GCSB seal
GCSB
Global Converged Security Board

Legal

Privacy Policy

This policy applies to everyone who uses gcsb.app, including visitors, candidates, credential holders, members and accredited partners.

Last updated: 5 October 2026

1. Who we are

The data controller is the Global Converged Security Board (GCSB), based in the United Kingdom. Full registered entity details, registered address and any ICO registration number will be published on the About page. Privacy contact: use the Contact page and select "Other", with the subject "Privacy request".

2. Personal data we collect

  • Credential records: name, qualification, grade, country, award year, status, verification ID and CPD hours, received from our credentialing platform (Certifier) when a credential is issued.
  • Account data: email address and password (stored only as a secure hash) when you create a member account.
  • Member profile: full name, job title, organisation, country, phone, LinkedIn address, professional summary and an optional CV that you upload.
  • CPD records: activity type, date, hours and description that you log.
  • Messages: name, email, subject and message sent through the Contact form.
  • Standards questions: the text of questions typed into "Ask the Standards". These are not linked to your identity and are not stored by GCSB.
  • Technical data: IP address, browser type and request logs created automatically by our hosting provider for security and reliability.

We do not collect data automatically from LinkedIn or other third-party sites, and we do not intentionally collect special category (sensitive) data.

3. How we use it

  • Awarding, maintaining, renewing, suspending or revoking credentials.
  • Publishing the Public Register and answering credential verification requests.
  • Running the member portal, CPD tracking and member requests.
  • Listing members in the Member Directory, only where they have opted in.
  • Responding to enquiries, complaints and appeals.
  • Keeping the site secure, preventing fraud and meeting legal obligations.

4. What is public

The Public Register and verification service show only name, credential, grade, country, award year, status, CPD hours for the current year and verification ID. The Member Directory additionally shows job title, organisation, LinkedIn link and summary for members who opt in. Email addresses, phone numbers and CVs are never published.

5. Sharing and service providers

We do not sell personal data, and we do not share it for targeted or cross-context behavioural advertising. We use these service providers, acting on our instructions:

  • Website hosting and database (Lovable Cloud and its infrastructure providers).
  • Certifier, for issuing and storing digital credentials.
  • An AI service used to answer "Ask the Standards" questions from the published standards.
  • Email delivery for account confirmation and password reset messages.

We may also disclose data where required by law, or to protect the integrity of GCSB credentials.

6. International transfers

GCSB is based in the UK and serves a global audience, so data may be processed outside your country, including in the United States and the EU. Where UK or EU data leaves those regions, we rely on adequacy decisions or standard contractual clauses (including the UK International Data Transfer Addendum) provided by our service providers.

7. How long we keep data

  • Credential and register records: for as long as the credential exists, plus the period needed to verify historic awards and handle disputes.
  • Member accounts, profiles and CVs: until you close your account, or remove the item yourself.
  • CPD records: for the renewal cycle plus up to six years for audit.
  • Contact messages: up to two years after the enquiry is closed.
  • Hosting security logs: short periods set by our hosting provider.

8. Security

Access to personal data is restricted by role. Members can see only their own records. CVs are held in private storage and opened only through short-lived links. Passwords are never stored in readable form.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or export your data, to object, and to withdraw consent. See the GDPR & UK GDPR, PIPEDA and CCPA/CPRA notices, and how to make a request.

10. Children

This site is intended for professionals aged 18 and over. We do not knowingly collect data from children.

11. Cookies

See the Cookie & Storage Policy.

12. Changes

We will post any changes here and update the date at the top of this page.