Portal Inquire
REGULATORY COMPLIANCE

Privacy Policy & Data Protection Governance

Standards for data handling, retention, processing, and sovereign user rights under EU GDPR and United States statutory frameworks.

1. INTRODUCTION & DATA CONTROLLER INFORMATION

Generative Intellectual ("Company", "we", "us", or "our") operates digital platforms, client command portals, strategic whitepapers, proprietary AI infrastructure, and creative brand engineering services. We are dedicated to ensuring the sovereignty, privacy, and confidentiality of personal data entrusted to us by clients, practitioners, partners, and platform visitors.

This Privacy Policy establishes our practices regarding the collection, handling, storage, retention, transfer, disclosure, and deletion of personal data when you interact with our websites, complete onboarding questionnaires, authenticate into client portals, execute service agreements, download project deliverables, or engage our strategic advisory services.

For the purposes of the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the UK Data Protection Act 2018, and applicable United States privacy statutes (including the California Consumer Privacy Act as amended by the California Privacy Rights Act - "CCPA/CPRA"), the designated Data Controller / Business entity is:

Entity: Generative Intellectual Group

Privacy & Compliance Desk: privacy@generativeintellectual.com

2. STATUTORY SCOPE & APPLICABLE LEGAL FRAMEWORKS

Our data processing practices are established to comply with applicable global privacy and data protection standards, including:

  • European Union General Data Protection Regulation (EU GDPR) and UK GDPR.
  • California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) (Cal. Civ. Code § 1798.100 et seq.).
  • United States State Privacy Laws, including the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and Utah Consumer Privacy Act (UCPA).
  • United States Electronic Communications Privacy Act (ECPA) and Federal Trade Commission Act (§ 5).
  • Electronic Signatures in Global and National Commerce Act (ESIGN) (15 U.S.C. § 7001 et seq.) and Uniform Electronic Transactions Act (UETA).

3. CATEGORIES OF PERSONAL DATA COLLECTED

We adhere to the principle of data minimization. We only collect personal data necessary to establish accounts, execute agreements, deliver contracted services, maintain account security, and fulfill client deliverables.

3.1 Identity and Contact Data

Full legal name, business entity name, professional title, primary email address, business telephone number, billing address, company website, and physical jurisdiction.

3.2 Account and Authentication Credentials

Account username/email, secure login credentials, temporary access passcodes, verification tokens, and session state identifiers.

3.3 Business Intake and Project Specifications Data

Information submitted via our onboarding intake questionnaires (Business Intake and Practitioner Intake), including target audience details, brand preferences, color palettes, typography choices, feature selections, booking integrations, disclaimer texts, and strategic project goals.

3.4 Contractual and Electronic Signature Data

Executed service agreements, typed signature names, legal consent confirmations, agreement version identifiers, remote IP addresses, timestamped execution events, and electronic signature audit records.

3.5 Technical, Network, and Diagnostic Data

Internet Protocol (IP) addresses, browser type and version, operating system, device identifiers, referral URLs, access timestamps, asset download records, and system logs maintained for diagnostic and operational security purposes.

3.6 Commercial and Billing Data

Service tier selections, contracted milestone fees, payment terms, invoice transaction statuses, milestone acceptance logs, subscription renewal records, and revision hour utilization records. We do not store raw payment card numbers or card security codes; all payment transactions and recurring subscriptions are processed securely through certified PCI-DSS Level 1 compliant payment processing gateways utilizing encrypted tokenization.

4. LAWFUL BASES FOR PROCESSING UNDER GDPR

In accordance with Article 6 of the EU GDPR, we process personal data exclusively under the following recognized legal grounds:

  • Contractual Performance (Art. 6(1)(b)): Processing necessary to execute service agreements, build custom web architectures, provision client accounts, deliver project milestones, and fulfill onboarding requests.
  • Legal Compliance (Art. 6(1)(c)): Processing required to maintain statutory financial records, fulfill tax obligations, verify electronic signature legal validity, and respond to lawful regulatory inquiries.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for our legitimate commercial interests, including operational monitoring, preventing unauthorized platform misuse, and safeguarding intellectual property assets, provided such interests are not overridden by your fundamental rights.
  • Explicit Consent (Art. 6(1)(a)): Processing based on affirmative consent, such as opting into direct communications, which may be withdrawn at any time.

5. DATA SECURITY & PROTECTION SAFEGUARDS

Generative Intellectual maintains appropriate and commercially reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure.

Access to personal information is strictly restricted to authorized personnel, contractors, and sub-processors who require access to fulfill legitimate business and contractual duties, all of whom are subject to binding confidentiality obligations.

6. DATA RETENTION AND DISPOSAL SCHEDULES

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, auditing, and contractual requirements:

  • Active Client Accounts & Intake Records: Retained throughout the duration of the active service relationship and up to seven (7) years following contract conclusion to satisfy commercial and statutory recordkeeping requirements.
  • Executed Legal Agreements & E-Sign Records: Retained for ten (10) years following contract fulfillment to maintain evidentiary integrity under commercial law.
  • Deliverable Staging Files: Stored for the active project milestone duration plus a minimum of ninety (90) days following formal milestone acceptance.
  • System Access & Diagnostic Logs: Automatically rotated and purged after ninety (90) days, unless retained for ongoing incident review.

Upon expiration of the applicable retention window, personal data is either securely deleted or irreversibly de-identified in accordance with standard data management procedures.

7. SUB-PROCESSORS AND INTERNATIONAL DATA TRANSFERS

We do not sell personal data. We disclose personal information only to vetted third-party service providers (sub-processors) strictly necessary to operate our services:

  • Cloud Infrastructure Providers: Secure hosting and computing infrastructure.
  • Transactional Email Dispatchers: Communications services for sending account passcodes, agreement notifications, and milestone receipts.
  • Payment Processors: Certified PCI-DSS Level 1 compliant gateways for processing one-time invoices and recurring subscription transactions.

Where data is transferred internationally outside the European Economic Area (EEA) or the United Kingdom, we implement recognized contractual safeguards, including the European Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.

8. ZERO DATA SALE & SHARING DECLARATION (CCPA / CPRA)

EXPLICIT STATUTORY NOTICE

Generative Intellectual does not sell, rent, lease, or trade personal data to third parties for monetary compensation. Furthermore, we do not share personal data for cross-context behavioral advertising. We have not sold or shared any consumer personal information in the preceding twelve (12) months.

9. DATA SUBJECT RIGHTS UNDER EU/UK GDPR

If you are a resident of the European Economic Area or the United Kingdom, you possess the following statutory rights under the GDPR:

  • Right of Access (Art. 15): You have the right to obtain confirmation as to whether your personal data is being processed and receive a structured copy of that data.
  • Right to Rectification (Art. 16): You have the right to request immediate correction of inaccurate or incomplete personal records. Clients may directly update intake data via their portal dashboard.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): You may request the deletion of your personal data where it is no longer necessary for the original collection purposes, subject to statutory recordkeeping obligations.
  • Right to Restriction of Processing (Art. 18): You may request that we suspend processing your data under specific contestation circumstances.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON standard) or have it transferred directly to another controller.
  • Right to Object (Art. 21): You may object at any time to the processing of your data based on legitimate interests.
  • Right to Lodge a Complaint: You have the right to file a complaint with your local EU Data Protection Authority (DPA) or the UK Information Commissioner's Office (ICO).

10. CONSUMER RIGHTS UNDER US STATE PRIVACY LAWS (CCPA/CPRA)

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or other US states with applicable comprehensive privacy statutes, you are entitled to the following rights:

  • Right to Know / Access: Request disclosure of the specific pieces and categories of personal information collected, sources, purposes, and third parties to whom data is disclosed.
  • Right to Delete: Request deletion of personal information collected from you, subject to statutory exceptions.
  • Right to Correct: Request correction of inaccurate personal information maintained about you.
  • Right to Limit Sensitive Data: Request limitations on the use and disclosure of sensitive personal information. We only use sensitive data as strictly necessary to provide requested services.
  • Right to Non-Discrimination: We will never discriminate against you, alter service rates, or deny access for exercising any statutory privacy rights.

11. COOKIES, SESSION TOKENS, AND LOCAL STORAGE

Our platform utilizes strictly necessary session cookies and authentication tokens to verify user sessions, secure portal access, and remember user interface preferences (such as dark mode vs. light mode). We do not deploy non-essential third-party advertising cookies or cross-site tracking scripts. You may configure your browser to reject cookies, though authenticated client portal features may cease to function correctly.

12. CHILDREN'S PRIVACY (COPPA COMPLIANCE)

Our platforms, services, and client command portals are exclusively designed for enterprise organizations, commercial entities, and adult professionals. We do not knowingly collect or solicit personal information from individuals under eighteen (18) years of age. If we discover that personal data of a minor has been submitted, we will take immediate steps to delete the record.

13. EXERCISING YOUR PRIVACY RIGHTS & CONTACT

To exercise any of your statutory rights under GDPR or US State Privacy Laws, or to submit questions regarding our privacy practices, you may submit a request through our compliance channels:

Email: privacy@generativeintellectual.com

Subject Line: Statutory Data Privacy Request [GDPR / CCPA]

Verification: Requests will be verified against registered account credentials to prevent unauthorized disclosure.

Response Timeline: Within thirty (30) days for GDPR requests and forty-five (45) days for CCPA/CPRA requests.

We may periodically update this Privacy Policy to reflect evolving regulatory frameworks or service updates. Updates will be published on this page with an updated effective timestamp.