Legal · Privacy policy

Your data, handled like a referral.

We're a small cooperative of operators. We collect the minimum needed to evaluate fit, deliver mandates, and answer when you reach out — nothing more. This page lays out exactly what we do with it.

Effective · 24 May 2026Version · 3.0Reading time · ~6 min
/ 01

Who we are.

Gravitas, Acumen & Co (referred to as "GAC", "we", "us") is an international cooperative of independent operators, registered in Canada and Panama, with members across three continents.

We are the data controller for the personal information you share with us through this website, our application forms, and direct correspondence with our Managing Partners.

/ Legal entity
Gravitas, Acumen & Co — Cooperative
/ Registered offices
Montréal, Canada & Panama City, Panama
/ Data inquiries
cx@gravitasacumen.org
/ Response window
Within 30 days of receipt
/ 02

What we collect.

We collect only the data we need to do our job. Most of it is information you give us directly when you book a call, apply for a scorecard, or apply to join the cooperative.

CategoryWhat's in it
Identity & contactFirst and last name, work email, phone (optional), role, company, website.
Engagement contextReason for reaching out, current challenges, team size, channels, tooling, budget range. Only what you choose to share in a form or call.
Candidate profileFor coop partner applications: referral source, background, prior roles, LinkedIn, motivation. We never request government IDs at this stage.
CorrespondenceEmails, meeting notes, and call transcripts (only when we tell you we're recording and you consent).
TechnicalIP address, browser type, device, referring URL, and aggregated analytics events. No third-party advertising trackers.

We do not collect special-category data (health, race, religion, biometric, financial account numbers). If you accidentally include any in a form, we delete it on review.

/ 03

Why we collect it.

Each piece of data we hold maps to a specific, narrow purpose and a corresponding legal basis (GDPR, PIPEDA, CCPA, and equivalents):

  • To evaluate fit. Reviewing whether your operation matches our mandate criteria. (legitimate interest)
  • To deliver what you requested. Scheduling discovery calls, running scorecards, responding to candidacy applications. (contract / pre-contract)
  • To staff cooperative mandates. Matching the right partner to the right client when there's mutual interest. (contract)
  • To improve our practice. Aggregated benchmarks across mandates — always anonymized. (legitimate interest)
  • To meet our obligations. Tax, accounting, anti-money-laundering, professional record-keeping. (legal obligation)

We do not sell, rent, or trade your data. We do not use it to train third-party AI models. We do not run ad-retargeting.

/ 04

Who we share it with.

By design, your data stays close. Three categories of recipients only:

  • Managing Partners and assigned operators within the cooperative — only those staffed on your mandate or evaluating your application.
  • Service providers that operate under written data-processing agreements: our email host, calendar tool, document storage, accounting software, and analytics provider. Each is contractually bound to use your data only on our instructions.
  • Authorities, when legally required by valid court order or regulatory request. We push back on overbroad requests and notify you when we're permitted to.
/ Plain English We never share your data with brokers, ad networks, or third-party marketing platforms. The only humans who touch it are the cooperative members and the suppliers we depend on to run our small business.
/ 05

International transfers.

Because our cooperative spans three continents, some of your data is processed outside your home country. We use only providers that offer either Standard Contractual Clauses (EU), adequacy decisions, or equivalent safeguards under PIPEDA and other applicable laws.

Primary processing locations: Canada, the European Union, and Panama. No data is processed in jurisdictions without recognized data-protection frameworks.

/ 06

How long we keep it.

Data typeRetention
Inquiry & discovery-call notes (no engagement)12 months, then deleted.
Scorecard application data24 months from delivery, then anonymized.
Coop partner application (not accepted)18 months, then deleted.
Active engagement recordsFor the duration of the mandate + 7 years (professional record-keeping).
Accounting & tax records7 years (Canadian tax law minimum).
Server logs & analytics13 months, rolling window.

After retention expires, data is either deleted irreversibly or anonymized so it can no longer be linked to you.

/ 07

Your rights.

Depending on where you live, you have most or all of the following rights over the personal data we hold about you. We honor them regardless of jurisdiction unless local law explicitly restricts us.

Access

Request a copy of what we hold about you.

Rectification

Correct inaccurate or incomplete information.

Erasure

Ask us to delete your data when no longer needed.

Restriction

Limit how we process your data in specific cases.

Portability

Receive your data in a machine-readable format.

Object

Opt out of processing based on legitimate interest.

Withdraw consent

At any time, where processing relies on consent.

Lodge a complaint

With your local supervisory authority.

To exercise any of these rights, email cx@gravitasacumen.org from the address you used with us. We confirm receipt within 5 business days and respond in full within 30 days.

/ 08

Cookies & tracking.

This site uses only what's necessary to run smoothly. We don't deploy advertising cookies, fingerprinting, or cross-site trackers.

  • Essential cookies — session state, form submission protection. Always on; no consent banner needed under most regimes.
  • Aggregated analytics — anonymized pageview counts via a privacy-respecting provider. No cross-site tracking, no IP storage.

Most browsers let you block or delete cookies. Doing so won't break the site, but may reset your form state.

/ 09

Security.

We take reasonable, role-appropriate measures to protect your data:

  • TLS encryption in transit, AES-256 at rest where supported by our providers.
  • Role-based access — only the Managing Partner reviewing your file can see it.
  • Two-factor authentication required on every internal account.
  • Annual access review and supplier audit.
  • Incident-response protocol: affected individuals notified within 72 hours of confirmed breach.

No system is perfectly secure. If you suspect a vulnerability in ours, please email cx@gravitasacumen.org. We don't pursue good-faith researchers.

/ 10

Children.

Our services are intended for business professionals. We don't knowingly collect data from anyone under 16. If you believe a minor has submitted a form, contact us and we'll delete the record.

/ 11

Changes to this policy.

When we materially change how we handle your data, we update the version number and effective date at the top of this page, and — when the change affects you — notify you by email or in-app prompt before it takes effect.

Minor edits (typos, formatting, clarifications that don't expand processing) are made silently. The current version is always the one shown above.

/ 12

Contact us.

The fastest way to reach us about anything privacy-related:

/ General privacy questions
cx@gravitasacumen.org
/ Security disclosures
cx@gravitasacumen.org
/ Mailing address (Canada)
Gravitas, Acumen & Co — Montréal, QC
/ Mailing address (Panama)
Gravitas, Acumen & Co — Panama City

If we can't resolve your concern, you have the right to lodge a complaint with the data-protection authority in your country of residence — the OPC in Canada, the CNIL in France, the ICO in the UK, your state attorney general in the US, etc.

Questions we didn't answer?

Email cx@gravitasacumen.org or book a 15-minute call with a Managing Partner — we'd rather talk it through than leave you guessing.

Book a call
© 2026 Gravitas, Acumen & Co