Privacy Policy
How GONZO CONSULTING, LLC collects, uses, discloses, and safeguards your personal information.
Contents
- Introduction and Scope
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Disclosure of Your Information
- Data Retention
- Data Security
- Your Privacy Rights
- Cookies and Tracking Technologies
- Children's Privacy
- International Data Transfers
- Third-Party Services and Links
- Do Not Track Signals
- Data Breach Notification
- Changes to This Privacy Policy
- Contact Us About Privacy
1. Introduction and Scope
This Privacy Policy describes how GONZO CONSULTING, LLC, a Utah limited liability company doing business as Gonzo Consult, collects, uses, stores, shares, and protects personal information obtained through our website at www.gonzoconsult.autos, through any related digital properties, through our professional services, and through any other interactions you may have with our organization. This policy applies to all visitors, users, clients, prospective clients, vendors, and job applicants who interact with Gonzo Consult.
Gonzo Consult is a computer systems design and related services firm specializing in enterprise systems architecture, cloud infrastructure engineering, systems integration, cybersecurity, and managed IT operations. Our engineering center is located at 866 W 1150 S, Springville, Utah 84663-6110, United States of America. Throughout this document, references to Gonzo Consult, we, us, and our refer to GONZO CONSULTING, LLC and its affiliated operating entities. The website was developed and is maintained by the Gonzo Consult engineering team.
By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision contained herein, you should discontinue use of our website and services immediately. We reserve the right to modify this policy at any time, and such modifications will be effective immediately upon posting to this page. Your continued use of our website or services after any changes constitutes your acceptance of the revised policy.
This Privacy Policy is designed to comply with applicable privacy laws in the jurisdictions where we operate, including but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and applicable provisions of the General Data Protection Regulation to the extent they govern our processing activities. We are committed to the principles of transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality in all of our data handling practices.
2. Information We Collect
2.1 Information You Provide Directly
We collect information that you voluntarily provide when you interact with our website, communicate with our team, or engage our services. This includes information submitted through our contact forms, email correspondence, phone calls, service inquiry forms, and client onboarding documentation. The categories of information we may collect include your full name, business email address, personal email address if provided, telephone number, job title, organization name, physical business address, billing address, payment information including bank account details and credit card data where applicable for service engagement, tax identification numbers, and any other information you choose to include in messages, project descriptions, or service requests submitted to us.
When you engage Gonzo Consult for professional services, we may also collect additional information necessary for the performance of our contractual obligations. This can include system access credentials provided under strict security protocols, network configuration data, infrastructure documentation, architectural diagrams, and other technical information related to your existing systems environment that you authorize us to review and optimize as part of the services we provide.
2.2 Information Collected Automatically
When you visit our website, certain information is collected automatically through standard web technologies. This automatic collection includes your Internet Protocol address, browser type and version, operating system type and version, device type and manufacturer, screen resolution, referring and exit pages, date and time stamps of your visit, pages viewed and time spent on each page, clickstream data including the sequence of links and buttons you interact with, and form interaction behavior. We also collect information about your network including Internet Service Provider name, approximate geographic location derived from your IP address at the city or regional level, connection speed, and language preferences as indicated by your browser settings.
We use server logs, web beacons, tracking pixels, and similar technologies to collect this information. Server log data is typically retained for a period of thirty days before being archived and eventually purged, unless required for security investigations or legal compliance purposes.
2.3 Information from Third Parties
We may receive information about you from third-party sources to supplement our own records and to help us provide more relevant services. These sources may include business intelligence platforms, publicly available business registries, professional networking platforms, trade association directories, credit reporting agencies where applicable for business account verification, and referral partners who introduce you to our services. We treat all information received from third-party sources in accordance with this Privacy Policy and applicable law.
3. How We Use Your Information
We use the information we collect for specific business purposes necessary to provide our services, operate our business, and comply with legal obligations. We use your information to provide, maintain, and improve our services including the delivery of contracted computer systems design, architecture consulting, cloud infrastructure engineering, systems integration, cybersecurity assessment, and managed IT operations services. This includes using your contact information to communicate about project status, deliverables, milestones, and service-related notifications.
We use your information to respond to inquiries submitted through our website, by email, or by telephone. When you request information about our services, pricing, or availability, we process your contact details and the content of your inquiry to provide a responsive and personalized reply. We may follow up on inquiries that do not result in an immediate engagement to determine whether your needs have changed or whether additional information would be helpful to your decision-making process.
We use your information to process payments, manage billing and invoicing, maintain financial records, and fulfill our accounting obligations. This includes the use of payment information for transaction processing, invoice generation, payment reconciliation, collection activities where necessary, and financial reporting and auditing purposes required by applicable law.
We use your information to send marketing communications about our services, industry insights, technical white papers, event invitations, and company updates where you have provided consent or where otherwise permitted by applicable law. You may opt out of marketing communications at any time by using the unsubscribe link included in every marketing email or by contacting us directly.
We use your information to analyze website usage patterns, improve user experience, optimize website performance, and develop aggregate statistical insights about our audience. We use your information to protect the security and integrity of our systems, networks, and data, including monitoring for unauthorized access attempts, investigating security incidents, detecting and preventing fraud, enforcing our Terms of Service, and complying with legal obligations including responding to lawful requests from law enforcement and regulatory authorities.
4. Legal Bases for Processing
For individuals located in jurisdictions that require a specified legal basis for the processing of personal data, we rely on the following legal grounds. Contractual Necessity means processing is necessary for the performance of a contract with you, such as delivering services you have engaged us to provide. Legitimate Interests means we process information where necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your data protection rights. Our legitimate interests include operating and improving our business, providing customer support, protecting against fraud and security threats, conducting business analytics, and marketing our services to existing and prospective clients. Consent means that where required by applicable law, we obtain your consent before processing your personal data for specific purposes, such as sending direct marketing communications. Legal Obligation means we process information where necessary to comply with applicable laws, regulations, court orders, or government requests. Vital Interests means that in rare circumstances, we may process information where necessary to protect vital interests.
5. Disclosure of Your Information
We do not sell your personal information. We do not rent, trade, or otherwise disclose your personal information to third parties for their independent commercial use. We may share your information only in limited circumstances and always subject to appropriate confidentiality and data protection obligations.
We may share information with service providers and subcontractors who perform functions on our behalf, including cloud hosting providers, payment processors, CRM platform operators, email service providers, analytics services, professional advisors including legal counsel and accountants, auditors, and insurance providers. Each service provider is bound by contractual obligations that limit their use of your information to the specific purpose for which it was disclosed and require them to implement appropriate technical and organizational security measures.
We may disclose information as required by law, regulation, legal process, or governmental request, including responding to subpoenas, court orders, or search warrants. We will make reasonable efforts to notify you of such disclosure unless prohibited by law or where notification would compromise an ongoing investigation. We may disclose information in connection with a corporate transaction, including a merger, acquisition, or sale of assets, requiring the acquiring entity to honor the commitments in this Privacy Policy. We may disclose aggregated, de-identified, or anonymized information that cannot reasonably be used to identify you for any lawful purpose.
6. Data Retention
We retain personal information for no longer than is necessary to fulfill the purposes for which it was collected, or as required by applicable law, regulation, or contractual obligation. Contact form submissions and inquiry correspondence are retained for two years from the date of last communication. Client engagement records are retained for the duration of the client relationship plus seven years following termination. Financial records are retained for seven years in accordance with applicable tax laws. Website server logs are retained for thirty days before being purged. Anonymized aggregate analytics data may be retained indefinitely for trend analysis and business planning.
7. Data Security
We implement and maintain comprehensive administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information. Our security program is aligned with industry standards and is regularly reviewed and updated. Technical safeguards include TLS 1.3 encryption for data in transit, AES-256 encryption for data at rest, multi-factor authentication for all administrative access, role-based access controls with least privilege, automated vulnerability scanning, intrusion detection and prevention systems, endpoint detection and response, SIEM with real-time alerting, and regular third-party security assessments. Administrative safeguards include a documented security policy reviewed annually, mandatory security awareness training for all personnel, background checks for personnel with access to sensitive systems, formal incident response procedures, vendor risk management, and business continuity and disaster recovery plans tested at least annually. While we implement robust security measures, no method of electronic transmission or storage is perfectly secure. In the event of a data breach affecting your personal information, we will notify you and relevant authorities in accordance with applicable legal requirements.
8. Your Privacy Rights
Depending on your jurisdiction of residence, you may have certain rights regarding your personal information. We honor all applicable privacy rights and will respond to verified requests in accordance with governing law. Rights may include access and data portability, correction of inaccurate information, deletion under certain circumstances, restriction of processing, opt-out of sale or sharing (Gonzo Consult does not sell personal information and has not done so in the preceding twelve months), and non-discrimination for exercising privacy rights. To exercise any of these rights, submit a verifiable request using the contact information in Section 16. We will acknowledge within ten business days and respond within the time period required by applicable law, typically forty-five calendar days. We will verify your identity before fulfilling any request.
9. Cookies and Tracking Technologies
Our website uses cookies, web beacons, tracking pixels, local storage, and similar technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors originate. Essential cookies enable core functionality such as security and accessibility and do not require consent under most privacy regulations. Analytics cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. You may configure your browser settings to block, delete, or alert you about cookies. Disabling essential cookies may affect website functionality. We do not currently respond to browser-based Do Not Track signals in a standardized manner, as there is no universally adopted standard for interpretation of such signals.
10. Children's Privacy
Our website and services are directed at business professionals and are not intended for use by individuals under the age of eighteen. We do not knowingly collect, solicit, maintain, or process personal information from children under the age of thirteen, or under the age of sixteen where applicable law sets a higher threshold. If we become aware that we have inadvertently collected personal information from a child without verified parental consent, we will take immediate steps to delete such information from our records.
11. International Data Transfers
Gonzo Consult is headquartered in the United States of America, and our primary data processing activities occur within the United States. If you are visiting our website or using our services from outside the United States, your information will be transferred to, stored in, and processed within the United States, which may have data protection laws that differ from the laws of your country of residence. When we transfer personal information across international borders, we implement appropriate safeguards as required by applicable data protection laws. By using our website or services, you acknowledge that your information will be subject to the laws of the United States.
12. Third-Party Services and Links
Our website may contain links to third-party websites and services not owned or controlled by Gonzo Consult. We are not responsible for the privacy practices, content, or security of any third-party websites. We encourage you to review the privacy policies of every third-party website you visit before providing any personal information. When we engage third-party service providers, we conduct due diligence to assess their data protection practices and enter into written agreements imposing data protection obligations consistent with this Privacy Policy.
13. Do Not Track Signals
Certain web browsers offer a Do Not Track feature that sends a signal to websites requesting that they refrain from tracking browsing activities. At present, there is no consensus among industry participants, standards bodies, or regulatory authorities regarding the meaning of Do Not Track signals. As a result, our website does not currently take action to respond to Do Not Track signals. You may manage tracking preferences through the cookie controls described in Section 9.
14. Data Breach Notification
In the event of a security incident resulting in unauthorized access to, disclosure of, or loss of personal information under our control, we will execute our incident response procedures to contain the incident, assess scope and impact, and notify affected individuals and relevant regulatory authorities in accordance with applicable legal requirements. Notifications will include a description of the incident, categories and approximate number of affected individuals, categories of personal information involved, likely consequences, measures taken to address the breach, and contact information for obtaining additional information.
15. Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time. When we make material changes, we will post the updated policy on this page with a new Last Updated date and, where required by applicable law, provide additional notice. Changes that are purely administrative, technical, or editorial in nature may be made without prior notice. We encourage you to review this Privacy Policy periodically to stay informed about our information practices.
16. Contact Us About Privacy
If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our data handling practices, if you wish to exercise your privacy rights as described in Section 8, or if you believe that we have not adhered to the terms of this Privacy Policy, please contact us at:
GONZO CONSULTING, LLC
Attn: Privacy Office
866 W 1150 S
Springville, UT 84663-6110
United States of America
Email: contact@gonzoconsult.autos
Phone: +1 (442) 304-5724
Website: www.gonzoconsult.autos
If you are located in a jurisdiction that provides for a right to lodge a complaint with a data protection supervisory authority, you have the right to do so. We encourage you to contact us first so that we have the opportunity to address your concerns directly. The Gonzo Consult engineering team built and maintains this website with data privacy and security as foundational design principles.