Who we are
GRandC Consulting LLC (“GRandC”, “we”, “us”) is a United States-registered governance, risk, compliance, and intelligence advisory organisation.
This Privacy Policy explains how we handle information across our public websites and platforms, including grandcconsulting.com and GRandCIndex (together, the “Services”).
For any privacy question or request, contact legal@grandcconsulting.com.
Scope of this policy
This policy applies to information we collect through the Services and through related communications (email, inquiry forms, gated downloads).
It does not apply to third-party websites we link to, or to information you provide directly to organisations that we partner with on engagements.
What we collect
We collect only what is necessary to operate the Services, respond to inquiries, deliver publications and intelligence, and protect our systems.
Information you provide
- Inquiry and contact forms — name, organisation, role, email, and the contents of your message.
- Gated publication and signals access — name, work email, organisation, jurisdiction, and the publication requested.
- Diagnostic baseline and engagement requests — institutional context you provide so we can scope a response.
- Newsletter and intelligence updates (future-ready) — when we introduce email subscriptions, we will collect your email and consent record, and provide one-click unsubscribe.
Information collected automatically
- Technical and log data — IP address, user agent, referrer, timestamps, and pages accessed. Used for security, abuse-prevention, and aggregate analytics.
- Cookies and similar technologies — see our Cookie Policy.
We do not knowingly collect special-category data (such as health, biometric, or political-opinion data). Please do not submit such data through our forms.
How we use information
We use the information described above to:
- Respond to inquiries and deliver requested materials.
- Operate, secure, and improve the Services and the GRandCIndex platform.
- Maintain institutional records of correspondence and engagements.
- Send transactional communications (e.g. publication delivery, engagement coordination).
- Send newsletters or intelligence updates where you have opted in (future-ready; not currently active).
- Comply with legal obligations and enforce our Terms & Conditions.
We do not sell personal information. We do not use your information to train third-party AI models.
Legal bases (EU / UK / EEA visitors)
For visitors located in the EU, UK, or EEA, we rely on the following legal bases under the GDPR and UK GDPR:
- Legitimate interests — to operate, secure, and improve the Services; to respond to institutional inquiries; to maintain records.
- Consent — for non-essential cookies, optional analytics, and newsletter subscriptions where applicable. You may withdraw consent at any time.
- Performance of a contract / steps prior to a contract — to deliver materials or services you have requested.
- Legal obligation — where we must process information to comply with applicable law.
International data transfers
GRandC is established in the United States. Information you submit may be processed in the US and in other jurisdictions where our service providers operate.
For transfers of personal data out of the EU, UK, or EEA, we rely on appropriate safeguards — including the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organisational measures where required.
How long we retain information
We retain information for as long as needed to fulfil the purposes described in this policy, to maintain institutional records, to comply with legal obligations, and to resolve disputes.
Retention periods vary by category — for example, inquiry correspondence is typically retained for the duration of any consequent engagement plus a reasonable archival period; technical logs are typically retained for a shorter, security-driven window. You may ask us to delete information sooner, subject to legitimate retention reasons.
Security
We use technical and organisational measures appropriate to the institutional and sensitive nature of our work, including access controls, encryption in transit, segregation of environments, and vendor due diligence.
No method of transmission or storage is perfectly secure. Please do not send confidential or privileged material through public web forms without prior arrangement.
Your rights
EU / UK / EEA visitors (GDPR & UK GDPR)
You have the right to:
- Access the personal data we hold about you.
- Request rectification of inaccurate or incomplete data.
- Request erasure of your data in certain circumstances.
- Restrict or object to certain processing.
- Request data portability where applicable.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection supervisory authority.
California residents (CCPA / CPRA)
You have the right to:
- Know what personal information we collect and how we use it.
- Request deletion of your personal information.
- Request correction of inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
- Non-discrimination for exercising your rights.
All other visitors
You may contact us at any time to ask about, correct, or delete information we hold about you.
How to exercise rights
Send your request to legal@grandcconsulting.com. We will respond within the timeframes required by applicable law (generally within 30 days for GDPR/UK GDPR requests and 45 days for CCPA/CPRA requests). We may need to verify your identity before acting on a request.
Children
The Services are intended for institutional and professional audiences. They are not directed at children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, please contact us so we can delete it.
Changes to this policy
We may update this policy from time to time to reflect changes to the Services, our practices, or applicable law. The “Effective” date above indicates when the current version took effect. Material changes will be highlighted on this page.
Contact
GRandC Consulting LLC, United States — privacy contact: legal@grandcconsulting.com.
