot or four-page Discovery Brief and its PDF representation.

  • Content-limited completion metrics, including rounded active-working, AI-waiting, and service-waiting time, pause counts, and guided-question counts by organizational system.

  • Security and operational information, including request origin, Cloudflare Turnstile signals, random session identifiers, provider outcome data, and HMAC-derived rate-limit keys created from the request IP address and email address.

  • If you choose encrypted recovery, the encrypted in-progress draft and the contact information needed to provide a recovery link.

Do not enter confidential medical, financial, legally privileged, credential, client-identifying, or other highly sensitive information in free-text responses.

How we use information

Azimuth uses this information to establish and protect the assessment session, provide guided coaching, generate and deliver the requested report, retain a protected consultant copy with your consent, support limited service administration and follow-up, restore an unfinished draft when you choose that option, monitor service reliability, enforce usage limits, and improve the completion experience.

Processing occurs at your request and after the consent presented before an assessment session begins. Security counters, content-limited logs, and operational records are used to protect and operate the service. Where applicable law requires another legal basis or additional rights, Azimuth will apply that requirement.

Azimuth does not sell assessment information, does not share it for cross-context behavioral advertising, and does not use assessment submissions for marketing.

AI processing

Anthropic is the primary provider for guided coaching and report generation. OpenAI may be used only as an availability fallback after a qualifying temporary Anthropic failure; the service does not send the same request to both providers in parallel.

Before assessment content is sent to an AI provider, the application removes the dedicated first name, last name, organization name, department or group name, email address, scope name, consent, and follow-up-choice fields. The provider still receives the remaining organizational context and content, which may include role, organization size, sector, perspective, observation period, narrative text, ratings, coaching responses and corrections, evidence summaries, and completion metrics.

Removing dedicated identity fields does not anonymize a submission. Free text is not automatically scrubbed for names or other identifying details.

Anthropic describes standard commercial/API inputs and outputs as generally deleted within 30 days, subject to applicable agreements, safety, Usage Policy, and legal exceptions. The service's one-hour ephemeral Anthropic prompt cache applies only to stable system instructions; respondent content is sent separately and is not marked for prompt caching. OpenAI processing is governed by the applicable API data-use and retention terms in effect for Azimuth's account.

Browser, session, and recovery storage

The browser keeps in-progress information in the current tab's session storage. Before a protected service session is created, that local state carries a 24-hour expiration. Starting over removes saved tab state, and expired state is removed when restoration is attempted.

For assessments started on the public Snapshot website, an active assessment session normally expires four hours after it starts. Optional unfinished-draft recovery follows the separate deadline below. After a report is generated, temporary service state may remain available for up to four more hours to finish the requested report and related service steps. The service schedules cleanup at the applicable deadline. Cleanup failures may delay physical deletion without extending access.

For abuse prevention, the service creates keyed HMAC values from the request IP address and email address and stores dated hourly or daily counters. Raw IP addresses and email addresses are not stored in those counter keys. The application schedules deletion at the end of the applicable hour or day, retries recoverable cleanup failures after five minutes, and performs bootstrap cleanup when a later session start finds the retention alarm missing or overdue. In normal platform operation, Azimuth's active-storage ceiling for expired rate-limit keys is 48 hours after the applicable window ends. A provider outage may delay physical removal without making an expired key active in a later limiting window.

If you expressly choose encrypted recovery, the service stores an encrypted unfinished draft for no more than seven days from its first confirmed save. Autosaves and returns do not extend that deadline. After the configured inactivity period, the service may use Resend to send one stable recovery link to the same email address used to begin the assessment. Starting over or completing the lifecycle removes the active recovery record according to the service rules.

For these public-site assessments, to finish the report's PDF, protected archive and related service steps, Azimuth may temporarily retain an encrypted copy of your assessment inputs and generated report, including ratings and coaching answers. This temporary record is separate from the completed-report archive and may be needed even if you did not choose optional recovery. Access has a fixed deadline no later than four hours after the report is generated. The service attempts to remove this temporary encrypted copy when it is no longer needed. Access ends at the fixed deadline; cleanup failures may delay physical deletion.

For these public-site assessments, if you chose optional encrypted recovery and a draft was successfully saved, Resend may email you a private return link while the completed report's protected files still need a browser step. The email contains no assessment or report content. Anyone with the link can use it while it remains valid, so keep it private. Each use creates a one-time handoff valid for up to five minutes and never extends the report's fixed deadline. The link becomes unavailable when the required browser steps are complete or can no longer be retried, or when the deadline expires. Returning restores the existing report; it does not generate a new AI report.

Completed reports and administrator access

With the consent presented at intake, Azimuth retains the completed report, generated PDF, limited intake information, consent record, and content-free completion metrics in a protected consultant portal for up to 365 days. Raw ratings and coaching responses are not retained in that completed-report archive.

Access is limited to reviewed Azimuth administrators through the configured identity and entitlement controls. Administrative access, governance changes, exports, and deletions are recorded in content-limited audit records. Azimuth may remove a report earlier in response to a verified request or an operational need.

Consultant-saved synthesis files

When an authorized consultant explicitly saves a synthesis of completed reports, Azimuth stores four files: the executive-summary PDF, the consultant-analysis PDF, an export ZIP, and a review-history file. The files are held in private Cloudflare R2 storage, with supporting records in the protected consultant portal.

Saved synthesis files are available for up to 365 days from finalization. Archiving a synthesis does not restart that period. Access depends on the administrator's current permissions; the consultant-analysis PDF has additional restrictions and is not a public download.

If the owner deletes a synthesis, its files become unavailable immediately. The owner can recover it for up to seven days after deletion, or until the original 365-day period ends, whichever comes first. After the applicable deadline, the files and associated synthesis records are scheduled for permanent removal. Daily cleanup performs this removal; service delays or failed cleanup attempts can delay physical deletion without restoring access. Content-limited audit records may remain under the existing audit-retention rules.

An unfinished synthesis save expires after two days and is scheduled for cleanup. Its files are not available for download. This is separate from the optional encrypted recovery of an unfinished assessment described above.

Email, notifications, and GoHighLevel routing

You may choose to email the completed PDF to the same address used to begin the assessment. Resend provides the delivery service. Internal completion notices contain limited service information and exclude the respondent email address, score, ratings, coaching responses, generated narrative, and PDF.

Azimuth sends a limited contact and report summary to GoHighLevel for service administration and follow-up. The permitted fields are product and mode labels, assessment version and completion time, respondent contact and organization intake fields, follow-up intent, overall condition and evidence-completeness classification, and fixed product tags. Raw ratings, coaching responses, generated narrative, and the PDF are not sent to GoHighLevel.

GoHighLevel also hosts Azimuth's public website and this policy page. A visit to the policy page may cause GoHighLevel or LeadConnector to process ordinary web-request, device, cookie, and site-configuration information. Azimuth does not use assessment submissions for advertising and does not intentionally place an assessment form, chat widget, or CRM capture form on the policy page.

Service providers and international processing

The service uses Cloudflare Pages, Workers, Durable Objects, D1, R2, Workers Logs and metrics, and Turnstile for hosting, request processing, storage, operational visibility, and abuse protection; Anthropic and, when necessary, OpenAI for AI processing; Resend for authorized email delivery; GoHighLevel for limited service routing and website hosting; and WorkOS or the configured identity layer for protected administrator sign-in.

These providers may process information in the United States and other locations where they or their subprocessors operate, subject to Azimuth's applicable agreements and legal requirements. Cloudflare Durable Objects used by the service are not restricted to a single national jurisdiction and may be placed near an initial request.

Cloudflare Turnstile uses bot-detection signals that may include IP address, TLS fingerprint, user-agent information, site key, and origin. Cloudflare describes its role as a processor when providing website protection and may act separately as a controller for product improvement under its terms.

Provider-controlled recovery, logs, and metrics

Deletion from active Durable Object or D1 storage does not necessarily remove provider-controlled recovery copies immediately. Cloudflare's SQLite-backed services may retain point-in-time recovery history covering up to the prior 30 days. The application does not use recovery history during ordinary operation.

Production uses content-limited Cloudflare Workers Logs for events such as route or outcome, processing stage, provider and model, timing, token counts, schema or quality reason codes, and provider request identifiers. The application does not intentionally write names, email addresses, organization names, ratings, coaching responses, free text, generated narrative, or PDFs to these logs. Cloudflare's published maximum Workers Logs retention is up to seven days, and aggregate Workers metrics may remain available for up to three months.

Security

Azimuth uses HTTPS, origin and hostname restrictions, Turnstile, rate limits, random session credentials, HMAC-derived keys, encryption for optional draft recovery, provider-secret bindings, protected administrative access, least-privilege entitlements, and bounded retention controls. No internet service can guarantee absolute security. Please contact Azimuth promptly if you believe the service has been misused.

Your choices and rights

You may decline to begin the assessment. Encrypted recovery and respondent PDF email delivery are optional. Starting over removes the current tab state and triggers the applicable active recovery cleanup behavior.

Subject to applicable law, you may request access to, correction of, or deletion of personal information Azimuth retains about you. Azimuth may verify identity and authority and may limit or deny a request where law permits or requires, including for security, fraud prevention, legal claims, or recordkeeping. Azimuth targets a response within 45 days, or within another period required by applicable law. Where applicable, Azimuth will provide information about an appeal or the relevant regulator.

Because temporary session information expires and raw ratings and coaching responses are not retained in the completed-report archive, Azimuth may be unable to retrieve that information after the applicable active and provider-controlled retention periods.

Contact

Privacy questions and requests may be sent to [email protected]. Do not include assessment answers or other sensitive information in an initial request.

Changes to this policy

Azimuth will update the effective date when this policy changes. When applicable, Azimuth will provide additional notice before materially different processing begins.