Last Updated: July 25, 2026
This Privacy Policy describes how GEA Alliance, operating as a division of Gea Can Limited, a corporation duly registered in Canada with its principal place of business located at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada (CA), collects, uses, discloses, stores, and safeguards personal information obtained through our website located at https://www.geaalliance.mom, our related digital services, and our professional business operations. Throughout this policy, the terms we, us, our, and the Company refer to GEA Alliance and its parent entity Gea Can Limited.
We are deeply committed to protecting the privacy and security of all individuals whose personal information we process. This policy explains your rights regarding your personal data and describes the comprehensive measures we take to ensure its confidentiality, integrity, and availability. By accessing our website or utilizing our professional services, you acknowledge that you have read and understood this Privacy Policy and agree to the data handling practices described herein.
This policy applies to all information collected through our website, electronic communications, social media platforms, professional service engagements, industry events, and any other interaction where you provide personal data to us. It also covers information we may lawfully receive from third-party sources in connection with our business operations and the delivery of our computer systems design and related services.
When you interact with GEA Alliance, you may voluntarily provide certain categories of personal information. This information is collected when you fill out forms on our website at https://www.geaalliance.mom, correspond with us via electronic mail or telephone at service@geaalliance.mom or +1 (773) 897-4832, subscribe to our technical newsletters, request service proposals, participate in surveys or assessments, register for events, or engage our consulting and technical services. The types of information we may collect include:
When you visit our website at https://www.geaalliance.mom, certain technical information is automatically collected through server logs, cookies, web beacons, and similar tracking technologies. This information helps us understand how visitors interact with our digital properties, identify and resolve technical issues, enhance user experience, and maintain the robust security of our systems. The automatically collected data includes:
In the ordinary course of our business operations, we may receive personal information about you from third-party sources, including our technology alliance partners, data enrichment providers, credit reference agencies, publicly accessible databases and registries, social media platforms, professional networking services, and industry associations. We may also receive information when existing clients or business partners refer you to our services. All third-party data is handled in strict accordance with the terms established by the providing entity and the applicable requirements of relevant data protection legislation in Canada and other jurisdictions where we operate.
GEA Alliance and Gea Can Limited use the personal information we collect for the following legitimate business and commercial purposes:
The legal grounds upon which we process personal information depend on the nature of the data, the context of its collection, and applicable jurisdictional requirements. We process your information on the following legal bases:
GEA Alliance does not sell, rent, trade, or otherwise monetize your personal information to third parties for their own independent marketing purposes. We may share your information in the following carefully limited circumstances:
We engage carefully vetted third-party service providers to perform functions that support our business operations and professional service delivery. These providers are bound by comprehensive contractual agreements that require them to process personal information exclusively on our behalf, strictly in accordance with our documented instructions, and with appropriate technical and organizational security measures that meet or exceed industry standards. The categories of service providers we may share information with include cloud hosting and infrastructure providers, payment processors and financial institutions, communication and email delivery platforms, customer relationship management and support ticketing systems, analytics and website performance monitoring services, professional advisors including legal counsel and auditors, marketing automation platforms, and security and fraud prevention service providers.
Personal information may be shared within the Gea Can Limited corporate group, including its subsidiaries, operating divisions, and affiliated entities, for the purposes described in this policy. All entities within our corporate group are required to handle personal information in accordance with this Privacy Policy, applicable Canadian data protection standards including PIPEDA, and relevant international privacy frameworks.
We may disclose your personal information when we have a good faith belief, supported by reasonable assessment, that such disclosure is necessary to comply with applicable laws, regulations, legal processes, or enforceable governmental requests; to enforce our terms of service and contractual agreements; to detect, prevent, or address fraud, security breaches, or technical issues affecting our systems or those of our clients; or to protect the rights, property, or personal safety of GEA Alliance, Gea Can Limited, our clients, our employees and contractors, or the general public as required or expressly permitted by law.
In the event of a merger, acquisition, corporate reorganization, sale of all or substantially all assets, financing transaction, bankruptcy proceeding, or similar corporate transaction involving GEA Alliance or Gea Can Limited, personal information held by us may be among the assets transferred to the successor entity or acquiring party. You will be provided with reasonable notice of any such change in ownership or control of your personal information, as well as any meaningful choices you may have regarding the continued processing of your information by the successor entity.
We may share your personal information with third parties for purposes not described in this policy when we have obtained your explicit, informed consent to do so. You retain the right to withdraw your consent at any time by contacting us using the information provided in Section 12 of this policy, subject to legal and contractual limitations.
We retain personal information only for as long as is reasonably necessary to fulfill the purposes for which it was originally collected, including to satisfy any legal, regulatory, tax, accounting, audit, or reporting requirements applicable to our operations in Canada and other jurisdictions. The specific retention period applied to any category of personal information depends on the nature of the information, the purpose of its collection, and the applicable legal framework.
When determining the appropriate retention period for personal information, we carefully consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure; the specific purposes for which we process your personal information and whether we can reasonably achieve those purposes through alternative means; contractual obligations we have entered into with clients and technology partners; and applicable legal and regulatory requirements in the jurisdictions where we operate our business.
Upon expiration of the applicable retention period, personal information is securely deleted, irreversibly destroyed, or comprehensively anonymized in accordance with our established data disposal policies and industry best practices. In certain cases, we may retain information in a de-identified or aggregated form that can no longer be associated with an identifiable individual, for legitimate research, statistical analysis, or business planning purposes.
Specific retention practices include: client project data and deliverables are retained for the duration of the engagement plus a period of seven years to comply with tax, contractual, and professional liability obligations; marketing communications data and consent records are retained until you unsubscribe or formally withdraw consent, plus a reasonable period for audit trail purposes; website usage logs and analytics data are retained for up to twenty-four months; and employment and recruitment-related data is retained in strict accordance with applicable Canadian employment and human rights legislation.
GEA Alliance and Gea Can Limited implement and maintain industry-leading technical, administrative, and physical security measures designed to protect personal information against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, access, or use. Our comprehensive security framework is aligned with recognized international standards and best practices relevant to the computer systems design and integrated services industry.
Our multilayered technical safeguards include end-to-end encryption for all data in transit using TLS 1.3 protocols with forward secrecy; encryption at rest using AES-256 encryption for all stored personal data; mandatory multi-factor authentication for all system and platform access; rigorous network segmentation with next-generation firewalls; advanced intrusion detection and prevention systems with real-time threat intelligence feeds; regular vulnerability scanning and independent third-party penetration testing; automated patch management and security update protocols; continuous security event monitoring, correlation, and logging; distributed denial-of-service protection at the network edge; and secure, encrypted backup systems with regularly tested restoration and business continuity procedures.
Our comprehensive administrative controls include documented information security policies and procedures reviewed and updated quarterly; mandatory annual security awareness training for all employees and contractors with specialized modules for technical personnel; strict role-based access controls implementing the principle of least privilege across all systems; rigorous periodic access review and prompt revocation processes; thorough vendor security risk assessments and ongoing due diligence monitoring; detailed incident response and business continuity plans that are tested through regular tabletop exercises and live drills; and continuous compliance monitoring supported by internal and external audit programs.
Our physical security controls include access-controlled facilities requiring multi-factor authentication for entry; continuous high-definition video surveillance of all critical infrastructure areas; environmental monitoring systems with automated alerts and fire suppression; redundant and diverse power supplies with automatic failover and backup generation; redundant network connectivity through multiple carriers with diverse fiber paths; secure destruction procedures for all physical media containing personal information; and comprehensive visitor access management, logging, and escort procedures.
While we employ commercially reasonable and industry-standard measures to protect your personal information, no method of electronic transmission or storage is absolutely immune to all threats. We cannot and do not guarantee absolute security, but we continuously monitor, assess, and improve our security posture to address the evolving threat landscape. In the unfortunate event of a data breach that affects your personal information, we will notify you and relevant regulatory authorities in strict accordance with applicable breach notification laws and within the timeframes prescribed by those laws.
GEA Alliance is headquartered in Markham, Ontario, Canada, and our parent company Gea Can Limited is registered at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada (CA). As a global provider of computer systems design and related services operating in the Professional, Scientific, and Technical Services sector, we may process, store, and transfer personal information across international borders, including to countries where we maintain offices, engage service providers, or operate secure data centers to support our global client base.
When we transfer personal information from one jurisdiction to another, we ensure that appropriate and legally adequate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws. These safeguards may include transferring data only to countries that have been formally recognized by relevant regulatory authorities as providing an adequate level of data protection; implementing Standard Contractual Clauses or equivalent data transfer agreements approved by relevant data protection authorities; ensuring that recipients adhere to binding corporate rules or certified privacy frameworks; obtaining your explicit consent for the specific transfer where required by applicable law; and conducting thorough transfer impact assessments to evaluate and mitigate any risks associated with cross-border data flows.
By using our services and voluntarily providing your personal information, you acknowledge and consent to the transfer, processing, and storage of your information in countries outside your country of residence, which may have different data protection standards than those applicable in your home jurisdiction.
Cookies are small text files that are placed on your device when you visit a website. They are widely used across the internet to make websites function efficiently, provide analytical information to website operators, remember user preferences, and enhance the overall browsing experience. Cookies may be set by the website you are directly visiting, known as first-party cookies, or by other services and platforms that provide embedded functionality on that website, known as third-party cookies.
Our website at https://www.geaalliance.mom employs the following categories of cookies:
You have the right and the technical ability to control the use of cookies through your web browser settings. Most modern web browsers allow you to manage cookies through their settings or preferences menus, including options to block all cookies, delete existing cookies, or receive a notification before a cookie is set on your device. Please note that disabling certain categories of cookies, particularly strictly necessary and security cookies, may significantly impact the functionality, performance, and security of our website.
To manage your cookie preferences, you can typically find these settings in your browser under Options, Settings, Preferences, or Privacy and Security. You may also utilize browser extensions and dedicated privacy tools to manage tracking across websites. For more detailed and current information about cookies and practical guidance on how to manage them, you may consult industry and regulatory resources such as the website of the Office of the Privacy Commissioner of Canada.
Depending on your jurisdiction of residence, you may have certain substantive rights regarding the personal information we hold about you. These fundamental privacy rights may include:
To exercise any of the rights described above, please contact us using the information provided in Section 12 of this policy. We will acknowledge receipt of your request promptly and provide a substantive response within the timeframe required by applicable law, which is typically within thirty calendar days. We may need to verify your identity through reasonable means before processing your request to ensure the security of your information and prevent unauthorized access. In certain cases, we may require additional specific information to confirm your identity with sufficient certainty or to clarify the precise scope and nature of your request.
There are circumstances defined by law where we may not be able to fully comply with your request, such as when fulfilling the request would adversely and disproportionately affect the rights and freedoms of other individuals, when we are legally required to retain the information for specific purposes, or when a statutory exemption applies under applicable data protection legislation. In any such case, we will provide you with a clear, reasoned explanation of why we are unable to fulfill your request in whole or in part.
You may opt out of receiving marketing and promotional communications from us at any time by clicking the unsubscribe link included at the bottom of every marketing email we send, by updating your communication preferences in your client portal account settings, or by contacting us directly with your opt-out request. Please note that even if you exercise your opt-out right for marketing messages, we may continue to send you essential transactional and service-related communications that are necessary for the operation of your account, the performance of a contract, or our ongoing professional business relationship.
Our website currently does not respond to or alter its behavior based on Do Not Track signals transmitted by web browsers. Do Not Track is a preference you can set in your browser to inform websites that you do not wish to be tracked across different sites. Due to the lack of a uniform, widely adopted industry standard for interpreting and responding to DNT signals, we continue to monitor technological and regulatory developments in this area and will adjust our practices as appropriate and as consistent standards emerge.
Our website and professional services are designed and intended exclusively for business professionals, corporate clients, and individuals of legal age to enter into binding commercial agreements. We do not direct our services to, target, or knowingly collect, use, or disclose personal information from children under the age of sixteen. If we become aware that we have inadvertently collected personal information from a child without verified and documented parental consent, we will take immediate and comprehensive steps to delete such information from all of our systems and records.
Parents and legal guardians who have reason to believe that their child has provided personal information to us through our website or otherwise should contact us immediately using the contact details provided in Section 12 of this policy. We will investigate the matter with appropriate urgency and take all necessary corrective actions in full accordance with applicable laws and regulations concerning the protection of children's privacy in the online environment.
GEA Alliance and Gea Can Limited reserve the right to update, modify, amend, or replace this Privacy Policy at any time in our sole discretion to accurately reflect changes in our information practices, evolving legal obligations, or developments in industry standards and best practices. When we make material changes to this policy, we will provide you with prominent and timely notice through a conspicuous announcement on our website at https://www.geaalliance.mom, by sending a notification to the email address associated with your account if one exists, or through other appropriate and effective communication channels.
The Last Updated date displayed at the top of this policy indicates when it was most recently revised and should be used as your reference point. We strongly encourage you to review this Privacy Policy at regular intervals to stay informed about how we protect your personal information. Your continued use of our website and professional services following the posting of any modifications to this policy constitutes your acknowledgment of the changes and your acceptance of the updated policy terms.
In the specific event of a material change that would significantly and substantively alter how we process your personal information relative to the practices described at the time of collection, we will seek your explicit, affirmative consent before applying any new or modified practices to your previously collected personal data, where such consent is required by applicable law.
If you have any questions, concerns, requests, or complaints regarding this Privacy Policy or our data protection practices, or if you wish to exercise any of your privacy rights as described in this policy, please contact us through any of the following channels. We treat all privacy-related inquiries with the utmost seriousness and urgency.
Privacy Officer
GEA Alliance, a division of Gea Can Limited
108-200 Town Centre Blvd
Markham - L3R 8G5
Canada (CA)
Email: service@geaalliance.mom
Phone: +1 (773) 897-4832
Website: https://www.geaalliance.mom
We endeavor to acknowledge your privacy-related inquiry within forty-eight business hours and to provide a comprehensive substantive response within the timeframe required by applicable law. If you are not satisfied with our response to your concern, you have the right to contact the appropriate data protection supervisory authority in your jurisdiction, including the Office of the Privacy Commissioner of Canada for matters arising under Canadian federal privacy legislation.
For individuals located in Canada, this Privacy Policy is designed to comply in all material respects with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Ontario's Personal Health Information Protection Act where relevant. As a Canadian company headquartered at 108-200 Town Centre Blvd, Markham - L3R 8G5, Canada, we fully adhere to the ten fair information principles established under Canadian privacy law: accountability, identifying purposes, consent, limiting collection, limiting use and disclosure, accuracy, safeguards, openness, individual access, and challenging compliance.
Canadian residents have the right to access their personal information held by our organization and to challenge the accuracy and completeness of that information. They may also withdraw consent to the continued collection, use, and disclosure of their personal information at any time, subject to reasonable legal and contractual restrictions. Formal complaints regarding our handling of personal information may be directed to the Office of the Privacy Commissioner of Canada at their designated contact channels.
For individuals located in the European Economic Area or the United Kingdom, we process personal information in accordance with the General Data Protection Regulation and the UK Data Protection Act 2018 respectively. Under these comprehensive regulatory frameworks, you have specific and enforceable rights including the right to access, rectify, erase, restrict processing, object to processing, and data portability of your personal data. You also have the unconditional right to lodge a formal complaint with a supervisory authority in your EU member state of habitual residence or with the UK Information Commissioner's Office as applicable.
The legal bases for our processing activities are fully described in Section 3.2 of this policy. For any transfers of personal data outside the EEA or United Kingdom, we implement the robust safeguards described in Section 7, including the use of European Commission-approved Standard Contractual Clauses and comprehensive transfer impact assessments.
For individuals located in the United States, we comply with all applicable federal and state privacy and data protection laws. If you are a resident of a state that has enacted comprehensive consumer privacy legislation, such as the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, or similar privacy laws enacted in other states, you may have additional specific rights regarding your personal information beyond those described in the general sections of this policy.
These enhanced rights may include the right to know what categories of personal information we collect and how we use, disclose, and share it; the right to access and obtain a portable copy of your personal information; the right to request deletion of your personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising; and the right to be free from discrimination for exercising these statutory rights. To exercise any of these rights, please contact us using the information provided in Section 12.
GEA Alliance and Gea Can Limited are firmly committed to complying with all applicable data protection and privacy laws in every jurisdiction where we conduct business operations. If your country or territory of residence provides specific privacy rights beyond those comprehensively described in this policy, we will respect, honor, and facilitate the exercise of those rights in full accordance with the applicable legal framework. Please contact us using the information in Section 12 if you have any questions about jurisdiction-specific rights that may apply to your particular situation.
Our website may, from time to time, contain links to external websites, web applications, and online services operated by third parties that are not owned, controlled, or operated by GEA Alliance or Gea Can Limited. This Privacy Policy applies exclusively and solely to information collected through our own website at https://www.geaalliance.mom and the professional services we directly provide. We bear no responsibility whatsoever for the privacy practices, content accuracy, security posture, or data handling policies of any third-party websites, applications, or digital services.
We strongly and unequivocally encourage you to carefully review the privacy policies and terms of service of every website you visit and every online service you use, particularly before submitting any personal information of any kind. The mere inclusion of a hyperlink to a third-party website on our site does not constitute our endorsement, approval, or certification of that website, its content, or its privacy and security practices. All of your interactions with third-party websites and services are governed exclusively by their own terms, conditions, and policies, not by this Privacy Policy or our Terms of Service.
For our enterprise and institutional clients who engage GEA Alliance to provide computer systems design, cloud infrastructure management, software and platform engineering, cybersecurity services, data systems and analytics architecture, IT consulting, and related professional and technical services, we offer a comprehensive Data Processing Addendum that formalizes our respective roles, responsibilities, and obligations under applicable data protection laws worldwide.
The Data Processing Addendum addresses the specific subject matter and duration of processing; the detailed nature and business purpose of processing; the types and categories of personal data that will be processed; the categories of data subjects whose information may be involved; the technical and organizational security measures we implement and maintain; and the respective rights, obligations, and liabilities of each party under the governing data protection framework.
If your organization requires a signed Data Processing Addendum to formalize our mutual data protection commitments in connection with an existing or prospective service engagement, please contact us directly at service@geaalliance.mom. Our legal and compliance team will work with you to provide the appropriate documentation tailored to your specific compliance requirements, regulatory environment, and the precise scope of services being provided under the engagement.
This Privacy Policy constitutes the complete and entire agreement between you and GEA Alliance, a division of Gea Can Limited, regarding the collection, use, disclosure, and protection of your personal information through our website and professional services, superseding and replacing any prior communications, representations, or agreements on this specific subject matter.