GAIA Civil website privacy
Privacy Policy
This policy describes the GAIA Civil public website and contact workflow operated by Pegasus Strategies LLC. It does not replace a client agreement governing project, customer, or proprietary data used in the application.
Effective
Information the website collects
The contact form asks for a name, work email, company, GAIA Civil inquiry topic, and an optional short message. It also uses a hidden spam field and a submission-start timestamp. Do not include confidential project documents, credentials, pricing, or other sensitive information in the message.
The production website uses Google Analytics 4 for website measurement. GAIA Civil sends a canonical page location limited to an approved path and campaign-tag allowlist, a referring-site origin when available, and a small allowlist of interactions such as contact calls to action, form start, coarse failure class, acknowledged form success, and ORION workflow-tour steps. Google Analytics also collects standard user and session measurements, approximate location, browser and device information, language, screen information, and ordinary network metadata.
Pegasus Strategies does not send contact names, email addresses, company names, messages, delivery IDs, CRM identifiers, document content, project information, arbitrary URLs, or raw errors as custom analytics data. The site does not configure a user ID. Its code denies advertising storage and advertising-user-data consent, disables Google Signals and advertising personalization, and does not initialize analytics when a browser sends Global Privacy Control or a Do Not Track value of 1.
Hosting and server systems may process technical request data such as IP address, request time, user agent, response status, and diagnostic logs. The GAIA Civil site stores one functional preference in browser local storage so it can remember whether a visitor selected its light, dark, or system theme. That preference contains no contact information and is not used for analytics or advertising.
How contact information is used
When inquiry delivery is enabled, submitted contact information is used to review and respond to the selected GAIA Civil inquiry, operate spam and rate-limit controls, and diagnose delivery failures. The website does not include a public chatbot or project-file upload surface.
Website analytics is used to understand which sources and public pages lead to product interest, where the contact path loses visitors, and which content merits improvement. It is not configured for advertising audiences, session replay, user-provided identifiers, or automated decisions about a submitted inquiry.
Validated inquiries are sent through the canonical website's same-origin GAIA Civil server function to the selected business workflow and CRM destination. The website reports success only after the delivery workflow returns its required private acknowledgement.
Providers, subprocessors, and processing locations
The canonical website uses Firebase Hosting and a dedicated Firebase server function in the configured production region. A public preview may use separate preview hosting and does not submit contact inquiries. Provider account settings and deployment region can affect operational logging, retention, and processing location.
Zoho Flow and Zoho CRM are the selected contact workflow and business-record destination. In production, accepted inquiries are routed to the records used for review and response. Provider settings govern access, retention, processing region, operational logs, and any relevant subprocessors.
Google processes website analytics for the GAIA Civil website under the approved account and applicable terms. Processing locations, subprocessors, data-sharing settings, account access, two-factor authentication, retention, deletion, and any cross-border transfer terms remain part of the production approval record. Code disables advertising signals; the account must also exclude unapproved advertising links, audiences, user-provided-data collection, and Enhanced Measurement features.
Retention and deletion
Contact-request and diagnostic-log retention must follow the approved provider settings, deletion process, and legal or operational exceptions. Access must be limited to the people responsible for reviewing inquiries and operating the delivery path.
Website analytics is retained under the approved GAIA Civil property settings. Retention, deletion handling, and dashboard access are limited to the reviewed account configuration and approved users.
Security and data-handling boundaries
The website configures transport and browser security headers, keeps delivery credentials out of the browser bundle, validates form submissions again on the server, and requires an acknowledged provider response before reporting success. Final behavior must still be verified on the deployed canonical host.
Project or proprietary data used during a client engagement must be governed by the approved agreement and GAIA Civil application controls for that engagement, not by assumptions made from this public website policy.
Your questions and requests
Pegasus Strategies LLC operates the GAIA Civil website. Use the contact form and choose "GAIA Civil general inquiry" for a privacy question or request.
View contact optionsPolicy changes
Pegasus Strategies may revise this policy when the GAIA Civil website's actual data collection, providers, retention, or contact process changes. The effective date will be updated for substantive revisions.