Enterprise Privacy Notice

Cairn Insights, Inc.

Effective date:
July 1, 2026
Privacy contact:
sam@cairninsights.ai

This Privacy Notice explains how Cairn Insights, Inc. (“Cairn,” “we,” “us,” or “our”) handles personal information in connection with our websites, enterprise organizational-intelligence platform, integrations, support, and related business activities.

1. Scope and our role

This Notice applies to cairninsights.ai and other Cairn websites that link to it; Cairn AI and related hosted services, applications, integrations, reports, and support; and business interactions such as demonstrations, onboarding, contracting, events, and customer communications.

Cairn as a controller or business. Cairn determines why and how personal information is handled for our own website, sales, contracting, account administration, support, security, service operations, and legal-compliance activities. This Notice describes those activities directly.

Cairn as a processor or service provider. Enterprise customers decide which people, systems, data fields, time periods, use cases, and authorized users are included in Cairn AI. When Cairn processes that Customer Personal Data under the customer’s instructions, the customer is generally the controller, business, or equivalent decision-maker and Cairn is its processor, service provider, or contractor. The applicable customer agreement, order, and Data Processing Addendum govern that processing.

If you are an employee, contractor, candidate, guest, or external communication participant whose information was provided to Cairn by an enterprise customer, that customer is usually the appropriate first contact for questions or rights requests. Cairn will support the customer as required by applicable law and contract.

2. Personal information we handle

Information Cairn handles for its own business purposes

  • Contact and professional information. Name, work email address, telephone number, employer, job title, business unit, professional profile, and communications with Cairn.
  • Account and access information. Account identifiers, enterprise tenant and domain information, sign-in events, roles, permissions, authentication and authorization records, and integration-consent status. Where an integration uses OAuth or SSO, Cairn may receive tokens and authorization information rather than the user’s password.
  • Sales, contracting, and support information. Demo requests, procurement records, contracts, billing and transaction records, implementation notes, support tickets, feedback, survey responses, and related correspondence.
  • Website, device, and usage information. IP address, browser and device information, referring pages, pages or features used, timestamps, session information, and similar technical or analytics data.
  • Security and operational information. Audit trails, system events, application and extraction run identifiers, error and performance data, access records, incident materials, and other information used to secure, troubleshoot, and operate the Services.

Customer Personal Data processed through Cairn AI

The categories processed for a particular customer depend on the customer-approved order and onboarding configuration. They may include:

  • Identity and directory metadata. Names, work email addresses or user principal names, platform user or object identifiers, employee identifiers, account state and type, department, title, team, manager, role, and other approved organizational attributes.
  • Communication and collaboration metadata. Sender and recipient identifiers, timestamps, message and conversation identifiers, threading and reply information, communication frequency, importance or read-state indicators, attachment indicators or metadata, Teams chat, channel, team, and membership identifiers, and similar approved interaction data.
  • Calendar metadata. Organizer and attendee identifiers, event identifiers, start and end times, duration, cancellation state, importance, location label, and other approved meeting metadata.
  • Customer-provided workforce or validation data. Roster information, team and role information, schedule classifications, employment status, and approved outcome or validation labels supplied by the customer.
  • Derived analytics and outputs. Customer-scoped nodes, edges, graph weights, time windows, collaboration metrics, network roles, communities, baselines, risk indicators, reports, dashboards, investigation materials, prompts, queries, responses, and related product outputs.
  • Support and security records. Audit logs, support records, operational events, and security records relating to the customer environment.

Content is not part of the default scope. Message bodies, chat bodies, file content, subjects, body previews, chat topics, hosted content, and other content or content-adjacent fields are excluded by default. A customer may authorize specified content or content-adjacent fields only through an express written order, onboarding configuration, or change-control approval after appropriate privacy and security review.

Sensitive information is not intended by default. Customers must not provide sensitive or special-category information unless expressly authorized in writing and subject to appropriate safeguards. Communication metadata and derived analytics may nevertheless reveal or permit inferences about individuals, so Cairn treats Customer Personal Data as confidential and does not represent pseudonymized data as anonymous where re-identification remains possible.

3. Sources of personal information

We obtain personal information from:

  • you, when you contact Cairn, request a demonstration, sign in, use the Services, submit information, or communicate with us;
  • the enterprise customer that authorizes, configures, or uses Cairn AI, including its administrators and approved data owners;
  • customer-approved integrations and source systems, including Microsoft 365, Microsoft Entra, Microsoft Graph, Microsoft Teams, Google Workspace, and other configured enterprise systems;
  • service providers that support hosting, security, analytics, communications, customer support, and business operations; and
  • automated technologies used when you access our websites or Services.

4. How we use personal information

Depending on our role and the applicable agreement, we use personal information to:

  • provide, configure, administer, support, maintain, and secure the websites and Services;
  • authenticate users, apply customer-approved access controls, record consent and configuration state, and prevent unauthorized access;
  • extract and normalize approved source data; resolve identities; create customer-scoped graph and analytics artifacts; and generate dashboards, reports, investigations, and chat-assisted analysis;
  • perform customer-approved evaluation, quality assurance, troubleshooting, support, and service improvement;
  • monitor performance, detect and investigate security events, prevent fraud or misuse, and preserve service integrity;
  • manage demonstrations, onboarding, contracts, billing, customer relationships, requests, feedback, and business communications;
  • develop aggregated or de-identified technical, usage, security, operational, and product-improvement statistics that do not identify a customer, individual, team, department, small cohort, or pseudonymous node;
  • comply with law, enforce agreements, establish or defend legal claims, respond to lawful requests, and protect the rights and safety of Cairn, our customers, and others; and
  • carry out another purpose disclosed at collection or authorized by the relevant customer or individual.

5. Legal bases for Cairn’s own processing

Where the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require a legal basis, Cairn relies on one or more of the following for activities in which Cairn acts as controller:

  • Contract. Processing necessary to enter into or perform a contract with you or the organization you represent.
  • Legitimate interests. Operating, securing, supporting, and improving our Services; managing enterprise relationships; preventing misuse; and protecting our legal and business interests, balanced against the rights and interests of affected individuals.
  • Consent. Where we ask for consent, such as for certain optional communications or non-essential cookies. Consent may be withdrawn for future processing.
  • Legal obligation and public interest. Processing needed to comply with law, lawful process, regulatory obligations, or important public interests recognized by applicable law.

For Customer Personal Data processed on behalf of an enterprise customer, the customer is responsible for identifying an appropriate legal basis and providing required notices, consultation, approvals, or consent. Cairn processes that information under the customer’s documented instructions and applicable agreement.

6. AI, analytics, and model training

No training of shared or general-purpose models by default. Cairn does not use Customer Personal Data, customer-specific graph artifacts, prompts, reports, or outputs to train or improve a shared or general-purpose artificial-intelligence or machine-learning model unless the customer expressly authorizes that use in a separate written agreement.

Customer-specific analytics, scoring methods, evaluation, retrieval, baselines, or model components may process Customer Personal Data solely to provide the Services for that customer and under its instructions. They remain customer-scoped unless the customer expressly authorizes another use.

Cairn may use aggregated or de-identified service statistics to maintain and improve the Services only when the information no longer identifies or can reasonably be linked to a customer, person, team, department, small cohort, or pseudonymous node. Cross-customer workforce benchmarking is not enabled by default and requires express written customer authorization and appropriate aggregation safeguards.

7. How we disclose personal information

We may disclose personal information in the following circumstances:

No sale or targeted advertising use. Cairn does not sell Customer Personal Data or use or disclose it for cross-context behavioral advertising. Cairn does not sell personal information collected through its websites or share it for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws.

  • Enterprise customers and authorized users. Customer administrators and users may access Customer Personal Data and outputs according to the customer’s configuration, roles, and permissions.
  • Service providers and subprocessors. Providers may support cloud hosting, storage, databases, security, monitoring, support, communications, and other service operations. They are permitted to process information only for authorized purposes and subject to contractual confidentiality and data-protection obligations. A current customer-specific subprocessor list is available through the applicable agreement or from Cairn upon request.
  • Professional advisers. Lawyers, auditors, insurers, accountants, and other advisers may receive information as reasonably necessary to provide professional services and protect legal interests.
  • Legal and safety disclosures. We may disclose information when we reasonably believe it is required by law or legal process, or necessary to protect rights, security, integrity, or safety.
  • Business transactions. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate protections.
  • With authorization. We may disclose information for another purpose with the authorization of the relevant customer or individual.

8. Security

Cairn maintains administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction. Depending on the deployed environment and customer agreement, these safeguards include access restrictions, customer-scoped environments and permissions, encryption in transit and at rest, secret-management controls, logging and monitoring, vulnerability management, backup and recovery measures, and incident-response procedures.

No system can be guaranteed completely secure. Customers are responsible for configuring authorized users, permissions, extraction scope, and source-system controls appropriately and for promptly notifying Cairn of suspected unauthorized use. Cairn will address confirmed security incidents and notify affected enterprise customers as required by applicable law and contract.

9. Retention and deletion

Customer Personal Data

Cairn retains Customer Personal Data according to the applicable order, Data Processing Addendum, onboarding configuration, and customer instructions. The customer should approve the retention periods for raw source records, derived analytics, reports, logs, backups, and audit records, together with export, reprocessing, and deletion requirements.

After termination or a valid customer request, Cairn will return or delete Customer Personal Data as required by the applicable agreement, subject to limited legal, security, dispute-resolution, log, and backup exceptions. Information retained under an exception remains protected and is not used for another purpose.

Information Cairn controls

For information Cairn handles as controller, retention depends on the nature of the information and the purpose for which it was collected. We consider the duration of the customer or business relationship; account, support, security, and operational needs; applicable limitation periods; tax, accounting, and legal requirements; consent or marketing preferences; and whether information can be securely deleted or de-identified.

10. International processing and transfers

Cairn Insights, Inc. is based in the United States. Our standard hosted Services are scoped for processing in the United States unless the applicable order, statement of work, Data Processing Addendum, or onboarding configuration states otherwise.

If personal information is transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction that restricts international transfers, Cairn and the relevant customer will implement an approved transfer mechanism and supplementary safeguards where required before the transfer begins. Depending on the circumstances, those mechanisms may include adequacy decisions or approved standard contractual clauses.

11. Workforce analytics and automated processing

Cairn AI may produce network metrics, role profiles, communities, baselines, risk indicators, alerts, reports, and other analytical outputs. These outputs are decision-support information. They are not final employment determinations, medical or psychological assessments, legal conclusions, or proof that a particular individual will resign, underperform, violate policy, or experience burnout.

Cairn does not make employment decisions on behalf of customers and does not intend its Services to be used as the sole basis for hiring, firing, promotion, compensation, discipline, scheduling, performance evaluation, benefits, investigation outcomes, or another consequential workplace decision. Customers must maintain meaningful human review, verify data quality and context, consider alternative explanations, and use independent evidence before taking action.

Customers are responsible for assessing whether a proposed deployment constitutes employee monitoring, profiling, high-risk AI, or automated decision-making; completing any required privacy or algorithmic impact assessment; consulting works councils, unions, or workforce representatives where required; providing notices and choices; and ensuring the use is lawful, proportionate, and consistent with employment and labor obligations.

12. Privacy rights and choices

Depending on your location, role, and the information involved, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing; withdraw consent; opt out of certain uses; or appeal a refusal of a request. You may also have a right to complain to a data-protection regulator.

Requests concerning Customer Personal Data

If your information was provided to Cairn by your employer or another enterprise customer, please submit your request to that organization first. Because Cairn processes the information under the customer’s instructions, Cairn may need to refer your request to the customer. Cairn will provide reasonable assistance to the customer as required by law and contract.

Requests concerning Cairn-controlled information

To exercise a right concerning information Cairn controls, email sam@cairninsights.ai. Describe your request and the relationship or interaction involved. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require evidence of authorization and direct identity verification.

Rights are not absolute. Applicable law may permit or require us to deny, limit, or retain information in certain circumstances. We will not unlawfully discriminate against you for exercising a privacy right. If applicable law provides an appeal right, you may appeal our decision by replying to the response or using the contact information below.

Additional U.S. state disclosures

The categories of personal information Cairn may collect, the sources, business purposes, and recipient categories are described in Sections 2 through 7. Cairn does not sell personal information or share it for cross-context behavioral advertising. Cairn’s standard scope excludes sensitive personal information unless it is expressly authorized. If Cairn uses or discloses sensitive personal information in a manner that gives rise to a right to limit under applicable law, Cairn will provide the required notice and request mechanism. Residents of states with comprehensive privacy laws may submit applicable requests using the contact information in Section 17.

13. Cookies, analytics, and communications

Cairn uses cookies and similar technologies that are necessary to operate websites and Services, maintain sessions, support authentication, remember settings, protect security, and understand performance. We may use analytics technologies where permitted by law and, when required, after obtaining consent.

You can control cookies through your browser and, where provided, Cairn’s consent controls. Blocking necessary cookies may prevent features from working. You may opt out of non-transactional marketing email by using the unsubscribe link in the message or contacting us. We may still send service, security, legal, and account-related communications.

14. Google Workspace API data

When a customer enables a Google Workspace integration, Cairn accesses, uses, stores, and discloses Google Workspace API data only as described in this Notice, the applicable customer agreement, and the customer-approved configuration. Cairn’s use and transfer to any other application of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Cairn does not use Google Workspace API data to create, train, or improve a shared or general-purpose artificial-intelligence or machine-learning model. Any customer-specific processing is limited to the approved user-facing enterprise use case and the customer’s instructions.

15. Children

The websites and Services are designed for enterprise and professional use and are not directed to children. Customers must not configure the Services to process children’s personal information unless expressly agreed in writing and supported by an appropriate lawful basis, notices, permissions, and safeguards. If you believe a child’s personal information has been provided to Cairn improperly, contact us.

16. Changes to this Notice

We may update this Notice to reflect changes in our Services, data practices, contractual commitments, or applicable law. We will post the revised Notice and update its effective date. If a change materially expands how Cairn uses Customer Personal Data, we will follow the applicable customer agreement and obtain any authorization required before applying the new use.

17. Contact us

For privacy questions or requests concerning information Cairn controls, contact:

Email: sam@cairninsights.ai

If your request concerns information processed for an enterprise customer, please identify the customer and understand that Cairn may forward or refer the request to that organization.