Readiness Xchange®

Privacy & Security Policy

Last updated: August 10, 2026

Readiness Xchange® (“we,” “us,” “our”) is a cloud-based Software as a Service (SaaS) platform. This Privacy & Security Policy explains how we collect, use, store, separate, and protect information when organizations and their authorized users access or interact with the Readiness Xchange platform.

Questions may be directed to info@readinessxchange.com

1. Platform Architecture & Hosting

Readiness Xchange is delivered as a multi-tenant SaaS application. The browser-based front end is written in JavaScript. Application data is stored in a Microsoft Azure database environment and supported by Microsoft Azure cloud infrastructure.

Customer organizations are logically separated within the platform using a unique client/organization identifier (ID). This tenant-level separation is used to associate data with the appropriate customer organization and to prevent one client’s data from being presented as another client’s data. This is logical data separation within the SaaS environment and does not imply that each customer has a physically separate database unless separately contracted.

2. Information We Collect

Readiness Xchange is designed to minimize the collection of personally identifiable information (PII). The platform does not require sensitive personal information to operate.

  • Authorized User Account Data: for individuals who are provided access to the application, Readiness Xchange stores only the information needed to establish and manage the user account, including the user’s name and business email address.
  • Organizational Information: company/organization name, department or organizational unit names, and assigned role or permission level may also be stored to configure access, reporting, and organizational structure within the platform.
  • Platform and Assessment Data: readiness, adoption, sentiment, capacity, survey, activity, comments, notes, and other information entered or generated through use of the platform.
  • Technical Data: authentication and session data, IP address, device/browser information, and essential cookies or logs used for security and platform operation.

Readiness Xchange does not require users to provide home addresses, personal telephone numbers, Social Security numbers, dates of birth, financial account information, or other sensitive personal identifiers as part of normal platform use.

3. How We Use Information

We use collected information to:

  • Provide, operate, maintain, and improve the Readiness Xchange platform.
  • Generate readiness, adoption, and trend insights.
  • Support user authentication and secure access.
  • Respond to customer support and service requests.
  • Maintain platform security and system performance.
  • Support product improvement and roadmap development.

We follow principles of data minimization, purpose limitation, secure storage, and transparency.

4. Data Separation, Access & Role-Based Visibility

Readiness Xchange uses client/organization IDs, role-based access controls, and application permissions to support appropriate separation and visibility of customer data.

The platform also uses screen-level masking for certain sensitive fields. Details such as email addresses may be blurred or hidden by default and revealed only according to the user’s permissions and application behavior. This reduces accidental exposure during meetings, screen sharing, presentations, and team reviews.

Users are intended to see only the information available to their organization and permitted by their assigned role.

5. Data Sharing

We do not sell, trade, or rent personal data.

We may share or make data accessible only as reasonably necessary to operate and support the service, including with:

  • Microsoft Azure, for cloud hosting, database services, and secure platform operation.
  • Service providers assisting with authentication, analytics, security, or system performance.
  • Authorized internal team members or approved technical support personnel who require access for support, maintenance, or troubleshooting.

We may also disclose information when required by law or valid legal process.

6. Security Measures

We use technical and organizational safeguards designed to protect information from unauthorized access, alteration, loss, misuse, or disclosure. These measures include, as applicable:

  • Encryption in transit and at rest.
  • Microsoft Azure cloud infrastructure and database services.
  • Logical client/tenant separation using unique organization IDs.
  • Role-based access control and permission management.
  • Secure authentication and session practices.
  • Limited access to operational data by authorized personnel.
  • Screen-level masking of certain sensitive details.

7. Microsoft Azure Compliance

Readiness Xchange utilizes Microsoft Azure cloud infrastructure and database services. Microsoft states that Azure and other in-scope Microsoft cloud services undergo independent third-party SOC audits. Microsoft’s certifications and attestations apply to the applicable Microsoft services and do not independently constitute certification of Readiness Xchange.

Official Microsoft compliance resources: SOC 2 Type 2 | SOC 1 Type 2 | SOC 3 | Azure Compliance Offerings

8. Data Retention & Customer Requests

We retain customer data for as long as an organization maintains an active Readiness Xchange account or as otherwise required by contract or law.

Where applicable, organizations may request export of their data, deletion of data, or closure of their account. Certain information may be retained when legally required or reasonably necessary for security, dispute resolution, or contractual obligations.

9. Cookies and Tracking Technologies

We use essential cookies and similar technologies for authentication, security, session stability, and basic usage analytics. Users may disable cookies in their browser, although doing so may affect platform functionality.

10. Privacy Rights

Subject to applicable law and the organization’s contractual relationship with Readiness Xchange, individuals may have rights to access, correct, or request deletion of personal information associated with them, and to exercise other privacy rights provided by applicable law.

Requests should be submitted to info@readinessxchange.com. In some cases, requests involving data controlled by a customer organization may need to be directed to or coordinated with that organization.

11. Consent and Authorized Use

By accessing or using the Readiness Xchange platform, users acknowledge the data practices described in this policy and agree to use the platform in accordance with their organization’s authorization and applicable terms.

12. Updates to This Policy

We may update this policy periodically to reflect changes in the platform, technology, security practices, legal requirements, or business operations. The current version will identify its effective or last-updated date.

13. Contact Us

For privacy or security questions and requests, contact: info@readinessxchange.com