This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can do about it. It is written to be read once and understood.
1. Who we are
Capacity Building International ("CBI", "we", "us") is the company behind Crisis Lab. Crisis Lab is CBI's operating brand. In this policy, "we" means CBI and its subsidiaries, including Crisis Lab. CBI is the controller of the personal data described here.
Capacity Building International
5900 Balcones Drive #13770
Austin, Texas 78731-4257
United States
Email: contact@crisislab.io
2. Where this policy applies
This policy covers the Crisis Lab properties we operate:
Our owned website (currently served at crisislab-v3.pages.dev and migrating to crisislab.io), including the pages you are reading now.
Our newsletter, paywalled articles, podcast pages, subscription checkout, and reader accounts, which are hosted by Beehiiv. Until the migration completes, these are served at crisislab.io and www.crisislab.io, so those addresses are Beehiiv surfaces today and Beehiiv's own cookie behavior applies on them.
Our community and courses at community.crisislab.io, including course checkout, which are hosted by Circle.
Beehiiv and Circle are independent companies. When you are on their surfaces, their own privacy policies and terms apply alongside this one. If anything in their policies conflicts with this one about how their platform works, their policy governs that platform. We remain responsible for the data we ask them to process on our behalf.
3. What we collect
When you subscribe to the newsletter
Our signup form sends the following to Beehiiv: your email address, plus three attribution fields that tell us where the signup came from. Those fields are utm_source (always "website"), utm_medium ("hero" or "footer_band", meaning which form on the page you used), and referring_site (the site you arrived from, if your browser sent one). We do not ask for your name at signup.
If you previously unsubscribed and enter your address again, we do not silently reactivate your subscription. Your address is handled according to Beehiiv's default behavior for a returning unsubscribed contact.
When you create an account or buy something
Account data held on Beehiiv (reader accounts) or Circle (community and course accounts): the email address you sign in with, your profile details, and your access level.
Purchase data collected at checkout by the payment processor behind Beehiiv or Circle: your billing details and the record of what you bought and when. We never receive or store your full card number. Card data goes to the payment processor, not to us.
Course progress and completion data held on Circle: which lessons you have completed, assessment results where a course has them, and the record needed to issue a certificate or CEUs.
Newsletter and podcast engagement data processed by Beehiiv: whether an email was delivered, opened, or clicked, and which posts an account has read.
When you simply visit our website
Our owned site, currently crisislab-v3.pages.dev and migrating to crisislab.io, runs no analytics and sets no non-essential cookies. We do not build a profile of your visit. Cloudflare, which hosts and delivers that site, processes your IP address transiently to route the request, deliver the page, and protect the site from attack. That processing is short-lived and serves security and delivery, not marketing.
This applies to the owned site. crisislab.io and www.crisislab.io are served by Beehiiv until the migration completes, and Beehiiv sets the cookies its platform needs there. See section 5.
When you email us
We receive whatever you put in your message, and we keep the correspondence so we can answer you and refer back to it.
4. Why we process it, and our legal basis
For readers in the EU, EEA, and UK, the General Data Protection Regulation requires us to name a legal basis for each purpose. Here they are.
Sending you the free newsletter, because you asked for it. Legal basis: your consent (GDPR Art. 6(1)(a)). You can withdraw it at any time using the unsubscribe link in any email.
Delivering what you paid for (subscriptions, courses, community access, certificates). Legal basis: performance of a contract (Art. 6(1)(b)).
Sending paid subscribers their Intelligence issues. For Intelligence and Intelligence+, the email is the product, not marketing. We send it to perform the contract you bought, so the basis is performance of a contract (Art. 6(1)(b)), not marketing consent. This is a different basis from the free newsletter above, and it has a consequence worth knowing: see section 9.
Taking payment and preventing payment fraud, which the payment processor handles at checkout. Legal basis: contract and our legitimate interests in being paid and not being defrauded (Art. 6(1)(b) and (f)).
Keeping the site and community secure and available, including Cloudflare's transient IP processing and moderation of the community. Legal basis: our legitimate interests in operating a secure service (Art. 6(1)(f)).
Understanding whether our own newsletter is being read, at the aggregate level Beehiiv reports to us. Legal basis: our legitimate interests in improving what we publish (Art. 6(1)(f)).
Telling existing customers about our own related products. Legal basis: our legitimate interests, or your consent where the law where you live requires it (Art. 6(1)(f) or (a)). Every such message carries an opt-out.
Keeping tax, accounting, and accreditation records. This includes the learner records our IACET accreditation requires us to retain. Legal basis: legal obligation and legitimate interests (Art. 6(1)(c) and (f)).
Responding to your inquiries. Legal basis: legitimate interests, or steps taken at your request before entering a contract (Art. 6(1)(f) or (b)).
5. Cookies, analytics, and tracking
On our owned site (crisislab-v3.pages.dev, migrating to crisislab.io): no analytics tools, no advertising cookies, no tracking pixels, no non-essential cookies of any kind. This is a change from our previous policy, which described analytics tools and interest-based advertising cookies that we no longer use.
Beehiiv and Circle set the cookies their platforms need to keep you signed in and to operate their services, and Beehiiv measures email opens and clicks. Those are described in their own policies. Because crisislab.io and www.crisislab.io are Beehiiv-served until the migration completes, this is what applies on those addresses today; the no-cookie statement above describes the owned site.
We do not sell personal information. We do not share personal information for cross-context behavioral or targeted advertising. We do not receive money or other value for disclosing your personal information.
Do Not Track and Global Privacy Control
Because we run no analytics and no advertising trackers on our owned site, there is nothing on it for a Do Not Track or Global Privacy Control signal to switch off. We honor recognized universal opt-out signals, including Global Privacy Control, as an opt-out of sale and targeted advertising, and we will continue to honor them if we ever introduce anything that such a signal would govern.
6. Who we share it with
We share personal information with service providers who process it on our instructions, and only for the purposes above. The categories of third parties, and the providers in each:
Email, publishing, and subscription platform: Beehiiv. Beehiiv hosts the newsletter, paywalled articles, podcast pages, reader accounts, and subscription checkout.
Community and course platform: Circle. Circle hosts the community, courses, course accounts, and course checkout.
Hosting, content delivery, and security: Cloudflare. Cloudflare serves our owned site and protects it from attack.
Payment processors engaged behind the Beehiiv and Circle checkouts. They take your payment details, run the transaction, and return a confirmation to us.
We also disclose personal information when the law requires it (a valid legal request, a court order, or the defense of a legal claim), and to a successor if the business is sold or reorganized, in which case this policy travels with the data until the successor gives you notice of a different one.
We do not disclose your personal information to data brokers, advertisers, or ad networks.
7. International transfers
We are based in the United States and our service providers are US companies. If you are in the EU, EEA, UK, or Switzerland, your personal information will be transferred to and processed in the United States, which does not have an adequacy decision covering every transfer. Where a transfer needs a safeguard, we rely on appropriate safeguards required by applicable law, including standard contractual clauses where our providers offer them, together with the technical and organizational measures our agreements with them require. You can ask us for details of the safeguard used for a particular transfer.
8. How long we keep it
We do not keep personal information indefinitely by default. The criteria we apply:
Newsletter subscription data stays with us for as long as you are subscribed. After you unsubscribe we keep a minimal suppression record (your email address and the fact that you opted out) so that we do not email you again. That record exists to protect you and is kept until you ask us to erase it.
Account data is kept for as long as your account is open, then deleted or anonymized on the platform's schedule after you close it.
Purchase and tax records are retained for the period US tax and accounting law requires, which is generally seven years from the transaction.
Course completion and CEU records are held for the period our IACET accreditation requires us to keep learner records, so that we can verify a credential you earned.
Correspondence we keep for as long as needed to resolve the matter, then for a reasonable period in case it resurfaces.
Security logs are transient, on our host's short retention schedule.
9. Your rights
If you are in the EU, EEA, or UK, the GDPR gives you the following rights over your personal data. We extend them, as a matter of policy, to anyone who asks.
Access. Get a copy of the personal data we hold about you, and be told how we use it.
Rectification. Have inaccurate data corrected and incomplete data completed.
Erasure. Have your data deleted where we no longer have a basis to keep it.
Restriction. Have us pause processing while a dispute about accuracy or legitimacy is resolved.
Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
Objection to processing based on our legitimate interests. If you object to direct marketing, we stop; there is no balancing test.
Withdraw consent at any time, for anything we do on the basis of consent. Withdrawing does not make what we did before unlawful.
Not be subject to solely automated decisions that produce legal or similarly significant effects. We do not make any (see section 11).
How to exercise them
Email contact@crisislab.io. We answer within 30 days, and tell you if we need longer and why. We may ask you to confirm your identity, usually by writing from the address we hold, before we act on a request, so that nobody else can use these rights against you. Exercising a right costs nothing and we will not treat you differently for using one.
You can also review and change your own information directly: newsletter and reader-account details through the account or preference link in any email we send you; community and course details in your profile on community.crisislab.io.
Unsubscribing, and what it does. If you receive the free newsletter, you can unsubscribe at any time using the link in its footer, and nothing else changes. If you are a paid Intelligence or Intelligence+ subscriber, be aware that on our publishing platform email delivery and paid access are inseparable: unsubscribing also cancels your paid subscription and ends your paid access at the end of the period you have paid for. There is no setting that turns the emails off and keeps the subscription. We flag it here because it is easy to click unsubscribe expecting a quieter inbox rather than the end of something you paid for. The cancellation terms are in our Terms of Service.
Complaints
If you think we have handled your data badly, tell us first. We would rather fix it. You also have the right to complain to a supervisory authority: in the EU or EEA, the data protection authority of the country where you live, work, or where the issue arose; in the UK, the Information Commissioner's Office. Using that right does not require you to come to us first.
10. US state privacy rights
If you live in a US state with a comprehensive privacy law (including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and the other states whose laws are now in force), you have rights over your personal information. We apply one standard to all of them:
Know and access what we collect about you, where we got it, why we process it, and who we disclose it to.
Correct inaccurate personal information.
Delete the personal information we hold about you.
Portability, a copy in a portable, readily usable format.
Opt out of sale, of targeted advertising, and of profiling that produces legal or similarly significant effects. We do none of these things, so there is nothing to opt out of. The right stands regardless, and we honor Global Privacy Control signals as described in section 5.
Appeal. If we refuse a request, you may appeal by replying to our refusal. We will respond to the appeal in writing with our reasons within the time your state's law allows, and tell you how to contact your state Attorney General if you remain unsatisfied.
No retaliation. We will not deny you service, charge you a different price, or give you a lesser experience for exercising a privacy right.
Use the same route as everyone else: contact@crisislab.io. An authorized agent may submit a request on your behalf with written proof of authority.
Categories, in the terms California uses
The categories of personally identifiable information we collect are: identifiers (email address, account identifier, and IP address processed transiently by our host); commercial information (what you purchased and when); internet activity limited to newsletter engagement and course progress on the platforms described above; and the content of any message you send us. We do not collect sensitive personal information, biometric data, precise geolocation, or government identifiers. The categories of third parties with whom we share it are listed in section 6.
11. Artificial intelligence and automated decisions
We use AI tools to help produce our published content, under human editorial review. Two commitments follow from that, and they are commitments, not aspirations:
We do not use subscriber or customer personal data to train AI models, not ours and not anyone else's. Your email address, your reading history, and your course record are not training data.
We make no solely automated decisions about you that produce legal effects or similarly significant effects. No algorithm decides your access, your price, your grade, or your standing without a person responsible for the outcome.
How AI is used in producing what we publish, and who is accountable for it, is set out in our Disclosure of Proprietary Interests.
12. Children
Our services are built for working professionals. They are not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If we learn that we have, we delete it promptly. If you believe a child has given us personal information, write to contact@crisislab.io and we will act.
13. How we protect your information
We keep the amount of personal data we hold small, which is the strongest protection available. Beyond that, we use technical, administrative, and physical safeguards appropriate to the risk: encryption in transit, access limited to people who need it, and platform providers who maintain their own security programs. No transmission over the internet can be guaranteed completely secure, and we do not claim otherwise.
14. If there is a data breach
If a breach of personal data occurs, we will investigate it, contain it, and notify the people and authorities that applicable law requires us to notify, within the deadlines that law sets. That includes notification to the relevant supervisory authority within 72 hours where the GDPR requires it, and to affected individuals without undue delay where the breach is likely to present a high risk to them.
15. Links to other sites
Our pages link to other organizations' websites. We do not control them and are not responsible for their privacy practices. Read their policies before giving them your information.
16. Changes to this policy
We may update this policy. When we do, we post the new version on this page and update the effective date at the foot. If a change is material (a new purpose, a new category of recipient, a change in your rights), we will say so prominently on this page, and where the law requires it or the change is significant enough to warrant it, we will notify subscribers by email before it takes effect.
17. Contact us
Questions, requests, and complaints about this policy or your personal information:
Capacity Building International
Attn: Privacy
5900 Balcones Drive #13770
Austin, Texas 78731-4257
United States
contact@crisislab.io
Version 2.0 · Effective 24 August 2026 · Supersedes the version effective 01 January 2023. Material changes will be announced on this page with an updated effective date.