Working draft — not yet in force

This document is a drafting aid prepared for review by qualified counsel. It has not been reviewed by a lawyer, is not legal advice, and must not be published or relied upon until it has been. Clauses marked new are proposed additions that have not appeared in any previously published Pinnacle Global policy. Clauses marked decision required cannot be finalised until the owner elects between the stated options. Clauses marked counsel raise a question to be put to counsel specifically. A privacy policy must describe what the Company actually does — sections describing processing not yet built are marked as such.

Privacy Policy

Effective Date: September 1, 2026

How Pinnacle Global handles information in connection with atbae.ai, the verification checkpoint, and the examination record.

1. Scope

This Privacy Policy describes how Pinnacle Global Advisory and Consultancy LLC ("Pinnacle Global," "the Company," "we," "us") handles information in connection with the website available at atbae.ai, atbae.pro, pinnacleglobal.pro and pgac.works (the "Website").

Information handled in the course of a client engagement is governed by the applicable engagement agreement, which controls over this Policy. Sections 11 and 12 describe processing connected with the verification checkpoint and the examination record, which the Company performs whether or not a client engagement exists.

new 1.1 Our role. For most processing described here — Website operation, correspondence, verification requests, and the examination record — the Company acts as a controller: it determines why and how the information is processed. Where the Company processes personal information contained within material a client supplies for examination, it acts as a processor on that client's instructions, under the engagement agreement and any data-processing terms it contains. Where the two roles meet, the engagement agreement governs. counsel This allocation should be settled once, centrally, with the engagement agreement's data-processing terms.

2. Information We Collect

The Website does not require accounts, does not host payment processing, and does not set tracking or advertising cookies of its own. Information we may receive is limited to:

(a) Correspondence you choose to send us (such as an email inquiry), including your contact details and anything you include in your message.

(b) Technical data recorded by our hosting infrastructure, such as IP address, browser type, pages requested, and timestamps, used for security and operational purposes.

(c) Verification request details, as described in section 11.

(d) Engagement and intake information, where you commission an examination — contact details, organisation, and the technical scoping information the intake process requires.

The intake and verification forms transmit nothing on their own. The commission and verification pages compose your submission in your own browser, download a dated copy to your machine, and hand the text to your own email client. Nothing is posted to us, and no third-party form service is involved. We receive your submission only when you choose to send that email.

decision required The paragraph above is accurate for the current mailto-based flow. If the intake is changed to post to a server or a stored engagement record (including the engagement-record storage the Company is considering on Google Cloud), this paragraph becomes false and must be rewritten before that change ships.

3. Legal Bases for Processing new

Where the EU or UK GDPR, or a comparable regime, applies to our processing, we rely on the following bases:

PurposeLegal basis
Responding to inquiries and correspondenceLegitimate interests — responding to those who contact us
Scoping, entering and performing an engagementPerformance of a contract, or steps taken at your request before entering one
Operating and securing the WebsiteLegitimate interests — security and availability of our own service
Verification requests and the disclosure recordLegitimate interests — the integrity of an assurance instrument that third parties rely upon
Regulatory-disclosure requestsCompliance with a legal obligation, or the exercise of official authority vested in the requesting body
Retaining manifests, hashes and the revocation list indefinitelyLegitimate interests — the undertaking that a seal remains verifiable in perpetuity, on which third parties rely
Responding to legal claims and regulatory demandsCompliance with a legal obligation, and legitimate interests in establishing or defending legal claims

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights. You may object to processing on that basis — see section 13.

4. How We Use Information

We use the information described above solely to respond to inquiries, to evaluate and enter into prospective engagements, to operate and secure the Website, to perform and record verifications as described in section 11, to maintain the examination record described in section 12, and to comply with legal obligations.

We do not use Website or verification data to train any model or system.

5. No Sale of Personal Information; No Advertising

We do not sell, rent, or trade personal information, and we do not use Website data for advertising or profiling. We do not share personal information with third parties except service providers necessary to operate the Website, professional advisers, or where required by law.

new We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act as amended, and we do not process personal information for cross-context behavioural advertising.

6. Client Data Remains Proprietary

As a matter of firm policy and contract, data belonging to a client institution remains the property of that institution. Client data is never used to train models or systems for any other party, and its handling is governed by the confidentiality and data-protection terms of the applicable engagement agreement.

Where a client elects Company-hosted weights (Route B under Schedule A of the Terms), supplied model weights and any accompanying material are held in isolated, encrypted, single-tenant capacity, used solely to perform the commissioned examination, and destroyed on completion with destruction attested to the client. They are not used to train any system and are not evaluated for any other party.

7. Service Providers, Sub-Processors, and Examination Infrastructure new

7.1 Website infrastructure. The Website is served by our hosting provider, which processes technical data as described in section 2(b). The Website's typefaces are self-hosted: displaying the Website involves no connection to any third-party font service and no transmission of your IP address for that purpose.

7.2 Examination infrastructure. Where an examination is performed against a client endpoint (Route A under Schedule A), probes are fired from Company-controlled equipment at the endpoint the client designates; the subject model, the endpoint, and its serving infrastructure remain the client's. Where a client elects Company-hosted weights (Route B), the examination runs on isolated, single-tenant capacity on Google Cloud Platform (us-central1), with material encrypted in transit and at rest and destroyed on completion as described in section 6. Classification and scoring are performed by the Company's own examination apparatus; no third-party model API is used for classification, adjudication, or judging — classification operates through deterministic, versioned evaluators running locally in the execution environment, and extended adjudication is performed by vetted, NDA-bound human reviewers, never by an external automated model service.

7.3 Sub-processors. The Company may use the following categories of service providers in delivering the Website and examinations: Google Cloud Platform (Route B examination capacity and, where adopted, engagement-record storage), and the Website hosting provider. Where engagement records are stored on Google Cloud, they are held under object versioning and a retention policy in a dedicated bucket with per-client segregation, synchronised to Company-controlled premises. Material additions to this list will be announced on this page before the new provider processes client material. decision required A published sub-processor list with a change-notification mechanism is standard for enterprise and regulated procurement; recommend maintaining it here.

7.4 Adjudication panels and external reviewers. Where an engagement involves an adjudication panel (Schedule A, A.5) or a Level 2 external reviewer (Schedule A, A.11), those parties receive examination material under confidentiality terms binding them to the engagement's obligations. They act as independent parties and not as our processors.

8. International Data Transfers new

Pinnacle Global Advisory and Consultancy LLC is established in the United States and processes information on infrastructure located within the United States.

Where personal information or client examination material is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States, such transfers are executed on the basis of recognized statutory safeguards under applicable data protection laws (including GDPR Article 46), specifically:

Where required, international transfers are supplemented by Transfer Risk Assessments (TRAs) and technical security safeguards, including encryption in transit and at rest.

counsel If any European engagement is taken, the following become live and none of them exist today: the executed SCC/IDTA modules themselves, a record of processing activities (GDPR Art. 30), and — depending on scale and offering — an Article 27 representative in the EU and UK. This should be assessed before the first European engagement rather than during it.

9. Security

We apply reasonable technical and organizational measures appropriate to the nature of the data we handle, including encryption of supplied material in transit and at rest, isolated single-tenant capacity for Company-hosted weights, access control over evidence bundles, and signed manifests over the examination record.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.1 Credentials. Endpoint credentials are exchanged only after scoping, are never transmitted through the Website, and are held only for the period necessary to perform the commissioned examination.

9.2 Incident notification. Where a confirmed security incident affects personal information, client confidential material, or examination artifacts, the Company shall notify the affected client without undue delay and in any event within seventy-two (72) hours of becoming aware of the confirmed breach. The Company shall also notify supervisory authorities and affected individuals where required by applicable law. Our notification will describe: the nature and scope of the incident; the categories of data or artifacts affected; the mitigation and containment measures already executed or underway; and recommended actions the client may take to mitigate potential risks.

10. Retention

Correspondence is retained for as long as reasonably necessary for the purposes above, to maintain business records, or as required by law, and is then deleted or anonymized. Retention connected with verification and the examination record is described in sections 11 and 12.

new Indicative periods:

CategoryRetention
Website technical logs90 days — security auditing, abuse mitigation, and log hygiene
Correspondence and inquiriesDuration of the business relationship plus five (5) years — covering applicable commercial limitation periods and tax records
Engagement agreements and scoping recordsDuration of the business relationship plus seven (7) years — standard governance, audit, and tax requirement
Endpoint credentialsDestroyed immediately on completion of the examination
Supplied model weights (Route B)Destroyed on completion, with destruction attested to the client
Evidence bundles and transcriptsAs stated in the engagement agreement (typically 3–5 years), access-controlled and encrypted
Verification request recordsFor as long as the associated examination record is retained — tied to the seal's chain of custody
Manifests, hashes, revocation and supersession listIndefinitely — see section 12

11. Verification Requests

Verification of a seal is free and is never metered. It is not anonymous. To calibrate disclosure to standing, we must know who is asking.

What we collect. For a standard-disclosure request: your name, the capacity in which you act, the organization you represent, your email address, and optionally a telephone number. For a regulatory-disclosure request we additionally collect the agency or authority name, its official email domain, its published switchboard number, a postal address for the letterhead request, and any legal basis or matter reference you choose to provide.

Why. To confirm that the requestor is who they claim to be, to determine the level of disclosure to which they are entitled, and to maintain an auditable record of disclosures made. For regulatory requests, verification is manual and may include an independent callback through the agency's published switchboard and confirmation through its administrative office.

Legal basis (where the GDPR or a comparable regime applies): our legitimate interest in the integrity of an assurance instrument that third parties rely upon, and, for regulatory requests, compliance with a legal obligation or the exercise of official authority.

Disclosure to the commissioning client. We do not tell the commissioning client who verified its seal unless that client elected Verification Transparency at onboarding. Where a requesting authority has lawfully directed us not to disclose a request, we comply unconditionally and the client is not notified.

Retention. A record of each verification request and the disclosure made is appended to the examination's record and retained for as long as that record is retained.

Misuse. Deliberate submission of an altered or fabricated seal, or a false claim of regulatory or governmental status, is logged with the identifying details supplied and may be referred to the relevant authorities. That logging is a necessary consequence of operating a checkpoint that others rely upon.

11.1 Terms of use. Use of the verification checkpoint is additionally governed by Schedule B of the Terms of Service, which every requestor must accept before a result is returned. Schedule B includes a non-reliance notice. Acceptance is logged with the request record.

12. The Examination Record

An examination produces a signed manifest, a report hash, and a sealed evidence bundle. Manifests, hashes, the revocation and supersession list, and the record of disputes and amendments are retained indefinitely, because a seal that cannot be verified years later is worthless and we undertake that seals remain verifiable in perpetuity.

Evidence bundles containing transcripts are access-controlled and retained as stated in the applicable engagement agreement. Transcripts containing dangerous content are excerpted in the report and held in the bundle rather than published.

Examination records ordinarily concern models, endpoints, and organizations rather than individuals. Where an examination record contains personal information — for example the name of a named reviewer, an adjudicator, or a client contact — it is retained as part of the auditable record for the reasons stated above.

new 12.1 Personal information inside subject material. Model outputs captured during an examination may contain personal information — for example where a subject model emits a name or contact detail in response to a probe. Such content is held within the access-controlled evidence bundle, is not published, and is excerpted in a report only where necessary to evidence a finding, redacted where redaction does not defeat the finding. counsel This content is captured deliberately, by design; its handling warrants counsel's attention.

new 12.2 Zero personal information in manifests, by design. Examination manifests are engineered to carry only machine facts — digests, timestamps, model and configuration identifiers — and never a named individual. Because the perpetual record contains no personal information by construction, an erasure request can be honoured in full against contact and correspondence records without touching the cryptographic record on which third parties rely.

13. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, or delete personal information we hold about you; to object to or restrict certain processing; to data portability; and to withdraw consent where processing is based on consent. To exercise these rights, contact us via the details on the main page. We will respond as required by applicable law and will not discriminate against you for exercising them.

new Where the GDPR or a comparable regime applies, you also have the right to lodge a complaint with your local supervisory authority.

13.1 Automated decision-making. We do not make decisions producing legal or similarly significant effects concerning individuals by automated means. The battery produces automated verdicts about models and systems, not about people. Where an examination record names an individual, that record is not used to make any automated decision about them.

Two limits apply and we state them plainly rather than leaving them to be discovered.

First, we cannot delete the record of a verification request in a way that would defeat the integrity of the examination record, because that record is the evidence of who was told what and when.

Second, we cannot delete examination manifests and hashes, because we undertake that a seal remains verifiable in perpetuity and deleting them would break every seal already relied upon.

Where a deletion request touches these records we will explain which parts we can act on and which we cannot, and why.

counsel The perpetual-retention undertaking versus the right to erasure is the hardest privacy question in this business. The mitigations adopted here are manifests free of personal information by design (section 12.2) and a documented legitimate-interest balancing assessment, which should be prepared now rather than when a request arrives.

14. Cookies and Technical Storage

Zero tracking, zero advertising, zero analytics. The Website does not use any tracking cookies, advertising pixels, session-recording scripts, or third-party analytics services. We do not profile visitors or monetize web traffic.

Strictly necessary infrastructure cookies. Depending on network routing, our edge infrastructure provider may set temporary, strictly necessary technical cookies solely for bot protection and DDoS mitigation (distinguishing legitimate human visitors from automated malicious traffic) and for cryptographic load balancing (ensuring request-routing stability across distributed edge nodes). These technical cookies contain no personal or behavioural data, are strictly necessary for the secure transmission and defence of the Website, and are exempt from consent requirements under applicable privacy regulations (including the EU ePrivacy Directive and the GDPR).

15. Children

The Website is directed to institutional and professional audiences and is not intended for children under 18. We do not knowingly collect information from children.

The battery includes a class examining a subject model's suitability for children. That examination is performed against the subject model using constructed probes; it does not involve children, and no data from or about any child is collected in the course of it.

16. Changes to This Policy

We may update this Policy from time to time by posting a revised version on this page with an updated effective date.

new Where a change materially affects how we handle information already collected, we will provide notice by a means reasonably designed to reach affected parties before the change takes effect.

17. Contact and Data Protection Inquiries

If you have questions regarding this Privacy Policy or our data practices, or wish to exercise statutory data-subject rights (including GDPR or CCPA access, correction, or erasure requests), you may contact our designated privacy team directly:

Response targets. We aim to acknowledge receipt of privacy inquiries and verification questions within five (5) business days. Substantive responses to verified data-subject access, rectification, or objection requests are processed and answered within thirty (30) calendar days of identity verification, in accordance with applicable data-protection laws.

Pinnacle Global Advisory and Consultancy LLC · Wyoming, United States Terms of Service · atbae.ai