GVRN Privacy Statement
version: September 2026
GVRN LLC Privacy Statement
Effective date: September 14, 2026
GVRN LLC (“GVRN,” “we,” “us,” or “our”) is committed to being clear and transparent about how we collect, use, and share personal information. This Privacy Statement explains our practices with respect to personal information we collect through our website, our advisory services, and related communications (collectively, the “Services”). It also describes the rights available to individuals in the European Economic Area, the United Kingdom, and the State of California, among others.
1. Who We Are
GVRN LLC is a California limited liability company providing concierge AI governance, privacy, and data governance advisory services to enterprise-bound technology companies. For purposes of the data protection laws described in this Statement, GVRN LLC is the controller (or “business,” as that term is used under California law) responsible for the personal information described in this Statement, unless we tell you otherwise.
2. Scope of This Statement
This Statement applies to personal information we collect from or about: (a) visitors to our website; (b) prospective, current, and former clients and their personnel; and (c) individuals who contact us or subscribe to our communications. This Statement does not apply to information we process on behalf of our clients as a service provider or processor under a separate data processing agreement — that processing is governed by the terms agreed with the applicable client.
3. Personal Information We Collect
We collect the following categories of personal information, depending on how you interact with us:
|
Category |
Examples |
Source |
|
Identifiers |
Name, business email, job title, company name, phone number |
Directly from you; publicly available business sources |
|
Commercial information |
Services purchased or inquired about, contract and billing details |
Directly from you |
|
Internet or network activity |
IP address, browser type, pages visited, referring URLs, cookie identifiers |
Automatically, via our website and analytics tools |
|
Professional information |
Employer, role, industry, LinkedIn profile details you provide |
Directly from you; publicly available sources |
|
Communications |
Content of emails, meeting notes, and support requests |
Directly from you |
|
Inferences |
Interests or preferences inferred from your interactions with our Services |
Generated internally from the categories above |
We do not require or intentionally collect sensitive personal information (such as government identification numbers, precise geolocation, or health information) through our Services. If you provide such information to us, please limit it to what is necessary for the purpose for which you are contacting us.
4. How We Use Personal Information
We use personal information for the following purposes:
- To provide, operate, and improve our advisory Services and respond to inquiries;
- To communicate with you, including sending requested materials, proposals, and administrative updates;
- To manage our client and vendor relationships, including billing and contract administration;
- To maintain and improve our website, including through analytics;
- To market our Services, where permitted, and in accordance with your communication preferences; and
- To comply with legal obligations, enforce our agreements, and protect the rights, property, and safety of GVRN, our clients, and others.
5. Legal Bases for Processing
If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases under the General Data Protection Regulation (GDPR) or UK GDPR to process your personal information:
- Contract: to take steps at your request before entering into a contract, or to perform a contract with you (e.g., delivering advisory Services).
- Legitimate interests: to operate, secure, and improve our Services, respond to inquiries, and market our Services in ways you would reasonably expect, provided these interests are not overridden by your rights.
- Consent: where we ask for it, such as for certain marketing communications or non-essential cookies. You may withdraw consent at any time.
- Legal obligation: to comply with applicable law, regulation, or legal process.
6. How We Share Personal Information
We share personal information with the following categories of recipients:
|
Recipient |
Purpose |
|
Service providers and subprocessors (e.g., cloud hosting, email, scheduling, analytics, and payment processors) |
To perform services on our behalf, under contractual confidentiality and data protection obligations |
|
Professional advisors (e.g., accountants, auditors, outside counsel) |
To obtain professional advice and meet compliance obligations |
|
Regulators, courts, and law enforcement |
Where required by law, legal process, or to protect our rights |
|
Successor entities |
In connection with a merger, acquisition, financing, or sale of assets |
GVRN LLC does not sell personal information for money, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. If this changes, we will update this Statement and provide the required notice and opt-out mechanism.
7. International Data Transfers
We are based in the United States, and personal information we collect may be transferred to, stored, and processed in the United States or other countries that may have data protection laws different from those in your country. Where we transfer personal information from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, as applicable. You may contact us for more information about the safeguards we use.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Statement, including to provide our Services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of information and the context in which it was collected; for example, client contract records are generally retained for the duration of the relationship plus the period required by applicable statutes of limitation.
9. Your Privacy Rights
9.1 If You Are in the EEA, UK, or Similar Jurisdictions
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you;
- Rectify inaccurate or incomplete personal information;
- Erase your personal information in certain circumstances;
- Restrict or object to our processing of your personal information;
- Receive a copy of certain personal information in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your local data protection supervisory authority.
9.2 If You Are a California Resident
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), California residents have the right to:
- Know the categories and specific pieces of personal information we have collected about you, and the categories of sources, purposes, and third parties involved;
- Delete personal information we have collected from you, subject to certain exceptions;
- Correct inaccurate personal information we maintain about you;
- Opt out of the sale or sharing of personal information (as noted above, we do not currently sell or share personal information);
- Limit the use or disclosure of sensitive personal information (we do not use sensitive personal information beyond what is necessary to provide our Services);
- Not receive discriminatory treatment for exercising any of these rights.
We will not discriminate against you for exercising your CCPA rights. To exercise these rights, you or your authorized agent may submit a request using the contact information in Section 14. We may need to verify your identity before completing your request, which may involve matching information you provide to information we already have on file. Authorized agents must provide proof of authorization, and we may still require you to verify your own identity directly with us.
9.3 Other Jurisdictions
If you are located in a jurisdiction with its own comprehensive privacy law (for example, certain other U.S. states), you may have similar rights to those described above. Please contact us using the details in Section 14, and we will respond in accordance with applicable law.
10. Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate the site, remember your preferences, and understand how visitors use our Services. You can control cookies through your browser settings; where required by law, we will request your consent before placing non-essential cookies and provide a mechanism to withdraw that consent.
11. Children's Privacy
Our Services are directed to businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
12. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Changes to This Statement
We may update this Statement from time to time to reflect changes in our practices or applicable law. We will post the updated notice on our website with a revised effective date, and, where required by law, provide additional notice of material changes.
14. Contact Us
If you have questions about this Statement or wish to exercise your privacy rights, please contact us at:
GVRN LLC
Attn: Privacy
Email: [email protected]