Privacy Policy

Your privacy is very important to the entire team at Thayer Leader Development Group, Incorporated (“Thayer”). To help protect your privacy, we adhere to the following guidelines:

For all participants:

  • What information is collected? If you are a participant in a Thayer program, we will collect personal information about you, including your name, contact information, job title, and potentially also your image in photos or videos and other identifying information (“Personal Data”). Except as provided below, we will not ask for sensitive personal information about you regarding, for example, health information, religious affiliation, geolocation, genetic information, sexual orientation, or political beliefs (“Sensitive Personal Data”), and ask you not to provide us with such information not necessary to provide the Thayer programs and services.
  • Why is your information is collected? We will use your Personal Data only to: (1) fulfill our contractual obligations to you by providing the Thayer materials and services, (2) verify your account information, (3) improve your user/participant experience, (4) send you occasional newsletters and other promotional and marketing information about Thayer (as provided further below), and/or (5) verify services to a faculty member’s credentialing organization in the event of an audit, but only if you received personal coaching services and only with your prior consent. More specifically, we process payments and process Personal Data to perform our contractual obligations to you. We use your Personal Data to secure systems, maintain records, prevent fraud, communicate with clients and participants, and improve services to perform our legal obligations and for Thayer’s legitimate business interests. We also use your Personal Data to send future sustainment and information communications and permit verification for coaching credential purposes with your consent. These processing activities are carried out pursuant to one or more of the following legal bases under applicable law: performance of a contract, Thayer’s legitimate business interests, compliance with legal obligations, and/or your consent, where required. We use your Personal Data for legitimate business purposes, to satisfy our contractual obligations to you, to comply with the law, and with your consent.
  • How long is your information retained? Thayer retains Personal Data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy unless a longer retention period is required or permitted by law. Retention periods are determined based upon contractual requirements, legal obligations, the duration of the program, dispute resolution needs, and legitimate business requirements. Generally, however, all Personal Data is deleted by Thayer promptly (i.e., within 30 days) upon completion of the Thayer program. You may be asked if you want to stay on our mailing list, either as part of your consent to our terms and conditions (for open enrollment programs, for blended or virtual programs, or as a third party participant in programs hosted by another party) or upon completion of the program via QR code provided by Thayer). If you sign up via QR code to receive our newsletter or ask to be contacted by Thayer, you can give your name and contact information. If you agreed to Thayer’s terms and conditions, your Personal Data is retained as part of such consent. Certain Personal Data may also be retained with your employer’s prior consent via contract and depending on the privacy notice provided by your employer when your Personal Data was collected in advance of the Thayer program. Further to the above agreements, your Personal Data (name, contact information, title and potentially which program you completed) alone is retained, and all of your Sensitive Personal Data is promptly deleted. Thayer will retain Personal Data only for as long as necessary to provide services to you or as provided in this policy, and shall permanently delete such information promptly thereafter. Notwithstanding the other provisions of this policy, we will retain Personal Data to the extent that: (1) we are required to do so by law, (2) if we believe that the documents may be relevant to any ongoing or prospective legal proceedings or investigations, (3) to establish, exercise, or defend our legal rights and (4) to verify accounts, monitor possibly fraudulent behavior and identify possible violations of this policy. Thayer may retain anonymous information about participants for statistical purposes. Information you provide in setting up your online Thayer account with Udemy (the platform provider of the online session) will be retained as long as you maintain the account. Your e-mail will be retained for the above-mentioned purposes (i.e., for future educational, training and promotional purposes) until you notify us of your wish not to be further contacted by us.

In all cases, Thayer does not sell your Personal Data or Sensitive Personal Data. Thayer does not share Personal or Sensitive Data for cross-context behavioral advertising.

For open enrolment participants: To complete your registration form to participate in an open enrollment Thayer program, you will also be required to provide certain additional personal and credit card information. This information is used to facilitate billing, fill your order and contact you about the products/services on our site in which you have expressed interest. Credit card numbers are only used for processing payments. If we have trouble processing an order, we’ll use this information to contact you and potentially process any refunds.

For open enrolment participants and participants in programs at West Point: For on-site programs at Thayer’s facility at West Point, you will need to provide government-issued photo ID information (driver’s license or passport information and, for US citizens, the last four digits of your social security number).  This additional Sensitive Personal Data is collected solely for submission to the Frederick V. Malek Visitors Center at the United States Military Academy at West Point for their verification and approval of your access onto and tour of the secure military base at West Point. This information is accessible only to those few Thayer personnel who need this information to facilitate your access. This information is collected and transmitted solely by Thayer via e-mails in a password-protected Excel file. As soon as the program is over, this additional Sensitive Information is promptly and permanently deleted. Note: This information is collected by Thayer for groups over 25 individuals as a courtesy to you to facilitate advance approval of your access to West Point.  For groups of participants under 25, Thayer is not permitted to facilitate such access and will not collect this Sensitive Personal Data. Instead, you will be required to go in person to the Visitors Center in advance of the start of the Thayer program to show your ID and obtain your own access approvals.

For participants in assessments: Assessment results are used solely to provide leadership development services and are not sold or shared for advertising purposes. Thayer does not authorize results to be used to make employment decisions unless expressly authorized by the client and participant.

Sub-processors: In order to deliver the program services to you, Thayer may provide certain Personal Data to certain sub-processors, including:

  • our web site hosting server;
  • credit card/payment processor;
  • subcontractors (including Thayer faculty); and
  • other vendors, including, for example:
    1. live virtual videoconferencing platform providers such as Zoom and Microsoft Teams;
    2. Udemy, the platform provider of our online sessions;
    3. Accredible, the platform provider of any digital completion certificates;
    4. SmartWaiver, the platform provider for our experiential session waivers;
    5. applicable other vendors required to deliver services (i.e., the companies providing battlefield experiential programs, rowing and dragon-boating experiential programs, bus transportation within West Point, calendar scheduling services for coaching sessions, etc.).

In all cases, such sub-processors are bound by obligations of confidentiality and non-disclosure regarding such information and to protect your privacy in accordance with applicable laws and regulations.

Thayer may disclose Personal Data to government agencies or authorities, law enforcement officials, regulators, courts, or other third parties where required to do so by applicable law, regulation, legal process (such as a subpoena, court order, or lawful request), or governmental request.

For participants whose program was paid for by another party: If your participation in the Thayer program has paid for by another party (i.e., your employer or a corporate host), we may provide information about your participation or attendance to the paying point of contact, without providing specifics regarding your contributions to any program. This includes ensuring that all coaching sessions and assessment data are kept confidential, except to the Thayer personnel or faculty required to deliver associated services. A summary anonymized report of all participation information may be provided to your host point of contact. Your Personal Data is only provided to an authorized sub-processor (see above) subject to your consent,  or other applicable legal basis, which has been verified by your employer or in the manifest collection form (for manifest information), or provided by you pursuant to the terms and conditions of registration (for open enrollment programs) or terms and conditions of log-in (for digital programs). Telephone numbers are only collected with your consent to verify access to enter West Point or as an optional way to contact you for open enrollment program registrations. If we intend to use Personal Data for another use, we will not do so without your explicit prior consent.

No information regarding children: Thayer does not collect Personal Data from anyone under the age of 18 years old. If we discover that a child has submitted Personal Data to us, we will attempt to delete such information as soon as possible. If you believe that we might have any Personal Data from a child under 18 years old, please contact us at info@Thayerleadership.com.

Your rights:

  • You may confirm whether we have collected, processed or stored any of your Personal Data and instruct us to provide you with any Personal Data we currently hold about you. We may take reasonable steps to verify your identity and authority before responding, and will then provide such information to you free of charge. We may withhold Personal Data that you request, to the extent permitted by law.
  • You may correct, update, amend, transfer, delete/remove Personal Data, or deactivate your account without charge, as well as object to, opt out of, or restrict the processing of further Personal Data, by emailing Thayer at mailto:info@thayerleadership.com.
  • You may instruct us at any time not to process your personal information for marketing purposes. While we do not provide your information to any third parties for marketing purposes, you can ask us any time to remove your information from our newsletters and internal marketing communications. You can also do this yourself by clicking the “Unsubscribe” button on such communications. Where required by law, Thayer will recognize legally required universal opt-out preference signals. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
  • You may object at any time to processing based upon legitimate interests.
  • You may, at your expense, request an audit (during business hours upon reasonable advance notice and by qualified independent auditors) to confirm our compliance with this policy.
  • If you are located within the European Economic Area or United Kingdom, you have the right to lodge a complaint with your local supervisory authority if you believe your Personal Data has been processed in violation of applicable law.
  • You may request a transferable or portable copy of all Personal Data stored by Thayer.
  • None of these requests will affect our services or prices to you, except to the extent that your deactivation of your account or deletion of Personal Data affects our ability to provide our services to you.
  • You may withdraw your consent to this policy or to any previously agreed terms and conditions by contacting us at the above e-mail address at any time.
  • If Thayer denies any such request above from you, you may appeal such denial by contacting Thayer within 30 days. We will review the appeal and respond within the time required by applicable law.

Privacy requests may be submitted by e-mail to Thayer at info@thayerleadership.com When responding to such requests, Thayer will:

  • Review each request to confirm that it is legally valid and within the authority of the requesting entity;
  • Disclose only the minimum amount of Personal Data necessary to comply with the request;
  • Where permitted by law, seek to limit or object to overly broad requests; and
  • Where legally permitted, notify affected individuals prior to disclosure.
  • In certain circumstances, applicable law may prohibit notice of such disclosure, in which case Thayer will comply with those legal restrictions.

 

We will respond to your request within a reasonable timeframe, not to exceed 45 days or within any extended period permitted by applicable law after providing any required notice. We will correct and update without delay information that we understand to be incorrect or outdated.

 

Certain Personal Data is necessary for Thayer to perform its contractual obligations and provide the requested services. If you choose not to provide required information, we may be unable to provide some or all requested services.

 

Responsible Party/Contact: Thayer’s Co-President, Karen Kuhla, is the Thayer representative and privacy officer responsible for maintaining and enforcing this policy. Please e-mail her at info@thayerleadership.com with questions or requests. Thayer shall train all its employees and inform its faculty regarding this policy. Thayer agrees to be responsible for any breach of this policy by such employees and faculty. To the extent reasonably practical, Thayer shall also inform all subcontractors (other than faculty) about, and request their compliance with, this policy and/or with a separate data processing agreement containing Standard Contractual Clauses or similar provisions regarding the protection of your Personal Data. Please be aware that we cannot prevent the use or misuse of any Personal Data that you disclose to other third parties or participants during our program. Our website or programs may include hyperlinks to, and details of, third party websites. We have no control over, and are not responsible for, the privacy policies and practices of third parties. If you believe Thayer has not adhered to these guidelines, please notify Thayer and we will use all commercially reasonable efforts to promptly determine and correct the problem.

Transfers of Personal Data: Personal Data that we collect may be stored, processed in, and transferred between any of the countries in which we operate in order to enable us to use the information in accordance with this policy. While Thayer’s only place of business is in West Point, NY, we may collect Personal Data from participants who are residents outside of the United States and we may deliver services outside of the United States. Thayer maintains its servers in the United States. If you are attending a Thayer program outside of the United States, please note that Personal Data is not localized. If you are visiting from outside the United States, by using our site and services, your personal information will be transferred to the United States for processing. Thayer is obligated to comply with U.S. government laws and regulations related to data collected by Thayer for the purposes of providing the services for which you have engaged Thayer. This could require local data storage or duplication of data storage across geographic regions. Collected Personal Data may be transferred to countries which do not have data protection laws equivalent to those in force in the European Economic Area or the United States. Where Personal Data is transferred from the European Economic Area or United Kingdom to the United States, Thayer implements appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms, to ensure an adequate level of data protection. Personal Data may be transferred as described in this Privacy Policy and in accordance with applicable law and where required, Thayer implements appropriate safeguards pursuant to Chapter V of the GDPR.

Controller/Processor: When we ask you directly for Personal Data, Thayer will be the controller of your Personal Data. When we receive your Personal Data from another party like your employer, Thayer will be the processor of your Personal Data. When Thayer processes Personal Data on behalf of a client or host organization, Thayer will be the processor of your Personal Data and processes such Personal Data only in accordance with the documented instructions of the controller, except as required by applicable law.

Cookies: Your visit to our site is tracked through a standard web traffic statistics program, which keeps records of traffic on the site. Our server automatically collects data about your server’s Internet address when you visit us. You should also be aware that your information may be automatically collected through the use of “cookies”. “Cookies” are small text files that our site can use to recognize repeat users, facilitate your ongoing access to and use of the site and allow our site to track usage behavior and compile aggregate data that will allow content improvements, website functionality, and measurement of website performance. Cookies are not programs that come onto a system and damage files. Generally, cookies work by assigning a unique number to each customer that has no meaning outside the assigning site. If you do not want information collected by cookies or wish to delete cookies already stored on your computer, most browsers have a simple procedure allowing you to deny or accept, and to delete, the cookie feature; however, you should note that cookies may be necessary to provide you with certain features (e.g., customized delivery of information) available on our web site. Thayer does not engage in targeted advertising by third parties as such term is defined by data privacy laws. Thayer only uses essential and analytics cookies. Before placing non-essential cookies, we obtain consent where required by applicable law.

Cyber-security: We take reasonable, industry-standard technical and organizational precautions to prevent the loss, misuse, or alteration of your personal information, including the storage of all Personal Data on our secure (password- and firewall-protected) servers. We maintain access controls and limit access to your Personal Data solely to those who are required to know such information to deliver or facilitate the delivery of the Thayer program, including using a policy of least privilege. Sub-processors authorized to receive your Personal Data are subject to the requirements listed in “Sub-processors” above. All electronic financial transactions entered into through our website will be protected by Secure Sockets Layer (SSL) encryption technology and will be processed in compliance with payment card industry standards (PCI DSS). However, you acknowledge that the transmission of information over the Internet is inherently insecure, and we cannot guarantee the security of data sent over the Internet. You are responsible for keeping the password you use for accessing any digital platforms of Thayer and our sub processors confidential. We will not ask you for your password. We do not use Personal Data to make solely automated decisions that produce legal or similarly significant effects concerning individuals. Accordingly, no decisions producing legal or similarly significant effects are made solely through automated processing. If Thayer adopts artificial intelligence tools involving Personal Data, it will do so in accordance with applicable law and contractual requirements and update this Privacy Policy as appropriate. Thayer periodically reviews and updates its administrative, technical, and physical safeguards to address evolving security risks.

Thayer has controls to detect a breach of security that are standard for companies of its size and industry. In the event of a breach of security of your Personal Data, Thayer will promptly investigate and formally document the breach and any actions taken to address the breach, and, if appropriate and necessary, report the breach to you and/or the appropriate authorities.

State-specific Data Privacy Laws: Certain U.S. state privacy laws apply only to businesses meeting specified statutory thresholds. To the extent any applicable law provides additional privacy rights to individuals, Thayer will honor those rights where required by law. Our website currently does not respond to browser “Do Not Track” signals because there is no universally accepted standard governing such responses.

By using the Thayer website, you consent to our use of your information as described in this Privacy Policy (last revised on July 13, 2026). Thayer will not discriminate against any individual for exercising privacy rights provided under applicable law or this policy. We reserve the right to change our privacy policy at any time without advance notice. Should a new policy go into effect, we will post it on this site, and the revised policy will apply only to information collected thereafter. You should check this page occasionally to ensure you understand any changes to this policy.