1. Scope and roles
This Notice describes how GC Total handles personal information through its public website, business relationships, authentication, billing, email and file intake, automated analysis, delivery, support, security, and improvement processes.
GC Total generally determines the purposes of account, website, commercial, billing, security, and service-administration processing. When GC Total processes personal information in a customer’s project material solely under customer instructions, the customer may be the controller or business and GC Total its processor or service provider.
The service is for U.S. business customers and Authorized Client Users age 18 or older. It is not directed to children or offered for personal, family, or household use. Capitalized service terms defined in the Terms retain those meanings here.
A Quarantined Original is the unchanged received file held in restricted storage with source, time, Access Scope, size, type, and hash recorded. An Execution Trace records a Processing Run’s inputs, lineage, prompts, model responses, durations, retries, provider costs, decisions, failures, and outputs. A Technical Intermediate is a reproducible cache, duplicate render, temporary crop, incomplete fragment, or similar artifact whose bytes ordinarily need not be retained.
2. Information handled
- Business identifiers, contact, employer, organization, title, role, authorization, recipient, and support information.
- Account, project, division, allowlist, authentication, session, device, IP-address, and security information.
- Subscription, plan, allowance, overage, invoice, tax, payment-status, consent, and transaction metadata.
- Emails, attachments, file links, bid documents, directions, corrections, and support communications.
- Quarantined Originals, inventories, extracted content, prompts and responses, source evidence, findings, quantities, risks, audit records, and Execution Traces.
- Generated workbooks and versions, downloads, delivery and recipient history, and accept/reject feedback.
- Public-site request information disclosed to hosting and font-delivery providers.
- Records needed to answer legal, privacy, accessibility, billing, or security requests.
GC Total should not receive credentials, payment-card details, or specially controlled project information through ordinary file intake. Stripe collects payment information directly; GC Total receives the billing, subscription, transaction, tax, status, and account details needed to administer the service. Clerk provides the identity, organization, authentication, session, device, IP-address, and configured profile details needed to secure accounts.
3. Sources and purposes
Sources include the individual; their employer, organization, administrators, authorized senders and recipients; service interactions; customer-submitted materials; generated processing; and contracted providers.
GC Total uses information to authenticate and enforce Access Scopes; receive, validate, quarantine, scan, inventory, analyze, and deliver work; maintain evidence, work products, history, and audits; administer subscriptions, additional jobs, payments, cancellations, and support; communicate; secure and debug operations; prevent misuse; comply with law; and perform the limited improvement in Section 4.
GC Total does not sell personal information. It will not silently add advertising, cross-context behavioral advertising, an advertising pixel, or a Google advertising service. Any such deployment requires prior data-flow and legal review, an updated notice, and required consent, opt-out, or browser-signal controls.
4. Internal improvement, exclusions, and opt-out
For ordinary eligible projects, improvement use is on by default under the accepted Terms. GC Total may use uploaded documents, extracted data, outputs, corrections, and accept/reject feedback internally to operate, evaluate, train, fine-tune, and improve GC Total-owned agents and models, including extraction accuracy and quantity takeoff for future runs and customers.
GC Total does not sell that material, disclose it publicly, use it for unrelated advertising, or authorize third-party providers to train general-purpose or provider-owned models. Project and customer provenance, access and confidentiality controls, and reasonable identifier minimization continue.
A customer may opt out at any time through legal@gctotal.com or a signed order or Data Handling Profile. Opt-out immediately stops new selection and future training use. Raw documents, extracted training examples, and identifiable feedback are removed from retained improvement corpora within 30 days and are not reused. GC Total does not promise retrospective untraining.
Sensitive, specially confidential, security-sensitive, government-controlled, export-controlled, owner-restricted, NDA-restricted, or otherwise contract-restricted material never enters the improvement corpus. No-retention disables improvement at intake. Processing fails closed when the approved provider and storage route cannot enforce the profile.
Material marked confidential, or that GC Total knows or reasonably should know is confidential or use-restricted, is excluded regardless of the default. GC Total reviews retained improvement material at least annually and removes it when it is no longer reasonably needed for the stated improvement purpose.
5. Disclosures and recipients
GC Total may disclose information to customer-authorized users and recipients; contracted identity, authentication, hosting, database, storage, email, billing, compute, AI/model-routing, security, and support providers; advisers bound by confidentiality; a protected successor or transaction counterparty; and authorities or others when lawfully required or necessary to protect rights, safety, the service, customers, or the public.
GC Total does not make Customer Content public. Service-delivery processing does not itself authorize provider training. A Data Handling Profile may narrow the provider route.
6. Retention and deletion
| Category | Default period or criterion | Deletion and backup treatment |
|---|---|---|
| Project originals, material prompts/responses, evidence, communications, audits, and workbook versions | Active relationship plus seven years after last project activity | Delete from active systems after the period unless profile, dispute, law, or Legal Hold requires otherwise; rolling backups expire within 35 days |
| Account, contract, billing, tax, consent, legal-request, and transaction records | Seven years after account closure or transaction, as applicable | Delete subject to accounting, tax, dispute, and legal duties |
| Prospect and ordinary support records | Two years after last interaction | Delete unless converted to an active customer record or preserved for a dispute |
| Security and access logs | One year | Delete unless needed for an active security investigation or Legal Hold |
| Rejected or quarantined files | No more than 30 days | Delete sooner when safely possible; an investigation, law, or Legal Hold may extend |
| Reproducible Technical Intermediates | No more than 30 days after a terminal Processing Run | Delete unless materially supporting a delivered conclusion or a profile or Legal Hold requires them |
| Improvement corpus material | While eligible and reasonably needed, with necessity reviewed at least annually | Remove when no longer needed or within 30 days after verified opt-out; do not reuse source material; no promise to reverse completed model updates |
| No-retention project content | Only as needed to scan, process, verify, and deliver | Delete customer files, material prompts/responses, derived data, and server-side deliverables within 30 days after final delivery or sooner if signed terms require |
| Deletion proof and identity/hash tombstones | Minimum information needed to prove scope and completion | Retain under the applicable account, consent, security, or legal-request schedule without retaining deleted content |
A Data Handling Profile may require a shorter or longer period. A Legal Hold, mandatory law, security investigation, payment dispute, or legal claim may suspend deletion for affected material. GC Total documents reason, scope, provider propagation, backup treatment, and completion and does not promise immediate erasure from every backup.
A verified deletion request is completed within 30 days when no exception applies. The broader request periods in Section 8 still govern communications and appeals.
7. Current website, authentication, billing, and AI providers
GC Total uses or may use the providers and provider categories below as needed for the customer’s route and enabled features. Not every provider receives every customer’s information. GC Total limits each disclosure to information reasonably needed for that function and may replace a provider with one that performs a substantially similar function under compatible protections.
| Provider or category | Function | Information involved | Use limits |
|---|---|---|---|
| Clerk | Identity, authentication, organizations, and sessions | Business-user identity, organization, session, device, IP-address, and configured profile data | Account and service security; not project-document processing |
| Stripe | Checkout, billing, subscriptions, tax, and fraud prevention | Billing, invoice, transaction, payment-method, tax, device, account, and fraud data | No project documents or GC Total improvement-corpus material |
| Google Fonts | Public-site font delivery | IP address, requested URL, browser or operating-system headers, and referrer | No project documents; not used by GC Total for targeted advertising |
| Railway and PostgreSQL | Application hosting, runtime, and database | Account, service, project, operational, and security data needed to run the service | Service delivery, security, support, and retention under this Notice |
| Backblaze B2 | Object storage | Customer files, work products, related metadata, and backups | Route and retention restrictions apply |
| Postmark | Transactional email | Recipient, sender, delivery metadata, and service-message content | Transactional communications; avoid restricted project content in ordinary email |
| Modal | Compute and document processing | Project files, excerpts, derived data, outputs, and processing metadata needed for the assigned run | Route and Data Handling Profile restrictions apply |
| OpenRouter and routed model providers | AI routing and model processing | Prompts, necessary project excerpts, responses, and processing metadata | No provider training on project material; restricted and no-retention routes fail closed |
Clerk states that its required authentication cookies cannot be disabled and that Customer Personal Data is deleted within 90 days after termination or expiry under its DPA. Stripe states that roles depend on product and context and that some payment data supports fraud- and loss-prevention model training. These payment uses are separate from GC Total’s project improvement program. Managed Payments, if enabled, changes checkout, support, refunds, and deletion and requires a new review.
8. Privacy requests and appeals
Requests may be submitted to legal@gctotal.com or the registered-office/legal mailing address without creating a new account. GC Total supports access, correction, deletion, a portable copy, training opt-out, and applicable sale, targeted-advertising, or qualifying-profiling opt-outs.
GC Total will authenticate the requester and authorized agent, acknowledge within 10 business days, and respond without undue delay and within 45 calendar days. One explained additional 45-day extension may be used when reasonably necessary. Up to two requests per person annually are free unless manifestly unfounded, excessive, or repetitive.
GC Total explains denials, accepts appeals through the same channels, decides appeals in writing within 60 days, supplies an applicable attorney-general complaint route, and does not discriminate for exercising rights. Customer-controlled project requests may be referred to the customer and assisted under the DPA.
GC Total honors the access, correction, deletion, portability, and training opt-out choices described here for verified U.S. requesters even when a particular state law does not require every choice. GC Total recognizes an authorized agent when authority and identity can be verified. GC Total does not currently sell personal information or use it for targeted advertising. If that changes, GC Total will update this Notice before use and honor applicable browser-based universal opt-out signals, including Global Privacy Control.
This Notice serves as GC Total’s online notice at collection when it is presented or linked at or before the point where personal information is collected.
9. Security, children, changes, and contact
GC Total applies safeguards designed for the service and information as described in the Trust and Accessibility Statement and applicable contract. No system is guaranteed secure, and this Notice makes no certification or data-residency promise.
The service is not directed to children and does not permit users under 18. A child-data issue outside authorized business use will be quarantined and routed for privacy, security, and deletion review.
GC Total will date each version and communicate material changes through the account email and, where appropriate, the website or service. It will not retroactively expand an improvement license or materially different use without required notice, agreement, or consent.
Privacy questions, requests, and appeals: legal@gctotal.com or the registered-office/legal mailing address shown above.