Transparent commercial models for your South India expansion & GCC setup. Explore Pricing →
Transparency & Data Protection • DPDPA 2023 & GDPR Aligned

Privacy & Data Protection Policy

How Overseas Bridge collects, secures, processes, and protects enterprise, candidate, and personal data across our global business establishment, workforce, and operational infrastructure ecosystems.

📅 Effective Date: January 1, 2026
🔄 Version: 2.4 (Enterprise Edition)
🌐 Scope: Global & South India Hubs
🔒
Strict Rule

Zero Data Monetization

We never sell, rent, trade, or monetize your corporate intelligence, candidate details, or operational information under any circumstances.

🛡️
Enterprise Sec

AES-256 & TLS 1.3 Security

All client communications, entity formation data, and talent records are secured with end-to-end encryption at rest and in transit.

⚖️
Global Law

DPDPA & GDPR Compliant

Structured specifically to meet the statutory mandates of India's Digital Personal Data Protection Act 2023, EU GDPR, and US CCPA/CPRA.

👤
Your Rights

Full Subject Control

Transparent access to request complete data extraction, rectification, portability, or verified erasure at any time within 72 business hours.

01

Introduction & Scope

Welcome to Overseas Bridge (referred to herein as "Overseas Bridge", "we", "us", or "our"). Overseas Bridge is a premier business facilitation, entity structuring, Global Capability Centre (GCC), workforce recruitment, and operational infrastructure partner assisting international and high-growth enterprises in establishing and scaling operations in South India (including Bengaluru, Chennai, Hyderabad, Coimbatore, and Kerala).

We are steadfastly committed to respecting, safeguarding, and maintaining the privacy, confidentiality, and integrity of personal, corporate, and proprietary information entrusted to us. This Privacy & Data Protection Policy ("Policy") details how we collect, store, process, transfer, and protect your information when you visit our website (https://overseasbridge.in), engage our advisory services, request feasibility reports, communicate with our specialists, or enter into corporate establishment agreements.

💡
Statutory Scope: This Policy operates in compliance with India's Digital Personal Data Protection Act (DPDPA 2023), the European Union's General Data Protection Regulation (EU GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA / CPRA).
02

Information We Collect

We collect information across three primary operational categories:

A. Information You Voluntarily Provide

  • Enterprise Contact & Inquiries: Full name, corporate email address, phone number, corporate designation, organization name, headquarter jurisdiction, and corporate website.
  • India Strategy & Expansion Requirements: Target industry vertical, proposed headcount scale (e.g., 2 → 500+ employees), operational models, target South Indian hub preferences, timeline requirements, and budget parameters.
  • Entity Structuring & Statutory Details: Corporate registration records, authorized signatory identification, tax registration documents, and board resolutions necessary for entity incorporation or commercial leasing.
  • Candidate & Workforce Information: Resumes, employment histories, technical certifications, and references submitted during hiring drives and GCC team assembly.

B. Information Collected Automatically

  • Telemetry & Device Data: IP address, browser type and version, operating system, time zone settings, referral URLs, and access timestamps.
  • Interaction Metrics: Pages viewed, time spent per section, navigation clickstream, and interaction with our interactive tools (e.g., hub selectors, talent wizards).

C. Information from Verified Enterprise Sources

We may receive verified corporate information from authorized industry associations, public company registries (such as the Ministry of Corporate Affairs in India), and verified enterprise partners solely to validate corporate credentials.

03

How We Use Your Information

We process collected data exclusively for legitimate enterprise purposes, including:

📊
Strategy Consultation

Developing custom India entry roadmaps, CapEx vs. OpEx feasibility models, and comparative hub analysis.

🏢
Entity & Infrastructure Setup

Facilitating company registration, commercial workspace leasing, IT infrastructure procurement, and statutory filings.

👥
Workforce Assembly

Matching enterprise skill requirements with vetted South Indian engineering, BPO, management, and technical talent.

🔐
Security & Legal Compliance

Preventing fraud, verifying corporate identity, fulfilling anti-money laundering (AML) protocols, and maintaining audit trails.

04

Legal Bases for Processing (GDPR & DPDPA)

Under international privacy regulations, our processing of personal and corporate data relies upon the following legal grounds:

  • Contractual Performance: Processing required to negotiate, execute, or perform our master service agreements, entity establishment contracts, or workforce advisory retainers.
  • Explicit & Informed Consent: Where you have granted unambiguous consent for exploratory consultation, receiving market intelligence, or participating in advisory sessions.
  • Compliance with Legal Obligations: Adhering to statutory requirements under the Indian Companies Act, Income Tax Act, Goods and Services Tax (GST) Act, Foreign Exchange Management Act (FEMA), and Reserve Bank of India (RBI) guidelines.
  • Legitimate Enterprise Interests: Enhancing our platform security, optimizing user experience, preventing fraudulent inquiries, and ensuring business continuity.
05

Data Security & Enterprise Encryption

Overseas Bridge applies rigorous, defense-in-depth technical and organizational safeguards to ensure that all enterprise information remains protected against unauthorized access, destruction, alteration, or disclosure:

🔒TLS 1.3 In-Transit Encryption
💾AES-256 Bit Encryption At Rest
🛡️Role-Based Access Control (RBAC)
🔑Multi-Factor Authentication (MFA)

All staff members and contractors handling client information are bound by strict, legally enforceable Non-Disclosure Agreements (NDAs). Access to client repository files is restricted on a strict need-to-know basis.

06

Sharing & Third-Party Disclosures

Strict No-Sale Commitment: Overseas Bridge does not sell, rent, commercialize, or trade personal or corporate data to third-party advertisers or data brokers under any circumstances.

Information is disclosed solely in the following controlled circumstances:

  • Government & Regulatory Authorities: Ministry of Corporate Affairs (MCA), Registrar of Companies (RoC), GST Network, Income Tax Department, and Reserve Bank of India strictly when instructed by you for legal company formation and compliance filings.
  • Vetted Infrastructure Sub-processors: Secure Tier-4 cloud infrastructure providers (AWS, Microsoft Azure, Google Cloud) operating within strict Data Processing Addendums (DPAs).
  • Legal & Professional Advisors: Certified chartered accountants, corporate attorneys, and statutory auditors assisting in client-authorized transactions under professional confidentiality privileges.
07

Cross-Border Data Transfers

Because Overseas Bridge collaborates with international enterprises located in the United States, United Kingdom, European Union, Middle East, and Asia-Pacific regions, information may be transferred across international borders between your corporate headquarters and our operational hubs in India.

When transferring data internationally, we implement Standard Contractual Clauses (SCCs) approved by the European Commission, ensure DPDPA cross-border adequacy compliance, and execute comprehensive Data Transfer Agreements with enterprise clients.

08

Data Retention & Erasure Schedules

We retain personal and enterprise data only for as long as strictly necessary to fulfill the operational objectives for which it was collected, or to satisfy legal, accounting, tax, or regulatory reporting mandates:

  • Advisory Inquiries & Feasibility Scopes: Retained for 24 months from the last date of communication, unless converted into an active engagement.
  • Corporate Entity Records: Retained for 8 years following the close of the applicable financial year pursuant to Section 128 of the Indian Companies Act, 2013.
  • Candidate & Talent Profiles: Retained for 12 months with candidate consent for potential future placement in client GCC teams.
09

Your Rights & Choices (Data Subject Rights)

Depending on your jurisdiction (under DPDPA, GDPR, CCPA/CPRA), you are entitled to exercise the following enforceable rights:

🔍
Right to Access: Request a full copy of personal records held about you.
✏️
Right to Rectification: Correct any inaccurate or incomplete details.
🗑️
Right to Erasure: Request permanent deletion (Right to be Forgotten).
📦
Data Portability: Obtain data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interests.
🔄
Withdraw Consent: Revoke previously granted processing consent.

To exercise any of these rights, please submit a formal request to our Data Protection Officer at privacy@overseasbridge.in. Requests are authenticated and responded to within 30 days without charge.

10

Cookies & Telemetry Policy

Our website uses cookies and similar telemetry tokens to ensure platform security, preserve user preferences, and analyze aggregate traffic trends:

  • Strictly Necessary Cookies: Essential for session authentication, security firewalls, and routing.
  • Performance & Analytics Cookies: Aggregated, anonymized metrics (via Google Analytics with IP anonymization enabled) to understand visitor flows.
  • Preference Cookies: Remembering your UI settings and regional preferences.

You may modify or block cookies through your browser settings at any time without impacting core informational browsing.

11

Policy Revisions & Notifications

We may periodically update this Policy to reflect changes in our operational services, regulatory frameworks, or statutory mandates. When material revisions occur, we will update the "Effective Date" at the top of this page and provide conspicuous notification across our website or via direct enterprise email.

12

Data Protection Officer & Grievance Redressal

In compliance with the Digital Personal Data Protection Act, 2023 and global data protection requirements, Overseas Bridge has designated an official Data Protection Officer (DPO) & Grievance Redressal Officer:

OB

Data Protection & Compliance Office

Overseas Bridge India Operations
Official Email: privacy@overseasbridge.in
Compliance Desk: compliance@overseasbridge.in
Primary Operational Hub: Bengaluru • Karnataka • India
Grievance Turnaround: < 72 Business Hours

Have questions about enterprise data governance in India?

Schedule a confidential consultation with our India compliance and entity setup specialists.