1. Introduction
Welcome to Gembacorp Solutions LLP (“we,” “us,” “our,” or “Gembacorp”). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website [www.gembacorp.in] or engage our consulting services.
By using our website or services, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use our website or services.
2. Information We Collect
2.1 Personal Information You Provide
We may collect the following personal information that you voluntarily provide to us:
Contact Information:
- Full name
- Business name/company name
- Email address
- Phone number
- Mailing address
- Job title and designation
Business Information:
- Industry sector
- Company size and number of locations
- Current business challenges
- Service requirements and preferences
- Budget and timeline information
Communication Records:
- Correspondence via email, phone, or contact forms
- Meeting notes and consultation records
- Feedback and survey responses
- Service inquiries and requests for proposals
Professional Information:
- Resume/CV (for recruitment services)
- References and background information
- Professional qualifications and certifications
- Employment history (when relevant to our services)
2.2 Information Collected Automatically
When you visit our website, we may automatically collect certain information:
Device and Browser Information:
- IP address
- Browser type and version
- Operating system
- Device type (desktop, mobile, tablet)
- Screen resolution
Usage Data:
- Pages visited and time spent on pages
- Referring website/source
- Click patterns and navigation paths
- Date and time of access
- Download and upload activity
Cookies and Tracking Technologies:
- Session cookies (temporary)
- Persistent cookies (stored on your device)
- Analytics cookies
- Functional cookies for website operation
2.3 Information from Third Parties
We may receive information about you from:
- Business references and referrals
- Public databases and directories
- Industry associations and networks
- Social media platforms (LinkedIn, etc.)
- Background verification agencies (with your consent)
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Delivery
- Providing consulting services as per engagement agreements
- Conducting business audits and assessments
- Developing customized strategies and recommendations
- Delivering training and development programs
- Managing events and international tours
- Communicating project updates and deliverables
3.2 Business Operations
- Processing service inquiries and quotations
- Scheduling consultations and meetings
- Invoicing and payment processing
- Contract management and administration
- Quality assurance and service improvement
- Record keeping and documentation
3.3 Communication
- Responding to your inquiries and requests
- Sending service confirmations and updates
- Providing customer support
- Sharing relevant industry insights and resources
- Distributing newsletters (with your consent)
- Notifying you of new services or offerings
3.4 Marketing and Business Development
- Understanding client needs and preferences
- Improving our services and website
- Conducting market research and analysis
- Developing case studies and testimonials (with permission)
- Promoting our services to relevant prospects
- Building long-term client relationships
3.5 Legal and Compliance
- Complying with applicable laws and regulations
- Responding to legal requests and court orders
- Protecting our rights and property
- Preventing fraud and security threats
- Enforcing our terms and conditions
- Resolving disputes
4. Legal Basis for Processing (Applicable Law)
We process your personal information based on the following legal grounds under Indian law, including the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
Consent: You have given explicit consent for specific purposes
Contractual Necessity: Processing is necessary to fulfill our service agreements with you
Legal Obligation: Processing is required to comply with Indian laws and regulations
Legitimate Interests: Processing serves our legitimate business interests while respecting your privacy rights
5. Data Sharing and Disclosure
5.1 We May Share Your Information With:
Service Providers and Partners:
- IT service providers and hosting companies
- Payment processors and financial institutions
- Communication service providers
- Analytics and research firms
- Professional advisors (lawyers, accountants, auditors)
Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity.
Legal Requirements: We may disclose information when required by law, court order, or government authority, including:
- Tax authorities and regulatory bodies
- Law enforcement agencies
- Courts and tribunals
- Government departments
With Your Consent: We may share information with third parties when you explicitly authorize us to do so.
5.2 We Do NOT:
- Sell your personal information to third parties
- Share your information for third-party marketing without consent
- Disclose confidential business information without authorization
- Transfer data internationally without appropriate safeguards
6. Data Security
We implement reasonable security measures to protect your information:
Technical Safeguards:
- Secure Socket Layer (SSL) encryption for data transmission
- Firewall protection and intrusion detection
- Regular security audits and vulnerability assessments
- Secure data backup and recovery systems
- Access controls and authentication mechanisms
Organizational Measures:
- Confidentiality agreements with employees and contractors
- Role-based access to personal information
- Regular employee training on data protection
- Incident response and data breach protocols
- Secure document storage and disposal procedures
Physical Security:
- Restricted access to offices and data centers
- Secure storage of physical documents
- Visitor management and monitoring
- Locked cabinets for sensitive information
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods:
Active Clients: Duration of engagement plus 7 years (as per Indian accounting and tax laws)
Prospective Clients: 3 years from last contact (unless you request earlier deletion)
Employee/Recruitment Data: 1 year from application or as required by labor laws
Website Analytics: 26 months from data collection
Marketing Communications: Until you unsubscribe or request deletion
Legal/Compliance Records: As required by applicable laws (typically 7-10 years)
After the retention period expires, we will securely delete or anonymize your information unless we are required to retain it for legal or regulatory purposes.
8. Your Rights and Choices
Under Indian law and our commitment to privacy, you have the following rights:
8.1 Access and Correction
- Request access to your personal information we hold
- Request correction of inaccurate or incomplete information
- Receive a copy of your data in a structured format
8.2 Withdrawal of Consent
- Withdraw consent for processing at any time (subject to legal/contractual obligations)
- Opt-out of marketing communications
- Disable cookies through browser settings
8.3 Deletion and Restriction
- Request deletion of your personal information (subject to legal retention requirements)
- Request restriction of processing in certain circumstances
- Object to processing based on legitimate interests
8.4 Data Portability
- Request transfer of your data to another service provider (where technically feasible)
- Receive your data in a commonly used electronic format
8.5 Complaints
- File a complaint with us regarding data handling practices
- Approach relevant authorities if concerns are not adequately addressed
To Exercise Your Rights: Contact us using the details provided in Section 13 below. We will respond to your request within 30 days or as required by applicable law.
9. Cookies Policy
9.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us provide a better user experience and analyze website performance.
9.2 Types of Cookies We Use:
Essential Cookies (Required):
- Enable core website functionality
- Remember your preferences during a session
- Maintain security and authentication
Analytics Cookies (Optional):
- Google Analytics for traffic analysis
- Understanding user behavior and popular content
- Improving website performance
Functional Cookies (Optional):
- Remember your language and region preferences
- Provide personalized content and features
- Enable social media sharing
Marketing Cookies (Optional – with consent):
- Track effectiveness of marketing campaigns
- Display relevant advertisements
- Measure conversion from marketing efforts
9.3 Managing Cookies
You can control cookies through your browser settings:
- Block all cookies
- Accept only first-party cookies
- Delete existing cookies
- Receive notifications before cookies are set
Note: Disabling essential cookies may limit website functionality.
Browser-Specific Instructions:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Options > Privacy & Security > Cookies
- Safari: Preferences > Privacy > Cookies
- Edge: Settings > Privacy & Security > Cookies
10. Third-Party Links
Our website may contain links to third-party websites, including:
- Industry resources and publications
- Partner organizations
- Social media platforms
- Service providers
We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
11. Children’s Privacy
Our services are intended for businesses and professionals. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that we have inadvertently collected information from a minor, we will take steps to delete it promptly.
12. International Data Transfers
Our services and data storage are primarily based in India. If we transfer your information outside India, we will:
- Ensure adequate data protection measures are in place
- Comply with Indian data transfer regulations
- Obtain your explicit consent where required
- Use standard contractual clauses or other approved mechanisms
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our business practices
- New legal or regulatory requirements
- Feedback from clients and users
- Technological developments
Notification of Changes:
- Updated “Last Updated” date at the top of this policy
- Email notification for material changes (to active clients)
- Prominent website notice for significant updates
Your continued use of our services after changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
15. Grievance Redressal
In accordance with Information Technology Act, 2000 and rules made thereunder, if you have any grievances regarding the processing of your personal information, you may contact our Grievance Officer:
Grievance Officer:
[Name]
[Designation]
Gembacorp Solutions LLP
Email: grievance@gembacorp.com
Phone: [Insert Phone Number]
The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 30 days from the date of receipt.
If you are not satisfied with our response, you may escalate your complaint to:
- The relevant data protection authority in India
- Consumer forums and courts as per applicable law
16. Specific Information for Different User Categories
16.1 Website Visitors
- We collect minimal information for analytics and improvement
- You can browse most of our website without providing personal information
- Contact forms and downloads require some personal details
16.2 Prospective Clients
- Information collected during inquiries and consultations
- Used to understand your needs and propose solutions
- Retained for business development purposes
- Can request deletion if you decide not to engage our services
16.3 Active Clients
- Comprehensive information collection as per service agreements
- Confidentiality maintained for all business information
- Data used for service delivery and project management
- Retained as per contractual and legal obligations
16.4 Newsletter Subscribers
- Email address and name collected for communications
- Can unsubscribe at any time through email links
- Information not shared with third parties
- Used exclusively for Gembacorp updates and insights
17. Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Assess the breach within 24 hours of discovery
- Contain and remediate the security incident immediately
- Notify affected individuals within 72 hours if the breach poses a significant risk
- Report to authorities as required by law
- Provide assistance to help you protect your information
- Implement additional safeguards to prevent future incidents
Breach notifications will include:
- Nature of the breach
- Types of information affected
- Potential consequences
- Measures taken to address the breach
- Steps you can take to protect yourself
- Contact information for questions
18. Consent
By using our website or engaging our services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your information as described in this Privacy Policy.
For Sensitive Personal Information: We will obtain your explicit written consent before collecting or processing:
- Financial information (bank details, credit card information)
- Health information (if relevant to services)
- Biometric data
- Sexual orientation or preferences
- Political or religious beliefs
You may withdraw your consent at any time, subject to legal and contractual obligations.
19. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of India, including:
- Information Technology Act, 2000
- Information Technology (Reasonable Security Practices) Rules, 2011
- Consumer Protection Act, 2019
- Other applicable Indian data protection laws and regulations
Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of courts in [City], India.
20. Disclaimer
While we make every effort to ensure the accuracy and completeness of this Privacy Policy, we do not warrant that:
- The policy covers every possible data processing scenario
- Third-party practices align with our standards
- Information is completely secure from unauthorized access
- Services will be uninterrupted or error-free
This Privacy Policy should be read in conjunction with our Terms of Service and other applicable agreements.
Acknowledgment:
This Privacy Policy was last updated on [Date] and is effective immediately. We reserve the right to modify this policy at our discretion, and such modifications shall be effective immediately upon posting on our website.
For the most current version of our Privacy Policy, please visit: [Website URL/Privacy Policy Page]
© 2025 Gembacorp Solutions LLP. All rights reserved.
