Privacy Notice
1. Who we are
Global Support Services (UK) Ltd (“GSS”, “we”, “us” or “our”) is a company registered in England and Wales under company number 07462040. Our registered office is: 5–9 Headstone Road, Harrow, England, HA1 1PD.
For the personal information covered by this notice, GSS will normally be the controller, which means we decide why and how that information is used.
In some security, surveillance or related assignments, our client decides why personal information is used and GSS acts only on that client’s documented instructions. In that situation, the client is the controller and its privacy notice will primarily apply. You may contact us if you are unsure which organisation is responsible.
You can contact us about privacy or exercise your data protection rights by: emailing operations@global-support.org; writing to Data Protection Contact (Daniel Mailly), Global Support Services (UK) Ltd, 5–9 Headstone Road, Harrow, England, HA1 1PD; or calling 0203 751 8383.
2. Who this notice covers
This notice explains how we use personal information about: visitors to www.global-support.org and users of GSS online services; people who contact us or ask about our services; current and prospective clients, suppliers, advisers and other business contacts; job applicants, prospective workers and referees; visitors to GSS premises or sites at which we work; and people named or recorded in operational, access-control, security, incident or investigation records where GSS is the controller.
Employees, workers and contractors may receive a separate workforce privacy notice. A specific notice provided at the point of collection will take priority if it explains a particular activity in more detail.
Site-specific signs or notices may provide additional information about CCTV, body-worn video, access control or other monitoring where those systems are used.
Our website and services are not directed at children. However, information about a child may occasionally appear in an enquiry or operational or incident record. We use additional care and only process that information where necessary and lawful.
3. Personal information we collect
Depending on your relationship with us, we may collect:
Identity and contact information. Your name, title, organisation, role, postal address, email address, telephone number and preferred means of contact.
Business and service information. Information about enquiries, quotations, contracts, instructions, site requirements, service delivery, correspondence, meetings, complaints and your relationship with a client, supplier or other organisation.
Financial and due-diligence information. Billing and payment information, transaction records and information used for proportionate identity, fraud-prevention, sanctions or business credit checks.
Recruitment and vetting information. Your CV, application and interview records; employment and education history; qualifications; professional memberships; SIA, NASDU or other relevant licences and certifications; references; right-to-work and identity documentation; driving information where relevant to the role; availability; and information needed to assess your suitability for a role.
Where lawful, necessary and relevant to the role, this may include health information, equality-monitoring information or criminal-offence and background-check information. We will not request a criminal record check unless the role and the law permit it.
Security and operational information. Site access records, shift or deployment information, security reports, incident details, statements, allegations, descriptions of individuals or vehicles, photographs, video or audio recordings, location information and communications relating to an incident or the protection of people, animals, premises or property.
These records may occasionally reveal health information or other special category information, or contain information about suspected or alleged offences.
Website and technical information. IP address; device and browser information; security events; pages viewed; referring pages; interactions with our website; and cookie or similar-technology identifiers.
Communications and marketing information. Messages, call notes, survey responses, communication preferences, marketing choices and a record of whether you have asked us not to contact you.
4. How we obtain personal information
We collect information: directly from you, including through email, telephone calls, forms, applications and meetings; from your employer, organisation, agent or another person acting for you; from GSS clients, site operators, suppliers, personnel and security teams; from referees, previous employers, recruitment businesses, licensing bodies and lawful screening providers; from credit reference, fraud-prevention and identity-verification providers where proportionate; from public sources, such as Companies House, professional registers and information you have deliberately made public; from security systems, access-control systems or recording equipment where GSS is responsible for operating them; and automatically when you use our website.
If a client supplies information to us for a service that the client controls, the client is responsible for giving you appropriate privacy information unless an exemption applies.
5. Why we use personal information and our lawful bases
We only use personal information where we have a lawful basis. The bases that normally apply are set out below.
| Purpose | Normal lawful basis |
|---|---|
| Responding to enquiries, preparing quotations and taking steps towards an agreement | Taking steps at your request before entering a contract, where the agreement is with you; and our legitimate interests in developing and administering business relationships |
| Managing clients, suppliers and other business contacts | Performance of a contract where the agreement is with you; our legitimate interests in managing our services and business relationships; and compliance with legal obligations |
| Delivering, monitoring and improving contracted services | Performance of a contract; our legitimate interests in delivering effective services, maintaining standards and protecting people, premises and property; and compliance with legal and regulatory obligations |
| Managing site access, security events, incidents and investigations | Our legitimate interests, and those of our clients and others, in safety, security, preventing and investigating wrongdoing and establishing facts; compliance with legal obligations; and establishing, exercising or defending legal claims |
| Operating and securing our website and systems | Performance of a contract where applicable; and our legitimate interests in providing reliable services, maintaining audit trails and preventing misuse or cyber incidents |
| Recruitment, selection and pre-employment checks | Taking steps at your request before a contract; our legitimate interests in recruiting suitable personnel and maintaining service standards; and compliance with employment, right-to-work, licensing, safeguarding and other legal obligations |
| Carrying out proportionate identity, business credit, fraud, sanctions or due-diligence checks | Our legitimate interests in assessing business risk, preventing fraud and protecting GSS and its clients; and compliance with legal obligations |
| Billing, accounting, tax, insurance, audit and record keeping | Performance of a contract, compliance with legal obligations and our legitimate interests in financial administration |
| Handling complaints, data protection requests, disputes and legal claims | Compliance with legal obligations and our legitimate interests in resolving concerns and establishing, exercising or defending legal rights |
| Sending relevant business-to-business service information | Our legitimate interests in promoting our services, subject to your rights and the Privacy and Electronic Communications Regulations 2003 ("PECR") |
| Sending electronic marketing where consent or the "soft opt-in" is required | Consent, or the PECR soft opt-in where its conditions are met |
| Measuring and improving our website | Your consent where required; or, where the technology has been configured to meet the statutory statistical-purposes exception, our legitimate interests in understanding aggregate use and improving the website |
| Protecting or reorganising our business | Our legitimate interests in managing corporate transactions, obtaining professional advice and protecting our business and assets |
When we rely on legitimate interests, we consider the necessity of the processing, its likely effect on you and whether your interests or rights should take priority. You may ask us for more information about this assessment.
The contractual basis applies only where you personally are, or may become, a party to the relevant contract. A contract between GSS and a company does not by itself make “contract” the lawful basis for using the personal information of that company’s personnel.
6. Special category and criminal-offence information
We only use special category information—such as health, biometric data used for identification, racial or ethnic origin, religious beliefs, trade-union membership or sexual orientation—when both a normal lawful basis and an additional condition under Article 9 of the UK GDPR apply.
Depending on the circumstances, the additional condition may be: carrying out obligations or rights under employment law; protecting someone’s vital interests where they cannot consent; establishing, exercising or defending legal claims; processing information you have manifestly made public; or a substantial-public-interest condition set out in the Data Protection Act 2018, with the safeguards and appropriate policy document required by that Act.
We only process criminal-offence information where Article 10 of the UK GDPR and a condition in the Data Protection Act 2018 authorise us to do so. This may apply to lawful role-specific vetting, regulatory requirements, the prevention or detection of unlawful acts, security incidents or legal claims. We restrict access, apply enhanced safeguards and keep an appropriate policy document where required.
7. Marketing
We may send relevant information about GSS services to business contacts where we believe it will be of professional interest and the law permits us to do so.
We obtain consent where PECR requires it. In limited circumstances, PECR may allow us to contact an existing customer about our own similar services under the “soft opt-in”, provided that we offered a clear opt-out when we collected the details and in every later message.
You may stop direct marketing at any time by using the unsubscribe option in the message or emailing operations@global-support.org.
You have an absolute right to object to the use of your personal information for direct marketing. If you object, we will stop.
We may keep the minimum information needed on a suppression list so that we can respect your choice.
8. Cookies and analytics
Our website uses a small number of cookies and similar technologies. Essential cookies keep the website working and secure. Optional cookies are used only with your consent — currently limited to video-playback cookies set by our video host, Wistia, when you play a video. We also use Sentry, an error-monitoring service that processes technical information to help us diagnose faults; it is not used for advertising. This website does not use advertising cookies, cross-site tracking or Google Analytics.
You can accept or decline optional cookies using the banner when you first visit, and change your choice at any time via our Cookie Notice, which lists the current technologies, providers, purposes and lifespans.
9. Who we share personal information with
Where necessary and lawful, we may share information with: clients, prospective clients and site operators, where relevant to a service or incident; authorised GSS personnel, workers and subcontractors; website hosting, IT, cloud, communications and cyber-security providers; recruitment, referencing, vetting, identity-verification, licensing, credit-check and fraud-prevention providers; banks, insurers, auditors, accountants, solicitors and other professional advisers; regulators, licensing bodies, courts, tribunals, law-enforcement agencies, emergency services and public authorities; a buyer, investor or adviser involved in a proposed sale, restructuring or transfer of our business; and other parties where you ask us to share the information or the law permits or requires it.
Our service providers may only use personal information for the agreed purpose and must protect it appropriately. We do not sell personal information.
Where we act as a processor for a client, we share information only as the client instructs or as the law requires.
10. International transfers
Some of our suppliers or their support teams process personal information outside the United Kingdom — for example, our video hosting, error-monitoring and email providers. When information is transferred to a country that is not covered by UK adequacy regulations, we use an approved safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another lawful transfer mechanism. We also assess relevant risks and apply supplementary protections where appropriate. You may ask us for information about the applicable safeguard by emailing operations@global-support.org.
11. How long we keep personal information
We keep information only for as long as it is reasonably needed for the purpose for which it was collected, including legal, regulatory, contractual, insurance, security and accounting requirements.
Subject to any need to preserve information for a complaint, investigation, legal claim or legal hold, our intended retention periods are:
| Record | Intended retention period |
|---|---|
| General enquiries that do not become a contract | 24 months after the last meaningful contact |
| Client, supplier and service-contract records | Contract term plus 6 years |
| Invoices, accounts and tax records | Normally 6 years after the relevant financial year |
| Unsuccessful recruitment applications | 6 months after the recruitment decision |
| Candidate talent pool | 12 months, with the candidate's clear agreement |
| Successful candidate records | Transferred to the workforce record and retained under the workforce retention schedule |
| Vetting and licence-check records | For the period required by the relevant licensing requirement and our retention schedule |
| Website and cyber-security logs | 12 months, unless required for an investigation |
| Routine images or recordings controlled by GSS | Normally 31 days, unless preserved for an incident |
| Security, incident and investigation records controlled by GSS | Up to 6 years after closure where needed for claims |
| Data protection requests and complaints | 6 years after closure |
| Direct-marketing contact records | Until you opt out; minimal suppression information may be kept for as long as needed to honour an opt-out |
| Cookie information | The period stated in the Cookie Notice |
When a fixed period is not possible, we consider the amount, nature and sensitivity of the information, the risk of harm, the purpose, whether that purpose can be achieved another way, and relevant legal or contractual requirements.
12. Security
We use appropriate technical and organisational measures designed to protect personal information. These include measures appropriate to the nature and risk of the processing, such as access controls, authentication, staff confidentiality, supplier due diligence, backups, monitoring and incident-response arrangements.
No internet or storage system can be guaranteed to be completely secure.
13. If you do not provide information
Some information is optional. However, we may be unable to answer an enquiry, enter into or perform a contract, process an application, complete a legally required check or deploy someone to a regulated role if the information reasonably required for that purpose is not provided.
We will tell you when information is required by law or contract, and the likely consequence of not providing it, where this is not already obvious.
14. Automated decision-making
GSS does not currently make decisions that produce legal or similarly significant effects about you solely through automated processing. Credit, vetting, recruitment and security decisions involve meaningful human review.
If this changes, we will provide the information required by law about the decision, its likely effect, the information and logic involved, and your right to obtain human intervention, express your view and challenge the decision.
15. Your data protection rights
Depending on the circumstances and our lawful basis, you may have the right to: access your personal information and receive a copy; rectify inaccurate information and complete incomplete information; erase information where there is no lawful reason for us to keep it; restrict how information is used in certain circumstances; object to processing based on legitimate interests or for a task in the public interest; object to direct marketing at any time; receive information you provided in a structured, commonly used and machine-readable form and have it transferred to another controller, where the right to data portability applies; withdraw consent at any time, without affecting processing already carried out lawfully; and receive the safeguards that apply to certain significant decisions made solely by automated means.
These rights are not absolute. For example, we may need to retain information to comply with law, protect another person’s rights or establish, exercise or defend legal claims. We will explain any relevant restriction when responding.
You may make a request verbally or in writing using the contact details in section 1. We may ask for proportionate information to confirm your identity or clarify your request. We normally respond within one month, although the law permits an extension for a complex request or multiple requests. There is usually no fee.
16. Complaints
Please contact us first if you have a concern about how we use personal information: Email: operations@global-support.org · Post: Data Protection Contact (Daniel Mailly), Global Support Services (UK) Ltd, 5–9 Headstone Road, Harrow, England, HA1 1PD.
We will acknowledge a data protection complaint within 30 days, take appropriate steps to investigate and respond without undue delay, keep you informed where appropriate, and tell you the outcome.
You may also complain to the Information Commissioner’s Office (“ICO”): Website: https://ico.org.uk/make-a-complaint/ · Telephone: 0303 123 1113 · Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
You do not have to complain to us before contacting the ICO, although the ICO may ask whether you have first raised the matter with us.
17. Links to other websites
Our website may link to websites or services operated by other organisations. Those organisations are responsible for their own privacy practices. Please read their privacy information before providing personal information.
18. Changes to this notice
We review this notice regularly and will publish updates on this page. If a change would materially affect how we use information, we will take reasonable steps to bring it to the attention of affected people and seek consent where the law requires it.
The date at the top shows when this notice was last updated.
