Effective date: 3 July 2026 · Last updated: 3 July 2026 · Supersedes the version dated 22 May 2026
This Privacy Policy explains how Chartered Times LLP, an Indian limited liability partnership operating under the brand “GCCPROs” (“we”, “us”, “our”), collects, uses, shares and protects personal data when you use our websites and services: the GCC intelligence database (Individual edition), the GCCPROs Enterprise Data API, the Opportunities talent platform, the GCC Leaders’ Community benchmark console, our community programmes (Insider Community, Leadership Council) and our events (together, the “Services”). We are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the data controller where the EU/UK GDPR applies. Contact: admin@gccpros.com.
1. What we collect, by service
Service
Personal data collected
All services
Name, work email, sign-in identity from Google/Microsoft SSO or Firebase Authentication (we do not receive or store SSO passwords), approximate IP address, device/session data, usage logs (searches, reveals, logins, timestamps), communications with us, cookie-free session/local storage for sign-in and preferences.
GCC Database (Individual)
Account status and credit balance, credit purchases (processed by Razorpay — card details never touch our servers; we receive payment confirmation and order metadata), reveal/search history, watermark logs (your email + timestamp on revealed profiles), feedback and data submissions/corrections you make.
Opportunities — job seekers
Profile (name, phone, LinkedIn, city, employer, designation, experience, notice period), current and expected CTC, PAN number, qualifications, skills, CV/resume files, references you nominate, application answers.
Opportunities — partners
Profile and professional photo, referral records, and for payouts: KYC data — PAN, name on PAN, address-proof document (e.g., Aadhaar, Voter ID, passport, utility bill), bank account holder name, bank name, IFSC, last 4 digits of the account, cancelled-cheque image.
Leaders’ Community / Councils / Events
Application details (role, seniority, employer, LinkedIn, WhatsApp), one-time sign-in codes, your confirmations of your company’s record, stated priorities (held against a masked profile), event RSVPs (mirrored to a Google Sheets backup).
Enterprise Data API
Organisation, seat/user identity via SSO, access tier, API usage metering (queries, records returned, timestamps, IP) for billing, quotas and security.
The GCC database itself contains business and professional information about companies and senior business roles (e.g., a publicly listed company leader’s name and title), compiled from public and licensed sources for legitimate business-intelligence purposes. If you believe an entry about you is inaccurate or should not be processed, contact us and we will review it promptly.
2. Why we use it (purposes)
To provide, operate, secure and improve the Services; to authenticate users and enforce entitlements (credits, caps, seats, tiers, quotas);
To process payments, meter usage, invoice, prevent fraud and abuse, and maintain audit and security logs;
Opportunities: to match candidates with roles, share shortlisted profiles and CVs with hiring employers, verify partner identity and pay referral earnings (KYC is collected solely for payout compliance);
Leaders’ Community: to verify membership eligibility, maintain masked peer-verification, and publish only aggregated, anonymised benchmarks;
To respond to you and to send service messages; marketing messages (email/WhatsApp) only with your consent, which you may withdraw at any time;
To comply with legal obligations (including tax record-keeping).
3. Legal bases
Under the DPDP Act we process personal data on the basis of your consent (collected at each form) and for legitimate uses permitted by law (e.g., where you voluntarily provide data for a specified purpose, security, and compliance with law). Where the EU/UK GDPR applies, we rely on contract performance, legitimate interests (running and securing the Services; business intelligence), consent, and legal obligation.
4. Sharing
We do not sell personal data. We share it only with:
Processors under contract: Supabase (database, storage and serverless hosting), Google Firebase (authentication), Google and Microsoft (SSO), Razorpay (payments), Resend (transactional email), Cloudflare (Turnstile bot protection), Google Workspace (operational mailbox and Sheets backup of sign-ups/RSVPs);
Hiring employers — Opportunities only: shortlisted candidates’ profiles, CVs and application details are shared with the specific employer for the role; recruiters access CVs via time-limited signed links;
Your organisation — Enterprise API: your org admin may see usage associated with your seat;
Authorities or third parties where required by law, to protect our rights, or in a corporate transaction.
5. Storage, security and international transfers
Encryption in transit (TLS 1.2+) and at rest (AES-256 platform encryption);
Service-role database keys are held server-side only and never sent to a browser; row-level security on database tables; end users access data only via credit-checked, field-filtered endpoints;
CVs and KYC documents are stored in private storage and accessed via signed URLs only; admin actions, credit events and reveals are audit-logged; rate limits and monthly caps apply;
Our infrastructure providers may process data outside India/your country; where required we use appropriate safeguards (such as standard contractual clauses).
6. Retention
Account and profile data: for the life of your account, then deleted within 30 days of account closure;
Paid-transaction records: retained (anonymised where possible) for 8 years as required by Indian tax law;
Partner KYC documents: retained while you remain an active partner and for the statutory period required for payout/tax compliance, then deleted;
CVs and applications: retained while your account is active or until you ask us to delete them;
Security, usage and audit logs: retained for a reasonable period for security and billing, then deleted or anonymised;
Deleted accounts: a minimal archival snapshot is retained for the record; the email/phone/LinkedIn become free to re-register.
7. Your rights (DPDP Act 2023 · GDPR where applicable)
Access (Sec. 11) — request a structured export of your data;
Correction and erasure (Sec. 12) — update or delete your data / close your account;
Withdraw consent (Sec. 6) — including marketing via email/WhatsApp, without affecting your account;
Nominate (Sec. 14) — authorise another individual to exercise your rights in case of death or incapacity;
Grievance redressal (Sec. 13) — see below. If you remain dissatisfied, you may escalate to the Data Protection Board of India (Sec. 18). GDPR users may additionally object to or restrict processing and lodge complaints with their supervisory authority.
Exercise any right via the “Manage my data” panel on the database portal or by emailing admin@gccpros.com. We honour requests within 7 working days.
8. Grievance Officer
Shammi Prabhakar · Chartered Times LLP (GCCPROs) · admin@gccpros.com · Acknowledgement within 48 hours; resolution SLA 7 working days.
9. Children
The Services are for business use by adults and are not directed to anyone under 18. We do not knowingly collect children’s data.
10. Changes
We may update this policy from time to time. We will post updates here and revise the “Last updated” date; material changes will be communicated via the Services or email.