Privacy Policy
Website & Business Contacts Privacy Notice
Global Quality Certificate Ltd (GQCL) Effective Date: 13-5-2026 | Last Updated: 13-5-2026 | Version: 1.1
1. Introduction
This notice explains how Global Quality Certificate Ltd (“GQCL”, “we”, “us”) collects, uses, and protects personal data through our website at www.gqcl.co.uk and in the course of ordinary business contact with enquirers, prospective and existing client contacts, and training or workshop registrants. GQCL is a UK-registered, independent, accredited validation, verification, inspection, and certification body. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
The data controller is: Global Quality Certificate Ltd (GQCL) Registered Address: 20-22 Wenlock Road, London, N1 7GU, United Kingdom Email: info@gqcl.co.uk Phone: +44 7411 567732 Website: www.gqcl.co.uk For data protection enquiries, please contact us at info@gqcl.co.uk marked “Data Protection Enquiry”.
3. Scope of this Notice and Related Privacy Information
This notice covers personal data we process about: Separate privacy information is provided for:
- visitors to www.gqcl.co.uk;
- individuals who contact us through general business enquiries;
- prospective clients and their representatives;
- contact persons at client and supplier organisations;
- registrants for training courses, webinars, and workshops collected through our website or general business channels;
- recipients of our B2B service communications.
- candidates and job applicants (Recruitment Privacy Notice);
- employees, contractors, auditors, and technical experts (Personnel Privacy Notice or other applicable internal notice);
- cookies and similar technologies on our website (Cookie Policy);
- detailed personal data processing in the course of certification, inspection, validation, verification, and related accredited services (Client and Accredited Services Privacy Notice or the relevant service agreement schedule).
4. Our Role When Delivering Accredited Services
When carrying out certification, inspection, validation, verification, and related conformity-assessment activities, GQCL generally acts as an independent data controller. Our accreditation requirements, including those under ISO/IEC 17021-1, ISO/IEC 17020, ISO/IEC 17029, and ISO 14065, oblige us to exercise independent judgment, maintain audit trails, and retain records for defined periods. We determine the means and certain purposes of that processing in our own right and cannot accept third-party instructions that would compromise our impartiality. Where GQCL processes personal data only on another party’s documented instructions and in a manner that does not engage these accreditation duties, the relevant contract will set out the processor and controller roles. Clients may, in the course of accredited engagements, provide GQCL with personal data relating to their employees, contractors, customers, or other third parties (for example, named auditees, witnesses, or technical experts). Clients remain responsible for ensuring they are entitled to share that data with GQCL and for providing any required notices to those individuals.
5. Personal Data We Collect
Depending on how you interact with us, we may collect: Detailed accredited audit-file content (for example, full audit findings, witness records, and certification decision papers) is governed by our Client and Accredited Services Privacy Notice or the applicable service agreement.
- Identity and contact data: name, job title, employer, business email, business phone, business address, professional qualifications.
- Enquiry and engagement data: the content of your enquiry, scope of services discussed, quotation and proposal correspondence.
- Training and event data: registration details, attendance, assessment results where applicable.
- Financial and invoicing data: billing contacts, purchase order references, payment records (typically corporate rather than personal).
- Website and technical data: IP address, device and browser information, pages viewed, referral source, and cookie-derived data (see section 15).
- Correspondence: emails, letters, meeting notes, and records of calls relating to your interaction with us.
6. How We Collect Personal Data
We collect personal data:
- directly from you, when you contact us, request a quote, register for an event, or interact with us in a business capacity;
- through our website, including via online forms and the analytics described in our Cookie Policy;
- from your employer or the client organisation that has engaged us;
- from publicly available business sources, such as company registries, professional directories, and accreditation databases;
- occasionally from third parties such as accreditation bodies, regulators, referrers, or industry partners, where relevant to a specific engagement.
7. Purposes and Lawful Bases
We process personal data for the following purposes and on the following lawful bases under Article 6 of the UK GDPR: Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may ask for further information about that assessment using the contact details in section 2.
Purposes and lawful bases in detail
Responding to enquiries and preparing quotations
Categories of Data
Identity, contact, enquiry data
Lawful Basis
Art. 6(1)(b) – steps prior to contract; Art. 6(1)(f) – legitimate interests in responding to business contacts
Delivering services and managing client relationships
Categories of Data
Identity, contact, engagement, correspondence data
Lawful Basis
Art. 6(1)(b) – performance of contract; Art. 6(1)(f) – legitimate interests in account management
Maintaining accredited records, certificates, and audit files
Categories of Data
Identity, engagement, audit-related data
Lawful Basis
Art. 6(1)(c) – legal obligation, where applicable; Art. 6(1)(f) – legitimate interests of GQCL and the wider conformity-assessment system in defensible records
Administering training, webinars, and workshops
Categories of Data
Identity, contact, training data
Lawful Basis
Art. 6(1)(b) – performance of contract; Art. 6(1)(f) – legitimate interests in event administration
Invoicing, payment processing, and financial administration
Categories of Data
Identity, contact, financial data
Lawful Basis
Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligation under tax and accounting law
B2B service communications and marketing to corporate contacts
Categories of Data
Identity, contact data
Lawful Basis
Art. 6(1)(f) – legitimate interests; Art. 6(1)(a) – consent, where required by law (see section 8)
Operating and securing the website
Categories of Data
Website and technical data
Lawful Basis
Art. 6(1)(f) – legitimate interests in the integrity, availability, and security of our website
Website analytics and other non-essential cookies
Categories of Data
Website and technical data, cookie identifiers
Lawful Basis
Art. 6(1)(a) – consent (obtained through our cookie banner); see also PECR
Security, fraud prevention, and protection of our systems and premises
Categories of Data
Website, technical, correspondence data
Lawful Basis
Art. 6(1)(f) – legitimate interests; Art. 6(1)(c) – legal obligation, where applicable
Establishing, exercising, or defending legal claims and complying with regulatory and accreditation requirements
Categories of Data
All categories, as relevant
Lawful Basis
Art. 6(1)(c) – legal obligation; Art. 6(1)(f) – legitimate interests
8. B2B Communications and Marketing
We may send service updates, sector briefings, training announcements, and similar B2B communications to corporate contacts where this is permitted by law and where our legitimate interests in maintaining business relationships are not overridden by your rights. Where the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) require prior consent, we will obtain it before sending the communication. You may opt out of marketing at any time by using the unsubscribe link in our emails or by contacting info@gqcl.co.uk. After opt-out we retain a minimal suppression record (typically your email address and the fact that you have opted out) so that we do not contact you again.
9. Sharing Personal Data
We do not sell personal data. We share personal data only where necessary, with: Where GQCL provides public certificate-verification tools (for example, look-up of a certificate barcode or reference number), we may display limited certificate-status information necessary to confirm validity, scope, and authenticity. We do not publish personal data through these tools beyond what is reasonably required to identify the certified entity and the scope of its certification.
- accreditation bodies (including EGAC and other International Accreditation Forum signatory bodies) and scheme owners, in connection with surveillance, peer evaluation, witness audits, and complaints handling;
- regulators, competent authorities, and courts, where we are legally required or permitted to disclose;
- our group offices and authorised partners in the United Kingdom, Egypt, Lebanon, Iraq, Saudi Arabia, and the United Arab Emirates, to coordinate engagements and maintain consistent service quality, subject to appropriate confidentiality and data protection obligations;
- service providers acting on our behalf, including IT and cloud infrastructure, communications platforms, and document-management providers, under contracts requiring them to process data only on our instructions and to apply appropriate safeguards;
- professional advisers, such as lawyers, auditors, and accountants, who may act as independent controllers where they determine how they use personal data for their own professional purposes;
- a successor entity, in the event of a corporate reorganisation, sale, or transfer of part of our business, subject to appropriate confidentiality and data protection commitments.
10. International Data Transfers
GQCL operates through offices and authorised partners across the United Kingdom and the Middle East. Personal data may therefore be transferred to, accessed from, or stored in countries outside the United Kingdom, including Egypt, Lebanon, Iraq, Saudi Arabia, and the United Arab Emirates. Where we transfer personal data outside the UK, we rely on one or more of the following lawful transfer mechanisms: Where required, we carry out a transfer risk assessment and put additional technical, contractual, or organisational measures in place. You may request further information about our transfer mechanisms by contacting info@gqcl.co.uk.
- UK adequacy regulations, where the destination country has been recognised by the UK Government as providing an adequate level of protection;
- the UK International Data Transfer Agreement (UK IDTA) issued by the Information Commissioner;
- the UK Addendum to the EU Standard Contractual Clauses;
- other transfer tools approved under UK data protection law.
11. Retention
We retain personal data only for as long as necessary for the purposes set out in this notice, including to meet legal, regulatory, accreditation, and contractual requirements. Indicative retention periods are: After the applicable retention period, personal data is securely deleted, destroyed, or anonymised.
- Certification, inspection, validation, and verification records: retained for the period required by the applicable accreditation standards and scheme rules, and thereafter as needed for legal-claims and quality-system purposes.
- Financial and invoicing records: normally seven years under our internal retention policy, including to meet UK tax, accounting, and legal-claims requirements.
- Enquiry and quotation records: typically up to two years from last contact, unless a contract is concluded.
- Training and event records: for the duration of the participant relationship and for a reasonable period thereafter, taking into account scheme-specific requirements.
- Marketing records: until you unsubscribe or otherwise withdraw consent. After opt-out we retain minimal suppression data so that we do not contact you again.
- Website analytics data: as configured in our analytics platform.
12. Security
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit and at rest where appropriate, network and endpoint protection, secure storage of physical records, staff training, and incident-response procedures. In the event of a personal data breach likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of it and will inform affected individuals where required by law.
13. Your Rights
Subject to the conditions and exceptions in UK data protection law, you have the right to: To exercise any right, please contact info@gqcl.co.uk with the subject line “Data Subject Request”. We may need to verify your identity before responding. We will respond within one month, extendable by up to two further months for complex or numerous requests, with notification. Some rights are not absolute. In particular, where personal data is held within accredited audit files that we are required to retain for defined periods, we may be unable to delete it on request.
- request access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure of your data;
- request restriction of processing;
- object to processing carried out on the basis of legitimate interests, including direct marketing;
- request data portability for data you have provided to us, where processing is based on consent or contract and is carried out by automated means;
- withdraw consent at any time, where processing is based on consent;
- complain to the Information Commissioner’s Office (see section 19).
14. Automated Decision-Making
GQCL does not make decisions producing legal or similarly significant effects on individuals based solely on automated processing. Certification, inspection, and verification decisions involve qualified personnel exercising professional judgment.
15. Cookies
Our website uses cookies and similar technologies. Strictly necessary cookies are used for the basic operation of the site. Non-essential cookies (such as analytics) are used only where you have consented through our cookie banner. You can change your preferences at any time. For full details, including the categories of cookies used, the providers, retention, and how to control them, please see our Cookie Policy.
16. Children
Our services are directed at organisations and business professionals. We do not knowingly collect personal data from children. If you believe a child has provided personal data through our website, please contact us and we will take appropriate steps.
17. Third-Party Websites
Our website may contain links to external sites. We are not responsible for the content or privacy practices of those sites. We encourage you to read their privacy notices.
18. Changes to This Notice
We may update this notice from time to time. The current version is always available at www.gqcl.co.uk, with the effective date shown above. Where changes are material, we will take reasonable steps to inform affected individuals.
19. Complaints
If you are dissatisfied with how we handle your personal data, please contact us first at info@gqcl.co.uk so that we can try to resolve the matter. You also have the right to lodge a complaint with the UK Information Commissioner’s Office: Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 Website: www.ico.org.uk
20. Contact
For any privacy-related question or request: Global Quality Certificate Ltd (GQCL) Data Protection Contact 20-22 Wenlock Road, London, N1 7GU, United Kingdom Email: info@gqcl.co.uk Phone: +44 7411 567732 Website: www.gqcl.co.uk
