PRIVACY

Privacy Policy

Last Updated: August 14, 2026

Obsidian Management (“Obsidian,” “we,” “us,” or “our”) respects your privacy and is committed to handling personal information responsibly.This Privacy Policy explains the types of information we may collect when you visit our website, submit an inquiry, schedule a meeting, or otherwise communicate with us; how we use and disclose that information; and the choices and rights that may be available to you.

By using our website, you acknowledge the practices described in this Privacy Policy.

1. Information We Collect

Information You Provide to Us

We may collect personal information that you voluntarily provide when you contact us, submit an inquiry, schedule a meeting, or otherwise communicate with Obsidian.

This may include:

Name

Email address

Company or venue name

Business website

Information about your business, operation, project, challenges, objectives, or requested services

Scheduling and meeting information

Communications you exchange with us

Other information you voluntarily choose to provide

Please do not submit sensitive personal information through our website inquiry form unless it is specifically requested and necessary for your communication with us.

Information Collected Automatically

When you visit our website, certain information may be collected automatically through analytics, cookies, server logs, and similar technologies.

Depending on the technologies enabled on the website, this may include:

IP address

Browser and device information

Operating system

Approximate geographic location

Referring website or source

Pages viewed

Date and time of visits

Session information

Interactions with website features

General website usage and performance information

Google states that its default Analytics implementation collects users and session statistics, approximate geolocation, and browser/device information. GA4 also uses first-party cookies to distinguish users and sessions. �

Google Support +1

2. How We Use Information

We may use information we collect to:

Receive, review, and respond to inquiries

Evaluate potential consulting, management, recruiting, development, operational, leadership, or strategic engagements

Determine whether an opportunity may be an appropriate fit for Obsidian

Communicate with prospective, current, and former clients or business contacts

Schedule, administer, and follow up on meetings

Provide requested services and information

Operate, maintain, secure, and improve our website

Understand how visitors find and interact with our website

Measure website traffic, performance, and effectiveness

Develop and improve our services and business operations

Maintain appropriate business and communication records

Detect, investigate, and prevent fraud, misuse, security incidents, or unlawful activity

Establish, exercise, or defend legal rights

Comply with applicable laws, regulations, legal processes, and governmental requests

Submitting an inquiry, communicating with us, or scheduling an introductory meeting does not by itself create a client, advisory, fiduciary, employment, partnership, or other professional relationship with Obsidian Management.

3. Analytics, Cookies, and Similar Technologies

We use Google Analytics to help us understand website traffic and visitor interactions.

Google Analytics may use first-party cookies and similar technologies to collect information about website usage. Google identifies _ga and _ga_<container-id> as cookies used by GA4 to distinguish users and maintain session state. �

Google Support

Analytics information may include general usage statistics, approximate location, device and browser information, pages visited, traffic sources, and interactions with the website. �

Google Support

We may modify the analytics and technology services used by the website over time. If our practices materially change, we will update this Privacy Policy as appropriate.

4. Cookie Choices

Most web browsers allow you to manage, block, or delete cookies through browser settings.

Where required by applicable law or policy, we may provide additional mechanisms for visitors to control non-essential analytics or tracking technologies.

Google provides consent controls that allow analytics storage to be granted or denied, and its documentation states that website operators should obtain consent where required before Google tags write or read cookies. �

Google Support +1

We will separately evaluate and implement an appropriate consent-management mechanism for the website based on the technologies we use and the jurisdictions in which we operate.

5. How We Disclose Information

Obsidian Management does not sell personal information in exchange for money.

We may disclose personal information when reasonably necessary to service providers and technology providers that support our operations, including providers of:

Website hosting and infrastructure

Website forms and submission processing

Analytics

Email and business communications

Calendar and scheduling services

Video conferencing

Information technology and security

Professional services

Our current technology environment may include Webflow, Google Analytics, and Microsoft 365 services such as Microsoft Bookings, Outlook, and Microsoft Teams.

For example, Webflow can store website form submissions and trigger email notifications, depending on how the form is configured. � Microsoft also documents that Bookings can process customer contact and appointment information associated with scheduling. �

Webflow Help Center

Microsoft Learn

We may also disclose information:

When required by law, regulation, subpoena, court order, or other lawful process

In response to lawful governmental requests

To protect the rights, property, security, or safety of Obsidian, our clients, website visitors, or others

To investigate suspected fraud, security incidents, misuse, or unlawful conduct

In connection with establishing, exercising, or defending legal claims

6. Business Transfers

If Obsidian Management is involved in a merger, acquisition, financing, restructuring, sale of assets, transfer of operations, or similar business transaction, information may be disclosed or transferred as part of that transaction, subject to applicable law.

7. Data Retention

We retain personal information for only as long as reasonably necessary for the purposes for which it was collected and for legitimate business or legal purposes.

Factors used to determine appropriate retention periods may include:

The nature of the information

The purpose for which it was collected

Whether an active or prospective business relationship exists

Operational and recordkeeping needs

Legal, tax, accounting, contractual, or regulatory requirements

The need to resolve disputes or enforce agreements

Security and fraud-prevention considerations

When information is no longer reasonably required, we may delete, anonymize, or otherwise dispose of it consistent with applicable requirements and our operational capabilities.

8. Data Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information from unauthorized access, loss, misuse, alteration, or disclosure.

However, no website, electronic communication, transmission method, or information-storage system can be guaranteed to be completely secure. Accordingly, we cannot guarantee the absolute security of information transmitted to or maintained by us.

9. Your Privacy Rights and Choices

Depending on your place of residence and applicable law, you may have rights concerning your personal information.

These may include the right to request:

Access to certain personal information we maintain about you

Correction of inaccurate information

Deletion of certain information

Information about how personal information is collected, used, or disclosed

Restriction of or objection to certain processing

Withdrawal of consent where processing is based on consent

Data portability where applicable

Not all rights apply in every jurisdiction or circumstance.

To submit a privacy request, contact us at info@obsidianhosp.com.

We may take reasonable steps to verify your identity before processing certain requests. We may also retain information where permitted or required by law.

10. California Residents

California residents may have privacy rights under applicable California law.

Whether particular requirements of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), apply to Obsidian depends on factors including the nature and scale of our operations and applicable statutory thresholds.

Regardless of whether a particular statutory requirement applies, California residents may contact us at info@obsidianhosp.com with questions or requests concerning personal information.

We will update this section and implement any additional notices or mechanisms that become applicable as our business, data practices, or legal obligations evolve.

11. International Visitors

Our website may be accessed by visitors outside the United States.

Information submitted to Obsidian may be processed or stored in the United States or in other jurisdictions where our technology or service providers operate. Privacy laws in those jurisdictions may differ from the laws where you reside.

If laws such as the European Union General Data Protection Regulation, UK GDPR, or similar laws apply to particular processing activities, we will process personal information in accordance with applicable requirements, including relying on an appropriate lawful basis where required.

12. Marketing Communications

If we offer newsletters, promotional communications, or other marketing subscriptions in the future, recipients will be provided with an appropriate method to unsubscribe from those communications.

Transactional, administrative, or relationship-based communications may still be sent when appropriate.

We do not currently need to pretend the Contact form is a marketing opt-in. It isn't.

13. Third-Party Websites and Services

Our website may contain links to websites, social media platforms, or services operated by third parties.

We do not control and are not responsible for the privacy, security, content, or practices of those third parties. Your interactions with third-party services are governed by their respective terms and privacy policies.

14. Children's Privacy

Our website and services are intended for businesses and professionals and are not directed to children.

We do not knowingly use the website to solicit or collect personal information from children.

If we learn that personal information from a child has been collected through the website in circumstances where it should not have been, we will take reasonable steps to address it.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our business, services, technology, legal requirements, or privacy practices.

When we update the Policy, we will revise the Last Updated date at the top of this page.

Where required by applicable law, we may provide additional notice regarding material changes.

16. Contact Us

Questions, concerns, or requests regarding this Privacy Policy or our privacy practices may be directed to:

Obsidian Management

Email: info@obsidianhosp.com

Website: obsidianhosp.com

OBSIDIAN MANAGEMENT

Built on hospitality, driven by operations.

© 2026 Obsidian Management. All Rights Reserved.