← Back to GXM
Privacy Policy
Effective: June 29, 2026 · Version 1.1
This Privacy Policy describes how GXM Consulting (“GXM,” “we,” “our,” or “us”) collects, uses, discloses, retains, and protects information when you visit https://gxmc.net, submit forms, request scans or assessments, pay invoices, communicate with us, or engage with our services. By using the site or submitting information, you acknowledge this Policy.
This Policy is designed to apply broadly as GXM’s site, vendors, forms, services, audits, automations, and productized offerings evolve. Where a separate written agreement, data processing addendum, business associate agreement, confidentiality agreement, or client-specific privacy term applies, that document controls for the covered engagement.
1. Information we collect
Information you provide directly
- Contact, booking, and inquiry information: name, email address, phone number if provided, company, role, website, selected engagement type, scheduling preferences, budget or urgency signals, and any free-text message you write.
- Forensic Readiness intake information: your name, email, business name, website URL, role, urgency, situation stage, providers, tools, systems, involved parties, timeline, description of the situation, uploaded or linked materials if offered, and confirmation of authority to engage GXM on the business’s behalf.
- AI Workspace Audit and assessment information: company information, domains, tools, public URLs, workspace descriptions, authorized system details, configuration details, audit answers, scan inputs, scan outputs, and findings returned by the review you authorize.
- Payment and billing information: invoice details, billing contact, business address, payment status, transaction references, subscription status, receipts, tax or accounting metadata, and payment information processed by Stripe or another payment provider. We do not intentionally store full payment card numbers on our own servers.
- Communications and engagement records: emails, call notes, scheduling data, support requests, approvals, authorization records, contract status, project context, feedback, and other information you send or approve.
- Optional sensitive information: information about security incidents, personnel, disputes, vendors, customers, credentials, regulated data, or confidential business matters if you choose to submit it or if a separate engagement requires it. Do not submit social security numbers, full payment card numbers, medical records, account credentials, trade secrets, or other highly sensitive information unless we have expressly requested it through an appropriate channel.
Information collected automatically
- Usage analytics: pageviews, click events, form-start and form-submit events, time-on-page, path context, referrer, device and browser signals, and external-link clicks. We currently store our own analytics in our own database and use browser
sessionStorage to assign a per-session identifier. We do not currently set tracking cookies for our own analytics.
- Server, security, and delivery logs: IP address, user agent, request path, referring page, response status, timestamp, error logs, rate-limit events, bot-detection signals, abuse-prevention records, and delivery metadata retained by us or our infrastructure providers.
- Device and interaction signals from third-party tools: for example, Cloudflare Turnstile may process device, browser, network, and interaction signals to determine whether a form submission is likely human.
2. Sources of information
We collect information from you, your browser or device, your employer or organization when you act on its behalf, authorized third parties you ask us to communicate with, payment processors, scheduling or email providers, public sources you direct us to review, vendors that help us operate the site, and systems or tools you authorize us to assess.
3. How we use information
We use information for the following business, operational, legal, and security purposes:
- To respond to inquiries, schedule calls, evaluate fit, prepare quotes, and run engagements you initiate or authorize.
- To perform authorized audits, scans, forensic-readiness reviews, technical assessments, builds, support, reporting, automation, and related services.
- To send transactional and engagement-related email, including acknowledgments, scheduling, invoices, receipts, updates, reports, follow-ups, security notices, and administrative messages.
- To process payments, manage invoices, maintain billing records, reconcile transactions, prevent fraud, and satisfy accounting and tax obligations.
- To operate, secure, debug, monitor, personalize, improve, and measure the site, forms, analytics, reports, workflows, automations, and service paths.
- To detect, prevent, investigate, and respond to spam, abuse, unauthorized activity, security incidents, unlawful conduct, payment disputes, or violations of our Terms.
- To comply with legal obligations, enforce agreements, preserve rights, resolve disputes, respond to lawful requests, and protect GXM, clients, users, and third parties.
- To create aggregated, de-identified, or anonymized insights that do not reasonably identify you and may be used for analytics, benchmarking, service improvement, or business planning.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your submitted intake, audit, or assessment information to train third-party AI models unless you expressly agree in writing.
4. AI-assisted processing and automation
GXM may use internal tools, automation, scripts, AI-assisted systems, and service providers to help process submissions, summarize context, identify operational issues, draft work product, analyze authorized inputs, improve workflows, and support engagements. Human review, written scope, and engagement-specific terms control where required.
We may process information through AI or automation providers when reasonably necessary for an authorized engagement or operational purpose. We configure those workflows to protect client information and do not authorize third-party providers to train their public models on submitted intake or audit information unless you expressly agree in writing.
5. How we disclose information
We disclose information only as reasonably necessary for the purposes described in this Policy, as authorized by you, or as required or permitted by law. Categories of recipients may include:
- Infrastructure and hosting providers: hosting, database, storage, deployment, logging, monitoring, and security providers.
- Email, communication, and scheduling providers: transactional email, notifications, calendar coordination, and engagement follow-up.
- Payment and billing providers: invoice, payment, subscription, receipt, fraud-prevention, tax, and accounting support.
- Security, abuse-prevention, analytics, and CDN providers: bot mitigation, rate limiting, forms protection, font or asset delivery, diagnostics, analytics, and performance.
- Professional advisors and contractors: lawyers, accountants, insurers, technical contractors, or advisors who support GXM and are bound by appropriate duties or agreements.
- Engagement-authorized third parties: vendors, counterparties, platforms, tools, or client-designated contacts when you authorize or request that we coordinate with them.
- Legal, safety, and business-transfer recipients: courts, regulators, law enforcement, counterparties in disputes, successors, purchasers, or other parties when disclosure is necessary to comply with law, enforce rights, protect safety, collect amounts owed, or support a merger, acquisition, financing, reorganization, sale of assets, change of control, or transfer of operations.
6. Subprocessors and third-party services
Current services used to operate the site and related workflows include:
- Render: web hosting, request routing, server logs, and deployment operations.
- Neon: managed Postgres database for form submissions, analytics, content, and application data.
- Resend: transactional email delivery for notifications and follow-ups.
- Stripe: payment processing, invoices, receipts, subscription billing, payment status, and related payment records for paid engagements.
- Cloudflare Turnstile: spam and abuse protection on forms. Turnstile may process device and request signals to verify that a submission is likely human. Its use is governed by Cloudflare’s Privacy Policy and Terms.
- Google Fonts: typography delivery. Your IP address and browser metadata may be logged by Google when font files load.
- jsDelivr: CDN delivery for icon assets and related static resources.
We may add, replace, or remove vendors that provide materially similar hosting, database, email, payment, security, analytics, CDN, AI, automation, communication, document, or operational functions. When a vendor materially changes how personal information is used or disclosed, we will update this Policy when required by law or when we determine the change is material.
7. Cookies and similar technologies
Our own analytics is currently cookie-free. We use sessionStorage, which is generally cleared when you close the browser tab, to assign a per-session identifier. We may use cookies, local storage, session storage, pixels, logs, or similar technologies in the future for security, abuse prevention, preferences, analytics, payments, forms, or product features. If we deploy technology that requires additional consent or notice under applicable law, we will provide it where required.
Some forms use Cloudflare Turnstile for abuse prevention. Turnstile may process device, browser, interaction, and network signals controlled by Cloudflare. Payment, email, font, hosting, and CDN providers may also collect technical information when their services are used.
8. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, contract, accounting obligations, security needs, dispute preservation, backup systems, or legitimate business needs. Retention depends on the nature of the information, the sensitivity of the data, the relationship with you, the status of an engagement, legal requirements, and operational risk.
- Contact, booking, and intake submissions: retained for the life of the inquiry or engagement plus a reasonable period for follow-up, legal, accounting, security, quality, and business-record purposes.
- Forensic, audit, and assessment information: retained according to the applicable engagement terms, authorization, legal hold, security need, or operational purpose.
- Billing and payment records: retained as needed for accounting, tax, audit, dispute, fraud-prevention, and legal obligations.
- Analytics events: retained in aggregated or pseudonymized form as needed for operational analytics; individually identifying analytics records are not retained longer than reasonably necessary for site operations and analysis.
- Server and security logs: retained according to our and our providers’ operational defaults, security needs, and legal obligations.
- Backups: deleted on a rolling schedule according to backup lifecycle practices, unless preserved for security, continuity, or legal reasons.
You may request deletion using the contact below. We will honor requests to the extent required by applicable law and to the extent we are not required or permitted to retain information for legal, accounting, security, contract, dispute, fraud-prevention, or legitimate business purposes.
9. Your privacy rights
Depending on where you live and whether applicable law covers GXM’s processing of your information, you may have rights to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of information.
- Receive a copy of information in a portable format.
- Opt out of sale, sharing, targeted advertising, or certain profiling where applicable. We do not currently sell personal information or share it for cross-context behavioral advertising.
- Limit certain uses or disclosures of sensitive personal information where applicable.
- Object to or restrict certain processing where applicable.
- Withdraw consent where processing is based on consent.
- Appeal a denied privacy request where applicable law provides an appeal right.
To exercise a right, email [email protected]. We may verify your identity, request information needed to process the request, decline requests that are fraudulent, unverifiable, legally exempt, or not required by applicable law, and retain a record of the request as permitted by law. You may use an authorized agent where applicable law allows it, but we may require proof of authorization and identity verification. We will not retaliate against you for exercising a privacy right.
10. California and U.S. state privacy notice
For California residents and residents of other U.S. states with comprehensive privacy laws, this Policy describes the categories of personal information we collect, the purposes for collection and use, the categories of sources, the categories of disclosures, retention criteria, and privacy rights. The categories we may collect include identifiers, commercial information, internet or electronic network activity, professional or employment-related information, inferences, sensitive information you choose to provide or authorize, and other information you submit or that is reasonably related to our services.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share personal information of minors under 16. If those practices change, we will update this Policy and provide any required opt-out mechanism.
11. Security
We use reasonable administrative, technical, and organizational measures designed to protect information, including TLS encryption in transit, restricted database access, least-privilege controls, provider access controls, form abuse protection, and operational monitoring. No system is perfectly secure. You submit information at your own risk, and we cannot guarantee absolute security, uninterrupted availability, or prevention of every unauthorized access event.
12. Children’s privacy
The site is intended for adults and business users. We do not knowingly collect personal information from children under 13, and the site is not directed to minors. If you believe a child has submitted information, contact us and we will delete it where required by law.
13. International visitors
The site is operated from the United States and is intended primarily for U.S. business users. If you visit from outside the United States, your information may be transferred to, stored in, and processed in the United States and other locations where our providers operate. Those locations may have data protection laws different from those in your jurisdiction. If you are located in the EU, UK, EEA, Switzerland, or another jurisdiction with comprehensive data protection laws, you may contact us to exercise available rights, and engagement-specific terms may provide additional controls where required.
14. Third-party links and platforms
The site may link to third-party websites, platforms, documents, payment pages, scheduling tools, social profiles, or resources. We are not responsible for the privacy, security, content, or practices of third parties. Review their policies before providing information to them.
15. Changes to this Policy
We may update this Policy as the site, our services, our vendors, our data practices, our risk profile, or applicable law evolves. Material changes will be reflected by an updated effective date at the top of this page; for significant changes we may also provide additional notice when required by law or when we decide it is appropriate. Your continued use of the site after a change indicates acknowledgment of the updated Policy.
16. Contact
Questions about this Policy or your information: [email protected].