CritAlertResponse
Website & Service Privacy Policy
SOC-lite Platform
Effective Date: [4/1/2026] | Last Updated: [8/8/2026]
This Privacy Policy describes how CritAlertResponse, Inc. collects, uses, stores, and shares information through our website (critalertresponse.org) and our SOC-lite security alert escalation platform (“Platform” or “Service”). Please read this policy carefully. If you have questions, contact us at cy bersecurity@critalertresponse.org.
1. Who We Are
CritAlertResponse, Inc. is a Georgia corporation providing AI-assisted, after-hours security alert triage and escalation services primarily to K–12 school districts, municipalities, counties, educational service districts, and other public and nonprofit entities (“Members”).
CritAlertResponse, Inc.
Resaca, GA 30735
cybersecurity@critalertresponse.org
For purposes of applicable data protection law, CritAlertResponse acts as the “data controller” for Member organization data and as a “data processor” acting on Member instructions for alert content data forwarded to the Platform.
2. What Data We Collect
We collect two distinct categories of data: data about your organization and contacts (“Member Data”), and the security alert content you choose to forward to the Platform (“Alert Content”). These are treated differently and are described below.
2.1 Member Organization Data
When a Member subscribes to the Service, we collect:
2.2 Alert Content Data
When a Member’s security tools forward alert emails to the SOC-lite centralized mailbox, we receive and process:
Important: CritAlertResponse does not seek or require student personally identifiable information (PII), employee personal data, or financial records in alert emails. Members are responsible for configuring their forwarding rules to minimize the transmission of such data. If student PII or employee personal data is incidentally present in a forwarded alert email, it will be handled in accordance with applicable law and will not be used for any purpose other than processing that specific alert.
2.3 Audit and Operational Log Data
The Platform automatically generates and retains:
2.4 Website Visitor Data
When you visit critalertresponse.org, we may collect standard web analytics data including browser type, pages visited, time on page, and referring URL. We do not use tracking cookies for advertising purposes. See Section 10 for cookie details.
3. How We Use Your Data
We use data collected through the Platform strictly for the following purposes:
We do not use alert content for marketing, advertising, profiling, or any purpose outside direct service delivery. Alert content is never sold, licensed, or shared with any party for commercial purposes.
4. AI Processing Disclosure
The SOC-lite Platform uses three third-party Large Language Model (LLM) providers to perform AI triage analysis and failover protection for forwarded alert emails.
4.1 Third-Party LLM Providers
Each forwarded alert is independently analyzed by two different LLM company agents. Both providers are subject to data processing agreements that govern how they handle prompt data submitted via API.
4.2 No AI Training on Alert Content
Alert content submitted to the LLMsI via the SOC-lite API integration is not used by either provider to train, fine-tune, or improve their AI models. CritAlertResponse operates under API usage terms that prohibit model training on customer prompt data. Members should confirm this directly with each provider’s enterprise data handling documentation if required for their own compliance purposes.
4.3 Triple-LLM Consensus Protocol
To reduce the risk of AI errors (“hallucinations”), both LLM instances must independently agree that an alert meets “Absolutely Urgent” criteria before an escalation call is triggered.
4.4 Voice Delivery: Twilio
Automated outbound voice calls are delivered via Twilio, Inc. (San Francisco, CA). Twilio processes the destination phone number and the audio content of the escalation call as a data processor on CritAlertResponse’s behalf, subject to Twilio’s Data Protection Addendum. Twilio’s privacy information is available at twilio.com/en-us/legal/privacy.
5. Subprocessors
We will notify NDPA signed Members of material changes to our subprocessor list with at least [30] days’ written notice.
6. Data Sharing and Disclosure
CritAlertResponse does not sell, rent, or license Member Data or Alert Content to any third party. We disclose data only in the following circumstances:
7. Data Retention
We retain different categories of data for different periods, as described below:
Alert email content includes forwarded emails)
365 days from receipt
Audit logs (triage decisions, notifications)
for 3 years
Member contact information
Life of contract + 2 years
Account management and post-termination dispute resolution
Billing and invoicing records
7 years
Tax and financial recordkeeping requirements
Website visitor analytics
12 months (rolling)
Standard web analytics retention
Upon termination of a Member’s agreement, we will delete or return Alert Content and Member Data within 30 days of written request, subject to any legal hold obligations. Audit logs will be retained for the periods above and made available to the Member upon written request.
8. Security
CritAlertResponse implements reasonable and appropriate technical and organizational security measures to protect data against unauthorized access, disclosure, loss, or destruction. These measures include:
In the event of a data breach involving Member Data or Alert Content, CritAlertResponse will notify affected Members within 72 hours of becoming aware of the breach, or as otherwise required by applicable law, including the Washington State Data Breach Notification Law (RCW 19.255.010) to the extent applicable to the Member’s jurisdiction.
9. FERPA and Student Data
CritAlertResponse is not an educational institution and does not seek to collect student education records. However, because Members include K–12 school districts, the Company acknowledges the following:
10. Cookies and Website Tracking
The critalertresponse.org website uses minimal cookies limited to:
We do not sell or share website visitor data with advertising networks. You may disable analytics cookies via your browser settings or a cookie consent banner without affecting your ability to use the website.
11. Member Rights and Requests
As our Members are organizations rather than individual consumers, the following rights apply at the organizational level:
To submit a data request, contact: cybersecurity@critalertresponse.org. We will respond within [30] business days
12. Children’s Privacy
The SOC-lite Platform and the critalertresponse.org website are not directed to children under the age of 13 and are not intended for use by minors. We do not knowingly collect personal data from children under 13. As noted in Section 9, any student data incidentally received through alert forwarding is handled in accordance with FERPA and is not used for any commercial purpose.
13. Changes to This Policy
CritAlertResponse reserves the right to update this Privacy Policy from time to time. For material changes, we will:
Continued use of the Service after the effective date of a material change constitutes acceptance of the updated policy. If a Member does not agree to a material change, they may terminate their agreement in accordance with their service agreement terms.
15. Contact and Complaints
For privacy questions, data requests, or complaints, contact:
Privacy Officer, CritAlertResponse, Inc.
Email: cybersecurity@critalertresponse.org
We will acknowledge receipt of all privacy inquiries within [5] business days and provide a substantive response within [30] business days. If you believe your privacy rights have been violated and we have not adequately addressed your concern, you may contact your state’s Attorney General office or applicable regulatory authority.
CritAlertResponse, Inc. © [2026]. All rights reserved.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.