Privacy Policy

Last updated: 16 September 2026

1. Who we are

This website, gaianavia.com (the “Website”), is operated by GAIA GROUP GLOBAL ApS, which trades under its registered secondary name (binavn) “Gaianavia” (“we”, “us”, “our”). We are the data controller for the personal data described in this policy.

GAIA GROUP GLOBAL ApS · CVR 36021551 · Classensgade 15, 2100 Copenhagen, Denmark · Email: privacy@gaianavia.com

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data-protection law.

2. What we collect and why

For visitors browsing gaianavia.com, Gaianavia is an informational website: we do not operate public user accounts and we do not maintain a database of visitor personal data. We process personal data only in the following limited situations:

Contact form. When you use the contact form, we collect the email address and message content you provide, so that we can read and respond to your enquiry. Lawful basis: our legitimate interest in responding to enquiries and, where relevant, taking steps at your request prior to entering into a contract (GDPR Art. 6(1)(f) and 6(1)(b)).

On-site AI demo. Our interactive demo lets you enter a company name, which is sent to our AI provider to generate a response. If you choose to type additional text, that text is processed for the same purpose. We do not require or ask for personal data here, and we recommend you do not enter any. Lawful basis: our legitimate interest in providing an interactive demonstration of our service (GDPR Art. 6(1)(f)).

Gaianavia Property Twin. For clients under an active engagement, we operate a separate, invite-only client portal at twin.gaianavia.com (“Property Twin”). Using it requires an account - an email address and a password, which we store only as a salted cryptographic hash, never in plain text. The portal may also process property, portfolio, and business data that you or your organisation provide as part of the engagement, which can incidentally include personal data such as tenant or counterparty names in lease and property documents. Access is granted only to individually invited users, there is no public self-registration, and access can be revoked at any time. Lawful basis: performance of our contract with your organisation (GDPR Art. 6(1)(b)) and our legitimate interest in providing and securing the service (GDPR Art. 6(1)(f)).

Server logs. Like any website, our hosting providers automatically record technical data - such as IP address, browser type, and request metadata - in short-lived logs. Lawful basis: our legitimate interest in operating, securing, and preventing abuse of the Website and Property Twin (GDPR Art. 6(1)(f)).

We do not use analytics, advertising, or social-media tracking, and we do not build marketing or behavioural profiles of visitors.

3. Cookies and tracking

We do not use cookies for analytics, advertising, or tracking, and we do not set non-essential cookies. Because of this, the Website does not display a cookie-consent banner. Any data handling is limited to what is technically necessary to serve and secure the pages you request.

To improve your experience we store a single functional item in your browser’s local storage, which records that the introductory animation has already been shown. It contains no identifier, is never transmitted to us or to any third party, and is removed when you clear your site data.

4. How long we keep it

Contact-form and email correspondence: kept while we handle your enquiry and for up to 24 months after our last exchange, after which it is deleted, unless we are required to retain it for legal or accounting reasons.

AI-demo inputs: not stored by us beyond the short-lived server logs below; our AI provider processes them transiently to generate a response and does not use them to train its models.

Property Twin accounts and data: kept for the duration of your organisation’s active engagement with us, and deleted within 90 days of the engagement ending or the account being revoked, whichever is sooner, unless we are required to retain it for legal or accounting reasons.

Server logs: automatically expire within approximately 7 days.

5. Who we share it with

We do not sell your personal data. We share it only with the service providers (processors) that help us run the Website and communicate with you. Each is bound by a data-processing agreement and may only use the data to provide their service to us.

ProviderPurposeLocationTransfer safeguard
Vercel Inc.Website hosting, serverless functions, and short-lived request logsUSAEU Standard Contractual Clauses (Vercel DPA)
Formspree Inc.Processing and forwarding contact-form submissionsUSAEU Standard Contractual Clauses (Formspree DPA)
Anthropic PBCAI processing of company-name lookups entered in the on-site demoUSAEU Standard Contractual Clauses (Anthropic DPA); inputs are not used to train models
ImprovMXInbound email forwarding for @gaianavia.com addressesEU / USAEU Standard Contractual Clauses where a transfer occurs
Brevo (Sendinblue SAS)Outbound email delivery (SMTP)France (EEA)Processing within the EEA - no third-country transfer
Railway CorporationHosting for Gaianavia Property Twin (twin.gaianavia.com), our invite-only client portalUSAEU Standard Contractual Clauses (Railway DPA)

We may also disclose personal data where required by law, or in connection with a merger, acquisition, or sale of business assets.

6. International transfers

Some of our providers are located outside the European Economic Area (EEA), primarily in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (or another recognised safeguard) to ensure it receives an equivalent level of protection. The table in Section 5 sets out the safeguard applicable to each provider. You can request further detail on any specific transfer by contacting us.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected (rectification);
  • have your data erased (“right to be forgotten”);
  • restrict or object to our processing;
  • receive your data in a portable format;
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, email privacy@gaianavia.com. We will respond within one month. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet), www.datatilsynet.dk.

8. Security

The Website is served exclusively over encrypted HTTPS connections, and our providers encrypt personal data in transit and at rest. We apply appropriate technical and organisational measures to protect personal data, though no method of transmission or storage can be guaranteed to be completely secure.

9. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review it periodically.

10. Contact

Questions about this policy or our data practices? Contact GAIA GROUP GLOBAL ApS, Classensgade 15, 2100 Copenhagen, Denmark, or email privacy@gaianavia.com.