Legal
Privacy Policy
How CrossShore Business Solutions collects, uses, stores and protects personal data — for visitors to this website, for client contacts, and for job applicants.
TODO (owner) — legal review required before publishing
This document is a structural starting point, not legal advice, and it is not a compliant privacy notice as written. CrossShore operates across the US, UK and Australia, which engages UK and EU GDPR, US state privacy laws such as the CCPA and CPRA, and the Australian Privacy Act simultaneously. Have a qualified data protection lawyer review and complete this before publication, and confirm every bracketed detail — retention periods, lawful bases, sub-processors, transfer mechanisms and supervisory authority contacts.
Last updated:
1. Who we are
CrossShore Business Solutions (“CrossShore”, “we”, “us”) is a business process outsourcing company with a delivery centre in India, serving clients in the United States, United Kingdom and Australia.
Registered office: Ahmedabad, Gujarat, India.
For any privacy question, or to exercise your rights, contact us at info@crosshoresupport.com. [TODO: name your Data Protection Officer or privacy contact, and confirm whether a UK/EU representative is required under Article 27.]
2. Two different roles: controller and processor
This distinction determines which parts of this policy apply to you.
As a data controller — for personal data we collect for our own purposes: website visitors, prospective clients who submit an enquiry, and job applicants. This policy governs that data.
As a data processor — for personal data we handle on behalf of a client while delivering outsourcing services, such as our client's customer records. In that case our client is the controller, their privacy notice applies, and we process only on their documented instructions under a data processing agreement. If you are a customer of one of our clients and wish to exercise your rights, contact that company directly; we will support their response.
3. Personal data we collect
3.1 Website visitors
- Technical data — IP address, browser type, device type, operating system
- Usage data — pages visited, referring URL, time on page, interactions
- Cookie and similar technology data, where you have consented — [TODO: list your actual analytics and marketing tools, e.g. Google Analytics 4, and publish a cookie notice]
3.2 Enquiry and quote requests
- Name, business email address and company name
- Country, service interest and indicative team size
- The content of your message and any subsequent correspondence
3.3 Job applicants
- Contact details, CV, employment and education history
- Assessment results and interview notes
- Background verification data where lawful and relevant to the role — [TODO: confirm what checks you conduct and on what lawful basis]
4. How we use personal data, and our lawful basis
- Responding to your enquiry — legitimate interests, or performance of a contract where we are already engaged
- Providing services to clients — performance of a contract, and as processor on the client's instructions
- Recruitment — legitimate interests and, where applicable, steps prior to entering an employment contract
- Website analytics and improvement — consent, where cookies require it
- Marketing communications — consent, or legitimate interests for business-to-business communications where permitted, with an opt-out in every message
- Legal and regulatory compliance — legal obligation
- Security and fraud prevention — legitimate interests
We do not sell personal data. We do not use enquiry data for automated decision-making that produces legal effects.
5. Sharing and disclosure
We share personal data only with:
- Service providers acting on our instructions — hosting, email, CRM and applicant tracking. [TODO: list your sub-processors, or publish a maintained sub-processor page and link to it. Enterprise clients will require this.]
- Professional advisers — legal, accounting and audit — under confidentiality
- Authorities where required by law or to protect legal rights
- An acquirer in the event of a merger or business sale, subject to this policy
6. International transfers
We are based in India and serve clients in the United States, United Kingdom and Australia, so personal data is transferred internationally.
For UK and EU data we rely on [TODO: confirm mechanism — the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another lawful basis] supported by a transfer risk assessment. For Australian data we handle personal information consistently with Australian Privacy Principle 8. [TODO: have counsel confirm and document the mechanisms actually in place.]
7. Retention
We retain personal data only as long as necessary for the purpose it was collected, or as required by law.
- Enquiry data — [TODO: specify, e.g. 24 months from last contact]
- Client contract data — [TODO: specify, typically contract term plus statutory period]
- Unsuccessful applicant data — [TODO: specify, e.g. 12 months, with consent to retain]
- Website analytics — [TODO: specify per your analytics configuration]
Client data processed on a client's behalf is retained per their instructions.
8. Security
We maintain technical and organisational measures appropriate to the risk, including access controls with least-privilege permissions and named individual accounts, multi-factor authentication, encryption in transit, physically access-controlled operational floors, clean-desk enforcement, restricted removable media and printing, logged system access, staff confidentiality agreements and security training, and tested incident response procedures. Our control set is summarised on our security and compliance page.
No system is completely secure. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority within the applicable timeframe.
9. Your rights
Depending on where you are located, you may have the right to access your personal data, correct inaccuracies, request erasure, restrict or object to processing, receive your data in a portable format, withdraw consent at any time, and opt out of marketing. UK and EU residents may lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office. Australian residents may complain to the Office of the Australian Information Commissioner. California residents have additional rights under the CCPA and CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell personal data.
To exercise any right, email info@crosshoresupport.com. We respond within one month, or sooner where required. We may need to verify your identity first.
10. Cookies
[TODO: complete this section with your actual cookie inventory, and implement a consent mechanism before setting any non-essential cookie for UK, EU or California visitors. As currently built, this website sets no analytics or marketing cookies — if you add analytics, this section and a consent banner become legally required.]
11. Children
Our services are directed at businesses. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date above reflects the most recent revision. Material changes will be communicated where we have a means of contacting you.
13. Contact
CrossShore Business Solutions
Ahmedabad, Gujarat
India
Email: info@crosshoresupport.com
Phone: +1 (848) 349-2528