GILNEX PRIVACY POLICY
On this page
- 1. INFORMATION WE COLLECT
- 2. HOW WE USE YOUR INFORMATION
- 3. HOW WE SHARE YOUR INFORMATION
- 4. YOUR CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
- 5. HIPAA NOTICE (HEALTHCARE CLIENTS)
- 6. DATA RETENTION
- 7. COOKIES AND TRACKING
- 8. CHILDREN'S PRIVACY
- 9. DATA SECURITY
- 10. LINKS TO THIRD-PARTY SITES
- 11. CHANGES TO THIS POLICY
- 12. CONTACT OUR PRIVACY TEAM
Last Updated: June 28, 2026 Effective Date: June 28, 2026
GILNEX, LLC ("GILNEX," "we," "us," or "our") operates gilnex.com (the "Site") and the GILNEX Intelligent Growth System (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect information about you, and explains your rights under applicable law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the Health Insurance Portability and Accountability Act (HIPAA).
1. INFORMATION WE COLLECT
1.1 Information You Provide Directly
- Contact Information: Name, business name, email address, phone number, business address.
- Account Information: Username, password (hashed), profile details, industry, city.
- Payment Information: Billing address, last four digits of card (full card numbers are processed and stored solely by Stripe, Inc.—GILNEX does not store raw card data).
- Business Information: Industry type, number of locations, monthly revenue range, number of employees.
- Communications: Content of emails, support tickets, chat messages, and other communications with GILNEX.
- Tool Inputs: Information entered into GILNEX tools (e.g., website URL for analysis, missed-call data for revenue calculations).
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, click paths, session duration, browser type, device type, operating system.
- Network & Device Signals (hashed / approximate): We store a one-way hash of your IP address (not the raw IP), a hashed browser/device fingerprint derived from your user agent, and an approximate country or region code supplied by our hosting provider (e.g., US, CA). These signals help detect fraud, attribute marketing leads, and secure your account. They are not used to sell your data.
- Attribution Data: First HTTP referrer URL and UTM campaign parameters (utm_source, utm_medium, utm_campaign) when present in the landing URL.
- Anonymous Session Cookie: A random gilnex_visitor identifier (httpOnly, SameSite=Lax) to stitch anonymous browsing sessions to lead capture — no raw email or name in this cookie.
- Cookies and Tracking Technologies: See Section 7 (Cookies).
- Performance Data: API response times, error rates, and other technical telemetry.
1.3 Information from Third Parties
- Third-Party Integrations: If you connect Google Business Profile, Facebook, telephony providers, or calendar applications, we receive data from those services subject to their privacy policies.
- Stripe: We receive transaction confirmations and payment status notifications from Stripe, but not your full payment card information.
2. HOW WE USE YOUR INFORMATION
We use your information to:
(a) Provide, operate, and improve the Platform and its features; (b) Process payments and manage your subscription; (c) Send transactional communications (receipts, subscription confirmations, service updates); (d) Deliver AI-powered automation services on your behalf; (e) Provide customer support; (f) Send marketing communications (only with your consent where required by law); (g) Detect fraud, enforce our Terms of Service, and comply with legal obligations; (h) Analyze usage patterns to improve the Platform; (i) Generate anonymized, aggregated analytics for business reporting (never identifying individual clients).
3. HOW WE SHARE YOUR INFORMATION
We do not sell your personal information to third parties. We may share your information with:
3.1 Service Providers (Processors)
| Provider | Purpose | HIPAA BAA Available | |----------|---------|---------------------| | Stripe, Inc. | Payment processing | Yes | | Vercel, Inc. | Cloud hosting and infrastructure | Enterprise | | Resend, Inc. | Transactional email delivery | Contact us | | Twilio, Inc. | SMS and voice communication | Yes | | Upstash, Inc. | Database (Vercel KV) | Contact us | | Google, Inc. | Cloud infrastructure, analytics (when consented), Maps, Business Profile, and Gemini AI (Growth Advisor chatbot) | Yes (enterprise) |
All service providers are contractually required to protect your information and use it only to provide services to GILNEX.
3.2 Healthcare Clients (HIPAA)
For clients who have executed a Business Associate Agreement (BAA), PHI may be shared with HIPAA-eligible subprocessors only as permitted by the BAA and applicable law.
3.3 Legal Requirements
We may disclose your information when required by law, valid legal process, or to protect the rights, property, or safety of GILNEX, our clients, or the public.
3.4 Business Transfers
If GILNEX undergoes a merger, acquisition, or asset sale, your information may be transferred to the acquiring entity, subject to equivalent privacy protections.
4. YOUR CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, you have the following rights:
4.1 Right to Know
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you.
4.2 Right to Delete
You have the right to request deletion of personal information we have collected, subject to certain exceptions.
4.3 Right to Correct
You have the right to request correction of inaccurate personal information.
4.4 Right to Opt-Out of Sale or Sharing
GILNEX does not sell personal information. We do not share personal information for cross-context behavioral advertising.
4.5 Right to Limit Use of Sensitive Personal Information
You have the right to limit our use of sensitive personal information (such as health-related information) to uses necessary to provide our services.
4.6 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
4.7 How to Exercise Your Rights
Submit requests by:
- Email: [email protected] (include your name, email address, and specific request)
- Online form: gilnex.com/privacy/request
- Phone: +1 310 598 2636
We will respond within 45 days (extendable by 45 additional days with notice). We may need to verify your identity before processing requests.
Authorized Agents: You may designate an authorized agent to make requests on your behalf by providing written authorization or a power of attorney.
5. HIPAA NOTICE (HEALTHCARE CLIENTS)
If you are a healthcare provider, health plan, or healthcare clearinghouse (a "Covered Entity" under HIPAA), and you process Protected Health Information (PHI) through the Platform:
- PHI is handled only pursuant to a signed Business Associate Agreement (BAA).
- GILNEX implements Security Rule-compliant administrative, physical, and technical safeguards.
- PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Access to PHI is restricted to authorized GILNEX personnel on a need-to-know basis.
- In the event of a PHI breach, GILNEX will provide notification within 60 calendar days of discovery.
- To request a BAA: [email protected]
California CMIA: GILNEX also complies with the California Confidentiality of Medical Information Act (Cal. Civ. Code § 56 et seq.) for California-based healthcare clients.
6. DATA RETENTION
| Data Category | Retention Period | |--------------|-----------------| | Account data | Active subscription + 3 years | | Payment records | 7 years (tax compliance) | | Communication logs | 3 years | | Tool usage data | 2 years | | PHI (with BAA) | Per BAA terms, minimum HIPAA requirements | | Consent records | 7 years (California requirement) | | Anonymized analytics | Indefinite |
7. COOKIES AND TRACKING
We use cookies and similar tracking technologies. See our Cookie Policy (gilnex.com/cookies) for full details. Categories include:
- Strictly Necessary: Required for Platform functionality.
- Performance: Analytics to improve the Platform.
- Functional: Remember your preferences.
- Marketing: Targeted advertising (opt-out available via cookie banner).
CCPA/CPRA: You may opt out of marketing cookies at any time via our cookie preference center.
8. CHILDREN'S PRIVACY
The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn we have collected information from a minor, we will delete it promptly.
9. DATA SECURITY
We implement industry-standard security measures including TLS 1.2+ (transit), AES-256 (at rest), role-based access controls, audit logging, and regular security assessments. No system is perfectly secure. Promptly notify us of any suspected breach at [email protected].
10. LINKS TO THIRD-PARTY SITES
Our Platform may contain links to third-party websites. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy at any time. For material changes, we will provide at least 30 days' notice to your registered email address. Continued use of the Platform after the effective date constitutes acceptance.
12. CONTACT OUR PRIVACY TEAM
Privacy Officer / Data Protection Contact: GILNEX, LLC — Privacy Department 22647 Ventura Blvd, Suite 873, Woodland Hills, CA 91364 [email protected] +1 310 598 2636
Do Not Sell or Share My Personal Information: gilnex.com/privacy/do-not-sell
© 2026 GILNEX, LLC. All rights reserved.
Questions?