GCC Foundry Back to site

Privacy Policy

GCC FOUNDRY PRIVATE LIMITED

CIN: U85499DL2026PTC470115
Website: https://gccfoundry.com
Effective Date: 01 October 2026
Last Updated: 01 October 2026

1. Introduction and Company Details

This website is operated by GCC Foundry Private Limited, a company incorporated under the Companies Act, 2013, bearing CIN U85499DL2026PTC470115 and having its registered office at 293, Lane-2, Westend Marg, Near Saket Metro Station, Gadaipur, New Delhi, South West Delhi – 110030, Delhi, India (“Company”, “GCC Foundry”, “we”, “us” or “our”).

The Company provides executive and professional training, including executive education, leadership and management development, business and AI-enabled capability programmes, skilling, certification, assessment and advisory activities, primarily for leaders, managers and high-potential professionals seeking to advance their careers within the Global Capability Centre ecosystem (“Services”).

We respect your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, with whom we share it, and the choices available to you.

2. Scope and Applicable Law

This Policy applies to personal information processed in connection with gccfoundry.com (“Website”), including Fellowship applications, brochure requests, programme enquiries and related communications.

Where you subsequently enrol in a programme or use additional Services, we may provide a supplementary notice explaining any additional information collected, its purposes, recipients and retention arrangements. This Policy applies to such processing to the extent relevant.

We handle personal information in accordance with applicable Indian law, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable, and the Digital Personal Data Protection Act, 2023 and rules thereunder as their relevant provisions come into force (“Applicable Data Protection Law”).

Reading this Policy or merely browsing the Website does not constitute consent to every processing activity described herein. Where consent is required, we obtain it through an appropriate affirmative consent mechanism.

3. Information We Collect

We collect information relevant to your interaction with us. The current Website forms collect the following:

3.1 Fellowship application form

3.2 Brochure request form

3.3 Technical information associated with form submissions

3.4 Communications and admissions information

We may also collect information you voluntarily provide when communicating with us, including programme preferences, questions, interview responses, application-related correspondence and information reasonably necessary to administer the selection process.

3.5 Website operation and security information

Our hosting and security providers may process technical request information, logs and security signals when you access the Website, including where you do not submit a form. Such processing is limited to the purposes described in this Policy and the applicable provider arrangements.

3.6 Additional programme information

If you enrol in a programme, additional information may be required, such as billing details, attendance, assignments, assessment responses, progress, feedback and certification records. We will explain the relevant collection and use through the enrolment process or an appropriate supplementary notice before collecting such information.

We collect only the information reasonably necessary for the relevant purpose.

4. Sensitive Personal Information

The current application and brochure-request forms do not request financial information, government identification numbers, health information, biometric information or other sensitive personal information.

Please do not include such information in forms or ordinary enquiry communications unless we specifically request it through an appropriate process.

If sensitive personal information becomes necessary for a particular Service, we will explain the purpose, limit collection to what is necessary, obtain the consent required by applicable law, and apply the required safeguards.

5. How We Collect Information

We collect personal information directly from you when you submit a form, communicate with us or participate in an application or enrolment process.

Certain technical information is collected automatically through Website infrastructure, form submissions and security technologies.

Where an employer, sponsor or authorised representative provides your information to arrange Services, we will take reasonable steps to ensure that the disclosure and our processing are lawful and that you receive an appropriate notice.

If you provide another person’s information, you should have authority to do so and inform that person about this Policy. This does not replace any independent notice or consent obligation applicable to the Company.

6. Purposes for Which We Use Information

We use relevant personal information for the following purposes:

(a) Fellowship admissions: To review your application, assess suitability, administer interviews or selection activities, and contact you about the Fellowship and its selection process.

(b) Brochure requests and programme enquiries: To provide the brochure you request, respond to questions and communicate information about the programme in which you have expressed interest.

(c) Application and enrolment administration: To maintain application records, communicate outcomes and, where applicable, facilitate enrolment.

(d) Campaign attribution: To understand which advertisements, emails or other channels generate enquiries and applications, using campaign tags and related technical information.

(e) Website operation and protection: To operate and troubleshoot the Website, protect forms against spam, bots and abuse, detect security incidents and prevent misuse.

(f) Optional future communications: Where you separately opt in, to contact you about future cohorts, other programmes, events or relevant Company updates.

(g) Service delivery: Following enrolment and appropriate notice, to deliver training, administer assessments, provide support, manage payments and issue or verify certificates.

(h) Legal and compliance requirements: To maintain legally required records, respond to lawful requests, resolve complaints and establish, exercise or defend legal claims.

We do not use information for an undisclosed, unrelated purpose without providing the notice and obtaining the consent required by applicable law.

Where required, we process personal information on the basis of your informed, specific consent, obtained through the relevant form or other appropriate mechanism.

The form notice will identify the information collected and the purposes for which it will be used. Consent for optional promotional communications is separate from consent needed to respond to your application or brochure request.

You may decline to provide optional information. If information is necessary to process an application, fulfil a request or provide a particular Service, declining that information may prevent us from completing the relevant activity. We will explain this consequence where applicable.

Where processing without consent is permitted by a specific provision of applicable law, we may rely on that provision. We do not rely on a general, unrestricted claim of “legitimate interests” to process personal information.

8. Marketing and Future-Cohort Communications

Submitting an application or requesting a brochure permits us to respond to that request and communicate about the relevant programme, subject to the applicable consent requirements. It does not automatically authorise indefinite promotional communications about future cohorts or unrelated offerings.

Where you separately opt in, we may send information about future cohorts, programmes, events or Company updates through the communication channels you select.

You may withdraw this preference by using an unsubscribe facility, where provided, or emailing connect@gccfoundry.com.

Necessary communications relating to an active application, enrolment, payment or security matter may continue to the extent lawfully required or permitted.

We do not sell your personal information or share it with third parties for their independent marketing without appropriate consent.

9. Who May Receive Your Information

9.1 Authorised Company personnel

Relevant information is accessible to authorised members of the GCC Foundry admissions team and other personnel who require access for the purposes described in this Policy. Access is limited according to their responsibilities.

9.2 Website service providers

We use service providers to operate the Website and support its forms and communications. These include:

These providers may process relevant personal or technical information to perform their functions. Providers acting on our behalf are subject to appropriate contractual instructions, confidentiality obligations and security requirements.

If a provider acts independently for a particular processing activity, its applicable privacy notice will govern that activity, and we will provide relevant information where required.

9.3 Programme partners and sponsors

If you enrol in a programme involving trainers, assessors, certification bodies, institutions or an employer sponsor, necessary information may be shared for the disclosed programme purposes.

Any employer reporting, including attendance, progress or assessment results, will be explained through the relevant programme notice. Sponsorship does not authorise unrestricted disclosure.

9.4 Legal disclosures

We may disclose information to professional advisers, courts, regulators, law enforcement agencies or other authorised recipients where legally permitted or required, including to comply with lawful orders or address legal claims.

9.5 Business transactions

Where necessary for a proposed or completed merger, restructuring or transfer of business, information may be disclosed subject to confidentiality safeguards, applicable legal requirements and any required notice or consent.

Sensitive personal information will be disclosed only with the permission or contractual authorisation required by law, or under an applicable legal exception.

10. Cookies, Campaign Tags and Bot Protection

The Website does not currently use advertising cookies.

Campaign tags in links may be captured with a form submission to identify the source of an enquiry or application. Capturing these tags does not, by itself, mean that advertising cookies are used.

Where Cloudflare Turnstile or another notified security service is enabled, it may process technical signals and use cookies or similar technologies to distinguish human visitors from automated traffic and protect the Website against abuse.

You may manage cookies through your browser settings. Restricting technologies necessary for security or Website functionality may affect form submission or other features.

If we introduce optional analytics, advertising cookies or other tracking technologies, we will update the relevant disclosures and implement any legally required consent controls before activating them.

11. Storage and Transfers Outside India

Our service providers may store or process information on servers in India or outside India.

We will ensure that transfers comply with applicable legal restrictions and safeguards. Where the SPDI Rules apply, sensitive personal information will be transferred only to a recipient ensuring the same level of protection required under those Rules, and only where necessary to perform a lawful contract with you or where you have consented.

We will also comply with applicable cross-border restrictions under the DPDP framework as the relevant provisions become effective.

12. How Long We Retain Information

We retain personal information only for as long as necessary for its disclosed purpose or a lawful retention requirement.

Application and brochure-request information is retained for the relevant admissions or enquiry cycle and any reasonably necessary follow-up or administration period.

Retention for communications about future cohorts is based on your separate preference for those communications. We periodically review such records and remove information that is no longer necessary. A future-cohort mailing list is not a basis for indefinite retention of the complete application record.

Different retention periods may apply to enrolled participants, certification records, accounting documents, security logs, complaints or legal claims.

You may request deletion sooner by contacting us. Where information must lawfully be retained, we will explain the applicable reason where relevant.

When retention is no longer justified, we will securely delete or irreversibly anonymise the information. Backup copies will be protected against ordinary use and removed through the applicable backup cycle, subject to legal requirements.

13. Security and Breach Response

Form submissions are encrypted in transit and stored in an access-controlled database. Access to submission records is restricted to authorised personnel.

We maintain reasonable technical, organisational and physical safeguards appropriate to the information and processing risks, including access controls, confidentiality requirements, system maintenance and incident-response measures.

No system is completely secure. This does not exclude or limit our obligations under applicable law.

If a personal information breach occurs, we will investigate, take appropriate containment and remedial measures, and notify affected individuals and competent authorities where legally required, within the applicable timelines.

14. Your Choices and Privacy Rights

You may contact us to request that we:

Consent may be withdrawn by emailing connect@gccfoundry.com or using an available consent-management facility. Withdrawal will not affect processing lawfully undertaken before withdrawal.

We will stop the relevant consent-based processing and require processors acting on our behalf to do so, subject to processing or retention otherwise permitted or required by law. If the withdrawn consent is necessary to provide a Service, we will explain the effect on that Service.

As the relevant DPDP provisions come into force and apply to the processing, you may also exercise the statutory rights available to you, including access to prescribed processing and sharing information, correction, completion, updating, erasure, grievance redressal and nomination of another individual to exercise your rights in the event of death or incapacity.

We may reasonably verify your identity or authority before acting on a request. Verification will be proportionate and will not require unnecessary information.

15. Children’s Information

The Fellowship is intended for experienced professionals. The Website and ordinary application process are not intended for individuals under 18 years of age.

We do not knowingly collect children’s personal information through these forms. If we become aware that such information has been collected without the necessary authorisation, we will take appropriate steps to stop processing and delete it, subject to applicable law.

If a future programme expressly admits persons under 18, separate notices and legally compliant parental or guardian consent arrangements will apply, together with applicable restrictions on children’s data processing.

16. Recordings, Testimonials and AI-Enabled Services

The Website’s application and brochure-request forms do not, by themselves, authorise recording participants or using their identities for publicity.

Where a programme or event is to be recorded, we will provide advance notice explaining the intended use and access arrangements and obtain consent where legally required.

Public promotional use of an identifiable participant’s photograph, testimonial or recording requires separate, appropriate authorisation.

Where AI-enabled tools process participant information in connection with our Services, we will provide relevant notice and obtain consent where required. Identifiable participant information will not be used to train third-party general-purpose AI models without separate, specific consent.

17. Grievance Officer and Contact Details

For privacy enquiries, requests, consent withdrawal or complaints, please contact:

Grievance Officer: Debarati Sengupta

Designation: CEO

Email: connect@gccfoundry.com

Postal Address: Grievance Officer
GCC Foundry Private Limited
293, Lane-2, Westend Marg, Near Saket Metro Station,
Gadaipur, New Delhi, South West Delhi – 110030, Delhi, India.

Please describe your request and provide sufficient information to identify the relevant application, enquiry or interaction.

We will address privacy grievances expeditiously and within one month of receipt, or within any shorter mandatory period applicable to the matter. Other privacy requests will be handled within the applicable legal period.

When the relevant DPDP grievance provisions come into force and apply, you may approach the Data Protection Board of India in accordance with the prescribed procedure after exhausting the Company’s grievance-redressal mechanism.

Nothing in this Policy restricts a remedy otherwise available under applicable law.

18. External Websites and Services

The Website may contain links to independently operated websites, social media platforms or other external services. Their processing is governed by their respective privacy notices.

Please review those notices before providing information. This provision does not reduce the Company’s responsibilities for service providers processing information on its behalf.

19. Changes to This Policy

We may update this Policy to reflect changes in our Services, processing practices or applicable law. The revised Policy and updated date will be published on the Website.

Where required, we will provide additional notice and obtain fresh consent before using existing information for a new purpose.

Publication of an amended Policy or continued Website use does not, by itself, constitute consent to a new processing purpose.

20. Applicable Law and Jurisdiction

This Policy is governed by Indian law. Subject to mandatory statutory jurisdiction and remedies, disputes arising from this Policy shall be subject to the jurisdiction of the competent courts at New Delhi.

Nothing in this Policy excludes any non-waivable right or limits the jurisdiction of a competent statutory authority.