Gletra
Gletra

GDPR Compliance

Gletra commitments, legal bases, and user rights under the General Data Protection Regulation for EEA and UK users.

Updated June 19, 2026 4 min read Official Gletra Policy

Gletra Technologies Pvt. Ltd. respects the privacy rights of individuals in the European Economic Area (EEA), United Kingdom, and other jurisdictions where the General Data Protection Regulation (GDPR) and UK GDPR apply. This page outlines our GDPR-specific commitments, legal bases for processing, data subject rights, and contact information for our Data Protection Officer.

While Gletra primarily operates in India, our multi-vendor marketplace, chat, voice and video calling, home services booking, and wallet platform may process personal data of EEA/UK residents who create accounts, purchase products, book services, or interact with Gletra sellers and service providers.

Gletra processes personal data lawfully, fairly, and transparently. We implement appropriate technical and organizational measures to protect data and honor the rights of data subjects as defined in GDPR Articles 12–23.

This GDPR Compliance page supplements our Privacy Policy and Data Protection Policy. In case of conflict regarding EEA/UK users, GDPR-specific provisions in this document prevail.

Data Controller Information

Data Controller Information
Data Controller Information

Data Controller: Gletra Technologies Pvt. Ltd., 42 Brigade Tech Park, Whitefield, Bengaluru, Karnataka 560066, India.

EU Representative: Where required, Gletra appoints an EU representative accessible at dpo@gletra.com for EEA data subject inquiries.

Data Protection Officer: dpo@gletra.com

Legal Bases for Processing

Legal Bases for Processing
Legal Bases for Processing
Processing ActivityLegal BasisGDPR Article
Account creation and order fulfillmentContract performanceArt. 6(1)(b)
KYC and AML complianceLegal obligationArt. 6(1)(c)
Fraud prevention and platform securityLegitimate interestsArt. 6(1)(f)
Marketing communicationsConsentArt. 6(1)(a)
Chat and call metadata storageLegitimate interests / ContractArt. 6(1)(f)/(b)
Analytics and product improvementLegitimate interests (with opt-out)Art. 6(1)(f)

Personal Data Categories Processed

Personal Data Categories Processed
Personal Data Categories Processed
  • Identity data: name, email, phone, date of birth, government ID (KYC)
  • Transaction data: orders, bookings, payments, wallet activity
  • Communication data: chat messages, call metadata, support tickets
  • Technical data: IP address, device ID, browser type, cookies
  • Location data: delivery address, service location (with consent for GPS)
  • Profile data: preferences, reviews, seller/service provider credentials

Your GDPR Rights

Your GDPR Rights
Your GDPR Rights

Right of Access (Art. 15)

Request a copy of personal data Gletra holds about you.

Right to Rectification (Art. 16)

Correct inaccurate personal data via Account Settings or dpo@gletra.com.

Right to Erasure (Art. 17)

Request deletion where no legal retention obligation exists.

Right to Restriction (Art. 18)

Limit processing during dispute resolution or objection review.

Right to Data Portability (Art. 20)

Receive your data in structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent (Art. 7)

Withdraw marketing consent anytime via Account Settings without affecting prior lawful processing.

Exercising Your Rights

Exercising Your Rights
Exercising Your Rights

Submit requests to dpo@gletra.com with subject "GDPR Data Subject Request." Include account email and request type. Gletra responds within 30 days (extendable by 60 days for complex requests with notice). Identity verification required before disclosure.

International Data Transfers

International Data Transfers
International Data Transfers

Personal data of EEA/UK users may be transferred to India and other countries where Gletra or its processors operate. Transfers are protected by:

  • Standard Contractual Clauses (SCCs) approved by European Commission
  • UK International Data Transfer Agreement where applicable
  • Adequacy decisions where recognized by relevant authorities
  • Supplementary measures including encryption and access controls

Data Processors and Sub-Processors

Data Processors and Sub-Processors
Data Processors and Sub-Processors

Gletra engages vetted processors for payment processing, cloud hosting, KYC verification, email delivery, and analytics. All processors are bound by Data Processing Agreements requiring GDPR-equivalent protections. Sub-processor list available on request from dpo@gletra.com.

Data Retention for EEA/UK Users

Data Retention for EEA/UK Users
Data Retention for EEA/UK Users
Data CategoryRetention PeriodBasis
Account profileAccount lifetime + 2 yearsContract / legal claims
Transaction records7 yearsTax and AML legal obligation
Chat messages3 years from last activityDispute resolution legitimate interest
Marketing consent recordsDuration of consent + 3 yearsLegal obligation to demonstrate consent
KYC documents7 years after account closureAML legal obligation

Automated Decision-Making

Automated Decision-Making
Automated Decision-Making

Gletra uses automated systems for fraud scoring, product recommendations, and search ranking. These do not produce legal or similarly significant effects without human review. You may request human review of automated fraud holds by contacting dpo@gletra.com.

Frequently Asked Questions

GDPR applies based on residency and establishment, not citizenship alone. If you reside in India and use Gletra primarily in India, Indian privacy law governs. EEA residents are protected regardless of citizenship.

Email dpo@gletra.com with "Data Portability Request" or use Account Settings > Privacy > Export My Data where available. Receive a machine-readable export within 30 days.

Yes. Request erasure at dpo@gletra.com. Gletra deletes data not subject to legal retention (transactions, KYC) within 30 days. Residual anonymized analytics data may be retained.

No. Chat content is not used for advertising profiling. Chat metadata may be processed for safety, fraud prevention, and dispute resolution under legitimate interests.

Through Standard Contractual Clauses, encryption in transit and at rest, access controls, and regular security audits. Request our transfer impact assessment summary from dpo@gletra.com.

Contact our DPO at dpo@gletra.com for all GDPR-related inquiries, data subject requests, and supervisory authority correspondence.

Questions About This Policy?

Our legal and support teams are here to help.

Contact Legal Team