Last Updated: May 26, 2026
Effective Date: May 26, 2026
Version: 1.0
At a Glance
This policy explains how Genware collects, uses, and protects information about visitors to genware.com. The short version:
- We do not sell your personal information for monetary or other valuable consideration.
- We do not share your personal information for cross-context behavioral advertising.
- We use only essential, technically necessary storage on our website. We do not currently deploy analytics, advertising, or marketing tracking technologies on genware.com.
- We honor the Global Privacy Control (GPC) browser signal as a valid opt-out under California and other applicable U.S. state laws.
- You have rights to access, correct, delete, and port your information. Section 11 explains how to exercise them.
This summary is for orientation only and does not replace the full policy below.
1. Who We Are and Scope of This Policy
This policy is issued by
Genware (“Genware,” “we,” “us,” or “our”), an AI and advanced analytics consulting firm headquartered in Boise, Idaho, United States.
This policy applies to information collected through
genware.com and its subdomains (the “Website”). It does not apply to:
- Personal data processed under our client service agreements (governed by separate Data Processing Agreements with our enterprise clients);
- Personal data of Genware employees and job candidates (governed by separate employee notices);
- Third-party websites that we link to but do not operate.
1.1 Data Controller
The data controller for information collected through the Website is:
Genware
176 S. Capital Blvd
Boise, Idaho 83702
United States
hello@genware.com
For visitors located in the European Economic Area or the United Kingdom, see Section 16 for EU/UK-specific information.
1.2 Contact for Privacy Matters
Email: hello@genware.com
Mail: 176 S. Capital Blvd, Boise, Idaho 83702, United States
2. Information We Collect
We collect information in two ways: (a) directly from you when you provide it; and (b) automatically in limited ways when you use the Website.
2.1 Information You Provide
When you contact us through a form, email, or phone on the Website, you provide:
- Identifiers — name, work email address, telephone number, employer name, job title;
- Communication content — the contents of your message or inquiry.
If you apply for a position at Genware through the Website:
- Career-related information — résumé/CV, work history, location, and other professional details you choose to share.
2.2 Information Collected Automatically
When you visit the Website, the following limited information is collected automatically through server logs and technically necessary site mechanisms:
- Internet activity — IP address, browser type and version, operating system, referring URL, pages viewed, and time of visit (captured in server access logs);
- Approximate geolocation — derived from IP address (typically resolves to city or region, not precise location).
We do not currently deploy analytics platforms, advertising pixels, or behavioral tracking technologies on genware.com. No cookies are set on initial page load. See Section 4 for the full cookie and storage inventory.
2.3 Categories under California Law
For California residents, the categories of personal information collected through the Website during the past 12 months map to the categories enumerated in Cal. Civ. Code §1798.140(v) as follows:
| CCPA Category |
Examples Collected |
Collected? |
| (A) Identifiers |
Name, email, phone, IP address |
Yes — from forms and server logs |
| (B) Customer records (Cal. Civ. Code §1798.80) |
Business contact details from forms |
Yes — from forms only |
| (C) Protected classification characteristics |
EEO data |
Limited — career forms only, if applicable |
| (D) Commercial information |
Records of services inquired about |
Yes — from forms |
| (E) Biometric information |
Not collected |
No |
| (F) Internet activity |
Server log data from our Website |
Yes — server logs only; no behavioral tracking |
| (G) Geolocation (precise) |
Not collected. Only city/region from IP. |
No (precise) |
| (H) Sensory data |
Not collected |
No |
| (I) Professional information |
Employer, title, professional history (career form) |
Limited — career forms only |
| (J) Education information |
From résumé/CV |
Limited — career forms only |
| (K) Inferences |
Not generated — no analytics platform deployed |
No |
| (L) Sensitive personal information |
See Section 2.4 |
See 2.4 |
2.4 Sensitive Personal Information
We do not knowingly collect sensitive personal information (as defined under CCPA/CPRA) through the Website. We do not collect government-issued identifiers, financial account information, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, mail/email/text contents not directed to us, genetic data, biometric data, health data, or sexual orientation/sex life information through the Website.
If sensitive personal information is incidentally provided to us in a free-form message field, we use it only to respond to the inquiry and we do not retain it longer than necessary for that purpose.
3. How We Use Information
We use information for the following purposes. The right column states the legal basis under the EU/UK GDPR. The same purposes apply to other jurisdictions, with the legal basis adapted under local law.
| Purpose |
GDPR Legal Basis |
| Operate, maintain, and secure the Website |
Legitimate interests (Art. 6(1)(f)) |
| Respond to inquiries submitted through forms or email |
Performance of pre-contractual measures (Art. 6(1)(b)) or legitimate interests |
| Process job applications submitted through the careers form |
Pre-contractual measures (Art. 6(1)(b)) |
| Conduct B2B sales outreach in a professional capacity |
Legitimate interests (Art. 6(1)(f)), subject to opt-out |
| Comply with legal obligations and respond to lawful requests |
Legal obligation (Art. 6(1)(c)) |
| Establish, exercise, or defend legal claims |
Legitimate interests (Art. 6(1)(f)) |
4. Cookies and Tracking Technologies
4.1 Current State
Genware does not currently deploy analytics, marketing, or advertising tracking technologies on genware.com. No cookies are set on your initial page load. No third-party tracking pixels or scripts are loaded when you visit the Website.
4.2 Technically Necessary Storage
The following technically necessary items may be present. None require consent under applicable ePrivacy rules because they are strictly essential to site function.
| Storage Item |
Source |
Purpose |
Category |
Retention |
| wpEmojiSettingsSupports |
WordPress (first-party) |
Browser emoji feature detection — allows WordPress to decide which emoji format to serve. No personal data transmitted to third parties. |
Strictly Necessary |
Session only (cleared on tab close) |
| cf-ray, cf-cache-status (response headers) |
Cloudflare |
Edge content delivery and bot management. Cloudflare operates as a network infrastructure provider, not a third-party data processor for behavioral purposes. |
Strictly Necessary / Infrastructure |
Not stored client-side |
4.3 No Consent Banner Required — Current State
Because we do not deploy non-essential cookies or tracking technologies, a cookie consent banner is not currently required under the ePrivacy Directive, PECR (UK), or U.S. state cookie laws. If we add non-essential cookies or tracking technologies in the future, we will deploy a consent management platform and update this section before those technologies go live.
4.4 Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of “sale” and “sharing” under California, Colorado, Connecticut, and other U.S. state laws that recognize it. Because we do not sell or share personal information, GPC signals will not change data processing behavior on our site — but we will treat any inbound GPC signal as an opt-out preference on record.
4.5 Your Cookie Choices
Browser controls. All major browsers allow you to block or delete cookies from settings. Because we do not set non-essential cookies, standard browser settings give you full control over the technically necessary storage items listed in Section 4.2.
Contact us. If you have questions about tracking practices on the Website, contact us at
hello@genware.com.
5. How We Share Information
We disclose information only in the limited circumstances below. We do not sell information to data brokers, and we do not share it for cross-context behavioral advertising.
5.1 Service Providers and Processors
We share information with vendors that process information on our behalf and are contractually limited to the purposes we specify. Current service providers that may receive information in connection with the Website include:
| Service Provider |
Function |
Location |
| WP Engine, Inc. |
Managed WordPress hosting — Website is served from WP Engine infrastructure |
United States |
| Cloudflare, Inc. |
Edge content delivery, DDoS protection, bot management |
United States / Global |
| HubSpot, Inc. |
CRM and contact form processing — form submissions from the Website are received and stored in HubSpot |
United States / EU |
5.2 Legal and Compliance
We may disclose information when required to comply with applicable law, lawful court orders or governmental requests, to enforce our terms, or to protect the rights, property, or safety of Genware, our clients, or others.
5.3 Business Transactions
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our business or assets, information may be transferred to the relevant counterparty subject to confidentiality protections and continued application of the protections in this policy (or equivalent protections).
5.4 With Your Consent
We share information for any other purpose only with your consent.
6. Sale and Sharing Disclosure
We do not sell your personal information for monetary or other valuable consideration. We do not share your personal information for cross-context behavioral advertising as that term is defined in Cal. Civ. Code §1798.140(ah). We have not sold or shared personal information of any consumer in the preceding 12 months.
We do not knowingly sell or share personal information of consumers under the age of 16.
Notwithstanding the above, you may exercise the right to opt out of “sale” and “sharing” at any time by contacting us at
hello@genware.com, by setting the Global Privacy Control browser signal (Section 4.4), or by using the contact methods in Section 15. We will treat the request as effective even though we currently do not engage in conduct that would otherwise require an opt-out mechanism.
7. International Data Transfers
Our Website and primary infrastructure are located in the United States. If you visit from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer requirements, your information will be transferred to and processed in the United States.
Our key service providers each offer Data Processing Agreements (DPAs) with Standard Contractual Clauses:
- WP Engine — DPA with SCCs (Module 2 controller-to-processor) available at wpengine.com/legal/dpa/
- HubSpot — DPA with SCCs and UK Addendum available at legal.hubspot.com/dpa
- Cloudflare — DPA with SCCs available at cloudflare.com/cloudflare-customer-dpa/
7.1 Transfers from the EU/EEA
For transfers of personal data from the European Economic Area to recipients in the United States, we rely on the European Commission’s Standard Contractual Clauses (Module 2 controller-to-processor) entered into with WP Engine, HubSpot, and Cloudflare, supplemented by technical safeguards including encryption in transit and at rest.
7.2 Transfers from the United Kingdom
For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or the Standard Contractual Clauses with the UK Addendum, as appropriate. WP Engine, HubSpot, and Cloudflare each offer UK Addenda to their standard DPAs.
7.3 Transfers from Other Jurisdictions
For visitors from Canada, Brazil, Australia, and other jurisdictions with cross-border transfer rules, we rely on the legal mechanisms recognized by the applicable law (typically contractual safeguards equivalent to Standard Contractual Clauses) with our service providers.
8. Data Retention
We retain personal information only for as long as needed for the purposes described in this policy, plus a reasonable period to comply with our legal obligations, resolve disputes, and enforce our agreements.
| Data Type |
Retention |
Rationale |
| Contact / inquiry form submissions |
Up to 7 years |
Sales-cycle and statute-of-limitations alignment |
| Career applications (not hired) |
Up to 2 years |
Future opportunities; applicable recordkeeping requirements |
| Server access logs (IP, referrer, user-agent) |
90 days |
Security investigation and abuse prevention |
| Technically necessary session storage (wpEmojiSettingsSupports) |
Session only |
Cleared automatically on browser tab close; no personal data retained |
9. Information Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption of data in transit (TLS 1.2+), encryption of data at rest where applicable, role-based access controls, and regular security reviews.
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach affecting your information, we will notify you and the relevant supervisory authorities to the extent required by applicable law.
10. Children’s Privacy
The Website is intended for business audiences and is not directed to children. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with information, please contact us at
hello@genware.com and we will delete it.
11. Your Privacy Rights
Your privacy rights depend on where you live. The table below summarizes the rights we recognize. Section 11.5 explains how to exercise them.
| Jurisdiction |
Rights Recognized |
Authority |
| California (US) |
Know, access, delete, correct, portability, opt out of sale/sharing, limit use of sensitive PI, non-discrimination |
CCPA / CPRA |
| Other U.S. states |
Access, delete, correct, portability, opt out of sale/targeted advertising/profiling, appeal denials |
VA, CO, CT, UT, TX, TN, FL, OR, MT, IA, DE, NJ, IN, NH, MN, MD, KY, RI |
| EU / EEA |
Access, rectification, erasure, restriction, portability, object, withdraw consent, complaint to supervisory authority |
GDPR Art. 15–22 |
| United Kingdom |
Same as EU/EEA |
UK GDPR / DPA 2018 |
| Canada |
Access, correction, withdrawal of consent |
PIPEDA, Quebec Law 25 |
| Other jurisdictions |
Rights granted by your local law — contact us and we will respond consistent with applicable law |
Various |
11.1 California (CCPA/CPRA) — Specific Notes
California residents have the right to non-discrimination for exercising any privacy right. We will not deny services, charge different prices, or provide a different level of service because you exercised a right. We do not offer financial incentives in exchange for personal information.
Authorized agents. California residents may designate an authorized agent to make requests. We will require proof of authorization (for example, a written, signed permission).
Sensitive Personal Information. We do not use or disclose sensitive personal information for purposes other than those specified in Cal. Civ. Code §1798.121(a). The “Limit the Use of My Sensitive Personal Information” link is not required because we do not use sensitive personal information for cross-context behavioral advertising or other purposes that trigger that right.
11.2 EU/UK — Specific Notes
You have the right to lodge a complaint with the supervisory authority in your member state of residence, place of work, or place of the alleged infringement.
For the
United Kingdom, the supervisory authority is the
Information Commissioner’s Office (ICO) — ico.org.uk.
For
EU/EEA residents, the relevant supervisory authority is the data protection authority in your member state.
11.3 GPC and Do Not Track
We honor the Global Privacy Control (GPC) browser signal as described in Section 4.4. We do not respond to Do Not Track (DNT) browser signals, which are a separate and non-standardized mechanism.
11.5 How to Exercise Your Rights
You may submit a privacy request through any of the following methods:
- Email: hello@genware.com (subject line: “Privacy Request”)
- Postal mail: 176 S. Capital Blvd, Boise, Idaho 83702, United States
We will respond within the timeframe required by applicable law (typically 45 days for CCPA, with one 45-day extension if reasonably necessary; one month for GDPR, with up to two additional months if necessary). We may need to verify your identity. We do not require account creation to submit a privacy request.
If we deny your request in whole or in part, you have the right to appeal under several U.S. state laws (Virginia, Colorado, Connecticut, and others). Appeals may be submitted to the same contact above with the subject line “Privacy Appeal.”
12. Automated Decision-Making
We do not engage in automated decision-making that produces legal effects or similarly significant effects on you based on data collected through the Website.
13. Third-Party Links and Services
The Website may contain links to third-party websites and services. This policy does not apply to those third parties. We encourage you to read their privacy notices.
14. Changes to This Policy
We will update this policy when our practices change or when required by law. Material changes will be communicated by posting a prominent notice on the Website at least 14 days before the change takes effect, and where required by law we will obtain renewed consent. The “Last Updated” date at the top of the policy will reflect the most recent change.
A history of prior versions is maintained internally and is available on request by contacting
hello@genware.com.
Important: If Genware adds analytics, advertising pixels, or any other non-essential tracking technology to the Website, this policy must be updated and a cookie consent management platform must be deployed
before those technologies are activated.
15. How to Contact Us
| General privacy inquiries |
hello@genware.com |
| Mailing address |
176 S. Capital Blvd, Boise, Idaho 83702, United States |
| Supervisory authority (UK) |
Information Commissioner’s Office · ico.org.uk |
| Supervisory authority (EU) |
Your local EU member state data protection authority |
16. Region-Specific Notices
16.1 California Notice at Collection
This policy serves as our “Notice at Collection” under Cal. Civ. Code §1798.100. The categories of personal information we collect are listed in Section 2.3. The purposes are described in Section 3. We do not sell or share personal information for cross-context behavioral advertising. Retention periods for each category are described in Section 8.
16.2 EU/UK Specific Information
The legal bases for processing are stated in Section 3. International transfer mechanisms are described in Section 7. You have the right to lodge a complaint with your local supervisory authority (see Section 11.2 and Section 15).
17. Definitions
| Term |
Definition |
| Personal information / personal data |
Information that identifies, relates to, describes, or could reasonably be linked to a particular consumer or household (CCPA), or any information relating to an identified or identifiable natural person (GDPR/UK GDPR). |
| Sale |
The disclosure of personal information to a third party for monetary or other valuable consideration, as defined in Cal. Civ. Code §1798.140(ad). We do not sell. |
| Share |
Disclosure of personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, as defined in Cal. Civ. Code §1798.140(ah). We do not share. |
| Service provider / processor |
An entity that processes personal information on behalf of a business under a written contract that limits the entity’s use of the information to the business’s specified purposes. |
| Cookie |
A small data file stored in your browser when you visit a website. Includes similar technologies such as pixels, web beacons, local storage, and server-side tags. |
| Cross-context behavioral advertising |
Targeted advertising based on personal information obtained from a consumer’s activity across businesses, distinctly-branded websites, applications, or services other than the business with which the consumer intentionally interacts. |
| Sensitive personal information |
Categories defined in Cal. Civ. Code §1798.140(ae), including government identifiers, financial account information, precise geolocation, racial or ethnic origin, religious beliefs, union membership, health data, biometric data, and genetic data. |
| Global Privacy Control (GPC) |
A browser-level signal that communicates a consumer’s choice to opt out of the sale and sharing of personal information. We honor GPC as a valid opt-out where applicable law recognizes it. |
Questions? Contact hello@genware.com.