Legal

Privacy Policy

What we collect, why we collect it, who sees it, how long we keep it, and what you can require us to do about it.

Effective 1 January 2026Global Management Systems Certification Private Limitedadmin@gmscpl.com

Introduction and scope

This policy explains what personal data Global Management Systems Certification Private Limited ("GMSCPL", "we", "us") collects through this website and in the course of providing certification, inspection and training services, how we use it, who we share it with, and the rights you hold over it. It applies to this website and to the enquiry, quotation, certification and training processes that follow from it.

Certification carries confidentiality obligations that go beyond ordinary data protection. Information we obtain during an audit is treated as confidential client information under ISO/IEC 17021-1, separately from and in addition to the protections described here.

Information we collect

Information you give us

  • Contact details submitted through enquiry, quotation, complaint or verification forms — name, company, email address and telephone number
  • Organisational information needed to scope an audit — employee numbers, sites, processes and the standards sought
  • Correspondence with us by email, telephone or through this website
  • Delegate details for training enrolment, including any information needed to issue a certificate
  • Application materials where you apply for a role or for auditor empanelment

Information collected automatically

  • Standard server log data, including IP address, browser type, referring page and timestamps
  • Cookie and local-storage data, described in full in our Cookie Policy — note that your light/dark theme preference is stored locally in your browser and never transmitted to us
  • Aggregate analytics about page usage, where analytics cookies have been accepted

How we use your information

PurposeLegal basis
Responding to your enquiry and preparing a quotationSteps taken at your request prior to entering a contract
Delivering certification, inspection or training servicesPerformance of a contract with you or your organisation
Maintaining certification and audit recordsLegal obligation and legitimate interest — accreditation requires us to retain them
Verifying a certificate on request from a third partyLegitimate interest in the integrity of certificates we have issued
Investigating a complaint or appealLegal obligation under our accreditation and legitimate interest
Sending standard updates and compliance insights by emailYour consent, withdrawable at any time
Analytics and site improvementYour consent, given through the cookie banner

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

Data sharing and third parties

We share personal data only where it is necessary, and only with the following categories of recipient:

  • Our accreditation body, where it assesses our files or witnesses an audit — this is a condition of accreditation and cannot be declined while remaining accredited
  • Auditors and technical experts assigned to your engagement, all of whom are bound by written confidentiality undertakings
  • Scheme owners where a certification scheme requires client data to be reported to them, such as IATF or FSSC
  • IT and communications providers hosting this website and our systems, acting under contract as processors
  • Regulatory or legal authorities where we are compelled by law — in which case we will tell you unless prohibited from doing so

Where certification status is published on a public certified-client directory, that publication covers the certified organisation, the certificate number, the standard and the scope. It does not publish the personal data of individuals.

Data security

  • Access to audit files and client data is restricted to personnel who need it for their role
  • Confidentiality undertakings are signed by every employee, auditor and technical expert
  • Data in transit to this website is encrypted using TLS
  • Access rights are reviewed periodically and revoked promptly when someone leaves or changes role
  • Security incidents are investigated, recorded and reported where notification is required

We hold ourselves to the practices we audit others against. If we did not, we would be in a poor position to raise a finding about them.

Your rights

  • Access — ask what personal data we hold about you and receive a copy
  • Correction — have inaccurate or incomplete data corrected
  • Erasure — ask us to delete data, subject to the retention obligations described below
  • Withdrawal of consent — unsubscribe from communications or withdraw cookie consent at any time, without affecting anything done beforehand
  • Objection and restriction — object to processing based on legitimate interest, or ask us to restrict processing while a dispute is resolved
  • Grievance — raise a complaint about how we have handled your data, and escalate it to the relevant data protection authority if you remain dissatisfied

To exercise any of these, write to admin@gmscpl.com. We will acknowledge within three working days and respond substantively within thirty days. We may ask you to verify your identity first, which is a protection for you rather than an obstacle.

Retention

Record typeRetention period
Enquiry and quotation correspondence that does not proceed24 months from last contact
Audit files, certification decisions and certificatesA minimum of one full certification cycle beyond expiry, per accreditation requirements
Complaints, appeals and their investigation recordsMinimum 6 years
Training records and issued training certificatesMinimum 6 years
Job applications where no offer is made12 months, unless you ask us to keep them longer
Newsletter subscription dataUntil you unsubscribe
Server logsTypically 90 days

International transfers

Our operations are based in India. Where a service provider or scheme owner processes data outside India, we require appropriate contractual safeguards before any transfer. Where an audit is conducted internationally, the audit file remains under our control in India.

Changes to this policy

We update this policy when our practices change. The effective date at the top of this page reflects the current version. Where a change materially affects how we use data you have already given us, we will tell you directly rather than relying on this page alone.

Contact for privacy queries

Privacy queries, data subject requests and grievances: admin@gmscpl.com, or by post to Global Management Systems Certification Private Limited, Flat No. 503, 5th Floor, Balsiddi Heights, Road No. 14, Banjara Hills, Hyderabad – 500034, Telangana, India.

Questions about this policy?

Ask us directly

Write to admin@gmscpl.com and a person will answer. Requests relating to your personal data are handled within the timeframes set out above.