Legal

Privacy Policy

Gullia Filing LLC ("Gullia Filing", "we", "us" or "our") treats client data with the same care we expect from our own bank or lawyer. This policy explains what personal information we collect, why we collect it, how we protect it, who we share it with, and the rights you have under the EU GDPR, UK GDPR, California CCPA/CPRA, Canadian PIPEDA and UAE PDPL.

Effective date: 17 July 2026 · Last updated: 17 July 2026 · Version 3.0

AES-256 encryption at rest
TLS 1.3 in transit
KYC and AML compliant
Data residency options

1. Overview & Scope

This Privacy Policy applies to personal data we process through gulliafiling.com, related subdomains, our client portal, our email and messaging channels, and any professional service we provide to clients in the United States, United Kingdom, Canada and the United Arab Emirates. It should be read together with our Terms of Service.

2. Controller, Processor & Contact

Gullia Filing LLC is the data controller of personal information we collect from prospective and existing clients. Where we process information on written instructions from a client (for example, personal data of members, directors or beneficial owners of an entity we are forming or administering for you) we act as a data processor on your behalf. In every case, our Data Protection Officer can be reached at privacy@gulliafiling.com.

3. Information We Collect

  • Identity and contact data: full legal name, date of birth, nationality, residential address, email and phone number.
  • Government identification: passport, national ID, driver's licence, tax identification numbers (SSN, ITIN, EIN, UTR, BN, TRN, Emirates ID), proof of address (utility bill or bank statement dated within the last 90 days), and a selfie or live liveness check where required by our licensing partners.
  • Business information: entity name, jurisdiction, ownership structure, directors, officers, registered agent, business activity, source of funds, source of wealth and financial summaries submitted for accounting or tax.
  • Screening data: sanctions, PEP and adverse-media results returned by our identity verification and compliance vendors.
  • Payment data: billing address and the last four digits of your card. Full card numbers are processed directly by our PCI-DSS Level 1 payment processors and are not stored on our servers.
  • Communications: messages, attachments, meeting notes and, where you consent, call recordings between you and our concierge team.
  • Technical and usage data: IP address, device identifiers, browser type, pages visited, referring URL and timestamps, collected via cookies and similar technologies.

4. How We Use Your Information

  • To create, file and maintain your business entity with the relevant authority.
  • To perform identity verification, KYC, customer due diligence, AML, sanctions, PEP and beneficial ownership screening required by law and by our licensed filing and registered-agent partners.
  • To process payments, issue invoices and prevent fraud or chargeback abuse.
  • To provide client support, send service-related notices and respond to your requests.
  • To secure and improve the Services, troubleshoot, and develop new features.
  • To send marketing communications you have opted in to (unsubscribe any time).
  • To comply with legal obligations and to enforce our Terms.
  • Contract: to provide the Services you have requested and to take pre-contractual steps at your request.
  • Legal obligation: to meet KYC, AML/CTF, tax, accounting, corporate filing and beneficial ownership reporting requirements (for example the US Corporate Transparency Act, UK MLR 2017, Canada PCMLTFA and UAE Cabinet Decision No. 58 of 2020).
  • Legitimate interests: to operate, secure and improve our business, provided your interests and fundamental rights do not override those interests.
  • Consent: for non-essential cookies, optional marketing and for sensitive data where required. Consent can be withdrawn at any time.

6. Identity Verification, KYC & AML

As a professional filing intermediary we are required to identify and verify every beneficial owner and controlling person of an entity we help to form or administer. We collect certified identification and proof of address, screen against sanctions, PEP and adverse-media lists, and re-verify periodically or on a trigger event. We will refuse or terminate service where verification cannot be completed, where a customer refuses to provide required information, or where our licensed partners decline the file. Screening data is retained for the period required by applicable AML rules.

7. How We Share Information

We share personal data only as needed and only with:

  • Government and regulatory authorities: Secretaries of State, IRS, Companies House, HMRC, CRA, FTA, FinCEN, FINTRAC, DIFC, ADGM and equivalent bodies, for the purpose of your filings and any statutory reporting.
  • Licensed filing and registered-agent partners: only the personal data those partners require to accept, license and file your matter (see Section 8).
  • Service providers: payment processors, cloud hosting, identity verification, e-signature, email delivery, analytics and customer support, under written data-processing agreements.
  • Professional advisers: lawyers, accountants and auditors bound by confidentiality.
  • Successors in interest: in connection with a merger, acquisition or sale of assets, subject to equivalent privacy protections and prior notice where required.
  • When legally required: to comply with a subpoena, court order, warrant, regulatory demand or other lawful request.

We do not sell your personal information and we do not share it for cross-context behavioural advertising.

8. Licensed Agents & Filing Partners

To operate lawfully in each jurisdiction, Gullia Filing engages independent, locally licensed commercial registered agents, corporate service providers and freezone agents. By purchasing a service you authorise us to disclose to the applicable partner only the personal data reasonably necessary to onboard you, license your entity and file your paperwork. Those partners act as independent controllers or joint controllers under their own privacy notices and are contractually required to apply equivalent security and confidentiality standards.

9. International Data Transfers

We operate globally and may transfer personal data to countries other than the one in which you reside, including the United States, the United Kingdom, Canada, the UAE and India (support operations). For transfers out of the EEA, UK or Switzerland we rely on adequacy decisions or Standard Contractual Clauses (together with the UK International Data Transfer Addendum) and, where relevant, supplementary technical measures such as encryption in transit and at rest.

10. Data Retention

We retain personal data for as long as your account is active and for as long as needed to provide the Services, comply with our legal and AML record-keeping obligations (typically 5 years after the end of the business relationship in the UK and EU, 5 years in Canada and the UAE, and up to 7 years for US tax and filing records), resolve disputes and enforce our agreements. When no longer required, data is deleted or irreversibly anonymised.

11. Security & Breach Notification

We use administrative, technical and physical safeguards including TLS 1.3 in transit, AES-256 at rest, hardware-backed key management, role-based access controls, least-privilege service accounts, mandatory multi-factor authentication for staff, formal vendor risk reviews and continuous monitoring. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required and affected users without undue delay.

12. Your Privacy Rights

Subject to applicable law, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, to withdraw consent and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@gulliafiling.com. We will verify your identity and respond within the time limits set by applicable law (usually 30 days).

13. Cookies & Tracking

We use strictly necessary cookies to operate the Services and, only with your consent, analytics and marketing cookies (such as Google Analytics, Meta Pixel and LinkedIn Insight). You can manage cookie preferences through your browser settings or our on-site cookie banner. Do Not Track browser signals are honoured for optional cookies.

14. Marketing & Communications

Transactional emails (order updates, filing status, KYC requests, invoices, security notices) are essential to the Services and cannot be turned off while your account is active. Marketing emails and SMS are opt-in and include a one-click unsubscribe link or STOP reply keyword.

15. Children's Privacy

Our Services are intended for adults acting in a business capacity and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

16. California Residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete, the right to correct, the right to opt out of "sale" or "sharing" of personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA/CPRA. To submit a verifiable request, email privacy@gulliafiling.com.

17. UK & EU Residents (UK GDPR / GDPR)

You may lodge a complaint with the UK Information Commissioner's Office (ICO) or your local EU supervisory authority. Our lead supervisory authority for cross-border processing is the ICO. Where we rely on legitimate interests, you have the right to object at any time.

18. Canadian Residents (PIPEDA)

We handle personal information in accordance with the ten fair information principles of PIPEDA and any applicable provincial statutes such as Quebec's Law 25. You may contact our Privacy Officer with any questions or complaints, and escalate to the Office of the Privacy Commissioner of Canada if unresolved.

19. UAE Residents (PDPL)

We comply with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and any applicable freezone data protection laws (DIFC DP Law 2020, ADGM DPR 2021). You may exercise your PDPL rights by contacting our Data Protection Officer.

20. Automated Decision-Making

We use automated tools to screen for sanctions, PEP and fraud risk. A qualified human reviewer makes the final onboarding decision. You have the right to request human review of any decision that produces legal or similarly significant effects on you.

21. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. If changes are material we will notify you by email or through an in-app notice before they take effect.

22. Contact & Data Protection Officer

Privacy questions and rights requests can be sent to privacy@gulliafiling.com or by post to Gullia Filing LLC, Attn: Data Protection Officer, 1209 Orange Street, Wilmington, Delaware 19801, United States.