Last updated: 28 September 2026

Data Protection & Handling Policy

How Global Cloud Media manages business and customer data across our software, cloud applications, and related services.

01

Purpose and scope

This public-facing Data Protection & Handling Policy describes how Global Cloud Media (Pvt) Ltd manages business and customer data across its software development, cloud applications, and related services. It applies to our personnel and the systems we operate or manage.

A signed customer agreement, data processing agreement, or product-specific policy may set more detailed obligations for a particular service. This policy does not itself grant a customer a right to audit systems or change agreed service levels.

02

Responsibility for data

For our own business records, Website inquiries, marketing, hiring, billing, and supplier management, we determine the purposes and methods of processing. For data that a customer uploads to or processes through a service under its control, the customer determines its lawful purpose, notices, permissions, recipient choices, and user access.

We process that customer data on documented instructions, except where applicable law requires otherwise, and we notify the customer where legally permitted if an instruction creates an apparent compliance issue.

Customers should not upload data that the contracted service is not designed to handle, especially sensitive personal data, credentials, or regulated data, without agreeing the necessary safeguards with us first. A customer is responsible for the accuracy of its data, its authorized users, and the instructions it gives through the service.

03

Collection and permitted use

We collect or receive only data needed for a defined business or service purpose. We do not use customer-controlled content for our own unrelated marketing or disclose it for another customer's benefit.

Personnel may access customer data only when needed to provide, maintain, secure, or support the contracted service, or when otherwise authorized or legally required. Product analytics should be designed to use aggregated or de-identified information where practical.

04

Security controls

We apply safeguards proportionate to the nature of the data and the service, including role-based access, least-privilege permissions, authentication controls, secure transmission, appropriate encryption at rest where supported, logging and monitoring, patch and vulnerability management, backups, and staff confidentiality duties.

Access is reviewed and removed when no longer needed. Specific technical controls and recovery commitments are those in the relevant service documentation.

05

Service providers and data location

We assess vendors that may access or host customer data and require appropriate confidentiality, security, and processing terms. A current list or description of relevant subprocessors, hosting regions, and any international transfers should be available in the product's data processing documentation or on request.

We will give notice of material subprocessor changes where the customer agreement requires it. Transfers outside Sri Lanka will follow applicable legal requirements and contractual safeguards.

06

Retention, return, and deletion

We retain data according to the applicable contract, documented retention schedule, and legal requirements. At the end of a service, customer data will be made available for export and deleted or returned as the agreement provides, subject to outstanding legal obligations and normal backup lifecycles.

We do not promise immediate removal from every backup unless that is technically supported and contractually agreed.

07

Incidents and continuity

Personnel must promptly report suspected loss, unauthorized access, disclosure, or alteration of data through our internal incident process. We investigate, contain, document, and remediate confirmed incidents.

Where customer data is affected, we notify the customer in accordance with the contract and applicable law, sharing information reasonably available to support required notices. We maintain backup and recovery arrangements suited to each service; any guaranteed recovery time or recovery point must be stated in its SLA.

08

Requests and accountability

We maintain a process for privacy requests and complaints. For customer-controlled data, we direct individuals to the customer or assist the customer in responding, as appropriate.

We periodically review access, suppliers, security measures, and this Policy as our services and legal requirements develop. Questions about a specific service's processing terms may be sent to info@globalcloudmedia.lk.

09

Contact

Global Cloud Media (Pvt) Ltd, No. 20, Old Kesbewa Road, Nugegoda, Sri Lanka.

Email: info@globalcloudmedia.lk. Phone: +94 11 216 0328.