1. Introduction
This Privacy Policy explains how Human-Centric AI Governance, LLC ("we," "us," "our," or "the Company") collects, uses, discloses, and protects personal information when you visit our website at https://hcaigov.com (the "Site") or interact with us through the Site, including by scheduling a consultation.
Human-Centric AI Governance, LLC is a Wyoming-formed Limited Liability Company providing AI governance, regulatory compliance, and third-party risk consulting services. We are committed to transparency in how we handle your personal information and to compliance with applicable data protection laws.
This Privacy Policy is designed to comply with major data protection laws including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and Brazil's Lei Geral de Proteção de Dados (LGPD). Visitors in other jurisdictions may have additional rights under their local laws; please contact us at [email protected] to exercise any data subject rights, and we will respond in accordance with applicable law.
2. Contact Information
For privacy-related inquiries, data subject rights requests, or any questions about this Privacy Policy, you may contact us through either of the following channels:
Mailing Address
Human-Centric AI Governance, LLC
c/o Registered Agents Inc.
30 N Gould St Ste R
Sheridan, WY 82801
United States
We will respond to verifiable data subject requests within the timeframes required by applicable law (typically 30 days under GDPR, 45 days under CCPA).
3. Information We Collect
We collect personal information only when you voluntarily provide it to us, or automatically through standard web technologies as described below.
3.1 Information You Provide Directly
When you book a consultation through our scheduling tool (Calendly), you provide the following information:
- First name and last name
- Email address
- Role and organization (the company or entity you represent)
- Description of your AI tool, regulation, or compliance situation
- Description of what a successful outcome from the consultation would look like for you
3.2 Information Collected Automatically
When you visit the Site or use the embedded scheduling widget, certain information is collected automatically by our service providers:
- IP address (collected by Calendly when the booking widget is loaded)
- Time zone (collected by Calendly to display accurate booking times)
- Page views, referrer URLs, visitor location at country level, browser type, and device type (collected by Carrd.co, our website host, for basic analytics)
- Server log information including IP addresses, request timestamps, and user agent strings (standard web server logging by Carrd.co)
3.3 Information We Do NOT Collect
Human-Centric AI Governance, LLC does not accept payments through this website. All consulting engagements are paid via direct invoice through our business banking provider (Mercury). No credit card, banking, or other payment data is collected, processed, or stored by this website.
Additionally, we do not collect:
- Protected Health Information (PHI) as defined under HIPAA — our engagement model does not involve receipt or processing of PHI
- Social Security numbers, government-issued ID numbers, or other sensitive personal identifiers
- Biometric information
- Children's data — this Site is not directed at children under 13
4. Cookies and Tracking Technologies
The Site uses cookies set by our third-party service providers. We have audited the cookies present on the Site and disclose each one below in the interest of full transparency.
4.1 Cookies Currently Set on This Site
All cookies on this Site are set by the embedded Calendly scheduling widget (calendly.com domain). Carrd.co (our website host) does not set additional first-party tracking cookies.
In plain terms: When you visit this Site, the scheduling tool we use (Calendly) automatically loads a small piece of software that sets several cookies on your browser. Some cookies keep the site secure and are always on (essential cookies). Some track anonymous visitor behaviour for Calendly's analytics and can be declined (non-essential cookies). The CookieYes consent banner that appears when you visit the Site lets you choose which cookies you accept, decline, or customise. The table below describes each cookie in detail.
| Cookie Name | Provider | Purpose | Type |
|---|---|---|---|
__cf_bm | Cloudflare (Calendly) | Bot management and security | Essential |
_cfuvid | Cloudflare (Calendly) | Unique visitor identification, load balancing | Essential |
OptanonAlertBoxClosed | CookieYes (via OneTrust technology) | Remembers that you have seen the cookie consent banner so it does not appear again on every page visit | Essential |
OptanonConsent | CookieYes (via OneTrust technology) | Saves your cookie preferences — what you accepted or declined — so your choices are respected on future visits | Essential |
ajs_anonymous_id | Segment.io (Calendly) | Anonymous user analytics via Calendly's standard integration | Non-essential |
__stripe_mid | Stripe (via Calendly) | Fraud detection on Calendly's infrastructure; see Section 4.3 | Non-essential |
4.2 Cookie Consent Banner (CookieYes)
This Site uses CookieYes, a third-party cookie consent management platform, to obtain and record your cookie consent preferences. When you visit the Site, a consent banner appears allowing you to Accept All cookies, Reject All non-essential cookies, or Customise your preferences by category. Your consent choices are recorded and respected for subsequent visits. CookieYes supports GDPR (EU & UK), LGPD (Brazil), CCPA (California), and other major privacy frameworks. For more information, see CookieYes's privacy policy at cookieyes.com/privacy-policy.
4.3 Note on the Stripe Cookie
The Calendly scheduling widget on this Site loads code from Stripe (a payment processor) as part of Calendly's standard integration. While Human-Centric AI Governance does not accept payments through the website, this cookie (__stripe_mid) is set by Stripe for fraud detection purposes on Calendly's infrastructure. We do not have access to or control over this cookie. To opt out, see Stripe's privacy policy at stripe.com/privacy.
4.4 Managing Cookies
You can control cookies through your browser settings:
- Most browsers allow you to block or delete cookies through their privacy settings
- Blocking cookies may affect the functionality of the Calendly scheduling widget
- You can manage or change your cookie consent preferences at any time by clicking the cookie settings icon on the Site (provided by CookieYes)
5. How We Use Your Information
We use the personal information we collect for the following purposes:
- Responding to inquiries and scheduling consultations: to confirm your booking, send meeting details, and prepare for the consultation.
- Following up after consultations: to send proposals, statements of work, or other engagement materials when appropriate.
- Improving the website: using aggregate analytics data to understand visitor patterns and improve content.
- Legal and compliance purposes: to comply with applicable laws, respond to lawful requests, and protect our legal rights.
We do NOT use your personal information for:
- Marketing to past visitors through retargeting ads or third-party advertising
- Selling or sharing your data with third parties for advertising purposes
- Newsletter or marketing email distribution (unless you specifically opt in)
- Automated decision-making or profiling with legal or significant effects on you
6. Third-Party Service Providers
We use the following third-party service providers to operate the Site and conduct our business. Each provider has its own privacy practices, governed by its own privacy policy:
6.1 Service Providers Receiving Visitor Data
- Carrd.co (US-based) — Website hosting and basic analytics. Privacy policy: carrd.co/privacy
- Calendly (US-based) — Meeting scheduling and intake form processing. Calendly receives all data you submit through the booking widget. Privacy policy: calendly.com/privacy
- Zoho Mail (India-headquartered with US data centers) — Email service for our business address ([email protected]). Receives your email communications when you contact us. Privacy policy: zoho.com/privacy.html
- Google Calendar and Google Meet (Google LLC, US-based) — When you book a consultation, your name, email, booking time, and intake form responses are added to our business calendar. Consultations are conducted via Google Meet. Privacy policy: policies.google.com/privacy
- CookieYes (Cyrus Digital Ltd, UK-based) — Cookie consent management platform. When you visit the Site, CookieYes displays a consent banner and records your cookie preferences. Non-essential cookies are blocked until you provide consent. Privacy policy: cookieyes.com/privacy-policy
6.2 International Data Transfers
Most of our service providers are based in the United States. Zoho is headquartered in India with data centers in the United States. By using the Site, you acknowledge that your personal information may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction.
For visitors in the European Economic Area (EEA) or other jurisdictions with cross-border transfer restrictions, our US-based service providers have implemented Standard Contractual Clauses (SCCs) or other appropriate safeguards under applicable law. CookieYes is based in the United Kingdom (UK). The European Commission has issued an adequacy decision recognising that UK data protection law provides equivalent protection to GDPR. Accordingly, transfers of personal data to CookieYes do not require additional safeguards beyond those already in place.
7. Data Retention
We retain personal information only as long as necessary for the purposes described in this Privacy Policy. Specific retention periods:
- Inquiries that do not convert to engagements: retained for 12 months from the date of last contact, then deleted. This allows for reasonable follow-up if regulatory developments make our services relevant to your stated situation.
- Inquiries that convert to engagements: retained for the duration of the engagement plus seven (7) years following engagement conclusion, consistent with applicable tax and legal record retention requirements.
- Website analytics data: retained according to Carrd.co's standard retention practices; we do not store or maintain this data separately.
- Cookie data: retained according to each cookie's expiration date as listed in Section 4.1.
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
8.1 Rights Available to All Visitors
- Right to access: request a copy of personal information we hold about you
- Right to correct: request correction of inaccurate personal information
- Right to delete: request deletion of your personal information (subject to legal retention obligations)
- Right to object: object to processing of your personal information for certain purposes
8.2 Additional Rights for EU/UK Visitors (GDPR)
- Right to portability: receive your personal information in a structured, commonly used format
- Right to restrict processing: limit how we use your personal information
- Right to withdraw consent: where processing is based on consent, withdraw that consent at any time
- Right to lodge a complaint with your local data protection authority
8.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to know what personal information is collected and how it is used
- Right to delete personal information (with limited exceptions)
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (note: we do not sell or share personal information for cross-context behavioral advertising)
- Right to non-discrimination for exercising your privacy rights
8.4 Additional Rights for Brazilian Visitors (LGPD)
- Right to confirmation of processing and access to data
- Right to anonymization, blocking, or deletion of unnecessary or excessive data
- Right to data portability to another service or product provider
- Right to information about public and private entities with which we share data
8.5 How to Exercise Your Rights
To exercise any of these rights, please contact us using the methods in Section 2. We will respond to verifiable requests within the timeframes required by applicable law. We may need to verify your identity before processing certain requests.
9. Data Security
We take reasonable and appropriate measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
- Multi-factor authentication on business-critical accounts
- Encryption in transit (HTTPS/TLS) for all data submitted through the Site
- Strong access controls limiting who can access personal information
- Selection of reputable service providers with established security practices
- Regular review of our security practices and the security practices of our service providers
However, no method of transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
10. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities without undue delay, and in any event within 72 hours of confirming a reportable breach, in accordance with GDPR Article 33 and applicable US state law.
Notification will include, where applicable:
- The nature of the breach and categories of personal information affected
- The approximate number of individuals affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further inquiries
11. Children's Privacy
The Site is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe we may have collected information from a child under 13, please contact us using the methods in Section 2.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or applicable law. When we make material changes, we will:
- Update the 'Effective Date' at the top of this Privacy Policy
- Post the updated Privacy Policy on the Site
- For material changes affecting how we use existing personal information, notify affected individuals through the email address provided at booking
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Governing Law
This Privacy Policy and any disputes arising from it shall be governed by and construed in accordance with the laws of the State of Wyoming, United States, without regard to its conflict of law principles. This does not limit any data subject rights you may have under applicable privacy laws in your jurisdiction.
© 2026 Human-Centric AI Governance, LLC · A Wyoming limited liability company