Privacy Policy

Last Updated: May 26, 2026 Effective Date: May 26, 2026 Version: 1.0

At a Glance

This policy explains how Genware collects, uses, and protects information about visitors to genware.com. The short version:
  • We do not sell your personal information for monetary or other valuable consideration.
  • We do not share your personal information for cross-context behavioral advertising.
  • We use only essential, technically necessary storage on our website. We do not currently deploy analytics, advertising, or marketing tracking technologies on genware.com.
  • We honor the Global Privacy Control (GPC) browser signal as a valid opt-out under California and other applicable U.S. state laws.
  • You have rights to access, correct, delete, and port your information. Section 11 explains how to exercise them.
This summary is for orientation only and does not replace the full policy below.

1. Who We Are and Scope of This Policy

This policy is issued by Genware (“Genware,” “we,” “us,” or “our”), an AI and advanced analytics consulting firm headquartered in Boise, Idaho, United States. This policy applies to information collected through genware.com and its subdomains (the “Website”). It does not apply to:
  • Personal data processed under our client service agreements (governed by separate Data Processing Agreements with our enterprise clients);
  • Personal data of Genware employees and job candidates (governed by separate employee notices);
  • Third-party websites that we link to but do not operate.

1.1 Data Controller

The data controller for information collected through the Website is: Genware 176 S. Capital Blvd Boise, Idaho 83702 United States hello@genware.com For visitors located in the European Economic Area or the United Kingdom, see Section 16 for EU/UK-specific information.

1.2 Contact for Privacy Matters

Email: hello@genware.com Mail: 176 S. Capital Blvd, Boise, Idaho 83702, United States

2. Information We Collect

We collect information in two ways: (a) directly from you when you provide it; and (b) automatically in limited ways when you use the Website.

2.1 Information You Provide

When you contact us through a form, email, or phone on the Website, you provide:
  • Identifiers — name, work email address, telephone number, employer name, job title;
  • Communication content — the contents of your message or inquiry.
If you apply for a position at Genware through the Website:
  • Career-related information — résumé/CV, work history, location, and other professional details you choose to share.

2.2 Information Collected Automatically

When you visit the Website, the following limited information is collected automatically through server logs and technically necessary site mechanisms:
  • Internet activity — IP address, browser type and version, operating system, referring URL, pages viewed, and time of visit (captured in server access logs);
  • Approximate geolocation — derived from IP address (typically resolves to city or region, not precise location).
We do not currently deploy analytics platforms, advertising pixels, or behavioral tracking technologies on genware.com. No cookies are set on initial page load. See Section 4 for the full cookie and storage inventory.

2.3 Categories under California Law

For California residents, the categories of personal information collected through the Website during the past 12 months map to the categories enumerated in Cal. Civ. Code §1798.140(v) as follows:
CCPA Category Examples Collected Collected?
(A) Identifiers Name, email, phone, IP address Yes — from forms and server logs
(B) Customer records (Cal. Civ. Code §1798.80) Business contact details from forms Yes — from forms only
(C) Protected classification characteristics EEO data Limited — career forms only, if applicable
(D) Commercial information Records of services inquired about Yes — from forms
(E) Biometric information Not collected No
(F) Internet activity Server log data from our Website Yes — server logs only; no behavioral tracking
(G) Geolocation (precise) Not collected. Only city/region from IP. No (precise)
(H) Sensory data Not collected No
(I) Professional information Employer, title, professional history (career form) Limited — career forms only
(J) Education information From résumé/CV Limited — career forms only
(K) Inferences Not generated — no analytics platform deployed No
(L) Sensitive personal information See Section 2.4 See 2.4

2.4 Sensitive Personal Information

We do not knowingly collect sensitive personal information (as defined under CCPA/CPRA) through the Website. We do not collect government-issued identifiers, financial account information, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, mail/email/text contents not directed to us, genetic data, biometric data, health data, or sexual orientation/sex life information through the Website. If sensitive personal information is incidentally provided to us in a free-form message field, we use it only to respond to the inquiry and we do not retain it longer than necessary for that purpose.

3. How We Use Information

We use information for the following purposes. The right column states the legal basis under the EU/UK GDPR. The same purposes apply to other jurisdictions, with the legal basis adapted under local law.
Purpose GDPR Legal Basis
Operate, maintain, and secure the Website Legitimate interests (Art. 6(1)(f))
Respond to inquiries submitted through forms or email Performance of pre-contractual measures (Art. 6(1)(b)) or legitimate interests
Process job applications submitted through the careers form Pre-contractual measures (Art. 6(1)(b))
Conduct B2B sales outreach in a professional capacity Legitimate interests (Art. 6(1)(f)), subject to opt-out
Comply with legal obligations and respond to lawful requests Legal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claims Legitimate interests (Art. 6(1)(f))

4. Cookies and Tracking Technologies

4.1 Current State

Genware does not currently deploy analytics, marketing, or advertising tracking technologies on genware.com. No cookies are set on your initial page load. No third-party tracking pixels or scripts are loaded when you visit the Website.

4.2 Technically Necessary Storage

The following technically necessary items may be present. None require consent under applicable ePrivacy rules because they are strictly essential to site function.
Storage Item Source Purpose Category Retention
wpEmojiSettingsSupports WordPress (first-party) Browser emoji feature detection — allows WordPress to decide which emoji format to serve. No personal data transmitted to third parties. Strictly Necessary Session only (cleared on tab close)
cf-ray, cf-cache-status (response headers) Cloudflare Edge content delivery and bot management. Cloudflare operates as a network infrastructure provider, not a third-party data processor for behavioral purposes. Strictly Necessary / Infrastructure Not stored client-side

4.3 No Consent Banner Required — Current State

Because we do not deploy non-essential cookies or tracking technologies, a cookie consent banner is not currently required under the ePrivacy Directive, PECR (UK), or U.S. state cookie laws. If we add non-essential cookies or tracking technologies in the future, we will deploy a consent management platform and update this section before those technologies go live.

4.4 Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of “sale” and “sharing” under California, Colorado, Connecticut, and other U.S. state laws that recognize it. Because we do not sell or share personal information, GPC signals will not change data processing behavior on our site — but we will treat any inbound GPC signal as an opt-out preference on record.

4.5 Your Cookie Choices

Browser controls. All major browsers allow you to block or delete cookies from settings. Because we do not set non-essential cookies, standard browser settings give you full control over the technically necessary storage items listed in Section 4.2. Contact us. If you have questions about tracking practices on the Website, contact us at hello@genware.com.

5. How We Share Information

We disclose information only in the limited circumstances below. We do not sell information to data brokers, and we do not share it for cross-context behavioral advertising.

5.1 Service Providers and Processors

We share information with vendors that process information on our behalf and are contractually limited to the purposes we specify. Current service providers that may receive information in connection with the Website include:
Service Provider Function Location
WP Engine, Inc. Managed WordPress hosting — Website is served from WP Engine infrastructure United States
Cloudflare, Inc. Edge content delivery, DDoS protection, bot management United States / Global
HubSpot, Inc. CRM and contact form processing — form submissions from the Website are received and stored in HubSpot United States / EU

5.2 Legal and Compliance

We may disclose information when required to comply with applicable law, lawful court orders or governmental requests, to enforce our terms, or to protect the rights, property, or safety of Genware, our clients, or others.

5.3 Business Transactions

In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our business or assets, information may be transferred to the relevant counterparty subject to confidentiality protections and continued application of the protections in this policy (or equivalent protections).

5.4 With Your Consent

We share information for any other purpose only with your consent.

6. Sale and Sharing Disclosure

We do not sell your personal information for monetary or other valuable consideration. We do not share your personal information for cross-context behavioral advertising as that term is defined in Cal. Civ. Code §1798.140(ah). We have not sold or shared personal information of any consumer in the preceding 12 months. We do not knowingly sell or share personal information of consumers under the age of 16. Notwithstanding the above, you may exercise the right to opt out of “sale” and “sharing” at any time by contacting us at hello@genware.com, by setting the Global Privacy Control browser signal (Section 4.4), or by using the contact methods in Section 15. We will treat the request as effective even though we currently do not engage in conduct that would otherwise require an opt-out mechanism.

7. International Data Transfers

Our Website and primary infrastructure are located in the United States. If you visit from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer requirements, your information will be transferred to and processed in the United States. Our key service providers each offer Data Processing Agreements (DPAs) with Standard Contractual Clauses:
  • WP Engine — DPA with SCCs (Module 2 controller-to-processor) available at wpengine.com/legal/dpa/
  • HubSpot — DPA with SCCs and UK Addendum available at legal.hubspot.com/dpa
  • Cloudflare — DPA with SCCs available at cloudflare.com/cloudflare-customer-dpa/

7.1 Transfers from the EU/EEA

For transfers of personal data from the European Economic Area to recipients in the United States, we rely on the European Commission’s Standard Contractual Clauses (Module 2 controller-to-processor) entered into with WP Engine, HubSpot, and Cloudflare, supplemented by technical safeguards including encryption in transit and at rest.

7.2 Transfers from the United Kingdom

For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or the Standard Contractual Clauses with the UK Addendum, as appropriate. WP Engine, HubSpot, and Cloudflare each offer UK Addenda to their standard DPAs.

7.3 Transfers from Other Jurisdictions

For visitors from Canada, Brazil, Australia, and other jurisdictions with cross-border transfer rules, we rely on the legal mechanisms recognized by the applicable law (typically contractual safeguards equivalent to Standard Contractual Clauses) with our service providers.

8. Data Retention

We retain personal information only for as long as needed for the purposes described in this policy, plus a reasonable period to comply with our legal obligations, resolve disputes, and enforce our agreements.
Data Type Retention Rationale
Contact / inquiry form submissions Up to 7 years Sales-cycle and statute-of-limitations alignment
Career applications (not hired) Up to 2 years Future opportunities; applicable recordkeeping requirements
Server access logs (IP, referrer, user-agent) 90 days Security investigation and abuse prevention
Technically necessary session storage (wpEmojiSettingsSupports) Session only Cleared automatically on browser tab close; no personal data retained

9. Information Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS 1.2+), encryption of data at rest where applicable, role-based access controls, and regular security reviews. No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach affecting your information, we will notify you and the relevant supervisory authorities to the extent required by applicable law.

10. Children’s Privacy

The Website is intended for business audiences and is not directed to children. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with information, please contact us at hello@genware.com and we will delete it.

11. Your Privacy Rights

Your privacy rights depend on where you live. The table below summarizes the rights we recognize. Section 11.5 explains how to exercise them.
Jurisdiction Rights Recognized Authority
California (US) Know, access, delete, correct, portability, opt out of sale/sharing, limit use of sensitive PI, non-discrimination CCPA / CPRA
Other U.S. states Access, delete, correct, portability, opt out of sale/targeted advertising/profiling, appeal denials VA, CO, CT, UT, TX, TN, FL, OR, MT, IA, DE, NJ, IN, NH, MN, MD, KY, RI
EU / EEA Access, rectification, erasure, restriction, portability, object, withdraw consent, complaint to supervisory authority GDPR Art. 15–22
United Kingdom Same as EU/EEA UK GDPR / DPA 2018
Canada Access, correction, withdrawal of consent PIPEDA, Quebec Law 25
Other jurisdictions Rights granted by your local law — contact us and we will respond consistent with applicable law Various

11.1 California (CCPA/CPRA) — Specific Notes

California residents have the right to non-discrimination for exercising any privacy right. We will not deny services, charge different prices, or provide a different level of service because you exercised a right. We do not offer financial incentives in exchange for personal information. Authorized agents. California residents may designate an authorized agent to make requests. We will require proof of authorization (for example, a written, signed permission). Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes other than those specified in Cal. Civ. Code §1798.121(a). The “Limit the Use of My Sensitive Personal Information” link is not required because we do not use sensitive personal information for cross-context behavioral advertising or other purposes that trigger that right.

11.2 EU/UK — Specific Notes

You have the right to lodge a complaint with the supervisory authority in your member state of residence, place of work, or place of the alleged infringement. For the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO) — ico.org.uk. For EU/EEA residents, the relevant supervisory authority is the data protection authority in your member state.

11.3 GPC and Do Not Track

We honor the Global Privacy Control (GPC) browser signal as described in Section 4.4. We do not respond to Do Not Track (DNT) browser signals, which are a separate and non-standardized mechanism.

11.5 How to Exercise Your Rights

You may submit a privacy request through any of the following methods:
  • Email: hello@genware.com (subject line: “Privacy Request”)
  • Postal mail: 176 S. Capital Blvd, Boise, Idaho 83702, United States
We will respond within the timeframe required by applicable law (typically 45 days for CCPA, with one 45-day extension if reasonably necessary; one month for GDPR, with up to two additional months if necessary). We may need to verify your identity. We do not require account creation to submit a privacy request. If we deny your request in whole or in part, you have the right to appeal under several U.S. state laws (Virginia, Colorado, Connecticut, and others). Appeals may be submitted to the same contact above with the subject line “Privacy Appeal.”

12. Automated Decision-Making

We do not engage in automated decision-making that produces legal effects or similarly significant effects on you based on data collected through the Website.

13. Third-Party Links and Services

The Website may contain links to third-party websites and services. This policy does not apply to those third parties. We encourage you to read their privacy notices.

14. Changes to This Policy

We will update this policy when our practices change or when required by law. Material changes will be communicated by posting a prominent notice on the Website at least 14 days before the change takes effect, and where required by law we will obtain renewed consent. The “Last Updated” date at the top of the policy will reflect the most recent change. A history of prior versions is maintained internally and is available on request by contacting hello@genware.com. Important: If Genware adds analytics, advertising pixels, or any other non-essential tracking technology to the Website, this policy must be updated and a cookie consent management platform must be deployed before those technologies are activated.

15. How to Contact Us

General privacy inquiries hello@genware.com
Mailing address 176 S. Capital Blvd, Boise, Idaho 83702, United States
Supervisory authority (UK) Information Commissioner’s Office · ico.org.uk
Supervisory authority (EU) Your local EU member state data protection authority

16. Region-Specific Notices

16.1 California Notice at Collection

This policy serves as our “Notice at Collection” under Cal. Civ. Code §1798.100. The categories of personal information we collect are listed in Section 2.3. The purposes are described in Section 3. We do not sell or share personal information for cross-context behavioral advertising. Retention periods for each category are described in Section 8.

16.2 EU/UK Specific Information

The legal bases for processing are stated in Section 3. International transfer mechanisms are described in Section 7. You have the right to lodge a complaint with your local supervisory authority (see Section 11.2 and Section 15).

17. Definitions

Term Definition
Personal information / personal data Information that identifies, relates to, describes, or could reasonably be linked to a particular consumer or household (CCPA), or any information relating to an identified or identifiable natural person (GDPR/UK GDPR).
Sale The disclosure of personal information to a third party for monetary or other valuable consideration, as defined in Cal. Civ. Code §1798.140(ad). We do not sell.
Share Disclosure of personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, as defined in Cal. Civ. Code §1798.140(ah). We do not share.
Service provider / processor An entity that processes personal information on behalf of a business under a written contract that limits the entity’s use of the information to the business’s specified purposes.
Cookie A small data file stored in your browser when you visit a website. Includes similar technologies such as pixels, web beacons, local storage, and server-side tags.
Cross-context behavioral advertising Targeted advertising based on personal information obtained from a consumer’s activity across businesses, distinctly-branded websites, applications, or services other than the business with which the consumer intentionally interacts.
Sensitive personal information Categories defined in Cal. Civ. Code §1798.140(ae), including government identifiers, financial account information, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health data, biometric data, and genetic data.
Global Privacy Control (GPC) A browser-level signal that communicates a consumer’s choice to opt out of the sale and sharing of personal information. We honor GPC as a valid opt-out where applicable law recognizes it.
Questions? Contact hello@genware.com.