Your privacy is very important to the entire team at Thayer Leader Development Group, Incorporated (“Thayer”). To help protect your privacy, we adhere to the following guidelines:
For all participants:
In all cases, Thayer does not sell your Personal Data or Sensitive Personal Data. Thayer does not share Personal or Sensitive Data for cross-context behavioral advertising.
For open enrolment participants: To complete your registration form to participate in an open enrollment Thayer program, you will also be required to provide certain additional personal and credit card information. This information is used to facilitate billing, fill your order and contact you about the products/services on our site in which you have expressed interest. Credit card numbers are only used for processing payments. If we have trouble processing an order, we’ll use this information to contact you and potentially process any refunds.
For open enrolment participants and participants in programs at West Point: For on-site programs at Thayer’s facility at West Point, you will need to provide government-issued photo ID information (driver’s license or passport information and, for US citizens, the last four digits of your social security number). This additional Sensitive Personal Data is collected solely for submission to the Frederick V. Malek Visitors Center at the United States Military Academy at West Point for their verification and approval of your access onto and tour of the secure military base at West Point. This information is accessible only to those few Thayer personnel who need this information to facilitate your access. This information is collected and transmitted solely by Thayer via e-mails in a password-protected Excel file. As soon as the program is over, this additional Sensitive Information is promptly and permanently deleted. Note: This information is collected by Thayer for groups over 25 individuals as a courtesy to you to facilitate advance approval of your access to West Point. For groups of participants under 25, Thayer is not permitted to facilitate such access and will not collect this Sensitive Personal Data. Instead, you will be required to go in person to the Visitors Center in advance of the start of the Thayer program to show your ID and obtain your own access approvals.
For participants in assessments: Assessment results are used solely to provide leadership development services and are not sold or shared for advertising purposes. Thayer does not authorize results to be used to make employment decisions unless expressly authorized by the client and participant.
Sub-processors: In order to deliver the program services to you, Thayer may provide certain Personal Data to certain sub-processors, including:
In all cases, such sub-processors are bound by obligations of confidentiality and non-disclosure regarding such information and to protect your privacy in accordance with applicable laws and regulations.
Thayer may disclose Personal Data to government agencies or authorities, law enforcement officials, regulators, courts, or other third parties where required to do so by applicable law, regulation, legal process (such as a subpoena, court order, or lawful request), or governmental request.
For participants whose program was paid for by another party: If your participation in the Thayer program has paid for by another party (i.e., your employer or a corporate host), we may provide information about your participation or attendance to the paying point of contact, without providing specifics regarding your contributions to any program. This includes ensuring that all coaching sessions and assessment data are kept confidential, except to the Thayer personnel or faculty required to deliver associated services. A summary anonymized report of all participation information may be provided to your host point of contact. Your Personal Data is only provided to an authorized sub-processor (see above) subject to your consent, or other applicable legal basis, which has been verified by your employer or in the manifest collection form (for manifest information), or provided by you pursuant to the terms and conditions of registration (for open enrollment programs) or terms and conditions of log-in (for digital programs). Telephone numbers are only collected with your consent to verify access to enter West Point or as an optional way to contact you for open enrollment program registrations. If we intend to use Personal Data for another use, we will not do so without your explicit prior consent.
No information regarding children: Thayer does not collect Personal Data from anyone under the age of 18 years old. If we discover that a child has submitted Personal Data to us, we will attempt to delete such information as soon as possible. If you believe that we might have any Personal Data from a child under 18 years old, please contact us at info@Thayerleadership.com.
Your rights:
Privacy requests may be submitted by e-mail to Thayer at info@thayerleadership.com When responding to such requests, Thayer will:
We will respond to your request within a reasonable timeframe, not to exceed 45 days or within any extended period permitted by applicable law after providing any required notice. We will correct and update without delay information that we understand to be incorrect or outdated.
Certain Personal Data is necessary for Thayer to perform its contractual obligations and provide the requested services. If you choose not to provide required information, we may be unable to provide some or all requested services.
Responsible Party/Contact: Thayer’s Co-President, Karen Kuhla, is the Thayer representative and privacy officer responsible for maintaining and enforcing this policy. Please e-mail her at info@thayerleadership.com with questions or requests. Thayer shall train all its employees and inform its faculty regarding this policy. Thayer agrees to be responsible for any breach of this policy by such employees and faculty. To the extent reasonably practical, Thayer shall also inform all subcontractors (other than faculty) about, and request their compliance with, this policy and/or with a separate data processing agreement containing Standard Contractual Clauses or similar provisions regarding the protection of your Personal Data. Please be aware that we cannot prevent the use or misuse of any Personal Data that you disclose to other third parties or participants during our program. Our website or programs may include hyperlinks to, and details of, third party websites. We have no control over, and are not responsible for, the privacy policies and practices of third parties. If you believe Thayer has not adhered to these guidelines, please notify Thayer and we will use all commercially reasonable efforts to promptly determine and correct the problem.
Transfers of Personal Data: Personal Data that we collect may be stored, processed in, and transferred between any of the countries in which we operate in order to enable us to use the information in accordance with this policy. While Thayer’s only place of business is in West Point, NY, we may collect Personal Data from participants who are residents outside of the United States and we may deliver services outside of the United States. Thayer maintains its servers in the United States. If you are attending a Thayer program outside of the United States, please note that Personal Data is not localized. If you are visiting from outside the United States, by using our site and services, your personal information will be transferred to the United States for processing. Thayer is obligated to comply with U.S. government laws and regulations related to data collected by Thayer for the purposes of providing the services for which you have engaged Thayer. This could require local data storage or duplication of data storage across geographic regions. Collected Personal Data may be transferred to countries which do not have data protection laws equivalent to those in force in the European Economic Area or the United States. Where Personal Data is transferred from the European Economic Area or United Kingdom to the United States, Thayer implements appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms, to ensure an adequate level of data protection. Personal Data may be transferred as described in this Privacy Policy and in accordance with applicable law and where required, Thayer implements appropriate safeguards pursuant to Chapter V of the GDPR.
Controller/Processor: When we ask you directly for Personal Data, Thayer will be the controller of your Personal Data. When we receive your Personal Data from another party like your employer, Thayer will be the processor of your Personal Data. When Thayer processes Personal Data on behalf of a client or host organization, Thayer will be the processor of your Personal Data and processes such Personal Data only in accordance with the documented instructions of the controller, except as required by applicable law.
Cookies: Your visit to our site is tracked through a standard web traffic statistics program, which keeps records of traffic on the site. Our server automatically collects data about your server’s Internet address when you visit us. You should also be aware that your information may be automatically collected through the use of “cookies”. “Cookies” are small text files that our site can use to recognize repeat users, facilitate your ongoing access to and use of the site and allow our site to track usage behavior and compile aggregate data that will allow content improvements, website functionality, and measurement of website performance. Cookies are not programs that come onto a system and damage files. Generally, cookies work by assigning a unique number to each customer that has no meaning outside the assigning site. If you do not want information collected by cookies or wish to delete cookies already stored on your computer, most browsers have a simple procedure allowing you to deny or accept, and to delete, the cookie feature; however, you should note that cookies may be necessary to provide you with certain features (e.g., customized delivery of information) available on our web site. Thayer does not engage in targeted advertising by third parties as such term is defined by data privacy laws. Thayer only uses essential and analytics cookies. Before placing non-essential cookies, we obtain consent where required by applicable law.
Cyber-security: We take reasonable, industry-standard technical and organizational precautions to prevent the loss, misuse, or alteration of your personal information, including the storage of all Personal Data on our secure (password- and firewall-protected) servers. We maintain access controls and limit access to your Personal Data solely to those who are required to know such information to deliver or facilitate the delivery of the Thayer program, including using a policy of least privilege. Sub-processors authorized to receive your Personal Data are subject to the requirements listed in “Sub-processors” above. All electronic financial transactions entered into through our website will be protected by Secure Sockets Layer (SSL) encryption technology and will be processed in compliance with payment card industry standards (PCI DSS). However, you acknowledge that the transmission of information over the Internet is inherently insecure, and we cannot guarantee the security of data sent over the Internet. You are responsible for keeping the password you use for accessing any digital platforms of Thayer and our sub processors confidential. We will not ask you for your password. We do not use Personal Data to make solely automated decisions that produce legal or similarly significant effects concerning individuals. Accordingly, no decisions producing legal or similarly significant effects are made solely through automated processing. If Thayer adopts artificial intelligence tools involving Personal Data, it will do so in accordance with applicable law and contractual requirements and update this Privacy Policy as appropriate. Thayer periodically reviews and updates its administrative, technical, and physical safeguards to address evolving security risks.
Thayer has controls to detect a breach of security that are standard for companies of its size and industry. In the event of a breach of security of your Personal Data, Thayer will promptly investigate and formally document the breach and any actions taken to address the breach, and, if appropriate and necessary, report the breach to you and/or the appropriate authorities.
State-specific Data Privacy Laws: Certain U.S. state privacy laws apply only to businesses meeting specified statutory thresholds. To the extent any applicable law provides additional privacy rights to individuals, Thayer will honor those rights where required by law. Our website currently does not respond to browser “Do Not Track” signals because there is no universally accepted standard governing such responses.
By using the Thayer website, you consent to our use of your information as described in this Privacy Policy (last revised on July 13, 2026). Thayer will not discriminate against any individual for exercising privacy rights provided under applicable law or this policy. We reserve the right to change our privacy policy at any time without advance notice. Should a new policy go into effect, we will post it on this site, and the revised policy will apply only to information collected thereafter. You should check this page occasionally to ensure you understand any changes to this policy.