Last Updated: July 25, 2026

1. Introduction and Overview

This Privacy Policy describes how GEA Alliance, operating as a division of Gea Can Limited, a corporation duly registered in Canada with its principal place of business located at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada (CA), collects, uses, discloses, stores, and safeguards personal information obtained through our website located at https://www.geaalliance.mom, our related digital services, and our professional business operations. Throughout this policy, the terms we, us, our, and the Company refer to GEA Alliance and its parent entity Gea Can Limited.

We are deeply committed to protecting the privacy and security of all individuals whose personal information we process. This policy explains your rights regarding your personal data and describes the comprehensive measures we take to ensure its confidentiality, integrity, and availability. By accessing our website or utilizing our professional services, you acknowledge that you have read and understood this Privacy Policy and agree to the data handling practices described herein.

This policy applies to all information collected through our website, electronic communications, social media platforms, professional service engagements, industry events, and any other interaction where you provide personal data to us. It also covers information we may lawfully receive from third-party sources in connection with our business operations and the delivery of our computer systems design and related services.

2. Information We Collect

2.1 Information You Provide Directly

When you interact with GEA Alliance, you may voluntarily provide certain categories of personal information. This information is collected when you fill out forms on our website at https://www.geaalliance.mom, correspond with us via electronic mail or telephone at service@geaalliance.mom or +1 (773) 897-4832, subscribe to our technical newsletters, request service proposals, participate in surveys or assessments, register for events, or engage our consulting and technical services. The types of information we may collect include:

  • Contact and Identification Information: Your full legal name, professional title, company or organization name, email address, telephone number, physical mailing address, and relevant professional affiliations.
  • Business and Technical Information: Details about your organization including its size, industry sector, existing technology infrastructure, current systems architecture, project requirements, technical constraints, and business objectives that you share during consultations, assessments, or service engagements.
  • Communication Data: The complete content of messages, inquiries, feedback, and requests you submit through our contact forms, email correspondence, support ticketing systems, and any attachments, documents, diagrams, or specifications you choose to share with our team.
  • Account Credentials: If you create an account on our client portal or platform, we collect usernames, encrypted passwords, multi-factor authentication preferences, and related authentication data required to secure your access.
  • Transaction and Financial Information: Billing details, payment instrument information, banking details for wire transfers, purchase history, invoicing records, and tax identification numbers necessary for processing payments for our professional services.
  • Event and Subscription Data: Information provided when registering for technical webinars, training sessions, industry conferences, or subscribing to our research publications, white papers, case studies, and technology briefings.
  • Employment Application Data: For job applicants, we collect resumes, cover letters, employment history, educational credentials, professional certifications, references, and other information relevant to the hiring process.

2.2 Information Collected Automatically

When you visit our website at https://www.geaalliance.mom, certain technical information is automatically collected through server logs, cookies, web beacons, and similar tracking technologies. This information helps us understand how visitors interact with our digital properties, identify and resolve technical issues, enhance user experience, and maintain the robust security of our systems. The automatically collected data includes:

  • Device and Browser Information: Internet Protocol address, browser type and version, operating system and version, device type and manufacturer, screen resolution, language preferences, time zone settings, and relevant hardware specifications.
  • Usage Data: Pages visited, duration of time spent on each page, navigation paths through the website, links and buttons clicked, search queries entered, files downloaded, videos viewed, and comprehensive interaction metrics.
  • Access Information: Precise date and time of access, referring and exit URLs, HTTP status codes, request and response sizes, server response times, and network latency measurements.
  • Geographic Location Data: Approximate geographic location derived from your IP address, including country, region, city, and postal code where technically available and reliable.
  • Cookie and Similar Technology Data: Information stored by cookies, web beacons, pixel tags, and similar technologies including session identifiers, user interface preferences, authentication tokens, security challenge data, and analytics tracking identifiers. Detailed information about our cookie usage practices is provided in Section 8 of this policy.

2.3 Information from Third Parties

In the ordinary course of our business operations, we may receive personal information about you from third-party sources, including our technology alliance partners, data enrichment providers, credit reference agencies, publicly accessible databases and registries, social media platforms, professional networking services, and industry associations. We may also receive information when existing clients or business partners refer you to our services. All third-party data is handled in strict accordance with the terms established by the providing entity and the applicable requirements of relevant data protection legislation in Canada and other jurisdictions where we operate.

3. How We Use Your Information

3.1 Primary Purposes

GEA Alliance and Gea Can Limited use the personal information we collect for the following legitimate business and commercial purposes:

  • Professional Service Delivery: To provide, operate, maintain, and continuously improve our computer systems design services, technical consulting, software and platform engineering, cloud infrastructure management, cybersecurity assessment and implementation, data systems and analytics architecture, and all related professional services that you have requested or engaged us to perform.
  • Communication and Technical Support: To respond to your inquiries with appropriate detail and urgency, provide multi-tier technical support, send essential service-related notifications, confirm appointments and milestones, deliver comprehensive project status updates, and communicate critical information about your engagement with our team.
  • Business Operations and Administration: To process payments in a timely manner, manage billing cycles and invoicing, fulfill contractual obligations and service level commitments, conduct internal administrative functions, perform financial reporting, and maintain accurate and complete business records.
  • Marketing and Professional Outreach: To send you carefully curated information about our service offerings, industry insights and analysis, technical articles authored by our engineers, case studies demonstrating real-world results, event invitations, and promotional materials that we reasonably believe may be relevant to your professional interests, subject to your expressed communication preferences and applicable consent requirements under Canadian and international law.
  • Personalization and Continuous Improvement: To analyze usage patterns across our digital properties, understand user preferences and behavior, improve website functionality and accessibility, develop new features and service offerings, enhance overall service quality, and deliver a more personalized and efficient client experience.
  • Security and Regulatory Compliance: To detect, prevent, investigate, and respond to fraud, unauthorized access attempts, security incidents and breaches, violations of our terms of service and contractual agreements, and other illegal or harmful activities; to comply with our legal obligations, regulatory requirements, and enforceable governmental requests.
  • Strategic Business Development: To conduct market research and competitive analysis, analyze industry trends and emerging technology patterns, evaluate new business opportunities and partnerships, and support data-driven strategic planning initiatives.

3.2 Legal Bases for Processing

The legal grounds upon which we process personal information depend on the nature of the data, the context of its collection, and applicable jurisdictional requirements. We process your information on the following legal bases:

  • Contractual Necessity: Processing is required to fulfill our contractual obligations to you, including delivering the professional services you have requested, managing our ongoing business relationship, and performing pre-contractual steps at your request.
  • Legitimate Business Interests: Processing is necessary for our legitimate business interests, including improving our service delivery, ensuring network and information security, preventing fraud and abuse, conducting business analytics, and marketing our services to relevant professional audiences, provided these interests are not overridden by your fundamental data protection rights and freedoms.
  • Consent: Where required by applicable law, we obtain your explicit, informed consent before processing personal information for specific purposes, such as sending direct marketing communications, using certain categories of cookies and tracking technologies, or processing sensitive personal data.
  • Legal Obligation: Processing is necessary to comply with applicable statutes, regulations, court orders, governmental requests, tax obligations, and other legal processes to which we are subject in Canada and other relevant jurisdictions.
  • Vital Interests: Processing is necessary to protect the vital interests of any individual, such as in emergency situations involving potential threats to health, safety, or personal security.

4. How We Share and Disclose Information

GEA Alliance does not sell, rent, trade, or otherwise monetize your personal information to third parties for their own independent marketing purposes. We may share your information in the following carefully limited circumstances:

4.1 Service Providers and Business Partners

We engage carefully vetted third-party service providers to perform functions that support our business operations and professional service delivery. These providers are bound by comprehensive contractual agreements that require them to process personal information exclusively on our behalf, strictly in accordance with our documented instructions, and with appropriate technical and organizational security measures that meet or exceed industry standards. The categories of service providers we may share information with include cloud hosting and infrastructure providers, payment processors and financial institutions, communication and email delivery platforms, customer relationship management and support ticketing systems, analytics and website performance monitoring services, professional advisors including legal counsel and auditors, marketing automation platforms, and security and fraud prevention service providers.

4.2 Corporate Affiliates and Related Entities

Personal information may be shared within the Gea Can Limited corporate group, including its subsidiaries, operating divisions, and affiliated entities, for the purposes described in this policy. All entities within our corporate group are required to handle personal information in accordance with this Privacy Policy, applicable Canadian data protection standards including PIPEDA, and relevant international privacy frameworks.

4.3 Legal and Regulatory Disclosures

We may disclose your personal information when we have a good faith belief, supported by reasonable assessment, that such disclosure is necessary to comply with applicable laws, regulations, legal processes, or enforceable governmental requests; to enforce our terms of service and contractual agreements; to detect, prevent, or address fraud, security breaches, or technical issues affecting our systems or those of our clients; or to protect the rights, property, or personal safety of GEA Alliance, Gea Can Limited, our clients, our employees and contractors, or the general public as required or expressly permitted by law.

4.4 Business Transfers

In the event of a merger, acquisition, corporate reorganization, sale of all or substantially all assets, financing transaction, bankruptcy proceeding, or similar corporate transaction involving GEA Alliance or Gea Can Limited, personal information held by us may be among the assets transferred to the successor entity or acquiring party. You will be provided with reasonable notice of any such change in ownership or control of your personal information, as well as any meaningful choices you may have regarding the continued processing of your information by the successor entity.

4.5 With Your Explicit Consent

We may share your personal information with third parties for purposes not described in this policy when we have obtained your explicit, informed consent to do so. You retain the right to withdraw your consent at any time by contacting us using the information provided in Section 12 of this policy, subject to legal and contractual limitations.

5. Data Retention

We retain personal information only for as long as is reasonably necessary to fulfill the purposes for which it was originally collected, including to satisfy any legal, regulatory, tax, accounting, audit, or reporting requirements applicable to our operations in Canada and other jurisdictions. The specific retention period applied to any category of personal information depends on the nature of the information, the purpose of its collection, and the applicable legal framework.

When determining the appropriate retention period for personal information, we carefully consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure; the specific purposes for which we process your personal information and whether we can reasonably achieve those purposes through alternative means; contractual obligations we have entered into with clients and technology partners; and applicable legal and regulatory requirements in the jurisdictions where we operate our business.

Upon expiration of the applicable retention period, personal information is securely deleted, irreversibly destroyed, or comprehensively anonymized in accordance with our established data disposal policies and industry best practices. In certain cases, we may retain information in a de-identified or aggregated form that can no longer be associated with an identifiable individual, for legitimate research, statistical analysis, or business planning purposes.

Specific retention practices include: client project data and deliverables are retained for the duration of the engagement plus a period of seven years to comply with tax, contractual, and professional liability obligations; marketing communications data and consent records are retained until you unsubscribe or formally withdraw consent, plus a reasonable period for audit trail purposes; website usage logs and analytics data are retained for up to twenty-four months; and employment and recruitment-related data is retained in strict accordance with applicable Canadian employment and human rights legislation.

6. Data Security

GEA Alliance and Gea Can Limited implement and maintain industry-leading technical, administrative, and physical security measures designed to protect personal information against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, access, or use. Our comprehensive security framework is aligned with recognized international standards and best practices relevant to the computer systems design and integrated services industry.

6.1 Technical Security Measures

Our multilayered technical safeguards include end-to-end encryption for all data in transit using TLS 1.3 protocols with forward secrecy; encryption at rest using AES-256 encryption for all stored personal data; mandatory multi-factor authentication for all system and platform access; rigorous network segmentation with next-generation firewalls; advanced intrusion detection and prevention systems with real-time threat intelligence feeds; regular vulnerability scanning and independent third-party penetration testing; automated patch management and security update protocols; continuous security event monitoring, correlation, and logging; distributed denial-of-service protection at the network edge; and secure, encrypted backup systems with regularly tested restoration and business continuity procedures.

6.2 Administrative Security Measures

Our comprehensive administrative controls include documented information security policies and procedures reviewed and updated quarterly; mandatory annual security awareness training for all employees and contractors with specialized modules for technical personnel; strict role-based access controls implementing the principle of least privilege across all systems; rigorous periodic access review and prompt revocation processes; thorough vendor security risk assessments and ongoing due diligence monitoring; detailed incident response and business continuity plans that are tested through regular tabletop exercises and live drills; and continuous compliance monitoring supported by internal and external audit programs.

6.3 Physical Security Measures

Our physical security controls include access-controlled facilities requiring multi-factor authentication for entry; continuous high-definition video surveillance of all critical infrastructure areas; environmental monitoring systems with automated alerts and fire suppression; redundant and diverse power supplies with automatic failover and backup generation; redundant network connectivity through multiple carriers with diverse fiber paths; secure destruction procedures for all physical media containing personal information; and comprehensive visitor access management, logging, and escort procedures.

While we employ commercially reasonable and industry-standard measures to protect your personal information, no method of electronic transmission or storage is absolutely immune to all threats. We cannot and do not guarantee absolute security, but we continuously monitor, assess, and improve our security posture to address the evolving threat landscape. In the unfortunate event of a data breach that affects your personal information, we will notify you and relevant regulatory authorities in strict accordance with applicable breach notification laws and within the timeframes prescribed by those laws.

7. International Data Transfers

GEA Alliance is headquartered in Markham, Ontario, Canada, and our parent company Gea Can Limited is registered at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada (CA). As a global provider of computer systems design and related services operating in the Professional, Scientific, and Technical Services sector, we may process, store, and transfer personal information across international borders, including to countries where we maintain offices, engage service providers, or operate secure data centers to support our global client base.

When we transfer personal information from one jurisdiction to another, we ensure that appropriate and legally adequate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws. These safeguards may include transferring data only to countries that have been formally recognized by relevant regulatory authorities as providing an adequate level of data protection; implementing Standard Contractual Clauses or equivalent data transfer agreements approved by relevant data protection authorities; ensuring that recipients adhere to binding corporate rules or certified privacy frameworks; obtaining your explicit consent for the specific transfer where required by applicable law; and conducting thorough transfer impact assessments to evaluate and mitigate any risks associated with cross-border data flows.

By using our services and voluntarily providing your personal information, you acknowledge and consent to the transfer, processing, and storage of your information in countries outside your country of residence, which may have different data protection standards than those applicable in your home jurisdiction.

8. Cookies and Tracking Technologies

8.1 Understanding Cookies

Cookies are small text files that are placed on your device when you visit a website. They are widely used across the internet to make websites function efficiently, provide analytical information to website operators, remember user preferences, and enhance the overall browsing experience. Cookies may be set by the website you are directly visiting, known as first-party cookies, or by other services and platforms that provide embedded functionality on that website, known as third-party cookies.

8.2 Categories of Cookies We Use

Our website at https://www.geaalliance.mom employs the following categories of cookies:

  • Strictly Necessary Cookies: These cookies are essential for the basic and secure operation of our website. They enable core functionality such as page navigation, secure access to protected areas, form submission processing, and load balancing. The website cannot function properly without these cookies, and under applicable privacy laws, they do not require your prior consent.
  • Performance and Analytics Cookies: These cookies collect aggregated and anonymized information about how visitors use our website, such as which pages are visited most frequently, how users navigate between different sections, how long they spend on technical content, and whether they encounter any error messages. This analytical data helps us continuously improve website performance, content relevance, and overall user experience.
  • Functional Cookies: These cookies allow our website to remember choices you make during your visit, such as your preferred language, region, or display settings, and to provide enhanced, more personalized features during subsequent visits. The information collected by these cookies is typically anonymized, and they are not capable of tracking your browsing activity on unrelated third-party websites.
  • Security Cookies: These specialized cookies help us detect, prevent, and respond to security threats, authenticate legitimate users, prevent fraudulent use of login credentials, and protect user data from unauthorized access or exfiltration. They are essential for maintaining the integrity and trustworthiness of our systems.

8.3 Managing Your Cookie Preferences

You have the right and the technical ability to control the use of cookies through your web browser settings. Most modern web browsers allow you to manage cookies through their settings or preferences menus, including options to block all cookies, delete existing cookies, or receive a notification before a cookie is set on your device. Please note that disabling certain categories of cookies, particularly strictly necessary and security cookies, may significantly impact the functionality, performance, and security of our website.

To manage your cookie preferences, you can typically find these settings in your browser under Options, Settings, Preferences, or Privacy and Security. You may also utilize browser extensions and dedicated privacy tools to manage tracking across websites. For more detailed and current information about cookies and practical guidance on how to manage them, you may consult industry and regulatory resources such as the website of the Office of the Privacy Commissioner of Canada.

9. Your Rights and Choices

9.1 Individual Rights Under Privacy Law

Depending on your jurisdiction of residence, you may have certain substantive rights regarding the personal information we hold about you. These fundamental privacy rights may include:

  • Right of Access: You have the right to request confirmation of whether we process your personal information and to obtain a copy of the personal data we hold about you, together with supplementary information about the categories of data, purposes of processing, and entities with whom we share it.
  • Right of Rectification: You have the right to request that we correct, update, or complete any inaccurate or incomplete personal information we hold about you without undue delay following verification of the corrected information.
  • Right of Erasure: In certain legally defined circumstances, you have the right to request the deletion or removal of your personal information from our systems, also referred to as the right to be forgotten, subject to applicable legal exceptions and mandatory retention requirements.
  • Right to Restrict Processing: You may request that we limit or suspend the processing of your personal information in specific circumstances, such as when you contest the accuracy of the data, object to our processing activities, or require the data for legal claims.
  • Right to Data Portability: Where technically feasible and legally required, you have the right to receive your personal information in a structured, commonly used, machine-readable format and, where applicable, to have it transmitted directly to another data controller without hindrance from us.
  • Right to Object: You may object to the processing of your personal information for specific purposes, including direct marketing and processing based on legitimate interests. Upon receiving a valid objection, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Right to Withdraw Consent: Where our processing of your data is based on your consent, you may withdraw that consent at any time with effect for the future. Withdrawal of consent does not affect the lawfulness of any processing conducted prior to the effective date of withdrawal.
  • Right to Non-Discrimination: We will never discriminate against you for exercising any of your privacy rights. This means we will not deny you access to our services, charge you different prices or rates, or provide a materially different level or quality of service as a result of your privacy choices and preferences.
  • Right to Complain to a Supervisory Authority: You have the unconditional right to lodge a formal complaint with a relevant supervisory authority or data protection regulator if you believe that our processing of your personal information violates applicable privacy or data protection law.

9.2 How to Exercise Your Rights

To exercise any of the rights described above, please contact us using the information provided in Section 12 of this policy. We will acknowledge receipt of your request promptly and provide a substantive response within the timeframe required by applicable law, which is typically within thirty calendar days. We may need to verify your identity through reasonable means before processing your request to ensure the security of your information and prevent unauthorized access. In certain cases, we may require additional specific information to confirm your identity with sufficient certainty or to clarify the precise scope and nature of your request.

There are circumstances defined by law where we may not be able to fully comply with your request, such as when fulfilling the request would adversely and disproportionately affect the rights and freedoms of other individuals, when we are legally required to retain the information for specific purposes, or when a statutory exemption applies under applicable data protection legislation. In any such case, we will provide you with a clear, reasoned explanation of why we are unable to fulfill your request in whole or in part.

9.3 Marketing Communications and Opt-Out

You may opt out of receiving marketing and promotional communications from us at any time by clicking the unsubscribe link included at the bottom of every marketing email we send, by updating your communication preferences in your client portal account settings, or by contacting us directly with your opt-out request. Please note that even if you exercise your opt-out right for marketing messages, we may continue to send you essential transactional and service-related communications that are necessary for the operation of your account, the performance of a contract, or our ongoing professional business relationship.

9.4 Do Not Track Signals

Our website currently does not respond to or alter its behavior based on Do Not Track signals transmitted by web browsers. Do Not Track is a preference you can set in your browser to inform websites that you do not wish to be tracked across different sites. Due to the lack of a uniform, widely adopted industry standard for interpreting and responding to DNT signals, we continue to monitor technological and regulatory developments in this area and will adjust our practices as appropriate and as consistent standards emerge.

10. Protection of Children's Privacy

Our website and professional services are designed and intended exclusively for business professionals, corporate clients, and individuals of legal age to enter into binding commercial agreements. We do not direct our services to, target, or knowingly collect, use, or disclose personal information from children under the age of sixteen. If we become aware that we have inadvertently collected personal information from a child without verified and documented parental consent, we will take immediate and comprehensive steps to delete such information from all of our systems and records.

Parents and legal guardians who have reason to believe that their child has provided personal information to us through our website or otherwise should contact us immediately using the contact details provided in Section 12 of this policy. We will investigate the matter with appropriate urgency and take all necessary corrective actions in full accordance with applicable laws and regulations concerning the protection of children's privacy in the online environment.

11. Changes to This Privacy Policy

GEA Alliance and Gea Can Limited reserve the right to update, modify, amend, or replace this Privacy Policy at any time in our sole discretion to accurately reflect changes in our information practices, evolving legal obligations, or developments in industry standards and best practices. When we make material changes to this policy, we will provide you with prominent and timely notice through a conspicuous announcement on our website at https://www.geaalliance.mom, by sending a notification to the email address associated with your account if one exists, or through other appropriate and effective communication channels.

The Last Updated date displayed at the top of this policy indicates when it was most recently revised and should be used as your reference point. We strongly encourage you to review this Privacy Policy at regular intervals to stay informed about how we protect your personal information. Your continued use of our website and professional services following the posting of any modifications to this policy constitutes your acknowledgment of the changes and your acceptance of the updated policy terms.

In the specific event of a material change that would significantly and substantively alter how we process your personal information relative to the practices described at the time of collection, we will seek your explicit, affirmative consent before applying any new or modified practices to your previously collected personal data, where such consent is required by applicable law.

12. Contact Information

If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data protection practices, or if you wish to exercise any of your privacy rights as described in this policy, please contact us through any of the following channels. We treat all privacy-related inquiries with the utmost seriousness and urgency.

Privacy Officer
GEA Alliance, a division of Gea Can Limited
108-200 Town Centre Blvd
Markham - L3R 8G5
Canada (CA)

Email: service@geaalliance.mom
Phone: +1 (773) 897-4832
Website: https://www.geaalliance.mom

We endeavor to acknowledge your privacy-related inquiry within forty-eight business hours and to provide a comprehensive substantive response within the timeframe required by applicable law. If you are not satisfied with our response to your concern, you have the right to contact the appropriate data protection supervisory authority in your jurisdiction, including the Office of the Privacy Commissioner of Canada for matters arising under Canadian federal privacy legislation.

13. Jurisdiction-Specific Provisions

13.1 Residents of Canada

For individuals located in Canada, this Privacy Policy is designed to comply in all material respects with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Ontario's Personal Health Information Protection Act where relevant. As a Canadian company headquartered at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada, we fully adhere to the ten fair information principles established under Canadian privacy law: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.

Canadian residents have the right to access their personal information held by our organization and to challenge the accuracy and completeness of that information. They may also withdraw consent to the continued collection, use, and disclosure of their personal information at any time, subject to reasonable legal and contractual restrictions. Formal complaints regarding our handling of personal information may be directed to the Office of the Privacy Commissioner of Canada at their designated contact channels.

13.2 Residents of the European Economic Area and United Kingdom

For individuals located in the European Economic Area or the United Kingdom, we process personal information in accordance with the General Data Protection Regulation and the UK Data Protection Act 2018 respectively. Under these comprehensive regulatory frameworks, you have specific and enforceable rights including the right to access, rectify, erase, restrict processing, object to processing, and data portability of your personal data. You also have the unconditional right to lodge a formal complaint with a supervisory authority in your EU member state of habitual residence or with the UK Information Commissioner's Office as applicable.

The legal bases for our processing activities are fully described in Section 3.2 of this policy. For any transfers of personal data outside the EEA or United Kingdom, we implement the robust safeguards described in Section 7, including the use of European Commission-approved Standard Contractual Clauses and comprehensive transfer impact assessments.

13.3 Residents of the United States

For individuals located in the United States, we comply with all applicable federal and state privacy and data protection laws. If you are a resident of a state that has enacted comprehensive consumer privacy legislation, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, or similar privacy laws enacted in other states, you may have additional specific rights regarding your personal information beyond those described in the general sections of this policy.

These enhanced rights may include the right to know what categories of personal information we collect and how we use, disclose, and share it; the right to access and obtain a portable copy of your personal information; the right to request deletion of your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising; and the right to be free from discrimination for exercising these statutory rights. To exercise any of these rights, please contact us using the information provided in Section 12.

13.4 Residents of Other Jurisdictions

GEA Alliance and Gea Can Limited are firmly committed to complying with all applicable data protection and privacy laws in every jurisdiction where we conduct business operations. If your country or territory of residence provides specific privacy rights beyond those comprehensively described in this policy, we will respect, honor, and facilitate the exercise of those rights in full accordance with the applicable legal framework. Please contact us using the information in Section 12 if you have any questions about jurisdiction-specific rights that may apply to your particular situation.

14. Third-Party Websites and Services

Our website may, from time to time, contain links to external websites, web applications, and online services operated by third parties that are not owned, controlled, or operated by GEA Alliance or Gea Can Limited. This Privacy Policy applies exclusively and solely to information collected through our own website at https://www.geaalliance.mom and the professional services we directly provide. We bear no responsibility whatsoever for the privacy practices, content accuracy, security posture, or data handling policies of any third-party websites, applications, or digital services.

We strongly and unequivocally encourage you to carefully review the privacy policies and terms of service of every website you visit and every online service you use, particularly before submitting any personal information of any kind. The mere inclusion of a hyperlink to a third-party website on our site does not constitute our endorsement, approval, or certification of that website, its content, or its privacy and security practices. All of your interactions with third-party websites and services are governed exclusively by their own terms, conditions, and policies, not by this Privacy Policy or our Terms of Service.

15. Data Processing Addendum for Enterprise Clients

For our enterprise and institutional clients who engage GEA Alliance to provide computer systems design, cloud infrastructure management, software and platform engineering, cybersecurity services, data systems and analytics architecture, IT consulting, and related professional and technical services, we offer a comprehensive Data Processing Addendum that formalizes our respective roles, responsibilities, and obligations under applicable data protection laws worldwide.

The Data Processing Addendum addresses the specific subject matter and duration of processing; the detailed nature and business purpose of processing; the types and categories of personal data that will be processed; the categories of data subjects whose information may be involved; the technical and organizational security measures we implement and maintain; and the respective rights, obligations, and liabilities of each party under the governing data protection framework.

If your organization requires a signed Data Processing Addendum to formalize our mutual data protection commitments in connection with an existing or prospective service engagement, please contact us directly at service@geaalliance.mom. Our legal and compliance team will work with you to provide the appropriate documentation tailored to your specific compliance requirements, regulatory environment, and the precise scope of services being provided under the engagement.

This Privacy Policy constitutes the complete and entire agreement between you and GEA Alliance, a division of Gea Can Limited, regarding the collection, use, disclosure, and protection of your personal information through our website and professional services, superseding and replacing any prior communications, representations, or agreements on this specific subject matter.