1. Introduction
GFT Consulting LLC (referred to as GFT Consult, we, us, or our) is committed to protecting the privacy of individuals who visit our website, engage our services, or interact with our organization. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at gftconsult.buzz or otherwise engage with us.
This policy applies to all information collected through our website, email communications, phone calls, and in-person or virtual consultations. By using our website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or services.
GFT Consult operates as a management consulting firm based in Taylorsville, Utah, United States. We developed this policy to be transparent about our data practices and to comply with applicable privacy laws including the Utah Consumer Privacy Act (UCPA), the California Consumer Privacy Act (CCPA) where applicable, the General Data Protection Regulation (GDPR) for our European users, and other relevant regulations.
2. Information We Collect
We collect information that you voluntarily provide to us when you express interest in our services, fill out forms on our website, subscribe to our newsletter, request a consultation, or contact us via email or phone. This information may include:
- Personal Identification Information: Full name, email address, telephone number, postal address, job title, and company name.
- Professional Information: Industry, company size, role or title, and information about your business needs or challenges.
- Communication Data: Records of your correspondence with us, including emails, call notes, and consultation summaries.
- Payment Information: If you engage our paid services, we collect billing information such as invoice details and payment method data. Payment transactions are processed through secure third-party payment processors and we do not store full credit card numbers on our servers.
We also collect certain information automatically when you visit our website, as described in Section 3 below.
3. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. Cookies are small text files stored on your device by your web browser. We use the following types of cookies:
- Essential Cookies: These are necessary for the website to function properly. They enable basic features such as page navigation and access to secure areas. The website cannot function properly without these cookies.
- Analytics Cookies: These help us understand how visitors interact with our website by collecting information about pages visited, time spent on the site, and error reports. We use this data to improve our website performance and user experience.
- Preference Cookies: These remember your settings and preferences, such as language choices or region, to provide a more personalized experience on future visits.
You can control and manage cookies through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, or alert you when a cookie is being set. Please note that disabling essential cookies may affect the functionality of our website.
4. How We Use Your Information
GFT Consult uses the information we collect for the following purposes:
- To provide, maintain, and improve our consulting services and website experience.
- To respond to your inquiries, consultation requests, and customer service needs.
- To communicate with you about our services, industry insights, events, and relevant updates (with your consent where required by law).
- To process transactions, send invoices, and manage billing and account administration.
- To comply with legal obligations, resolve disputes, and enforce our agreements.
- To analyze usage trends and improve the effectiveness of our website and marketing efforts.
- To detect, prevent, and address technical issues, fraud, or security incidents.
5. Legal Basis for Processing (GDPR)
For individuals located in the European Economic Area (EEA) or the United Kingdom, we process your personal information based on the following legal grounds under the GDPR:
- Consent: Where you have given us explicit consent to process your data for a specific purpose, such as receiving marketing communications.
- Contractual Necessity: Where processing is necessary for the performance of a contract with you, such as providing consulting services you have engaged.
- Legal Obligation: Where we are required to process your data to comply with applicable laws and regulations.
- Legitimate Interests: Where processing is necessary for our legitimate business interests, such as improving our services, maintaining security, and conducting business analytics, provided your rights do not override those interests.
6. Information Sharing and Disclosure
GFT Consult does not sell your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: We may share information with trusted third-party vendors who assist us in operating our website, processing payments, delivering communications, or analyzing data. These service providers are contractually bound to protect your information and use it only for the purposes we specify.
- Legal Requirements: We may disclose information if required to do so by law, regulation, legal process, or governmental request, or where disclosure is necessary to protect our rights, property, or safety, or that of others.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any such change in ownership.
7. Data Retention
We retain your personal information only as long as necessary to fulfill the purposes for which it was collected, including for the satisfaction of legal, accounting, or reporting requirements. Our retention periods are as follows:
- Consultation and client records: Retained for the duration of the engagement plus seven years for tax and legal compliance purposes.
- Marketing communication data: Retained until you unsubscribe or request deletion, after which we retain only a suppression record to honor your preferences.
- Website analytics data: Retained in aggregate form for up to 26 months.
- Inquiry and contact form submissions: Retained for up to two years after the last contact.
When data is no longer needed, we securely delete or anonymize it in accordance with our data retention and disposal policies.
8. Data Security
GFT Consult implements appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols for all web communications.
- Secure server infrastructure with restricted access controls and regular security audits.
- Staff training on data protection best practices and confidentiality obligations.
- Procedures for handling data breaches, including notification protocols as required by applicable law.
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to maintaining industry-standard safeguards.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States where our servers and operations are based. These countries may have data protection laws different from those in your jurisdiction. When we transfer data from the EEA or UK to the United States, we rely on appropriate safeguards such as:
- Standard Contractual Clauses approved by the European Commission.
- Data processing agreements that ensure equivalent levels of data protection.
- Compliance with applicable data transfer frameworks and regulations.
By providing your information, you consent to such transfers and processing in accordance with this Privacy Policy.
10. Your Rights (GDPR)
If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request that we correct any inaccurate or incomplete data.
- Right to Erasure: You may request deletion of your personal data under certain circumstances.
- Right to Restrict Processing: You may request that we limit the processing of your data in certain situations.
- Right to Data Portability: You may request a copy of your data in a structured, machine-readable format.
- Right to Object: You may object to the processing of your data for direct marketing purposes or based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at feedback@gftconsult.buzz. We will respond to your request within 30 days in accordance with applicable law.
11. Your Rights (CCPA)
If you are a resident of California, United States, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the business purpose for collection, and the categories of third parties with whom it was shared.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out: You have the right to opt out of the sale of your personal information. GFT Consult does not sell personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise your CCPA rights, please contact us at feedback@gftconsult.buzz. We will verify your identity before processing your request. You may also designate an authorized agent to make a request on your behalf.
12. Children's Privacy
Our website and services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us immediately.
13. Third-Party Links
Our website may contain links to third-party websites, plug-ins, or services that are not owned or controlled by GFT Consult. We are not responsible for the privacy practices or content of such third-party sites. We encourage you to review the privacy policies of any third-party websites you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. We will notify you of material changes by posting the updated policy on this page with a revised last updated date. Where required by law, we will obtain your consent before implementing significant changes. We encourage you to review this policy periodically.
15. Contact Information
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data handling practices, please contact us:
GFT Consulting LLC
4287 S Shady River Way APT 1716
Taylorsville, UT 84123-2889
United States
Email: feedback@gftconsult.buzz
Phone: +1 779-434-3956
We are committed to addressing your concerns promptly. If you are dissatisfied with our response, you may have the right to lodge a complaint with your local data protection authority (for EEA/UK residents) or with the Utah Division of Consumer Protection (for US residents).