Privacy Policy

How Gateway Contracting Company collects, uses, stores and protects your personal data under the Digital Personal Data Protection Act, 2023 of India.

Effective Date: 22 August 2026 Last Updated: 22 August 2026 Version: 1.0
Gateway Contracting Company ("Gateway", "we", "us" or "our") respects your privacy. This Privacy Policy explains how we handle your personal data when you visit www.gatewcc.com, submit an enquiry, apply for a role, or otherwise deal with us. It is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it, and with the Information Technology Act, 2000 and its rules to the extent they continue to apply. In respect of personal data covered by this Policy, we act as a Data Fiduciary.

01 Scope & Applicability

This Policy applies to the processing of digital personal data:

  • collected within the territory of India, whether collected in digital form or collected in non-digital form and later digitised; and
  • collected outside India, where the processing relates to offering goods or services to Data Principals within India.

It covers our website, enquiry and career forms, email and telephone correspondence, vendor and client onboarding, and site-related communications. It does not apply to personal data you make publicly available yourself, or which we are required by law to make public.

Where we process personal data on behalf of a client under a contract — for example, workforce records handled while delivering a project — we act as a Data Processor, and the client's own privacy notice governs that processing.

02 Key Definitions

  • Personal Data — any data about an individual who is identifiable by or in relation to such data.
  • Data Principal — the individual to whom the personal data relates. Where the individual is a child, it includes the parent or lawful guardian; where the individual is a person with disability, it includes their lawful guardian.
  • Data Fiduciary — the person who alone or with others determines the purpose and means of processing personal data.
  • Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
  • Processing — any wholly or partly automated operation on digital personal data, including collection, storage, use, sharing, indexing, disclosure and erasure.
  • Consent Manager — a person registered with the Data Protection Board through whom a Data Principal may give, manage, review and withdraw consent.

03 Personal Data We Collect

We practise data minimisation and collect only what is necessary for the specified purpose:

Category Data Items How It Is Collected
Identity & Contact Full name, email address, telephone number, company name, designation Enquiry form, email, telephone, business correspondence
Enquiry Content Service of interest, project requirements, and any details you choose to include in your message Submitted directly by you
Recruitment Curriculum vitae, qualifications, work history, trade certifications, references Career applications, recruitment partners
Vendor & Client Records Contact person details, business registration and tax identifiers, banking details for settlement Onboarding and contracting process
Technical & Usage IP address, browser and device type, pages visited, referring URL, timestamps Automatically by our web server and analytics tools
Site Access Visitor identification and safety induction records, where applicable Collected at project sites and offices

We do not knowingly seek data unrelated to these purposes. Please do not send us sensitive information — such as health records, biometric data or government identity numbers — through the website enquiry form unless we have specifically asked for it.

04 Purposes of Processing

We process personal data only for these specified, lawful purposes:

  • Responding to enquiries and preparing quotations or proposals;
  • Negotiating, entering into and performing contracts for our services;
  • Assessing job applications and managing recruitment and mobilisation;
  • Vendor evaluation, procurement, invoicing and payment;
  • Site safety, access control and statutory compliance records;
  • Operating, securing and improving www.gatewcc.com;
  • Sending service-related communications, and marketing updates where you have consented;
  • Meeting legal, regulatory, audit and tax obligations, and establishing or defending legal claims.

If we ever need to use your personal data for a purpose materially different from those listed above, we will give you a fresh notice and, where required, seek fresh consent.

05 Consent & Legitimate Uses

Under the DPDP Act we process personal data either on the basis of your consent or for certain legitimate uses recognised by the Act.

Consent

Where we rely on consent, it is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the stated purpose. Submitting an enquiry form or opting in to updates constitutes such an affirmative action for the purpose described at the point of collection. You may also give or manage consent through a registered Consent Manager.

Legitimate Uses

We may process personal data without separate consent where the Act permits, including:

  • where you have voluntarily provided data for a specified purpose and have not indicated that you object to its use for that purpose;
  • for compliance with any judgment, decree, order or legal obligation in India;
  • for responding to a medical emergency, or providing assistance during a disaster or breakdown of public order;
  • for purposes relating to employment, or to safeguard the employer from loss or liability, including maintaining confidentiality of trade secrets and intellectual property.

06 Notice & Withdrawal of Consent

Before or at the time of seeking consent, we give you an itemised notice describing the personal data sought, the purpose of processing, how you may exercise your rights, and how you may complain to the Data Protection Board of India. On request, we will provide this notice in English or in any language listed in the Eighth Schedule to the Constitution of India.

You may withdraw your consent at any time, and doing so must be as easy as giving it. Write to privacy@gatewcc.com to withdraw. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. On withdrawal, we will — within a reasonable time — cease processing and cause our Data Processors to cease processing, unless retention is required by law.

07 Data Processors & Sharing

We engage Data Processors only under a valid contract, and we share personal data only with:

  • IT, hosting, email and analytics service providers who support our website and operations;
  • professional advisers such as auditors, lawyers and accountants;
  • banks and payment processors, for settlement of invoices;
  • clients, joint-venture partners or principals where necessary to deliver a project you are involved in;
  • government authorities, courts or regulators where disclosure is required by law.

We do not sell personal data, and we do not trade or rent it to third parties for their own marketing. We remain accountable for the processing carried out by our Data Processors on our behalf.

08 Cross-Border Transfer

Gateway operates from the Kingdom of Saudi Arabia and engages service providers who may store or process data outside India. Personal data collected in India may therefore be transferred to and processed in Saudi Arabia or in other countries where our providers operate.

Any such transfer is made in accordance with Section 16 of the DPDP Act and is not made to any country or territory that the Central Government restricts by notification. Where a sectoral law imposes a stricter localisation requirement on the data in question, that stricter requirement prevails. We put contractual safeguards in place with overseas recipients requiring protection at least equivalent to that described in this Policy.

09 Retention & Erasure

We keep personal data only for as long as necessary for the purpose for which it was collected, or for as long as a law in force requires it to be retained — whichever is longer.

  • Website enquiries that do not lead to engagement — erased within a reasonable period after the enquiry is closed.
  • Unsuccessful job applications — retained for our recruitment cycle, then erased, unless you consent to remain in our talent pool.
  • Contract, invoicing and tax records — retained for the statutory period applicable to those records.
  • Marketing contacts — retained until you withdraw consent or unsubscribe.

When you withdraw consent, or when the specified purpose is no longer being served, we erase your personal data and cause our Data Processors to do the same, unless retention is necessary for compliance with law.

10 Security Safeguards

As required by Section 8(5) of the DPDP Act, we take reasonable security safeguards to prevent a personal data breach. These include:

  • encryption of data in transit over our website (HTTPS/TLS) and protection of stored data;
  • role-based access control, with access granted on a need-to-know basis;
  • secured, monitored hosting infrastructure and appropriate network controls;
  • backups, logging and monitoring to detect and recover from incidents;
  • contractual security obligations imposed on every Data Processor we engage;
  • staff confidentiality obligations and periodic awareness training.

No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot guarantee absolute security, and any transmission is at your own risk.

11 Personal Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the form and manner and within the timelines prescribed under the DPDP Act and the rules made under it. Our notification will describe the nature and extent of the breach, its likely consequences, the measures we have taken to mitigate risk, and the steps you may take to protect your own interests.

12 Your Rights as a Data Principal

The DPDP Act gives you the following rights, which you may exercise free of charge:

Right to Access Information

Obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared.

Right to Correction & Erasure

Have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose it was collected for.

Right of Grievance Redressal

Have your grievance about our processing, or about our response to your rights request, addressed by our Grievance Officer within the prescribed period.

Right to Nominate

Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

How to Exercise Your Rights

Email privacy@gatewcc.com with your request, stating clearly which right you wish to exercise. So that we can verify your identity, please write from the email address you originally shared with us, or provide sufficient particulars to allow us to locate your record. We will respond within the period prescribed under the DPDP rules. You may also exercise these rights through a Consent Manager registered with the Board.

13 Your Duties as a Data Principal

Section 15 of the DPDP Act places certain duties on you. You must:

  • comply with the provisions of applicable law when exercising your rights;
  • not impersonate another person while providing personal data for a specified purpose;
  • not suppress any material information while providing personal data for any document or identifier issued by the State;
  • not register a false or frivolous grievance or complaint;
  • furnish only information that is verifiably authentic when seeking correction or erasure.

14 Children & Persons with Disability

Our website and services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from any individual below eighteen (18) years of age.

Where we do process a child's personal data, we will obtain the verifiable consent of the parent or lawful guardian before doing so. We will not undertake any processing likely to cause a detrimental effect on the well-being of a child, and we will not carry out tracking, behavioural monitoring, or targeted advertising directed at children. The same protection applies to a person with disability who has a lawful guardian, whose verifiable consent we will obtain.

If you believe a child has provided us personal data, please contact our Grievance Officer and we will erase it.

15 Cookies & Tracking

Our website uses a limited number of cookies and similar technologies. Strictly necessary cookies keep the site functioning and secure. Any analytics or performance cookies are used to understand how visitors use the site, and are set only where you have consented.

Some pages embed third-party content, such as Google Maps and font or icon libraries. These providers may receive your IP address and set their own cookies, governed by their own privacy policies. You can control or delete cookies through your browser settings; blocking strictly necessary cookies may affect how the site works.

16 Grievance Redressal

In accordance with Section 8(9) and Section 13 of the DPDP Act, we have appointed a Grievance Officer to address questions and complaints about the processing of your personal data. Please include your name, contact details, and a clear description of your grievance so that we can act on it promptly.

Grievance Officer

  • The Grievance Officer, Gateway Contracting Company
  • privacy@gatewcc.com
  • +966 598609926
  • Gateway Contracting Company – India Liaison Office,
    [Street Address], [City], [State] [PIN Code], India

17 Data Protection Board of India

If your grievance is not resolved to your satisfaction, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act, in the manner it prescribes. Please note that the Act requires you to exhaust the Data Fiduciary's own grievance redressal mechanism before approaching the Board. An appeal against an order of the Board lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

18 Changes to This Policy

We may update this Policy to reflect changes in our practices or in the law. The revised version will be posted on this page with a new "Last Updated" date. Where a change materially affects how we process your personal data, we will notify you and, where required, seek fresh consent. Please review this page periodically.

19 Contact Us

For any question about this Privacy Policy or about how we handle personal data, reach us at:

Gateway Contracting Company

  • Industrial Area, Dammam 31411,
    Eastern Province, Kingdom of Saudi Arabia
  • Gateway Contracting Company – India Liaison Office,
    [Street Address], [City], [State] [PIN Code], India
  • privacy@gatewcc.com  |  info@gatewcc.com
  • www.gatewcc.com