CONFIDENTIALITY, PERSONAL DATA PROCESSING (PRIVACY) AND COOKIE POLICY

ControllerGSR SYSTEM FZ CO, licence No. DSO-IFZA-10697, Dubai Digital Park, Office A2, Dubai Silicon Oasis, Dubai, United Arab Emirates.
What this coversThe Website, enquiries, registrations and purchases, payments and refunds, GetCourse access, customer support, GSR Expert and Curator support, the AI learning bot, professional profiles, testimonials, and Website analytics.
Sensitive informationGeneral forms, group chats and the AI bot are not designed for health, psychological, intimate, children’s or third-party data. Private Expert support may process limited sensitive data only under the safeguards in this Policy and a service-specific notice.
Your choicesMarketing, non-essential analytics and publication of a testimonial require a separate choice. Refusing them does not prevent you from viewing the Website or purchasing a service.
PaymentsWe do not store the full number, expiry date or security code of your bank card. Payment providers process card details in their own secure interfaces.
Privacy contactorg_gsr@gsrsystem.com — use the subject line “Privacy Request”.

1. Scope and purpose

1.1. This Privacy and Cookie Policy explains how GSR SYSTEM FZ CO (“GSR”, “we”, “us”) processes personal data when you use https://gsrsystem.com, its pages and forms controlled by GSR (the “Website”), contact us, purchase or use a GSR service, or interact with a GSR channel described below.

1.2. It applies only where GSR determines why and how personal data is processed. A third-party platform or an independent Specialist may also process data under its own privacy terms. We explain the distinction in Sections 8 and 15.

1.3. This Policy is intended to reflect the Website’s current functions. It does not cover physical stores, delivery of goods, gift cards, saved bank-card details, precise geolocation, behavioural advertising, mobile-app functions or other processes that are not used on the Website.

1.4. A shorter notice may be shown at the point where data is collected. That notice forms part of this Policy and will identify any service-specific recipient, country, retention period or consent choice that is not described here.

1.5. If a new form, technology, provider or processing purpose is introduced, GSR will assess it and update the relevant notice before the processing begins.

2. Controller and privacy contact

ControllerGSR SYSTEM FZ CO
LicenceDSO-IFZA-10697
Business addressDubai Digital Park, Office A2, Dubai Silicon Oasis, Dubai, United Arab Emirates
Privacy e-mailorg_gsr@gsrsystem.com
Websitehttps://gsrsystem.com

2.1. The privacy e-mail is the current channel for questions, consent withdrawals and rights requests. It is not represented as a statutory Data Protection Officer contact unless GSR formally appoints and publishes a Data Protection Officer.

2.2. The Website footer, contracts, payment pages and collection notices must identify the same controller. Another GSR-branded legal entity may receive Website data only if its role, country and lawful transfer mechanism are disclosed before the transfer.

3. Principles and legal grounds

3.1. GSR processes personal data fairly, transparently and lawfully; for specific and clear purposes; in a manner compatible with those purposes; in an amount limited to what is necessary; accurately; for no longer than needed; and with appropriate security and accountability measures.

3.2. Depending on the activity, GSR relies on one or more grounds recognised by applicable UAE law:

  • your freely given, specific, informed and unambiguous consent;
  • the need to take steps at your request before entering into a contract or to perform a contract with you;
  • the need to comply with a legal obligation;
  • the establishment, exercise or defence of legal claims;
  • the protection of your interests in the limited circumstances recognised by law; or
  • another specific exception expressly permitted by applicable law.

3.3. GSR does not use a broad “legitimate interest” statement as a substitute for a specific lawful ground. Marketing, non-essential analytics, publication of testimonials and other optional activities are based on a separate choice where required.

3.4. You may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully, and it does not prevent GSR from retaining the minimum data required by law or to establish, exercise or defend legal claims.

3.5. GSR does not sell or rent personal data.

4. What we process, why, and for how long

The exact data depends on the way you interact with GSR. Mandatory fields are marked in the relevant form. If you do not provide information that is objectively necessary for a request or service, GSR may be unable to process that request or provide the service.

ContextPersonal dataPurpose and legal groundRetention
Website operation and securityIP address; date and time; requested page; referrer; browser, operating system and device type; security and error logs; necessary cookies and technical identifiers.Display and secure the Website, maintain availability, prevent abuse, investigate errors and protect users and GSR. Basis: service requested by the user; protection of rights and interests; consent where required.Technical logs: up to 12 months, or longer only for a documented security incident or legal claim.
Analytics through Yandex MetricaCookie or local identifiers; IP-derived region; device and browser data; referrer; pages viewed; actions and session duration. If session replay is enabled, form fields and private content must be masked.Measure visits, understand use of public pages and improve Website structure. Basis: consent through the cookie settings panel.Within the cookie lifetimes shown in the settings panel; raw or identifiable analytics no longer than 24 months unless anonymised earlier.
Enquiries and “Leave a request” formsName, phone number and, where provided, e-mail, Telegram username, preferred language, selected service and message content.Respond, clarify your request and take steps requested by you before a possible contract. Basis: pre-contractual steps and/or consent.Until the enquiry is completed, then up to 180 days after the last contact if no contract or claim arises.
Registration and purchase of a service or eventName, surname and optional middle name; phone; e-mail; Telegram username; country; selected programme, format, dates, number of participants and payment preference; contract and access information.Check eligibility, register the participant, conclude and perform the contract, provide organisational notices and arrange access. Basis: contract and pre-contractual steps.For the service period; transaction, tax and accounting evidence for at least 7 years after the relevant tax period, or another mandatory period.
Payments, invoices and refundsService and order details; amount, currency, payment date and status; transaction identifier; billing details; refund request and bank details needed for the refund. GSR does not store full card credentials.Accept and confirm payment, issue records, process refunds, prevent fraud and comply with tax and accounting rules. Basis: contract, legal obligation and legal claims.At least 7 years after the relevant tax period, or longer where required by law or an unresolved claim.
GetCourse account and course accessName; e-mail; phone; purchased course; account and access data; learning progress, support requests and course submissions to the extent used.Create and maintain access, deliver licensed and educational materials, send service notices and provide technical support. Basis: contract.For as long as the contractual access remains available, which may be indefinite for some materials. Minimal transaction evidence is retained for the mandatory period. Closing the account may end access.
E-mail, Telegram and customer supportName or username; contact details; message history; files and other information you choose to send.Answer questions, administer the service, handle complaints, refunds and privacy requests. Basis: contract, consent, legal obligation or legal claims, depending on the request.Normally up to 12 months after the matter is closed; up to 3 years where needed to evidence performance or a claim; longer only if legally required.
Private Expert or Curator support arranged by GSRIdentity and contact data; assigned Expert or Curator; schedule; support messages; and limited information about feelings, family circumstances or other sensitive matters that you voluntarily and expressly choose to share.Provide the requested support, maintain continuity and quality, and address safety or complaints. Basis: contract and, for sensitive personal data where required, separate express consent.Active support period plus up to 12 months, then deletion or anonymisation, unless a longer period is needed for a legal claim or required by law.
GSR AI learning botTelegram or account identifier; prompts and replies; technical usage and error logs. The bot is not intended to receive personal, health, psychological, family, children’s or third-party data.Answer general questions about course materials and improve technical reliability. Basis: contract for course support and consent where personal data is optional.Identifiable prompts and technical logs: up to 30 days, then deletion or anonymisation, unless a shorter service notice applies or a security incident requires limited retention.
Marketing communicationsName; e-mail, phone or Telegram contact; chosen channels; subscription and withdrawal records.Send GSR news and offers only through channels you select. Basis: separate consent.Until consent is withdrawn. A minimal suppression record may be retained to ensure that marketing is not resumed.
Profiles of Specialists, Experts and CuratorsName or professional name; photograph; qualification, status, level, experience, languages, format, contact or booking information; content approved for publication.Maintain professional directories and help users identify a suitable provider. Basis: contract and/or separate consent; image and content permissions as applicable.For the relationship and publication period; removed from public display after the basis ends. Evidence of permission may be kept for up to 3 years or a longer claim period.
Testimonials and reviewsOnly the data listed in a separate publication consent: name or pseudonym, photograph, text, audio or video, and selected contextual information.Publish a testimonial on specified GSR channels. Basis: separate express consent and the necessary image/content licence. Third-party sensitive data is not accepted without that person’s own lawful authorisation.Until the consent expires or is withdrawn, or the publication purpose ends. Public access is stopped without undue delay after a valid withdrawal.
Family events and limited child dataAdult caregiver’s details; child’s name and age; event selection and information strictly needed for safe participation. A child must not submit the form independently.Register and organise participation in a specifically identified family event. Basis: contract with the adult caregiver and verifiable caregiver consent where required.Event period plus up to 90 days; transaction evidence for the mandatory legal period. Unnecessary child data is deleted earlier.
Rights requests, complaints and legal mattersIdentity and contact information; request details; limited verification data; correspondence and outcome.Verify and respond to the request, demonstrate compliance and establish, exercise or defend rights. Basis: legal obligation and legal claims.Normally up to 3 years after closure, or longer where a claim or mandatory period applies.

5. Sensitive personal data and confidential communications

5.1. Information that reveals health, psychological or mental state, family or intimate circumstances, religious or political views, biometric or genetic characteristics, criminal records, or comparable matters may be sensitive personal data under UAE law.

5.2. General Website forms, public comments, Telegram group chats and the AI learning bot are not designed for sensitive personal data. Do not use those channels for medical records, diagnoses, intimate information, children’s information, identifiable client cases or personal data of another person.

5.3. A private GSR support process may involve discussion of feelings or family circumstances. Where GSR arranges that process, it will:

  • explain before the discussion who will have access and in which country;
  • limit access to the assigned authorised person on a need-to-know basis;
  • obtain separate express consent where required for sensitive personal data;
  • avoid collecting medical documents or information that is not necessary for the requested support;
  • apply confidentiality, access-control, deletion and incident-reporting duties to the recipient; and
  • not use the content for advertising, public testimonials or AI-model training without a new, separate permission.

5.4. An identifiable request will not be shared with an Expert’s Expert, another Specialist, a training group or a wider professional hierarchy unless you have been informed in advance and have agreed where required, or the case has been reliably anonymised. A request by an Expert alone is not sufficient.

5.5. Group-chat participants can see what other participants post. GSR cannot make a group chat confidential against other members. Administrators may remove content that violates these rules, but each participant should avoid posting sensitive or third-party data.

5.6. If information indicates an immediate and serious risk to a person, GSR may process or disclose the minimum necessary information where permitted or required by law to protect that person’s interests.

6. Children

6.1. The Website, purchases, GSR learning accounts, group chats and the AI bot are intended to be used by adults. A child must not independently submit a form, create an account, enter a group chat or use the AI bot.

6.2. An adult parent or legal guardian may provide limited data about a child only where a specific event form expressly allows family participation. The adult must be authorised to act for the child and must receive the child-specific notice shown with that form.

6.3. GSR will not knowingly collect, profile, publish or share personal data of a child under 13 without the safeguards and verifiable caregiver consent required by applicable UAE law. GSR does not use children’s data for behavioural advertising.

6.4. If GSR learns that child data was submitted without an appropriate basis, it will restrict the data, verify the circumstances and delete it unless retention is required to protect the child or comply with law.

7. Where personal data comes from

GSR may receive personal data:

  • directly from you through the Website, e-mail, Telegram, GetCourse, payment and support channels;
  • from an adult caregiver who registers a child for an expressly designated family event;
  • from an assigned Specialist, Expert or Curator where this is necessary to deliver a GSR-arranged service and permitted by the applicable notice;
  • from a payment provider, usually as payment status and transaction information rather than full card details;
  • from Website logs, necessary cookies and analytics used with your choice; and
  • from a person who submits professional profile content or a testimonial under a separate publication process.

If you provide another person’s data, provide only what is necessary and only where you are authorised to do so. GSR may ask you to remove or anonymise third-party information.

8. Who may receive personal data

8.1. Access is limited to the data needed for a defined task. Depending on the service, recipients may include:

  • authorised GSR personnel responsible for customer support, finance, legal, compliance, IT and service administration;
  • the specifically assigned Specialist, Expert or Curator, subject to an appropriate contract, confidentiality and access limits;
  • GetCourse, for course accounts, access and learning support;
  • Telegram, where you choose to communicate or participate through that platform;
  • banks, acquirers and payment providers shown on the relevant payment page;
  • Website hosting, DNS, e-mail, cybersecurity, backup and technical-administration providers;
  • Yandex Metrica, only after consent to analytics cookies;
  • an AI service provider identified in the AI-bot notice before first use;
  • professional advisers, auditors, insurers, courts and public authorities where lawfully required; and
  • a purchaser or successor in a genuine corporate transaction, subject to confidentiality and applicable law.

8.2. GSR selects processors that provide appropriate guarantees and requires written terms covering documented instructions, confidentiality, security, sub-processors, international transfers, assistance with rights, deletion or return of data and incident notification.

8.3. A Specialist or Expert may be a separate controller if you contact and contract with that person independently and the person determines the purposes and means of processing. In that case, the person must provide their own privacy information before collecting sensitive data. Where GSR arranges the service and determines the processing, the recipient must act within GSR’s documented framework.

8.4. GSR will not disclose an identifiable private support case to another Expert merely because the Website describes a professional hierarchy. The disclosure rule in Section 5.4 applies.

9. International transfers

9.1. The Website serves users internationally and uses platforms whose infrastructure, support teams or assigned service providers may be located outside the United Arab Emirates. A transfer may therefore occur even when you are located in the UAE.

9.2. Before transferring personal data outside the UAE, GSR will identify the purpose, recipient or category, country or processing region, data involved and the applicable transfer mechanism. Depending on the circumstances, GSR may rely on:

  • a destination recognised as providing an adequate level of protection;
  • a binding contract requiring protections consistent with the UAE Personal Data Protection Law;
  • your express consent after you have been informed of the transfer and relevant risks;
  • necessity for a contract requested by you or concluded in your interests; or
  • another transfer exception expressly permitted by applicable law.

9.3. GSR transfers only the minimum data needed and applies access, confidentiality, security and deletion controls. You may request the current list of material recipients, countries and transfer mechanisms from the privacy contact.

Channel/providerPurposeTypical locationTransparency rule
GetCourseCourse account, access and learning supportRussian FederationCore use is disclosed here; contract and transfer assessment required.
TelegramMessaging, group chats and bot accessUAE and other jurisdictions under Telegram’s infrastructureTelegram’s own policy also applies; avoid sensitive data in groups and the AI bot.
Yandex MetricaWebsite analytics after consentMay include the Russian Federation and other locations used by the providerExact cookies, provider and duration must appear in the settings panel.
Payment providerPayment and refund processingShown on the payment pageProvider identity and terms must be displayed before card details are entered.
Assigned Expert or CuratorGSR-arranged private supportThe recipient’s country, which may be outside the UAEIdentity, role and country must be disclosed before identifiable sensitive data is shared.
AI providerProcessing of AI-bot prompts and responsesShown in the bot noticeProvider, country, retention and model-training rules must be shown before first use.

10. Cookies and similar technologies

10.1. A cookie is a small file or identifier stored on or read from a device. The Website uses only the categories described below. The cookie settings panel must remain available from every page and show each current cookie or comparable technology, its provider, purpose and duration.

CategoryUse and dataChoiceRetention
Necessary and securityLoad pages, process forms, protect sessions, prevent abuse and remember the cookie choice. They may use session and technical identifiers.Used in the minimum necessary scope. Browser blocking may affect core functions.Session or the limited period shown in the settings panel.
Analytics — Yandex MetricaMeasure visits and interactions using identifiers, device/browser data, referrer, pages and session information. Session replay, if enabled, must mask all form fields and private content.Off until the user actively accepts analytics. Can be withdrawn in Cookie Settings.As shown in the settings panel; identifiable analytics no longer than 24 months.
Advertising / behavioural profilingNot used as a current Website function under this Policy.Must not be introduced without an updated notice and a separate prior choice.Not applicable unless introduced lawfully.
Embedded mediaA third-party video or social feature may receive device or account data when it is loaded or clicked.Non-essential embedded content should load only after the relevant choice.According to the settings panel and provider notice.

10.2. The cookie banner should provide equally clear choices: “Reject non-essential”, “Settings” and “Accept all”. Rejecting analytics must not prevent access to public pages or the purchase process.

10.3. You can also remove or block cookies in your browser. A browser choice is device- and browser-specific and may need to be repeated on another device.

10.4. GSR will record the consent status, time, Website version and technical evidence needed to demonstrate the user’s choice. Refusing or withdrawing consent is recorded with the same level of care as accepting it.

11. AI and automated processing

11.1. The GSR AI learning bot is intended only for general educational questions about course materials. Do not enter names, phone numbers, medical or psychological information, family situations, children’s data, client cases or other identifiable information into the bot.

11.2. Before first use, the bot notice must identify the provider, processing location, retention period and whether provider personnel or sub-processors can access prompts. GSR will contractually prohibit use of identifiable prompts to train a general-purpose model unless the user gives a new, separate and specific consent.

12. Retention, deletion and anonymisation

12.1. The principal retention periods are in Section 4. GSR periodically reviews active systems and removes, anonymises or restricts data that is no longer needed.

12.2. When consent is withdrawn or a purpose ends, GSR stops the consent-based processing and deletes or anonymises the data unless another lawful ground requires limited retention.

12.3. Data in backups is removed from active use and overwritten under a documented backup cycle. A backup copy is not restored for ordinary business use after a valid deletion request; if restoration is necessary for security, the deletion instruction is re-applied.

12.4. Anonymised statistics that no longer identify a person may be retained for research, service quality and planning.

12.5. GSR may place a legal hold on limited data needed for an investigation, complaint or claim. Access is then restricted to that purpose.

13. Your rights

Subject to applicable UAE law and any lawful exceptions, you may:

  • request information about whether and how GSR processes your personal data, including categories, purposes, recipients, transfers, retention and automated processing;
  • request access to or a copy of personal data held about you;
  • receive data you provided in a structured and machine-readable format, and request transfer where technically feasible and legally applicable;
  • correct inaccurate data or complete incomplete data;
  • request erasure where data is no longer needed, consent has been withdrawn and no other ground applies, or processing is unlawful;
  • request restriction or cessation of processing in the circumstances provided by law;
  • stop direct marketing and any related profiling at any time;
  • withdraw consent as easily as it was given;
  • object to a decision based solely on automated processing that has legal or similarly significant effects and request human review; and
  • submit a complaint to the UAE Data Office or another competent authority.

13.1. Send a request to org_gsr@gsrsystem.com with the subject “Privacy Request”. Describe the right you wish to exercise and provide the contact information used with GSR.

13.2. GSR will verify identity using the minimum information reasonably necessary to prevent disclosure to another person. A copy of an identity document will be requested only where proportionate; unnecessary fields should be obscured.

13.3. GSR will respond within the period required by applicable law. A request may be limited or refused only on a lawful ground, including protection of another person’s privacy, legal retention duties, an unresolved claim or a manifestly abusive request. GSR will explain the reason where permitted.

13.4. Exercising a privacy right is free unless applicable law permits a charge in exceptional circumstances. Withdrawing optional consent will not affect access to unrelated services.

14. Security and personal data incidents

14.1. GSR applies measures appropriate to the nature and risk of the data, including role-based access, confidentiality obligations, secure transmission, multi-factor authentication for privileged access, logging, backup and recovery, malware and vulnerability controls, vendor assessment, staff training and incident-response procedures.

14.2. Access to private support information is separated from general marketing and Website administration. Experts and Curators receive only the information necessary for the assigned service and must not export it to personal files, unapproved AI services or public/group channels.

14.3. No system is completely secure. If a personal data breach occurs, GSR will contain and investigate it, preserve evidence and notify the UAE Data Office and affected persons where and within the time required by applicable law.

14.4. You can report a suspected privacy or security incident to org_gsr@gsrsystem.com. Do not include sensitive details in the initial subject line.

15. External platforms, linked sites and independent providers

15.1. The Website links to or uses third-party services such as Telegram, GetCourse, payment pages, YouTube, social networks and a separately hosted reviews site. Those services may process account, device or usage data under their own terms.

15.2. Clicking an external link does not make GSR the controller of all processing carried out independently by that service. GSR remains responsible for its own decision to disclose data and for data it receives or controls.

15.3. If a testimonial is published on a separately operated reviews site, the consent and the relevant page must identify the responsible controller and the publication channels. Consent given to one controller or one channel is not automatically valid for another.

15.4. Before sending sensitive information to a Specialist or Expert contacted outside a GSR-arranged process, ask that person for their identity, country, privacy notice, retention period and confidentiality terms.

16. Changes to this Policy

16.1. GSR reviews this Policy when the Website, services, vendors, countries, data categories or applicable law change. The current version and effective date will remain available on the Website.

16.2. Material changes will be brought to users’ attention through an appropriate Website or service notice. A change to this Policy does not retroactively expand a consent already given. A new consent will be requested where required.

16.3. Earlier versions and the evidence of the notice shown at the time of collection will be retained as needed to demonstrate compliance.

17. Applicable framework and contact

17.1. This Policy is designed for processing governed by the United Arab Emirates Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, together with other applicable UAE laws, including child digital safety requirements where relevant. Mandatory rights under another applicable law are not excluded.

17.2. Questions, consent withdrawals, rights requests and incident reports may be sent to:

GSR SYSTEM FZ CO Dubai Digital Park, Office A2, Dubai Silicon Oasis, Dubai, United Arab Emirates org_gsr@gsrsystem.com  |  Subject: Privacy Request