Privacy Policy

Last updated: 11 August 2026

This policy is the notice required under Section 5 of the Digital Personal Data Protection Act, 2023 ("DPDPA"). It explains what personal data Green Outdoors Global Pvt Ltd collects, why we collect it, how long we keep it, and the rights you have as a Data Principal. For our Romania operations we also apply the EU General Data Protection Regulation (GDPR) where it applies.

1. Who is responsible for your data

Green Outdoors Global Pvt Ltd is the Data Fiduciary — we decide why and how your personal data is processed. We are an MEA Registered Recruiting Agent (Licence B-1873/GUJ/COM/100/5/10332/2023).

  • Registered office: Vadodara, Gujarat, India
  • Data protection contact: office@gogpl.in

2. What we collect, and why

We collect only what we need for the service you ask us for. We do not sell your personal data, and we do not use it for automated decision-making or profiling.

Data we collectPurposeOur lawful basis (DPDPA)
Name, phone, email, city, service interest, messageTo answer your enquiry and assess eligibility for the service you requestedYour consent, given when you submit the form
CV/resume, qualifications, trade experience, photographsTo match you with employer vacancies you have asked to be considered forYour consent
Passport, identity, medical fitness, police clearance and travel documentsVisa, permit, emigration clearance and employer onboarding formalitiesYour consent, collected separately and offline, plus legal obligation under emigration law
Employer/partner company contact detailsTo manage recruitment agreements and demand lettersPerformance of contract / legitimate use
Website usage data (see our Cookie Policy)To measure and improve the websiteYour consent via the cookie banner
Server logs, IP address, anti-abuse signalsSecurity, fraud prevention and keeping the service availableLegitimate use under Section 7 DPDPA
Email address (newsletter sign-up)To send the blog and company updates you opted intoYour consent, given when you subscribe

Providing your data is voluntary, but if you choose not to provide the documents required for a visa or employment application, we may be unable to deliver that service.

3. Who we share it with

We share personal data only where it is necessary for the service you engaged us for:

  • Prospective employers — candidate profiles and documents, for the roles you have applied to.
  • Embassies, consulates and government authorities (including the Ministry of External Affairs, eMigrate and, for Nepali candidates, DoFE-licensed agencies) — as required by law.
  • Service providers acting on our instructions (Data Processors) — our Zoho CRM (Zoho One), email and hosting providers, and Cloudflare for security. They may process your data only for us and may not use it for their own purposes.

We never sell your data, rent it, or share it with advertisers.

4. Transfers outside India

Some processing happens outside your home country. Lead data is processed in Zoho's India data centres. Candidate data relevant to European placements may be handled by our Bucharest (Romania) office and by employers in the destination country, under applicable EU data protection rules. Transfers are made only for the purpose you engaged us for, and only to countries not restricted by the Central Government under Section 16 of the DPDPA.

5. How long we keep it

  • CVs, resumes and uploaded documents: automatically deleted 3 years after you submit them. This is an automated daily job, not something left to someone remembering.
  • Enquiry records (your name, contact details and message): kept while we may still be able to help you and as a record of the service we provided. You can ask us to erase them at any time — see section 6 — and we will, unless a law requires us to keep them.
  • Candidate files and travel documents for a live application: for the duration of the engagement and afterwards for as long as emigration, tax and employment law require us to keep records.
  • Website analytics: as described in the Cookie Policy.
  • Newsletter sign-ups: kept until you unsubscribe or ask us to remove you — use the link in any update email, or email us at any time.

When you withdraw consent, or when the purpose is no longer being served, we erase your personal data — unless retaining it is required by law. Where we are required to keep records, we keep only what the law requires.

6. Your rights as a Data Principal

Under the DPDPA you have the right to:

  • Access — a summary of the personal data we hold about you and how it is being processed, and the identities of anyone we have shared it with.
  • Correction, completion and updating — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted where we are not legally required to keep it.
  • Withdraw consent — at any time, and as easily as you gave it. Withdrawal does not affect processing already carried out lawfully.
  • Grievance redressal — to complain to us first, and to receive a response (see below).
  • Nominate — to nominate another person to exercise your rights on your behalf in the event of your death or incapacity.

To exercise any right, email office@gogpl.in from the address you registered with, stating what you want. We respond within 30 days. There is no charge.

You also have a duty under Section 15 of the DPDPA not to submit false particulars or impersonate another person when exercising these rights.

7. Grievance Officer

If you are unhappy with how we handle your personal data, contact our Grievance Officer:

  • Grievance Officer: Ms Shivani, office@gogpl.in
  • Response time: acknowledgement within 7 working days; resolution within 30 days.

If we do not resolve your complaint to your satisfaction, you may escalate it to the Data Protection Board of India established under the DPDPA.

8. Children and persons with a guardian

Our services are directed at adults. We do not knowingly process the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children. Where a candidate is a person with a disability who has a lawful guardian, we obtain the guardian's consent. If you believe a child's data has been given to us, write to office@gogpl.in and we will delete it.

9. How we protect your data

We apply reasonable security safeguards as required by Section 8(5) of the DPDPA, including encryption in transit (HTTPS), access-restricted storage for CVs and documents kept separate from public website files, role-based access for staff, activity logging on our admin systems, and anti-abuse protection on our forms and admin login.

In the event of a personal data breach we will notify the Data Protection Board of India and every affected Data Principal, in the manner and within the timelines prescribed under the DPDPA.

10. Cookies

We use a small number of cookies and similar technologies. No analytics cookies are set, and no session-recording tool loads, until you consent through the cookie banner. Full detail — including each cookie, its purpose and how to withdraw consent — is in our Cookie Policy.

11. Changes and languages

We may update this policy as our services or the law change; the "last updated" date above always reflects the current version. This notice is available in English. You may request it in Hindi, Gujarati, Nepali or any other language listed in the Eighth Schedule to the Constitution of India by writing to office@gogpl.in.

This policy is provided for transparency and does not constitute legal advice. For legal interpretation, consult a licensed legal professional.