GSA SOLUTIONS, LLC respects the trust that clients and visitors place in this website. This Privacy Policy explains, in plain language, what information the GSA Core advisory practice collects when you visit gsacore.buzz or engage us for services, why that information is gathered, how it is protected and the choices available to you. The policy applies to the practice operated by GSA SOLUTIONS, LLC at 3268 W Rolling Creek Way, South Jordan - 84095-9380, United States (US).
We wrote this document to be read rather than skimmed. It describes the actual handling of personal information inside a small professional services firm, without legalistic fog and without hidden exceptions. If anything here is unclear, you may reach us at billing@gsacore.buzz or by telephone at +15156428502 and we will answer directly.
1. Introduction
This Privacy Policy governs the collection and use of personal information by GSA SOLUTIONS, LLC, a professional advisory firm operating the GSA Core practice. The firm provides management consulting and public sector advisory services to agencies, sponsors and enterprises. In the ordinary course of that work we receive names, contact details, employment information and project material. We treat all of it as confidential and we hold ourselves to the standard that clients expect of an independent professional adviser.
This Policy covers the website at gsacore.buzz and the advisory engagements conducted under the GSA Core brand. It does not cover the internal practices of our clients, nor does it cover websites operated by other organisations that we might link to for reference. Where a client engages us under a written agreement that contains stricter privacy terms, those stricter terms take precedence for the project material governed by that agreement.
By using this website or by engaging our services, you acknowledge that you have read this Policy. If you do not agree with the handling described here, please do not submit personal information through the website and contact us so that we can discuss an alternative arrangement.
We believe that privacy notices should describe what a firm actually does rather than recite abstract principles. Every statement in this Policy reflects a real practice inside our office. Where we rely on a service provider, the provider is named in our internal register and bound by contract. Where we retain a record, we can explain why. If you ever find a gap between this Policy and your experience of our service, we want to hear about it, because the document only has value when it matches reality.
2. Information We Collect
We collect only the information that is necessary to respond to enquiries, deliver engagements and operate the practice responsibly. The categories are described below.
Information you provide directly
When you complete the contact form, send us an email or telephone the practice, you may provide a name, an email address, a telephone number, an organisation name, a job title and the content of your message. If you engage us, you may also provide billing details, contracting information, project documentation and the names of colleagues who will participate in the work.
Information collected automatically
When you visit the website, our hosting environment may record technical information such as the internet protocol address, the browser type, the device type, the pages viewed and the time of the visit. This information is used in aggregate to keep the website secure and available. It is not used to build advertising profiles and it is not sold.
Information from third parties
We may receive limited information about you from a colleague who refers you, from a client who introduces you as a project contact, or from a public register that identifies you as an authorised representative of an organisation. We use that information only for the purpose for which it was shared with us.
3. How Information Is Collected
Personal information reaches us through a small number of clear channels. The contact form on the website submits the details you type into the fields. Email correspondence arrives in our mailbox when you write to billing@gsacore.buzz. Telephone calls to +15156428502 may result in written notes that record the substance of the conversation. During engagements, information is collected through interviews, workshops, document reviews and the ordinary exchange of project files.
We do not employ hidden tracking pixels, cross site advertising identifiers or covert profiling scripts. Where a client requests a collaboration platform for a project, the platform is selected jointly and its own privacy terms govern the material held inside it. We document the data flows of each engagement so that both parties understand where project information resides.
4. Purposes of Processing
We process personal information for the following purposes, each of which is tied to a legitimate business need.
- Responding to enquiries submitted through the website, by email or by telephone.
- Preparing proposals, statements of work and fee estimates for prospective clients.
- Delivering advisory engagements, including research, analysis, workshops and reporting.
- Managing contracts, invoicing, payment and accounting obligations.
- Maintaining project records that support audit, quality review and continuity of service.
- Meeting legal, tax, regulatory and professional record keeping duties.
- Improving the clarity and usefulness of our own website and service descriptions.
- Sending occasional practice updates to clients and contacts who have asked to receive them.
We do not process personal information for automated decision making that produces legal effects, and we do not use personal information to train general purpose artificial intelligence models.
Each purpose is reviewed when an engagement begins and again when it closes. If a new purpose emerges during a project, we document it and confirm that a lawful basis exists before processing continues. We avoid collecting information merely because it might be useful later. Data minimisation is not a slogan for us but a practical discipline that reduces both risk and administrative cost for everyone involved.
5. Legal Bases for Processing
Where data protection law requires a legal basis, we rely on one or more of the following. We process information to perform a contract with you or to take steps at your request before entering a contract. We process information for our legitimate interests in operating a professional advisory practice, provided those interests are not overridden by your rights. We process information to comply with legal obligations such as tax and accounting rules. Where none of the above applies, we ask for your consent and you may withdraw it at any time.
When we process special category information in the course of a project, we do so only where the client has established a lawful basis and where the project genuinely requires it. In practice this is rare, and we prefer to work with aggregated or de identified material whenever the engagement allows.
Where we rely on legitimate interests, we carry out a balancing assessment that weighs the necessity of the processing against the reasonable expectations of the individuals concerned. That assessment is recorded and reviewed if circumstances change. Where we rely on consent, we make the request clear and specific, and we never bundle consent into unrelated terms or treat silence as agreement.
7. Client and Project Records
Advisory engagements generate working papers, interview notes, data extracts and draft reports. These records may contain personal information about client staff, beneficiaries or third parties. We treat such records as confidential to the engagement. Access is limited to the advisers assigned to the project and to the small number of internal personnel who support quality review and administration.
Where the client is a public agency subject to open records law, we follow the client instructions regarding disclosure and we flag any record that appears to contain information deserving protection. We do not publish engagement material, use client names in marketing or present case studies without written permission. Anonymised and aggregated lessons may be used to improve our methods, provided no individual and no client can be identified.
9. Service Providers and Processors
We rely on a small set of reputable providers for hosting, email and accounting. Each provider is chosen for competence and security, and each is bound by a written agreement that limits processing to our documented instructions. Providers are not permitted to use our information for their own marketing or to build independent profiles.
Before onboarding a provider we assess its security posture, its breach notification commitments and its approach to sub processors. We review these arrangements periodically. If a provider cannot meet our standards, we replace it rather than accept the risk.
10. International Transfers
GSA SOLUTIONS, LLC is based in the United States. Some service providers may store data in other countries. Where personal information moves across borders, we take steps to ensure it remains protected, using contractual safeguards and provider commitments that reflect recognised data protection principles.
Clients with contractual requirements about data location should raise those requirements at the start of an engagement so that we can select hosting, collaboration and storage arrangements that satisfy them. We record any agreed location restrictions in the statement of work.
11. Data Retention
We keep personal information only as long as it serves the purpose for which it was collected. Enquiry correspondence that does not lead to an engagement is generally retained for a limited period and then removed. Contract, billing and tax records are retained for the period required by applicable law and professional standards. Project working papers are retained according to the terms of the engagement and the client record keeping obligations that apply.
When a retention period ends, we delete or destroy the information in a secure manner. Where deletion is impractical because information is embedded in a permitted archive, we isolate the archive and restrict access so that the information is not used for any active purpose.
12. Security Measures
We protect personal information with administrative, technical and physical safeguards appropriate to the sensitivity of the data. Measures include access controls that limit information to named personnel, strong authentication on accounts, encryption of data in transit, regular software updates and secure disposal of equipment.
No method of transmission or storage is perfectly secure. We therefore focus on reducing exposure, detecting incidents quickly and responding honestly if something goes wrong. If a breach affects your personal information and creates a risk to your rights, we will notify you and the relevant authorities without undue delay, describing what happened and what we are doing about it.
13. Your Rights and Choices
Depending on where you live, you may have the right to request access to the personal information we hold about you, to ask us to correct information that is inaccurate, to request deletion where there is no overriding obligation to retain it, to object to or restrict certain processing, and to receive a portable copy of information you provided to us. You may also withdraw consent where consent was the basis for processing.
To exercise any of these rights, write to billing@gsacore.buzz or telephone +15156428502. We will verify your identity, respond within the time required by applicable law and explain any lawful reason that prevents us from fulfilling a request. We do not charge a fee for reasonable requests and we do not discriminate against anyone who exercises privacy rights.
14. Privacy for Children
This website and our advisory services are intended for organisations and adults acting in a professional capacity. We do not knowingly collect personal information from children. If you believe that a child has provided information to us, please contact us immediately so that we can remove it.
Where an engagement involves programmes that serve young people, the client remains responsible for obtaining any consents required for participation, and we handle any resulting records strictly within the instructions and safeguards agreed for that project.
15. Marketing Communications
We send occasional practice notes to clients and contacts who have asked to hear from us. Every message includes a simple way to opt out, and an opt out request is honoured promptly. We do not buy mailing lists and we do not add people to our list merely because they corresponded with us about a project.
If you prefer not to receive any marketing communication, contact us at billing@gsacore.buzz and we will record your preference. Transactional messages that are necessary to deliver a service you requested are not marketing and will continue while the engagement is active.
16. Third Party Links
Our website may link to external resources that we believe are useful to visitors, such as funding authorities or professional bodies. Those sites operate under their own privacy policies and we have no control over their content or practices. We encourage you to review the privacy notice of any external site before providing personal information there.
Providing a link does not imply endorsement of an external organisation, and we are not responsible for the accuracy or availability of third party material.
17. Business Changes and Successors
If GSA SOLUTIONS, LLC is reorganised, merged or sold, personal information may be transferred as part of the practice. Any successor would be required to honour this Policy or to provide notice of changes that are at least as protective as the terms described here. We would inform affected clients and contacts before their information became subject to materially different terms.
18. Changes to This Policy
We review this Policy regularly and update it when our practices or the law change. The effective date at the top of the page shows when the current version took effect. Material changes will be highlighted on the website and, where appropriate, communicated directly to clients. Continued use of the website after an update indicates acceptance of the revised Policy.
We keep prior versions available on request so that you can see how our commitments have evolved.
When we make a change, we ask a simple question: would a reasonable client be surprised by this update? If the answer is yes, we treat it as material and communicate it directly rather than relying on a notice buried in a footer. Trust in an advisory relationship is built through predictable and honest behaviour, and the management of this Policy is one small expression of that principle.
19. How to Contact Us
Questions about this Privacy Policy, requests to exercise your rights and reports of a possible privacy concern should be directed to GSA SOLUTIONS, LLC at the address below. We take every privacy enquiry seriously and aim to respond promptly and clearly.
GSA SOLUTIONS, LLC — 3268 W Rolling Creek Way, South Jordan - 84095-9380, United States (US). Email billing@gsacore.buzz. Telephone +15156428502.