This Privacy Policy was last updated May 18, 2026.

  1. Privacy Policy Overview

This Privacy Policy describes how Capital Edge Consulting, LLC, a Delaware limited liability company, and its subsidiaries, affiliates, and related entities (collectively, “Capital Edge,” “Company,” “we,” or “us”) collects and processes information about consumers. Certain consumer privacy laws, such as The California Consumer Privacy Act and the California Privacy Rights Act of 2020 (collectively the “CCPA”), require us to provide our consumers with a privacy policy that contains a comprehensive description of our online and offline practices regarding our collection, use, sale, sharing, and retention of their Personal Information, along with a description of the rights they have regarding their Personal Information. This Privacy Policy provides the information required by applicable law, together with other useful information regarding our collection and use of consumers’ information. This Privacy Policy applies to information collected by Capital Edge offline and through our websites, including, without limitation https://capitaledgeconsulting.com/ (the “website”), regardless of where you access our website. This Privacy Policy also applies to and governs your use of any services, products, or other media forms related or connected to the website (collectively with the website, the “services”).

We may provide additional or different privacy policies that are specific to certain features, services, or activities. Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our services or providing us with your information, you agree to the collection, use, and sharing of your information as described in this Privacy Policy. This Privacy Policy may change from time to time (see “Changes to this Privacy Policy”). We will notify you of these changes before the occur, but your continued use of the services after we make changes as described herein is deemed to be acceptance of those changes, so please check this Privacy Policy periodically for updates.

  1. Collection of Information

We collect and use information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household (“Personal Information”). Our Personal Information collection does not include information about consumers we know are under age 16.

The chart below identifies which categories of Personal Information we have collected from our consumers in the last twelve (12) months:

CategoryExamples
Identifiers.A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) (“California Customer Records”).A name, signature, Social Security number, physical characteristics or description, photograph, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, membership in professional organizations, professional licenses and certifications, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.Some Personal Information included in this category may overlap with other categories.
Commercial information.Records of personal property, products, or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Internet or other similar network activity.Activity on our websites, mobile apps, or other digital systems, such as internet browsing history, search history, system usage, electronic communications with us, postings on our social media sites.
Geolocation data.Physical location or movements, such as the time and physical location related to use of our internet website, application, or device, and GPS location data from mobile devices of consumers who visit our websites or use our mobile apps.
Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) (“FERPA Information”).Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
Inferences drawn from other Personal Information.Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Sensitive Personal Information.Further identified in the list below.
  1. Collection of Sensitive Personal Information

The list below identifies which categories of sensitive Personal Information (as that term is defined in Cal Civ Code § 1798.140) we have collected from our consumers in the last twelve (12) months:

  • Complete account access credentials (i.e. usernames, account logins, account numbers, or card numbers combined with required access/security code or password).
  1. How Your Personal Information is Collected

We collect Personal Information from the following categories of sources:

  • You, directly in person, by telephone, text, or email, via our website, and via our other services;
  • From third parties with your consent (e.g. your bank, payment processors, email platform providers, analytics, security and anti-fraud services);
  • Advertising networks;
  • Internet service providers;
  • Data analytics providers;
  • Government entities;
  • Operating systems and platforms;
  • Social networks;
  • Data brokers;
  • Publicly accessible sources (e.g., property records);
  • Cookies on our website; and
  • Mobile device information (such as your mobile device ID, model and manufacturer), operating system, version information and IP address).

3. Use of Personal Information

Under data protection laws, we can only use your Personal Information if we have a proper reason such as:

  • To comply with our legal and regulatory obligations;
  • For the performance of our contract with you or to take steps at your request before entering into a contract;
  • For our legitimate interests or those of a third party (where a legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests); or
  • Where you have given consent.

The table below sets forth our reasons for collecting and using (processing) your Personal Information:

Our Commercial or Business Purposes for Using Your Personal Information:Our legal basis:
To provide products and services to youFor the performance of our contract with you or to take steps at your request before entering into a contract
To prevent and detect fraud against you or usFor our legitimate interests or those of a third party, i.e., to minimize fraud that could be damaging for us and for you
Ensuring business policies are adhered to, e.g., policies covering security and internet useFor our legitimate interests or those of a third party, i.e., to make sure we are following our own internal procedures so we can deliver the best service to you
Operational reasons, such as improving efficiency, training, and quality controlFor our legitimate interests or those of a third party, i.e., to be as efficient as we can so we can deliver the best service for you at the best price
Ensuring the confidentiality of commercially sensitive information• For our legitimate interests or those of a third party, i.e., to protect trade secrets and other commercially valuable information
• To comply with our legal and regulatory obligations
Statistical analysis to help us manage our business, e.g., in relation to our financial performance, customer base, product range or other efficiency measuresFor our legitimate interests or those of a third party, i.e., to be as efficient as we can so we can deliver the best service for you at the best price
Preventing unauthorized access and modifications to systems• For our legitimate interests or those of a third party, i.e., to prevent and detect criminal activity that could be damaging for us and for you
• To comply with our legal and regulatory obligations
Updating customer records• For the performance of our contract with you or to take steps at your request before entering into a contract
• To comply with our legal and regulatory obligations
• For our legitimate interests or those of a third party, e.g., making sure that we can keep in touch with our customers
Statutory returnsTo comply with our legal and regulatory obligations
Ensuring safe working practices, staff administration and assessments• To comply with our legal and regulatory obligations
• For our legitimate interests or those of a third party, e.g., to make sure we are following our own internal procedures and working efficiently so we can deliver the best service to you
Marketing our services to:
• Existing and former customers
• Third parties who have previously expressed an interest in our services
• Third parties with whom we have had no previous dealings
For our legitimate interests or those of a third party, i.e., to promote our business to existing and former customers
• External audits and quality checks, e.g., for ISO or Investors in People accreditation and the audit of our accounts• For our legitimate interests or a those of a third party, i.e., to maintain our accreditations so we can demonstrate we operate at the highest standards
• To comply with our legal and regulatory obligations

We do not use or disclose sensitive Personal Information for purposes other than the those explicitly permitted by Cal Civ Code § 1798.121 (the “Permitted SPI Purposes”).

  1. Sales, Sharing, and Business Purpose Disclosures of Personal Information

We may disclose the Personal Information we collect, including sensitive Personal Information, to third parties for the purposes described in Section 3 (“Use of Personal Information”) above. We only make these disclosures under written contracts that describe the purposes, require the recipient to keep the Personal Information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet other contract requirements of applicable data privacy laws for engaging service providers or contractors. 

  1. Personal Information We Sold or Shared.

We do not sell your Personal Information, including sensitive Personal Information, to third parties and have not sold it in the preceding 12 months. We may share your Personal Information with third parties for cross-context behavioral advertising purposes but have not shared your Personal Information in the preceding 12 months.

We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

We may also need to share some Personal Information with other parties, such as potential buyers of some or all of our business or during a re-structuring. We will typically anonymize information, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations as required by applicable law.

  1. Business Purpose Disclosures of Personal Information.

We may disclose the Personal Information we collect, including sensitive Personal Information, to third parties for the business purposes described below, such as to engage third parties to support our business functions. For example, we may disclose information from your visits to our website to a cybersecurity consultant to help secure the website.

The chart below sets forth:

  • the categories of Personal Information, including sensitive Personal Information, we have disclosed for a business purpose in the preceding twelve (12) months;
  • the categories, if any, of Personal Information, we have sold or shared in the preceding twelve (12) months.
  • the categories of third parties we have disclosed such Personal Information to or with; and
  • our business/commercial purpose for such disclosure.
Category of Personal Information Disclosed for a Business PurposeCategories of Recipients of Such Business Purpose DisclosureBusiness Purpose/Legal Basis for Such Business Purpose Disclosure
IdentifiersOur service providers (such as payment service providers)Our marketing partnersOur banksMarketing our servicesProviding products and services to youStatistical analysis to help us manage our businessUpdating customer recordsOperational reasonsTo prevent and detect fraud against you or us
California Customer RecordsOur service providers (such as payment service providers)Our marketing partnersOur banksMarketing our servicesProviding products and services to youStatistical analysis to help us manage our businessUpdating customer recordsOperational reasonsTo prevent and detect fraud against you or us
Commercial information.Our marketing partners• Marketing our services
• Statistical analysis to help us manage our business
Internet or other similar network activity.Our marketing partners• Marketing our services
• Statistical analysis to help us manage our business
Geolocation data.Our marketing partners• Marketing our services
• Statistical analysis to help us manage our business
Inferences drawn from other Personal Information.Our marketing partners• Marketing our services
• Statistical analysis to help us manage our business
  1. How Long We Retain Your Personal Information

We will keep your Personal Information while you have an account with us or while we are providing products and/or services to you. Thereafter, we will only keep your Personal Information for as long as is necessary:

  • To respond to any questions, complaints or claims made by you or on your behalf;
  • To show that we treated you fairly; or
  • To keep records required by law.

We will not retain your Personal Information for longer than necessary for the purposes set out in this Privacy Policy. Different retention periods apply for different types of Personal Information. When it is no longer necessary to retain your Personal Information, we will delete or anonymize it.

  1. Your State Privacy Rights
    1. For California Consumers

California consumers have the following rights under the CCPA and certain other privacy and data protection laws, as applicable:

  • Right to Know and Data Portability Requests. You have the right to request that we disclose certain information to you about our collection and use of your Personal Information (the “right to know”), including the specific pieces of Personal Information we have collected about you (a “data portability request”). Once we receive your request and confirm your identity (see “How to Exercise Your Data and Privacy Rights”), we will disclose to you (with such disclosures covering the 12-month period preceding the request):
    • The categories of: (x) Personal Information we have collected about you; and (y) the sources from which we collected your Personal Information. 
    • The business or commercial purpose for collecting your Personal Information and, if applicable, selling, sharing, or otherwise disclosing your Personal Information.
    • If applicable, the categories of persons, including third parties, to whom we disclosed your Personal Information, including separate disclosures identifying the categories of your Personal Information that we: (x) disclosed for a business purpose to each category of persons; and (y) sold or shared to each category or third parties.
    • When your right to know submission includes a data portability request, a copy of your Personal Information subject to any permitted redactions.

For more information on exercising this right, see below: “How to Exercise Your Data and Privacy Rights.”

  • Right to Delete and Right to Correct. You have the right to request that we delete any of your Personal Information that we collected from you and retained, subject to certain exceptions and limitations (the “right to delete”). Once we receive your request and confirm your identity, we will delete your Personal Information from our systems unless an exception allows us to retain it. We will also notify our service providers, contractors, and other recipients to take appropriate action.

You also have the right to request correction of personal information we maintain about you that you believe is inaccurate (the “right to correct”). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct personal information that our review determines is inaccurate and notify our service providers, contractors, and other recipients to take appropriate action.

For more information on exercising the rights set forth above, see “How to Exercise Your Data and Privacy Rights”.

  • Right to Limit Sensitive Personal Information Use and Disclosure. You have a right to ask businesses that use or disclose your sensitive Personal Information to limit those actions to just the CCPA’s Permitted SPI Purposes (the “right to limit”). As we do not use or disclose sensitive Personal Information beyond the CCPA’s Permitted SPI Purposes, we do not currently provide this consumer right.

For more information on exercising this right, see below: “How to Exercise Your Data and Privacy Rights.”

  • Personal Information Sales or Sharing Opt-Out and Opt-In Rights. You have the right to request that businesses stop selling or sharing your Personal Information at any time (the “right to opt-out”), including through a user-enabled opt-out preference signal. Similarly, the CCPA prohibits businesses from selling or sharing the Personal Information of consumers it actually knows are under 16 years old without first obtaining consent from consumers who are between 13 and 15 years old or the consumer’s parent or guardian for consumers under age 13 (the “right to opt-in”).

For more information on exercising this right, see below: “How to Exercise Your Data and Privacy Rights.”

  • Right to Non-Discrimination. You have the right not to be discriminated or retaliated against for exercising any of your data and/or privacy rights. We will not:
    1. Deny you goods or services because you chose to exercise your data and/or privacy rights.
    2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties because you chose to exercise your data and/or privacy rights.
    3. Provide you a different level or quality of goods or services because you chose to exercise your data and/or privacy rights.
    4. Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services because you chose to exercise your data and/or privacy rights.

While certain consumers have the right to opt-out of the sale and sharing of their Personal Information under CPRA, we do not sell or share Personal Information to any third parties, and therefore, we have not included a “Do Not Sell or Share My Personal Information” link on our Site. If our practices change, we will update this Privacy Policy and take any other necessary action to comply with applicable law.

If you are a California resident and wish to exercise any of your rights as set forth above, please see below: “How to Exercise Your Data and Privacy Rights.”

  1. Other States’ Privacy Notice

Other states provide their consumers with certain rights related to their Personal Information, including the rights to: (i) know; (ii) make a data portability request; (iii) delete; (iv) correct; (v) limit; and (vi) opt-in. While we do not currently sell or share data to trigger certain states’ opt-out requirements, if you have any questions about our collection, processing, sharing, or sale of Personal Information in your state, or if you wish to exercise any of your Personal Information rights, please use the forms found here or write us at: privacy@capitaledgeconsulting.com.

  1. How to Exercise Your Data and Privacy Rights

If you would like to exercise any of your rights as described in this Privacy Policy, you can do so here. You may also call us toll free at (855) 227-3343, send us email correspondence at: privacy@capitaledgeconsulting.com.com, or send us postal correspondence at:

Capital Edge Consulting, LLC
Attn: Privacy Manager
8521 Leesburg Pike, Suite 425
Vienna, VA 22182

  • Please note that you may only make a CCPA/CPRA-related data access or data portability disclosure request twice within a 12-month period.
  • If you choose to contact us directly by email or in writing, you will need to provide us with:
    • Enough information to identify you (e.g., your full name, username, address and customer, or matter reference number)
    • Proof of your identity and address (e.g., a copy of your driving license or passport and a recent utility or credit card bill); and
    • A description of what right you want to exercise and the information to which your request relates
  • We are not obligated to make a data access or data portability disclosure if we cannot verify that the person making the request is the person about whom we collected information or is someone authorized to act on such person’s behalf.
  • Any Personal Information we collect from you to verify your identity in connection with you request will be used solely for the purposes of such verification.
  1. Visitors and Users Outside of the United States
    1. Your Rights Under European Region Data Privacy and Protection Laws

Consumers who reside in the European Economic Area (“EEA”), the United Kingdom, Switzerland, or Gibraltar (collectively the “European Region”) have the following rights with respect to their Personal Information Under the European Union’s General Data Protection Regulation (“GDPR”), the Digital Services Act (“DSA”), the UK General Data Protection Regulation (“UK GDPR”), and certain other privacy and data protection laws, as applicable:

  • The right to know or be notified about the collection and use of your Personal Information;
  • The right to be provided with a copy of your Personal Information;
  • The right to require us to correct any mistakes in your Personal Information;
  • The right to require us to delete your Personal Information in certain situations;
  • The right to require us to restrict processing of your Personal Information in certain circumstances, e.g., if you contest the accuracy of the data;
  • The right to receive the Personal Information you provided to us, in a structured, commonly used, and machine-readable format and/or transmit that data to a third party in certain situations;
  • The right to object:
    1. At any time to your Personal Information being processed for direct marketing (including profiling); and 
    2. In certain other situations to our continued processing of your Personal Information, e.g., processing carried out for our legitimate interests; and
  • The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you.
  1. Exercising Your Rights. For more information on exercising the rights set forth above, see “How to Exercise Your Data and Privacy Rights” above.
  2. European Region Consumers: How to File a Complaint

The GDPR and other data privacy/protection laws give you right to lodge a complaint with a supervisory authority, in the European Region state where you work, normally live, or where any alleged infringement of data protection laws occurred. To file a complaint, please contact the appropriate supervisory authority in the country where you work, normally live, or where any alleged infringement of data protection laws occurred.

  1. Transfer, Storage, and Processing of Personal Information
    1. Where Your Personal Information is Held

Information may be held at our offices and those of our group companies, third-party agencies, service providers, representatives and agents as described above (see above: “Sales, Sharing, and Business Purpose Disclosures of Personal Information”).

Some of these third parties may be based outside the European Region. For more information, including on how we safeguard your Personal Information when this occurs, see below: “Transferring Your Personal Information.”

  1. Transferring Your Personal Information

If you are in the European Region, when we transfer your Personal Information outside of the European Region, we will ensure that: (i) the European Commission has deemed that there is an adequate level of protection; (ii) a contract is in place that contains the European Commission approved Standard Contractual Clauses or other similar clauses that are compatible with GDPR; or (iii) we use another legally recognized transfer mechanism in the applicable jurisdiction.

  1. Security of Personal Information

Capital Edge uses appropriate security measures in place to prevent Personal Information from being accidentally lost or used or accessed in an unauthorized way. We limit access to your Personal Information to those who have a genuine business need to access it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password and/or username for access to certain parts of our services, you are responsible for keeping such information confidential. We ask you not to share your password or username with anyone. We ask you to select unique and secure passwords when setting up profiles in our services.

  1. Changes to this Privacy Policy

We may change this privacy notice from time to time–when we do, we will inform you via our website or other means of contact such as email. If we need to use your Personal Information for any other purpose then as set forth in this Privacy Policy, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your Personal Information without your knowledge or consent where this is required or permitted by law.

  1. Dispute Resolution
    1. United States Dispute Resolution

This Privacy Policy shall be governed by the laws of the Commonwealth of Virginia. The provisions of Section 12.2 notwithstanding, the parties shall resolve any dispute, controversy, or claim arising out of or relating to this Privacy Policy (each a “Dispute”), including Disputes arising from or concerning the interpretation, violation, invalidity, non-performance, or termination of this Privacy Policy: (i) first, by good faith negotiations, and (i) second, if such negotiations do not resolve a Dispute within forty five (45) days of their commencement, to final and binding arbitration conducted by JAMS in Fairfax County, Virginia. The procedures set forth herein shall be the sole and exclusive mechanisms for resolving any Dispute that may arise. You hereby waive any and all objections to the exercise of jurisdiction over you by JAMS at such location and agree that the parties’ choice of arbitration as a dispute resolution mechanism under this Agreement is intended to be mandatory and not permissive thereby precluding the possibility of litigation in any other forum, provided that we retain the right to bring any pre-arbitration suit, action, or proceeding against you for breach of our Policies in order to seek pre-arbitration injunctive relief or security in any competent jurisdiction. Any arbitration award may be enforced in any court of competent jurisdiction.

  1. International Dispute Resolution

If you reside in the European Region and believe that Capital Edge is not processing your Personal Information in accordance with the requirements set out herein or applicable European Region data protection laws, you can at any time lodge a complaint with the data protection authority of the European Region country in which you live. We would, however, appreciate the chance to deal with your concerns before you approach the data protection authority so please contact us in the first instance.

Capital Edge commits to cooperate with European Region data protection authorities and comply with the advice given by such authorities with regard to human resources data transferred from the European Region in the context of the employment relationship.

In the event of any Dispute arising out of or relating to this Privacy Policy, or a breach thereof, Capital Edge shall consult and negotiate with you and, recognizing our mutual interests, attempt to reach a satisfactory solution. If we do not reach settlement within a period of 60 days, then, upon notice by any party to the other(s), any unresolved controversy or claim shall be settled by arbitration administered by the International Centre for Dispute Resolution in accordance with the provisions of its International Arbitration Rules and governed by the law of the Commonwealth of Virginia. The number of arbitrators shall be one. The location of arbitration shall exclusively be in Fairfax County, Virginia, USA. The language of the arbitration shall be English.

  1. Contacting Us

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your information described here, your choices and rights regarding such use, or if you would like this notice in another format (for example: audio, large print, braille) please do not hesitate to contact us via:

Email at: privacy@capitaledgeconsulting.com; or

Postal mail at: Capital Edge Consulting, LLC
Attn: Privacy Manager
8521 Leesburg Pike, Suite 425
Vienna, VA 22182