Legal

Privacy Policy

Effective July 15, 2026

1. Who we are

Wexler Gray operates Signal, a continuous, anonymous organizational early-warning system. A private equity firm commissions Signal to monitor one of its portfolio companies; verified participants inside that company submit brief, identity-protected observations, and Signal validates recurring cross-functional patterns. Beacon (escalation) and Bearing (interpretation) are embedded capabilities of Signal. This policy explains how we collect, use, share, and protect personal data in connection with these services. Wexler Gray is operated by Ardilawn Holdings LLC, a Tennessee limited liability company based in Nashville, Tennessee, United States. References to “Wexler Gray,” “we,” “us,” or “our” refer to that entity.

Three parties are relevant to how data flows through Signal:

  • The PE firm client. The investor that commissions and governs a Signal engagement. For personal data relating to its portfolio company, the client acts as the data controller and determines the purpose of processing.
  • Wexler Gray. We act as a data processor, handling data on the documented instruction of the instructing client and under a data processing agreement.
  • Signal participants. Individuals inside the portfolio company who submit anonymized input. They hold no account with Wexler Gray, and we do not collect their names or email addresses. A participant is represented only by an organizational function and a pseudonymous slot identifier.

For questions about this policy, reach us through the contact form.

2. Participant anonymity

Signal is built so that a participant can report honestly without Wexler Gray ever holding their identity. Three things hold true at once, by design:

  • We hold no participant identity. No name, email address, or account is created for a participant. Each is represented by an organizational function and a pseudonymous slot identifier. There is no record that could link a submission to a person, and none that could be disclosed if we were compelled to.
  • Eligibility is set by the client. The instructing firm — ordinarily through a designated sponsor at the portfolio company — decides who participates and distributes each submission link through their own channels. We issue the links; they decide who receives them. The record of who holds which link stays with that sponsor, outside the platform. We neither request nor retain it.
  • Nothing surfaces from one voice. Individual submissions are aggregated. A single submission is never disclosed to the investor or to company management, and no surfaced output attributes an observation to a named individual.

Before anything is presented, a pattern must clear thresholds for recurrence, cross-functional corroboration, and persistence over time. Separately, function-level detail is withheld until a minimum number of participants within that function have reported, and smaller functions are pooled so a withheld figure cannot be recovered by subtraction. A client may configure stricter thresholds than this platform minimum; a client cannot configure weaker ones.

3. Data we collect

We collect data in three categories:

  • Account information. Names, email addresses, job titles, and firm affiliations provided when accounts are created or updated. This applies to PE firm users and portfolio company users only. Signal participants have no account, and we collect no names or email addresses for them — only an organizational function, a pseudonymous slot identifier, and whether the slot is active and when it last submitted.
  • Usage data. Log data, session information, feature interactions, and access timestamps collected automatically when users interact with the platform. This data is used for security, performance monitoring, and product improvement.
  • Program data. Brief, structured participant observations submitted on a recurring cadence, together with the clustered patterns, confidence scores, escalation records, and interpretation content generated through use of the Signal, Beacon, and Bearing capabilities. This data is submitted by participants in connection with a specific client engagement.

Signal is deliberately narrow. It collects only what a participant chooses to submit. It does not:

  • Monitor email, chat or messaging tools, calls, or meetings
  • Track browsers, devices, keystrokes, or location
  • Measure individual productivity or activity
  • Evaluate or score the performance of any individual employee

4. How we use data

We use collected data to:

  • Provide, operate, and maintain the Signal platform and its capabilities
  • Authenticate users and enforce role-based access controls
  • Validate recurring patterns and generate escalations and board-ready interpretations
  • Send transactional communications including magic link authentication emails and platform notifications
  • Monitor platform security, investigate abuse, and maintain audit records
  • Improve platform features and address technical issues
  • Comply with applicable legal obligations

AI processing. Participant submissions are processed with AI assistance to normalize language, cluster observations into themes, and detect recurring patterns and contradictions. This processing supports pattern validation; it does not identify individuals or evaluate individual performance. We use a third-party AI provider under a commercial agreement whose terms provide that data sent through its API is not used to train the provider’s models.

We do not use program data for any purpose other than delivering the services requested by the instructing PE firm client. We do not use program data to train our own models or for cross-client analysis without explicit written consent.

5. Data sharing and management visibility

We do not sell personal data. We share data only in the following circumstances:

  • Within an engagement. Only validated themes are surfaced, and only to the recipients agreed with the instructing PE firm client. Raw submissions and participant identities are never shared with the investor or with company management.
  • Service providers. We engage third-party providers for infrastructure (database hosting), authentication (magic link delivery), communications (email), and AI processing. These providers act as subprocessors, process data only as instructed and under appropriate data processing agreements, and are disclosed to the client under the engagement agreement. The current list is published at wexlergray.com/subprocessors.
  • Legal requirements. We may disclose data when required by law, court order, or regulatory authority, or where necessary to protect the rights, safety, or property of Wexler Gray, its users, or third parties.

Management visibility. Signal is commissioned and governed by the investor. Raw submissions and participant identities are never exposed. Visibility into validated themes is controlled through an agreed escalation protocol established at the start of the engagement.

6. Data retention and deletion

Data is retained only for as long as needed to deliver the service or to meet a legal obligation. Where an engagement or data processing agreement sets a different period, that agreement governs and takes precedence over the table below.

InformationStandard retention
Client account recordsDuration of the account, then up to 24 months
Participant slot records (function label, slot identifier, activity dates)Duration of the engagement, then up to 90 days
Participant submissionsDuration of the engagement, then up to 12 months
Generated themes, escalations, and reportsDuration of the engagement, then up to 36 months
Authentication and security logsUp to 12 months
Support recordsUp to 24 months after the matter is closed
Contract, billing, and transaction recordsAs required by tax, accounting, and legal obligations
BackupsUntil overwritten on the standard cycle, ordinarily within 30 days of deletion from active systems

We may retain information longer where necessary to comply with law, respond to a regulatory inquiry, preserve evidence, resolve a dispute, or meet a legal hold. Deletion from active systems does not immediately remove data from encrypted backups or records we are required to keep; that data stays protected and is not returned to active use except for disaster recovery, security, or legal compliance.

Clients may request earlier deletion of program data through the contact form. We will action deletion requests within 30 days, subject to any applicable legal retention obligations.

7. Security

We implement appropriate technical and organizational measures to protect data against unauthorized access, alteration, disclosure, or destruction. These are encryption in transit and at rest, application-level authorization scoped to each user's role and organization on every request, and passwordless authentication.

We describe the controls we operate rather than a general list of good practice. Administrative actions — account changes, organization changes, and access grants — are recorded in an audit log. That log covers administrative changes; it is not a record of every page a user viewed.

Authentication uses a passwordless magic link model, eliminating the risk of password-based credential compromise. No passwords are stored in the Wexler Gray platform.

For a full overview of our security posture, see our Security overview.

8. What Signal is not for

Signal reports on organizational conditions — the recurring, cross-functional patterns that shape how a company operates. It is not a reporting channel for urgent personal, legal, human-resources, or safety matters, and it is not monitored for individual emergencies. Anything that needs an immediate or named response should be raised through the organization’s own channels, such as its people, legal, compliance, or whistleblowing functions. Where a matter falls outside what Signal is designed to handle, participants should use those channels rather than a Signal submission.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data, as well as rights to data portability and to object to certain processing activities. To exercise any of these rights, reach us through the contact form. We will respond to all requests within 30 days.

Where personal data is processed under a client engagement, the instructing PE firm client is the controller, and we will refer or route requests to that client as appropriate. Because participant submissions are anonymized and aggregated by design, we may be unable to isolate a specific individual’s submission without additional information that identifies it.

10. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify active users by email and post the updated policy at wexlergray.com/privacy with a revised effective date. Continued use of the platform following notification constitutes acceptance of the updated policy.

11. Contact

For privacy questions, requests, or complaints:

Wexler Gray — Attn: Privacy

Ardilawn Holdings LLC

Nashville, Tennessee, United States

wexlergray.com/contact

We do not publish a direct email address or street address. Requests submitted through the contact form reach the same team and are handled on the timelines described above.