Skip to content
GPS, Global Processing Services

Legal

Privacy Policy

What we collect, why we hold it, who we share it with, and how to make us stop.

Effective
1 August 2026
Last updated
1 August 2026
Version
1.0
Applies to
gpsbpo.com and all GPS services

1. Who we are

Global Processing Services (Pvt) Ltd, registered in Sri Lanka, with its registered office at 40, Vajira Road, Colombo 04, Sri Lanka. In this policy, “GPS”, “we” and “us” mean that company. “You” means anyone whose personal data we handle.

For anything covered by this policy, including requests about your own data, write to us at info@gpsbpo.com.

2. When we are a controller and when we are a processor

This distinction changes what we may do with your data, so we state it plainly.

SituationOur roleWhat it means
You contact us, apply for a job, or use this websiteControllerWe decide why and how the data is used, and this policy governs it.
We handle your data because you are a customer of one of our clientsProcessorOur client decides why and how. We act only on their documented instructions. Their privacy notice governs it, not this one.

If you contacted us because a GPS agent called you on behalf of another company, that company is the controller. We will pass your request to them and tell you who they are.

3. What we collect

Information you give us

  • Name, work email, phone number, company and country, when you submit an enquiry or request a proposal.
  • The content of your enquiry, and any subsequent correspondence.
  • CV, work history, education and references, when you apply for a role.
  • Contract, billing and contact details, when you become a client.

Information we collect automatically

  • IP address, browser type, device type, operating system and referring page.
  • Pages viewed, time on page and interactions, where you have accepted analytics cookies.

Information from third parties

  • Publicly available business contact information, where we have a legitimate interest in reaching you.
  • Background and reference checks for candidates, with your knowledge.

We do not collect special category data through this website, and we ask that you do not include health, biometric, religious, political or similar information in free-text fields.

4. Why we use it

  • To respond to your enquiry and prepare a proposal.
  • To deliver services under a contract and to invoice for them.
  • To assess job applications and manage recruitment.
  • To secure our systems, detect fraud and investigate incidents.
  • To meet legal, tax, audit and regulatory obligations.
  • To improve this website and understand which content is useful.
  • To send you relevant business communications, where you have asked us to.

We do not sell personal data. We do not share it with third parties for their own marketing.

5. Lawful basis

PurposeBasis
Responding to enquiriesConsent, and legitimate interest in answering people who contact us
Delivering contracted servicesPerformance of a contract
RecruitmentSteps prior to entering a contract, and consent for retention in our talent pool
Security and fraud preventionLegitimate interest in protecting our systems and our clients' data
Legal, tax and audit recordsLegal obligation
Analytics cookiesConsent

6. Who we share it with

  • Our clients, where we process data on their behalf.
  • Service providers under written contract: hosting, telephony, CRM, email delivery and analytics. Each is bound to process data only on our instructions.
  • Professional advisers: auditors, lawyers and insurers, where required.
  • Authorities, where we are legally compelled. We will tell you unless we are prohibited from doing so.

A current list of our sub-processors is available from info@gpsbpo.com.

7. International transfers

We operate from Sri Lanka and serve clients in Singapore, Canada, Australia, the United Kingdom and the European Economic Area. Personal data will therefore be transferred outside your country.

For transfers out of the UK and the EEA we rely on Standard Contractual Clauses together with a transfer risk assessment carried out per client. For transfers under the Singapore Personal Data Protection Act we ensure a comparable standard of protection by contract. Copies of the relevant safeguards are available on request.

8. How long we keep it

DataRetention
Website enquiries and proposal requests24 months from last contact
Unsuccessful job applications12 months, or longer with your consent
Client contracts and correspondence7 years after the contract ends
Financial and tax recordsAs required by Sri Lankan law
Call recordingsAs instructed by the client controller, typically 90 days
Security and access logs12 months

When a retention period ends we delete the data or irreversibly anonymise it.

9. How we protect it

We apply role-based access control, encryption in transit and at rest, network segregation for any payment-handling environment, clean-desk and no-device policies on the operations floor, and background screening of staff. Where a client requires a specific certification or control framework, we agree it in the contract.

We maintain a documented incident response plan. Where a breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you without undue delay. Report a suspected incident to info@gpsbpo.com.

10. Your rights

Depending on where you are, you have some or all of the following rights.

  • Access. Get a copy of the personal data we hold about you.
  • Correction. Have inaccurate or incomplete data fixed.
  • Erasure. Have data deleted where we no longer have grounds to keep it.
  • Restriction. Have us pause processing while a dispute is resolved.
  • Objection. Object to processing based on legitimate interest, and to direct marketing at any time.
  • Portability. Receive your data in a structured, machine-readable format.
  • Withdraw consent. At any time, without affecting processing already carried out.
  • Human review. We do not make decisions producing legal effects by automated means alone.

To exercise any of these, email info@gpsbpo.com. We respond within 30 days and will tell you if we need longer. There is no charge unless a request is manifestly excessive.

11. Cookies

We set strictly necessary cookies to run this site. We set analytics cookies, and load third-party embeds such as maps, only after you accept them. Rejecting non-essential cookies does not restrict access to any part of this site.

You can change or withdraw your choice at any time using the Cookie settings control at the foot of every page. Withdrawing is one click and takes effect immediately. Your choice is stored for 180 days, after which we ask again. Full detail is in our Cookie Policy.

12. Children

This website and our services are directed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact info@gpsbpo.com and we will delete it.

13. Changes to this policy

We will post any change on this page with a new version number and effective date. Where a change materially affects how we use data you have already given us, we will tell you directly before it takes effect. Previous versions are available on request.

14. Contact and complaints

Global Processing Services (Pvt) Ltd, 40, Vajira Road, Colombo 04, Sri Lanka. Email info@gpsbpo.com.

If you are not satisfied with our response, you may complain to the Data Protection Authority of Sri Lanka, the Personal Data Protection Commission of Singapore, the UK Information Commissioner's Office, or your local supervisory authority in the EEA. We would rather you came to us first.

Plain-language summary. We collect what you send us and a little about how you use this site. We use it to reply to you, do the work, and stay legal. We do not sell it. You can ask to see it, fix it or have it deleted by emailing info@gpsbpo.com.

Back to Legal