Our Policies
Transparency, trust and compliance are at the heart of how GCD Global Consultants operates.
GCD Global Consultants is committed to protecting the privacy and personal data of all clients, website visitors, and business partners. This Privacy Policy explains how we collect, use, store, and protect your information.
1. Information We Collect
We collect personal information only with your prior approval and consent, and only to the extent necessary to deliver our services. With that approval, the categories we may collect include:
- Identity data: name, date of birth, PAN, passport, national ID
- Contact data: email address, telephone numbers, postal address
- Financial data: bank details, income information, tax records
- Technical data: IP address, browser type, usage data from our website
- Business data: company registration details, financial statements, contracts
2. How We Use Your Information
We process your personal information solely for the following purposes:
- Providing taxation, accounting, compliance, and advisory services
- Communicating updates, deadlines, and regulatory changes relevant to your engagement
- Fulfilling statutory obligations under applicable tax and corporate laws
- Improving our website and service delivery
3. Legal Basis for Processing
We process your data on the basis of: (a) performance of a contract, (b) compliance with legal obligations, and (c) your explicit consent. We will never sell or rent your personal data to third parties for marketing purposes.
4. Data Sharing
Your data may be shared only with: regulatory authorities (Income Tax Department, GST authorities, MCA, FTA, HMRC, IRS) as required by law; professional advisors bound by confidentiality; and technology service providers operating under strict data processing agreements.
5. Data Retention
Client data is retained for a minimum of 7 years in accordance with Indian, UAE, UK, and US statutory requirements. After this period, data is securely deleted or anonymised unless a longer retention period is required by law.
6. Your Rights
You have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data subject to legal obligations; withdraw consent at any time; and lodge a complaint with the relevant data protection authority.
7. Data Security
We implement industry-standard technical and organisational measures including encryption, access controls, firewalls, and regular security audits to protect your data against unauthorised access, disclosure, or loss.
8. Cookies
Our website uses essential cookies to ensure proper functionality. We do not use tracking or advertising cookies without your consent. You may manage cookie preferences through your browser settings.
9. Contact Us
For any privacy-related queries, to exercise your rights, or to report a concern, please contact us at: info@gcdglobal.in
Last updated: May 2025 | Version 1.0
GCD Global Consultants provides offshore accounting, tax and advisory services and, in doing so, processes personal and financial information on behalf of its clients across India, the United Kingdom, the United Arab Emirates and the United States. This Data Protection Policy sets out the standards we apply to that information and demonstrates our alignment with the Digital Personal Data Protection Act, 2023 (India), the UK GDPR and Data Protection Act 2018, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and Internal Revenue Code §7216 (United States). Our commitment is simple: client data is handled only through authorised channels, is never disclosed to unauthorised persons, and is managed with full transparency and accountability.
1. Purpose & Scope
This policy applies to all personal data and client information that GCD Global Consultants collects, receives, stores, processes, transmits or returns in the course of any engagement, and to every partner, employee, contractor and associate who handles that data. It covers data in every form, electronic, cloud-hosted and physical, and across every stage of its lifecycle, from receipt through to secure deletion or return.
2. Regulatory Alignment
We design our processing to meet the requirements of each jurisdiction in which our clients operate:
- India, the Digital Personal Data Protection Act, 2023 (DPDP Act), under which we act as a Data Processor for our clients as Data Fiduciaries.
- United Kingdom, the UK GDPR and the Data Protection Act 2018, under which we act as a processor on the controller’s documented instructions.
- United Arab Emirates, the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, and its data-protection principles.
- United States, Internal Revenue Code §7216 and §6713, governing the use and disclosure of tax return information by preparers and their associates.
3. Our Role as a Processor
In almost all engagements GCD Global Consultants acts as a data processor or service provider, not as the owner of the data. We process personal and financial information strictly on the documented instructions and authorisation of our client, who remains the controller, data fiduciary or taxpayer. We do not determine the purposes of processing, and we do not use client data for any purpose of our own.
4. Authorised Channels Only
Client data is received, stored, accessed, processed and returned only through channels that the client has authorised and approved. These include encrypted client portals and secure file-transfer tools, invited-accountant access to the client’s own accounting software, and agreed, secured communication channels. Our people are prohibited from using personal email accounts, personal devices, removable media or any unapproved third-party application to handle client data. At no point in an engagement does data move outside an authorised channel.
5. No Disclosure to Unauthorised Persons
GCD Global Consultants does not forward, disclose, sell, publish or otherwise share client data with any unauthorised person or third party. Access is restricted to the specific, authorised team members assigned to an engagement, strictly on a need-to-know basis, and each is bound by confidentiality obligations. Where US tax return information is involved, we obtain the taxpayer’s consent in the form required by §7216 before any use or disclosure beyond preparing the return, and we handle identifiers such as Social Security Numbers in accordance with those rules.
6. Lawful Basis, Consent & Authorisation
We process data only where there is a lawful basis and a clear authorisation to do so. Where the applicable law requires consent, for example under the DPDP Act, or under §7216 for the disclosure or use of tax return information, that consent is obtained, recorded and honoured, and it may be withdrawn by the client or data principal at any time.
7. Data Minimisation & Purpose Limitation
We collect and process only the data necessary to deliver the agreed services, and we use it solely for the purpose for which it was provided. Client data is never repurposed, profiled or used for marketing without explicit authorisation.
8. Cross-Border Processing & Transfers
Because our delivery teams are based in India, data belonging to clients in the United Kingdom, the United Arab Emirates and the United States may be processed in India. Such transfers are carried out under appropriate safeguards, including data-processing agreements and recognised transfer mechanisms such as the UK International Data Transfer Agreement or Addendum, contractual safeguards under the UAE PDPL, and the taxpayer consents required under §7216 for the offshore handling of US tax return information.
9. Security Safeguards
We protect data with layered technical and organisational measures, including:
- Encryption of data in transit and at rest
- Role-based access controls and multi-factor authentication
- Secured, access-restricted networks and devices
- Signed confidentiality and data-protection agreements with all personnel
- Ongoing staff training and periodic access reviews
- Secure disposal and certified deletion of data
10. Retention & Deletion
We retain client data only for as long as it is needed to deliver the engagement and to meet legal, regulatory and professional record-keeping requirements. On completion of the engagement, or on the client’s instruction, data is securely returned or permanently and irrecoverably deleted.
11. Rights of Data Principals & Data Subjects
We respect the rights granted to individuals under each applicable law, including the rights to access, correct, update and erase personal data, and to withdraw consent. As a processor, we promptly assist our clients in responding to and fulfilling any such request from a data principal or data subject.
12. Sub-Processors
We engage sub-processors only where necessary, only with the client’s authorisation, and only under contractual obligations equivalent to those in this policy. We remain accountable for the data-protection performance of any sub-processor we appoint.
13. Personal Data Breach Response
In the unlikely event of a personal data breach, we act immediately to contain it and notify the affected client without undue delay, providing the information the client needs to meet any regulatory notification deadline under the DPDP Act, UK GDPR, UAE PDPL or other applicable law.
14. Transparency & Accountability
Accountability is built into how we operate. We maintain records of our processing activities, train our people, review access regularly, and make a named point of contact available for any data-protection question or concern. Clients may request information about how their data is handled, and we welcome reasonable audits and assurances of our practices.
15. Contact
For any question about this policy, to exercise a data-protection right, or to raise a concern, please contact us at info@gcdglobal.in.
This policy reflects the commitments and practices of GCD Global Consultants and is provided for transparency. It does not constitute legal advice, and the specific data-protection obligations of any engagement are set out in the applicable services agreement and data-processing terms.
Last updated: June 2026 | Version 2.0
This Cookie Policy explains how GCD Global Consultants uses cookies and similar technologies on this website. We take a deliberately minimal approach: we use only what is needed for the site to work properly, and we do not use cookies for advertising or cross-site tracking.
1. What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help the site function, remember preferences and, where enabled, understand how the site is used. Similar technologies such as local storage and pixels work in comparable ways.
2. How We Use Cookies
We use cookies only to keep this website secure and functioning correctly and, where enabled, to understand site usage in aggregate so we can improve it. We do not use cookies to build advertising profiles, and we do not sell or share cookie data with advertising networks.
3. Categories of Cookies We May Use
- Strictly necessary, essential for the website to load, navigate and operate securely; these are always active and cannot be switched off.
- Functional, remember choices such as language or display preferences to improve your experience.
- Analytics and performance, if enabled, these help us measure aggregate, anonymised usage; where required we ask for your consent before setting them.
4. Third-Party Cookies
This website does not deploy third-party advertising or social-media tracking cookies. If we embed third-party content such as a map or video, that provider may set its own cookies, governed by its own policy.
5. Managing Your Cookies
You can accept, block or delete cookies through your browser settings, and most browsers let you refuse non-essential cookies. Blocking strictly necessary cookies may affect how parts of the site work; guidance is available in your browser’s help section.
6. Updates & Contact
We may update this Cookie Policy to reflect changes in technology or law. For any question about our use of cookies, please contact us at info@gcdglobal.in.
Last updated: June 2026 | Version 1.0
GCD Global Consultants treats the security of the client, financial and personal data entrusted to us as fundamental to our business. This Information Security Policy summarises the technical and organisational controls we maintain to keep that data confidential, accurate and available, and complements our Data Protection Policy.
1. Purpose & Scope
This policy applies to all systems, devices, networks and people involved in delivering our services, and to all client and firm data in every form. Its objective is to protect the confidentiality, integrity and availability of that data throughout its lifecycle.
2. Governance & Responsibility
Information security is owned at leadership level, with clear accountability for setting controls, reviewing risks and responding to incidents. Every partner, employee, contractor and associate is responsible for following this policy, and security expectations are written into their engagement terms.
3. Access Control
- Access granted on a least-privilege, need-to-know basis, aligned to each person’s role on an engagement
- Unique user accounts and strong authentication, with multi-factor authentication on key systems
- Prompt provisioning and, critically, prompt removal of access when people join, change roles or leave
- Regular review of who has access to what
4. Encryption
Client data is encrypted in transit using secure protocols and protected at rest. Credentials and sensitive identifiers are stored and transmitted only through protected, encrypted means.
5. Network & Device Security
- Secured, access-restricted networks and managed devices
- Endpoint protection, firewalls and timely security patching
- A prohibition on using personal devices, personal accounts or removable media to handle client data
- Clear-desk and clear-screen discipline
6. Secure Data Handling & Transfer
In line with our Data Protection Policy, client data is received, stored, processed and returned only through client-authorised, secure channels, encrypted portals, secure file transfer and invited access to client systems. Data never moves through unauthorised or personal channels, and is never forwarded to unauthorised persons.
7. People & Confidentiality
- Confidentiality and data-protection agreements signed by all personnel
- Appropriate screening of staff who handle sensitive data
- Regular security-awareness training and updates
- A culture in which raising a security concern is expected and supported
8. Monitoring & Logging
Access to systems and client data is logged and periodically reviewed so that unusual activity can be identified and addressed, and so that access remains appropriate over time.
9. Incident Response
We maintain a defined process to detect, contain and resolve security incidents. If an incident affects client data, we notify the affected client without undue delay and provide the information they need to meet their own regulatory obligations.
10. Business Continuity & Backup
Client data is backed up securely and regularly, with tested recovery procedures and resilience built into our delivery, so that engagements can continue and data can be restored in the event of disruption.
11. Third-Party & Vendor Security
Any sub-processor or technology provider we rely on is selected with care and held to security and confidentiality standards equivalent to our own. We remain accountable for the security of data we entrust to them.
12. Continuous Improvement
We review our controls in line with recognised information-security principles, including those underpinning ISO/IEC 27001, and improve them as risks, technology and client expectations evolve. We welcome reasonable security due diligence from clients and partners.
13. Reporting a Security Concern
To report a security concern or request information about our controls, please contact us at info@gcdglobal.in.
This policy describes the security commitments and practices of GCD Global Consultants and is provided for transparency; it does not form part of any contract unless expressly incorporated, and the specific security terms of an engagement are set out in the applicable agreement.
Last updated: June 2026 | Version 1.0
These Terms of Use govern your access to and use of the GCD Global Consultants website. By using this website you agree to these terms. If you do not agree, please do not use the site.
1. About These Terms
This website is operated by GCD Global Consultants. These terms apply to all visitors and users of the site and should be read together with our Privacy Policy, Cookie Policy and Data Protection Policy.
2. Use of the Website
You may use this website for lawful, personal and business-information purposes. You agree not to misuse the site, including attempting to gain unauthorised access, disrupting its operation, or using it to transmit unlawful or harmful material.
3. No Professional Advice
The content on this website is provided for general information only and does not constitute accounting, tax, legal, financial or other professional advice. It should not be relied upon for decisions without taking advice specific to your circumstances, and using this website does not create a client or advisory relationship with GCD Global Consultants.
4. Accuracy of Information
We take care to keep the information on this site accurate and current, but laws, rates and requirements across India, the UK, the UAE and the USA change frequently. We make no warranty that all content is complete, current or error-free, and we may update it without notice.
5. Intellectual Property
All content on this website, including text, graphics, logos and design, is owned by or licensed to GCD Global Consultants and is protected by intellectual-property laws. You may not copy, reproduce, republish or distribute it without our prior written permission.
6. Third-Party Links
This site may contain links to third-party websites for convenience. We do not control and are not responsible for the content, accuracy or practices of those sites, and a link does not imply endorsement.
7. Limitation of Liability
This website is provided on an ’as is’ and ’as available’ basis. To the fullest extent permitted by law, GCD Global Consultants is not liable for any loss or damage arising from your use of, or reliance on, this website or its content.
8. Privacy & Data
Your use of this website is also governed by our Privacy Policy, Cookie Policy and Data Protection Policy, which explain how we handle personal data and cookies.
9. Governing Law
These terms are governed by the laws of India. Any dispute relating to this website or these terms is subject to the exclusive jurisdiction of the courts of Delhi, India.
10. Changes & Contact
We may revise these terms from time to time, and the current version will always be available on this page. For any question about these terms, please contact us at info@gcdglobal.in.
Last updated: June 2026 | Version 1.0