Legal

Privacy Policy

Effective date: June 24, 2026 · Last updated: June 24, 2026

1. Introduction

GRC Solutions Agency ("GSA," "we," "us," or "our") is a professional consultancy providing governance, risk, and compliance (GRC) advisory, bespoke software solutions, and organizational process design. We are based in California, United States.

Because privacy and data protection are central to our profession, we hold our own practices to recognized industry frameworks. This Privacy Policy is structured around the Secure Controls Framework (SCF) Data Privacy Management Principles and is designed to align with:

  • NIST Privacy Framework 1.0
  • ISO/IEC 27701 (Privacy Information Management) and ISO/IEC 29100 (Privacy framework)
  • AICPA Trust Services Criteria (TSC) — Privacy (used for SOC 2)
  • Generally Accepted Privacy Principles (GAPP)
  • APEC Privacy Framework
  • The EU General Data Protection Regulation (GDPR)
  • The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)

Where we process personal data in connection with artificial intelligence systems or features, we apply the risk-management practices described in the NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile (NIST AI 600-1).

This Policy explains what personal data we collect, how and why we process it, who we share it with, how long we keep it, how we protect it, and the rights you have over it.


2. Scope

This Policy applies to personal data we process about:

  • Visitors to our websites, including gsa.lc and the GRC Solutions Agency Portal;
  • Prospective, current, and former clients and their authorized representatives;
  • Individuals who contact us, request information, or use our services;
  • Vendors, partners, and contractors; and
  • Job applicants and personnel (where a separate personnel notice does not apply).

This Policy does not apply to third-party websites or services that we do not control, even where we link to them.


3. Roles and Accountability

(SCF Principle 1 — Data Privacy by Design; PRI-01, PRI-01.1; NIST PF GV.PO-P; ISO 27701 5.; GAPP "Management"; GDPR Arts. 5(2), 24, 37–39; CCPA/CPRA §1798.100)

GSA maintains a documented data privacy program with assigned accountability. We have appointed a privacy lead (acting as our Chief Privacy Officer / Data Protection Officer function) who is responsible for coordinating, developing, and implementing applicable data privacy requirements and managing data privacy risks across the data lifecycle.

For any questions about this Policy or our handling of personal data, contact our privacy team at privacy@gsa.lc (see Section 16).


4. Personal Data We Collect

(SCF Principle 3 — Limited Collection & Use; PRI-04, PRI-05.7; NIST PF ID.IM-P; ISO 29100 "Collection limitation"; GDPR Arts. 5(1)(c), 6, 9; CCPA/CPRA §1798.140(v), (ae))

We limit collection to what is directly relevant and necessary for a clearly identified, lawful purpose. Depending on how you interact with us, we may collect the following categories of personal data:

| Category | Examples | |---|---| | Identifiers | Name, email address, phone number, company, job title, account/portal username | | Professional information | Employer, role, engagement details, business correspondence | | Commercial information | Services requested or purchased, billing and contract details | | Internet/network activity | IP address, browser type, device identifiers, pages viewed, referring URLs, interactions with our site and Portal | | Communications content | The contents of messages, support requests, and inquiry forms you send us | | Sensitive personal information | Generally not collected. If a client engagement requires processing of sensitive or regulated categories of data, it is governed by a separate written agreement and handled under heightened safeguards (PRI-05.7) |

We do not knowingly collect personal data from children under 16. We do not sell the personal data of minors.


5. How We Collect Personal Data

We collect personal data:

  • Directly from you — when you contact us, fill out a form, request services, create a Portal account, or correspond with us;
  • Automatically — through cookies and similar technologies when you use our website and Portal (see Section 12); and
  • From third parties — such as business partners, referral sources, and publicly available professional sources, where permitted by law.

6. Why We Process Personal Data and Our Lawful Bases

(SCF Principle 3 — Limited Collection & Use; PRI-04.1 Authority to Collect; ISO 29100 "Purpose specification"; GAPP "Collection"; GDPR Art. 6; CCPA/CPRA §1798.100(b))

We process personal data only for purposes consistent with the notice given at collection. Our purposes and the corresponding GDPR lawful bases are:

| Purpose | Lawful basis (GDPR) | |---|---| | Respond to inquiries and provide requested information | Consent; or steps prior to a contract (Art. 6(1)(a)/(b)) | | Deliver advisory, software, and process-design services | Performance of a contract (Art. 6(1)(b)) | | Operate, secure, and maintain our website and Portal | Legitimate interests (Art. 6(1)(f)) | | Billing, accounting, and record-keeping | Legal obligation; contract (Art. 6(1)(c)/(b)) | | Marketing communications (where applicable) | Consent (Art. 6(1)(a)) | | Detect, prevent, and respond to security incidents and fraud | Legitimate interests; legal obligation (Art. 6(1)(f)/(c)) | | Comply with legal, regulatory, and contractual obligations | Legal obligation (Art. 6(1)(c)) |

We do not use personal data for new, incompatible purposes without providing updated notice and, where required, obtaining renewed consent.


7. Consent and Your Choices

(SCF Principle 2 — Data Subject Participation; PRI-03, PRI-03.4, PRI-03.5, PRI-03.8; NIST PF CT.PO-P; GAPP "Choice and Consent"; APEC "Choice"; GDPR Arts. 6(1)(a), 7; CCPA/CPRA §1798.120, §1798.135)

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. We provide clear and conspicuous choices to permit or limit the processing of your personal data, and we honor recognized opt-out preference signals such as Global Privacy Control (GPC) where applicable.

We do not sell or share your personal data for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. Should this ever change, we will provide a "Do Not Sell or Share My Personal Information" mechanism before doing so. We do not discriminate against you for exercising any privacy right.


8. How We Share Personal Data

(SCF Principle 10 — Third-Party Management; PRI-07, PRI-08; NIST PF CT.DM-P; ISO 27701 8.; GAPP "Disclosure to Third Parties"; GDPR Arts. 28, 44–49; CCPA/CPRA §1798.140(ag) service providers)

We disclose personal data only to trusted recipients under appropriate safeguards and contractual obligations:

  • Service providers and processors — hosting, cloud infrastructure, analytics, communications, and payment processors that act on our behalf under written contracts requiring them to protect personal data and use it only for the services we specify;
  • Professional advisors — legal, accounting, and audit professionals;
  • Authorities — regulators or law enforcement where required by law, valid legal process, or to protect rights and safety; and
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

We require service providers to validate that their data privacy and security controls are effectively implemented and aligned with recognized practices.

International transfers

Where personal data is transferred outside its country of origin (including from the EEA/UK to the United States), we rely on appropriate transfer mechanisms such as Standard Contractual Clauses and supplementary measures, consistent with GDPR Chapter V and the APEC accountability principle.


9. Data Retention and Disposal

(SCF Principle 5 — Data Lifecycle Management; PRI-05 Retention & Disposal; ISO 29100 "Use, retention and disclosure limitation"; GAPP "Retention"; GDPR Art. 5(1)(e); CCPA/CPRA §1798.100(a)(3))

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to satisfy legal, accounting, or reporting obligations, and to resolve disputes or enforce agreements. When personal data is no longer needed, we securely dispose of, destroy, erase, or anonymize it in accordance with documented retention schedules.


10. How We Protect Personal Data

(SCF Principle 7 — Cybersecurity by Design; ISO 27701/27001 Annex A; AICPA TSC Security & Confidentiality; GAPP "Security for Privacy"; GDPR Art. 32; CCPA/CPRA §1798.100(e))

As a GRC consultancy, security is foundational to our privacy program. We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These include access controls and least-privilege, encryption in transit and at rest where appropriate, data classification, logging and monitoring, secure development practices, and vendor security oversight. No method of transmission or storage is completely secure, but we continuously assess and improve our controls.


11. Incident Response and Breach Notification

(SCF Principle 8 — Incident Response; PRI principles 8.1–8.2; NIST PF; AICPA TSC; GDPR Arts. 33–34; CCPA/CPRA / Cal. Civ. Code §1798.82)

We maintain and test an incident response capability to identify, contain, and respond to security and privacy incidents in a coordinated manner. In the event of a breach involving personal data, we will notify affected individuals, regulators, and other parties as required by applicable law and contractual obligations, within the timeframes those laws prescribe.


12. Cookies and Similar Technologies

We use cookies and similar technologies to operate our website and Portal, remember your preferences, measure usage, and improve performance. You can control cookies through your browser settings and, where offered, through our cookie preferences tool. Some features may not function properly if certain cookies are disabled. Where required, we obtain consent before placing non-essential cookies, and we honor GPC signals.


13. Automated Decision-Making and AI

(NIST AI RMF 1.0; NIST AI 600-1 Generative AI Profile; GDPR Art. 22)

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Where we use AI or generative AI features in our software or services, we apply NIST AI RMF risk-management practices — including governance, transparency, data minimization, and bias and safety controls — and we do not use your personal data to train third-party AI models without an appropriate basis and notice.


14. Your Privacy Rights

(SCF Principle 6 — Data Subject Rights; PRI-06 and 6.1–6.6; NIST PF CT.PO-P/CT.DM-P; ISO 29100 "Individual participation and access"; GAPP "Access"; APEC "Access and Correction")

Subject to applicable law, you have rights to access, correct, and request deletion of your personal data, to inquire and complain, to seek redress, and to appeal an adverse decision. We provide a capability to receive and respond to these requests and will notify you and relevant third parties when data is corrected or amended.

14.1 If you are in California (CCPA/CPRA)

California residents have the right to:

  • Know / Access the categories and specific pieces of personal information we collect, use, and disclose;
  • Delete personal information, subject to exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information (note: we do not sell or share personal information);
  • Limit the use of sensitive personal information;
  • Non-discrimination for exercising these rights.

You may submit a request via privacy@gsa.lc. You may use an authorized agent to act on your behalf. We will verify your identity before fulfilling a request and respond within the timeframes required by the CCPA/CPRA.

14.2 If you are in the EEA or UK (GDPR)

You have the rights of access, rectification, erasure, restriction of processing, data portability, objection (including to direct marketing), and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority. We will respond within one month, as required by the GDPR.

14.3 How to exercise your rights

Contact us at privacy@gsa.lc with your request. We may need to verify your identity and may ask for additional information to locate your data. We will not charge a fee unless your request is manifestly unfounded or excessive.


15. Risk Management and Continuous Improvement

(SCF Principle 9 — Risk Management; NIST PF; AICPA TSC; ISO 27701)

We integrate privacy risk management into our broader risk program, including privacy impact assessments for higher-risk processing, periodic control reviews, and continuous improvement. This reflects the same discipline we bring to client engagements.


16. Contact Us

For privacy questions, requests, or complaints:

  • Privacy team / Data Protection contact: privacy@gsa.lc
  • Organization: GRC Solutions Agency
  • Website: https://gsa.lc

If you are not satisfied with our response, you may have the right to contact a relevant data protection or consumer protection authority in your jurisdiction.


17. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated through a conspicuous notice on our website and, where required, by obtaining renewed consent. The "Last updated" date at the top indicates when the Policy was last revised.


Framework Mapping Summary

This Policy is organized around the SCF Data Privacy Management Principles and maps to the following frameworks:

| SCF Privacy Principle | Policy Section | Aligned Frameworks | |---|---|---| | 1. Data Privacy by Design | 1, 3 | NIST PF (GV), ISO 27701, GAPP, GDPR 24/25, CCPA | | 2. Data Subject Participation | 7 | GAPP, APEC, ISO 29100, GDPR 7, CCPA 1798.120 | | 3. Limited Collection & Use | 4, 5, 6 | ISO 29100, GAPP, GDPR 5/6, CCPA 1798.100 | | 4. Transparency | 1, 6, 12, 17 | NIST PF, ISO 29100, GDPR 12–14, CCPA 1798.130 | | 5. Data Lifecycle Management | 9 | ISO 29100, GAPP, GDPR 5(1)(e), CCPA | | 6. Data Subject Rights | 14 | ISO 29100, GAPP, APEC, GDPR 15–22, CCPA/CPRA | | 7. Cybersecurity by Design | 10 | AICPA TSC, ISO 27701/27001, GDPR 32, CCPA 1798.100(e) | | 8. Incident Response | 11 | NIST PF, AICPA TSC, GDPR 33–34, Cal. §1798.82 | | 9. Risk Management | 15 | NIST PF, NIST AI RMF, AICPA TSC, ISO 27701 | | 10. Third-Party Management | 8 | ISO 27701, GAPP, GDPR 28/44–49, CCPA service providers | | 11. Business Environment | 2, 3 | NIST PF (ID.BE-P), ISO 27701 |

AI-specific processing aligns with NIST AI RMF 1.0 and the NIST AI 600-1 Generative AI Profile (Sections 13, 15).


This Privacy Policy is provided for GRC Solutions Agency's own data processing activities. It reflects alignment with recognized privacy frameworks but is not legal advice; specific legal obligations should be confirmed with qualified counsel for each jurisdiction in which GSA operates.

GSA
GRC Solutions AgencyPosture. Policy. Proof.

An information security GRC firm partnering with organizations across regulated industries to make compliance defensible by design.

Navigate

Contact

© 2026 GRC Solutions Agency, LLC. All rights reserved.

gsa.lc

Independent private entity; not affiliated with the U.S. Government or the U.S. General Services Administration (GSA). https://gsa.lc/non-affiliation