Effective date: September 7, 2026
Previous version: June 20, 2026 (archived)
Utah Safety Institute, LLC, doing business as Critical Dynamics Risk Management ("CDRisk," "we," "us," or "our"), provides safety consulting, training, inspection programs, and safety software. This Policy explains what personal information we collect through cdrisk.com, the client portal, the CDRisk Safety and CD Risk Inspector mobile apps, the inspection web app, regs.cdrisk.com, and our public QR and verification pages (together, the "Services"), how we use and share it, and the choices you have.
SDS.guide is a separate service we operate under its own Privacy Policy at sds.guide/privacy.
Visitors, prospects, and client contacts. If you visit our sites, submit a form, book training, or manage your organization's account, we collect information from you directly and we decide how it is used. This Policy applies to you in full.
Workers whose employer uses our Services. If your employer or another organization uses the CDRisk platform, that organization decides what information about you is entered and how it is used. We process it on that organization's instructions as its service provider. Requests about that information should go to the organization first; if you send them to us, we will forward them and assist. Sections 8 through 10 explain what we hold and how we protect it.
Information you give us. Name, business name and role, email address, phone number, mailing address, the contents of messages and form fields, account credentials, electronic signatures, and, when you buy a service, billing details collected by our payment processor (we do not store full card numbers).
Information your organization enters about you. Name, work email and phone, job role, location assignments, schedules and shifts, training records and certifications, safety-meeting attendance and signatures, time-and-attendance entries, evacuation muster status, work-permit requests, tasks and checks you complete, in-app messages, and incident, near-miss, and hazard reports you or others submit. Incident reports can include descriptions of injuries and the names of people involved. We collect only what your organization's safety program calls for.
Inspection and service data. Facility and equipment details, inspection responses and findings, compliance documents, signatures, and photographs taken during audits, inspections, and program visits.
Information from the mobile apps, with your permission. Camera and photo-library access to attach photos to reports; approximate or precise location when you choose to tag an incident report or when your organization enables geofenced time entry; a push-notification token so we can deliver alerts; and, if you turn on Face ID or fingerprint sign-in, a marker that biometric sign-in is enabled. Biometric matching is performed entirely by your device's operating system. We never receive or store fingerprints, face data, or any biometric template. You can turn each permission off in your device settings.
Information collected automatically. Browser and device type, pages and screens viewed, links and buttons clicked, scroll depth, time on page, referring site, and the country or region derived from your IP address. This is collected by our own first-party analytics, which sets no cookies and uses no third-party trackers. Our servers do not store the IP address in analytics records; they combine it with a key that changes daily to count visitors, then discard it. Separately, our systems record IP address and browser details when you sign in, sign a document, view a shared document, or take an action in the portal or apps, for security and audit purposes, and our contact form includes the sender's IP address in the notification we receive.
Information from third parties. From your employer or the organization that engaged us; from insurance carriers and third-party administrators that assign audit work; from sign-in providers you choose (Google, Microsoft, or Apple) or your organization's identity provider; and from service providers that help us operate.
To provide, perform, schedule, and document our audits, inspections, training, extinguisher programs, and safety programs; to operate and secure the platform and apps; to create accounts and authenticate users; to generate reports, certificates, permits, and compliance records for your organization; to send alerts your organization's program requires (task assignments, check reminders, expiring certifications, inspection schedules, incident routing); to process payments and subscriptions; to respond to inquiries; to send administrative and, where permitted, marketing communications (you can opt out); to measure and improve our sites and Services using aggregate statistics; to detect and prevent fraud and abuse; and to comply with law and enforce our agreements.
We do not sell personal information and we do not share it for cross-context behavioral advertising.
Service providers. Companies that process information on our behalf under contract:
We may use AI services, including Anthropic, PBC ("Claude"), to help analyze usage data and to support features in our Services. Where we do, we provide aggregated or de-identified data wherever possible. If we begin using AI services to process personal information in a way this Policy does not describe, we will update this Policy first.
Your organization. Inspection results, program records, and worker records are delivered to the organization that engaged us or that administers your account.
Your organization's identity provider. If your organization uses single sign-on, we exchange sign-in information with its identity provider.
SDS.guide. If your organization turns on SDS sync, Safety Data Sheets it uploads are published to SDS.guide's shared library, where they are visible to the public. This is off unless your organization enables it.
Legal and safety. To comply with law, respond to lawful requests, enforce our agreements, or protect the rights, safety, or property of any person, including providing information to emergency responders in a safety emergency.
Business transfers. In a merger, acquisition, financing, or sale of assets, subject to this Policy.
Equipment and vehicle QR pages show asset identity and service-date information and never show names, inspection verdicts, defects, or notes. Vehicle pages show the unit number, VIN, license plate, and document currency so a roadside officer can identify the unit. Roadside document-share links are time-limited and revocable, and each view is logged. The certificate verification page shows the certificate holder's name, course, dates, instructor, and status to anyone who enters a valid certificate number; certificate holders may ask us to remove their record from public lookup. Inspector verification pages show the inspector's name, photo, credentials, and, when a visit code is presented, the scheduled visit.
We use a first-party cookie to remember your cookie choices and, in the portal, session cookies to keep you signed in. We use no advertising cookies and no third-party analytics. Our own analytics is described in Section 2 and can be turned off on our Your Privacy Choices page or by sending a Global Privacy Control signal, which we honor. Details are in our Cookie Policy.
| Information | Kept for |
|---|---|
| Website analytics events | 13 months, then deleted |
| Contact and walkthrough inquiries | 24 months after our last contact, unless you become a client |
| Account and profile data | While the account is active; deleted or de-identified within 90 days after the organization's subscription ends, except as the organization directs or law requires |
| Inspection, training, incident, permit, and certificate records held for an organization | Seven years, or as the organization directs, to meet safety recordkeeping obligations |
| Signed agreements and acknowledgements | Seven years after the relationship ends |
| Security and access logs | 2 years |
| Record-change history attached to a client record | Kept with the record (seven years); IP and browser details removed after 2 years |
| Privacy requests and our responses | 24 months |
| Backups | Rolling; superseded copies are deleted on a fixed schedule |
We protect information with encryption in transit, hashed passwords, role- and location-scoped access, signed short-lived links for photos and documents, encrypted storage of identity-provider secrets, audit logging of staff and administrative actions, optional passkey sign-in and single sign-on, and regular dependency review. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you and your organization as required by law.
Everyone. You may ask us to access, correct, delete, or provide a copy of your personal information, to opt out of marketing, and to turn off analytics. Use the Your Privacy Choices page, email info@cdrisk.com, or call (844) 4-CDRISK. We will confirm receipt, verify your identity, and respond within 45 days (extendable once by 45 days where the law allows). If we deny a request, we will explain why and how to appeal. You may use an authorized agent where the law permits. We do not discriminate against anyone for exercising these rights.
Workers. If your information was entered by your employer or another organization, we will forward your request to that organization and act on its instructions, or act directly where the law requires.
California, Colorado, Connecticut, Texas, Utah, Virginia, and other states with privacy laws. You have the rights described above under your state's law. We do not sell personal information or share it for targeted advertising, and we honor the Global Privacy Control signal as an opt-out.
Text messages. If you opt in to text messages, reply STOP to stop and HELP for help. Message frequency varies and message and data rates may apply. Consent to texts is not a condition of purchase, and we do not share text opt-in data with third parties for their marketing.
Our Services are for businesses and adults. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
We are based in the United States and process information here. If you use our Services from elsewhere, your information will be processed in the United States.
We will post changes here with a new effective date and keep prior versions available. For material changes we will notify account holders by email or in the portal.
Utah Safety Institute, LLC d/b/a Critical Dynamics Risk Management
Attn: Privacy
299 S. Main St., Suite 1300, Salt Lake City, UT 84111
info@cdrisk.com · (844) 4-CDRISK