Who we are and what this policy covers
Gunja Consulting, Inc. (“Gunja Consulting”, “we”, “us”, or “our”) is a technology consulting company incorporated in Illinois, United States. This Privacy Policy explains how we handle personal information when you:
- visit gunjaconsulting.com or any of its subdomains;
- contact us by email, post, or telephone about our consulting services;
- engage us as a client, or work for an organization that does; and
- use a mobile or web application that we publish under our own name.
For the purposes of the EU and UK General Data Protection Regulation, Gunja Consulting, Inc. is the controller of the personal information described in this policy, except where we are processing data on behalf of a consulting client — in that case the client is the controller and we act as a processor under our written agreement with them. See Data we handle on behalf of clients.
Information we collect
Information you give us directly
When you email us, respond to a proposal, or become a client, we receive whatever you choose to send. Typically that is your name, email address, employer, job title, telephone number, and the contents of your message — including any project details, documents, or credentials you send us. Please do not send passwords, API keys, or other secrets by email.
If we enter into a contract, we also collect billing and business information necessary to invoice and be paid: billing contact, billing address, purchase order numbers, and tax identifiers.
Information collected automatically on this website
This website is a static marketing site. It sets no cookies, runs no analytics scripts, embeds no third-party trackers, and includes no advertising technology. There is no contact form and no login.
Our hosting provider automatically records standard server and security logs when a page is requested. These logs may contain your IP address, the requested URL, the referring URL, your browser user-agent string, and a timestamp. We use them only to keep the site available and to investigate abuse, and we do not attempt to identify you from them. See Service providers for who hosts the site.
Information collected by our applications
Our applications may collect account information, content you create, purchase and subscription status, and diagnostic or usage data. Exactly what each app collects — and whether it is linked to your identity — is disclosed in that app’s own privacy notice and in its App Store privacy label. We do not use data from our applications to track you across other companies’ apps and websites, and we do not sell it.
Information we do not collect
We do not knowingly collect government identification numbers, biometric identifiers, precise geolocation, or information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life, or sexual orientation. Please do not send us this kind of information unless it is genuinely necessary for an engagement and we have agreed in writing how it will be handled.
How we use personal information
We use personal information to:
- respond to enquiries and provide the consulting services you have asked for;
- negotiate, enter into, and perform contracts, including invoicing and collecting payment;
- operate, maintain, and improve our applications, and provide support to the people who use them;
- authenticate users, prevent fraud and abuse, and keep our systems secure;
- understand which product features are used, in aggregate, so we can prioritize what to build and fix;
- send service communications — receipts, security notices, material changes to terms — which are not marketing and cannot be opted out of while you hold an account; and
- comply with legal obligations and establish, exercise, or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your personal information to train machine learning models, and we do not submit client confidential material to third-party AI services except where a client has approved that service in writing for their engagement.
Legal bases for processing (EEA and UK)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry; performing a contract | Performance of a contract, or steps taken at your request before entering one |
| Providing and supporting an application account | Performance of a contract |
| Security, abuse prevention, and server logging | Legitimate interests in keeping our services secure and available |
| Aggregate product analytics and crash diagnostics | Legitimate interests in improving our products, or consent where required by local law |
| Invoicing, accounting, and tax records | Compliance with a legal obligation |
| Defending legal claims | Legitimate interests in protecting our legal position |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You may object to that processing at any time — see Your rights. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
Service providers and disclosure
We keep the number of third parties that touch personal information deliberately small. Those we do use act as our processors under contract, may only use the data to provide their service to us, and may not use it for their own purposes.
| Provider | What they do |
|---|---|
| Vercel Inc. | Hosts this website and processes the request logs described above. |
| Our email provider | Delivers and stores email correspondence with us. |
| Apple Inc. | Distributes our iOS applications and processes all in-app purchases and subscriptions. Apple, not us, handles your payment details. |
| Application hosting, analytics, and crash reporting providers | Named individually in each application’s own privacy notice, because they differ by app. |
| Professional advisers | Our accountants and lawyers, where necessary and under a duty of confidentiality. |
We may also disclose personal information:
- when required by law, subpoena, court order, or other valid legal process — we will notify you first unless we are legally prohibited from doing so;
- to protect the rights, property, or safety of Gunja Consulting, our clients, or the public; and
- in connection with a merger, acquisition, financing, or sale of assets, in which case the recipient will be bound by this policy until it is superseded and you will be notified of any material change.
Data we handle on behalf of clients
In the course of consulting work, we sometimes access systems that contain personal information about our client’s customers, employees, or users. When that happens:
- the client remains the controller of that data and we act only on their documented instructions;
- we access production data only when there is no reasonable alternative, and we prefer anonymized or synthetic datasets;
- we do not copy client data onto personal devices or unmanaged storage;
- we return or delete client data at the end of the engagement, on the timeline set out in the engagement agreement; and
- we enter into a data processing agreement, including the applicable Standard Contractual Clauses, where the client requires one.
If you believe your personal information was processed by us as part of a client engagement and you want to exercise your rights, please contact the organization whose service you were using. If you contact us directly, we will forward your request to them and assist them in responding.
How long we keep information
We keep personal information only for as long as we need it for the purpose it was collected, and then delete it or irreversibly anonymize it.
| Category | Retention period |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact |
| Client contracts and correspondence | 7 years after the engagement ends, for legal and tax purposes |
| Invoices and accounting records | 7 years, as required by tax law |
| Application account data | Until you delete your account, then removed within 30 days |
| Backups containing deleted data | Rotated out within 90 days |
| Web server and security logs | Up to 30 days |
| Aggregated, de-identified statistics | Indefinitely — this data cannot be linked back to you |
How we protect information
We apply security measures appropriate to the sensitivity of the data we hold, including encryption in transit (TLS) and at rest, least-privilege access controls, multi-factor authentication on all administrative accounts, managed and patched infrastructure, and logging of administrative access.
No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and the relevant supervisory authorities as required by law, and without undue delay.
If you have found a vulnerability, please report it to security@gunjaconsulting.com. Our security policy explains what to expect.
International transfers
We are based in the United States and our service providers are primarily located there. If you are outside the United States, using our services means your personal information will be transferred to and processed in the United States, which may not provide the same level of data protection as your home country.
Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures such as encryption. You can request a copy of the safeguards we use by emailing privacy@gunjaconsulting.com.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. We honour these requests for everyone who asks, regardless of your location, to the extent we are able.
- Access. Ask what personal information we hold about you and receive a copy.
- Correction. Ask us to fix information that is inaccurate or incomplete.
- Deletion. Ask us to delete your personal information. We may keep what we are legally required to keep, and will tell you if that applies.
- Portability. Receive your information in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Objection and restriction. Object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time.
- Opt out of sale, sharing, or profiling. We do not sell or share personal information or engage in profiling that produces legal or similarly significant effects, so there is nothing to opt out of — but you may still submit a request and we will confirm this in writing.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
How to make a request
Email privacy@gunjaconsulting.com and tell us which right you want to exercise. To protect your data we need to verify who you are, which usually means replying from the email address associated with your account or enquiry; for sensitive requests we may ask for additional confirmation.
We respond within 30 days. If your request is complex we may extend that by a further 45 days and will tell you why before the first period expires. Requests are free unless they are manifestly unfounded or repetitive.
You may use an authorized agent to submit a request on your behalf. We will ask for written proof of their authority and may still contact you directly to confirm.
If you are unhappy with our response
Please tell us first — email privacy@gunjaconsulting.com and we will review it. You also have the right to complain to your local data protection authority. In the EEA that is the supervisory authority in your country of residence; in the UK it is the Information Commissioner’s Office; in California you may contact the California Privacy Protection Agency or the Attorney General.
Notice for United States residents
This section supplements the rest of this policy for residents of California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, and other states with comprehensive privacy laws.
In the twelve months preceding the date of this policy we have collected the categories of personal information described in Information we collect — namely identifiers, customer records, commercial information, internet activity information, and professional or employment information — for the business purposes described in How we use personal information. We collect it from you directly and from your device when you use our services, and we disclose it only to the service providers listed in Service providers and disclosure.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months. We do not sell or share the personal information of minors under 16.
We do not collect or process sensitive personal information for the purpose of inferring characteristics about you, so the right to limit the use of sensitive personal information does not apply.
California residents may also request, once per year and free of charge, a list of the third parties to whom we disclosed personal information for their direct marketing purposes under the “Shine the Light” law. We do not make such disclosures.
Some states give you the right to appeal a refused privacy request. If we decline your request, our response will explain why, and you may appeal by replying to that email with the word “Appeal”. We will respond to an appeal within 45 days.
Children’s privacy
Our website and our consulting services are directed to businesses and are not intended for children. Our applications are not directed to children under 13, and we do not knowingly collect personal information from a child under 13 (or under the higher age of digital consent that applies in some jurisdictions, which may be up to 16).
If you are a parent or guardian and believe your child has provided us with personal information, email privacy@gunjaconsulting.com and we will delete it and terminate any associated account promptly.
Links to other sites
Our website and applications may link to services we do not operate. We are not responsible for their content or privacy practices, and this policy does not apply to them. Read their privacy notices before giving them your information.
Changes to this policy
We may update this policy as our services change or the law does. The “last updated” date at the top always reflects the current version. If we make a material change — for example, collecting a new category of data or using it for a genuinely new purpose — we will give prominent notice on this website and, where we have your email address and the law requires it, contact you directly before the change takes effect.
How to contact us
For any question about this policy or how we handle your information:
Email: privacy@gunjaconsulting.com
Gunja Consulting, Inc. is registered in Illinois, United States. We handle correspondence by email; a postal address for formal notices is available on request from privacy@gunjaconsulting.com.
We have not appointed a Data Protection Officer, as we are not required to. Privacy enquiries are handled directly by company management, at the contact details above.
Related: Terms of Use · Cookie Policy · Security
