Legal
Privacy notice
This notice says what personal data GTME collects and why. It says who we share it with and how long we keep it. It also says how you can see, fix or delete it. It covers visitors to this site and people who ask for a free LinkedIn audit or book a call. It also covers our clients and the people we contact on LinkedIn for a client. It covers the people named in someone’s audit too.
Version 2026-10-05. Effective .
Who we are
GTME is a LinkedIn outreach service, run by the GTME Consulting team, based in Delhi, India. When this notice says “GTME”, “we” or “us”, it means that business.
For the data in this notice, we’re the controller. The one exception is client work, where we act as a processor.
- Privacy contact
- privacy@gtme.consulting
- Grievance officer
- Prachi Agarwal, hello@gtme.consulting. Handles data questions and grievances, including for people in India.
- Postal address
- Delhi, India. We send the full postal address on request.
- EU and UK representative
- Not appointed yet. We’ll appoint one before the first client in the EU or UK starts outreach, and name them here.
The short version
- We collect what you type into our forms and what you tell us when you book a call. Our servers also log what they need to run the site.
- We use it to prepare your audit, reply to you and, if you become a client, run your outreach and bill you.
- We don’t sell personal data. We don’t use ad cookies. There’s no tracking pixel from LinkedIn or anyone else on this site.
- You can ask to see, correct or delete your data at any time by emailing privacy@gtme.consulting. We answer within 30 days.
What we collect, why, and the lawful basis
Under the EU and UK GDPR we need a lawful basis for each use of data. This table lists what we collect and where it comes from. It also lists what we use it for and the basis we rely on.
| What | Where it comes from | What we use it for | Lawful basis |
|---|---|---|---|
| Your LinkedIn profile link, work email and network size | You, in the free audit form | Scoring your profile, building your audit and sending it to you | Steps you asked for before a possible contract (GDPR Art 6(1)(b)) |
| The same details, after we’ve sent your audit | Our records | Up to 2 follow-up emails about your audit, each with a one-click unsubscribe | Our legitimate interest in following up on a request you made (Art 6(1)(f)). You can object at any time |
| Your country, the tags in the link you used, and a scrambled code made from your IP address | Your browser and our server | Stopping spam and repeat requests, and seeing which posts bring requests | Our legitimate interest in running and protecting the form (Art 6(1)(f)) |
| Your name, email, company website and the answers you give when you book a call | You, in the Cal.com booking form | Preparing for and holding the call | Steps you asked for before a possible contract (Art 6(1)(b)) |
| Pages viewed, the referring site, browser and device type, country | Plausible, a cookieless analytics service | Counting visits and seeing which pages help people | Our legitimate interest in knowing how the site is used (Art 6(1)(f)). Plausible stores nothing on your device |
| A check that a form was sent by a person | Cloudflare Turnstile | Keeping bots out of the form | Our legitimate interest in security (Art 6(1)(f)) |
| Contact, contract and billing details for clients | You, and our invoices and payment providers | Running the service, sending invoices and keeping tax records | The contract (Art 6(1)(b)) and our legal duties (Art 6(1)(c)) |
| Details of the people contacted from a client’s LinkedIn profile | The client’s LinkedIn account, LinkedIn Sales Navigator and public posts | Running that client’s outreach | We act as the client’s processor; see the section on client work |
| Name, title, company, public LinkedIn profile and the public signal behind the pick, for people named in someone’s audit | Public LinkedIn profiles and posts, and public company news | Showing the person who asked for a free audit the 10 people we’d contact first, and why | Our legitimate interest in showing our work to a business that asked for it (Art 6(1)(f)). See the section on audits |
We don’t ask for your phone number, team size or buyer title in any form. We don’t need them.
International transfers
GTME works from India, and several of the providers above are in the United States. So data from the EU and the UK goes to other countries. The EU and the UK haven’t found that those countries protect it well enough. India has no adequacy decision from the EU or the UK.
To protect it, we use the Standard Contractual Clauses from the European Commission. For the UK, we add the UK’s own addendum to them.
Both are part of each provider’s data processing agreement, and of our agreements with clients. You can ask us for a copy at privacy@gtme.consulting.
How long we keep it
| Data | How long |
|---|---|
| Requests for a free audit and bookings that don’t become clients | 24 months after we last hear from you. Then we delete it from our database, our records and our email |
| The people named in someone’s audit | The audit page expires after 30 days. We delete it after 30 days |
| Raw form submission logs, including the IP hash | 90 days |
| Our do-not-contact list | For as long as we operate, so anyone who asked us to stop stays stopped. It holds only what we need to recognise you |
| Client records and invoices | The length of the contract plus 6 years, for tax and accounting records |
| Data about the people contacted for a client | The client gets an export within 14 days of the end of the contract. We delete our copy within 30 days |
Your rights
If you’re in the EU or the UK, you have the right to:
- ask for a copy of the data we hold about you
- have inaccurate data corrected
- have your data deleted
- limit how we use it while a question is sorted out
- object to how we use it. You can always object to direct marketing
- get the data you gave us in a file you can take elsewhere
- take back your consent at any time, where we rely on it
- complain to a data protection body. In the UK that’s the Information Commissioner’s Office. In the EU it’s the body where you live or work
If you’re in India, the Digital Personal Data Protection Act 2023 gives you rights too. You can ask for a summary of the data we hold about you.
You can have it corrected, completed, updated or erased. You can use our grievance process, and you can name someone to act for you. If we don’t resolve a grievance, you can complain to the Data Protection Board of India.
If you’re in California or another US state, we don’t sell personal information. We don’t share it either, as those laws define it. We don’t use it for targeted advertising either. We’ll answer a request to know, correct or delete your data like any other.
To use any of these rights, email privacy@gtme.consulting. We may ask you to confirm your identity first. We answer within 30 days and don’t charge for it.
Cookies and similar technologies
This site doesn’t use cookies for analytics or ads. That’s why there’s no cookie banner.
- Plausible counts visits without cookies. It stores nothing on your device. It uses a daily visitor code made from your IP address and browser. It deletes that code every 24 hours.
- Cloudflare Turnstile loads when you reach the second step of the free audit form. It may use storage on your device to check that you’re a person. This is strictly necessary for the form you’re sending.
- Cal.com stores data on your device only when you open the booking calendar. It needs that to run the booking you asked for.
- Our fonts are served from this site, so no font provider sees your visit.
Automated decisions
The form sorts requests by when they arrive. If a day is full, you’re offered the next available day instead. The form tells you so straight away.
This sorting has no legal or similar effect on you, and a person reads every request. Software alone never makes a decision about you that has a legal or similar effect.
If we contacted you on behalf of a client
GTME runs LinkedIn outreach for business clients from their own LinkedIn profiles. If you got an invitation or a message that way, the client controls your data.
We’re their processor, under a written data processing agreement. This section gives you the information the GDPR asks for when data wasn’t collected from you directly (Article 14).
- What we hold: your name, job title, company and public LinkedIn profile. We also hold the public post or company news that led to the invitation. We hold the messages you exchanged too, and whether you replied or booked a meeting.
- Where it came from: your public LinkedIn profile, LinkedIn Sales Navigator, public posts and public company news.
- Why: so the client could contact you about a problem their product solves. The client’s own privacy notice gives their lawful basis. It is usually their legitimate interest in contacting business buyers.
- How long: until the client’s contract with us ends, then deleted within 30 days.
- How to object: reply to the message, or email privacy@gtme.consulting. We add you to one do-not-contact list that covers every client we work for. That way, you won’t hear from any of them through us again.
If you appear in someone’s audit
We may list your name, title, company and public profile link in a private audit for one person. That comes only from what is public on LinkedIn. It is not indexed, expires after 30 days and is deleted after 30. Email privacy@gtme.consulting to be removed at once.
Client work: when we act as a processor
For our clients, GTME handles the data of the people contacted from the client’s profile. The client decides who is contacted and why.
We follow their instructions under a data processing agreement that meets Article 28 of the GDPR. It covers confidentiality, security and the providers we use. It also covers help with people’s requests and breach notice to the client within 48 hours. It covers deletion when the contract ends too.
How we look after your data
Two-factor sign-in is switched on for every tool we use. Only the people who need access have it, and we check that every month.
Prospect data never goes onto our own phones, spreadsheets or chat apps. We never ask for, or store, a client’s LinkedIn password. If a breach affects your data, we’ll tell you fast. We’ll also tell the authorities where the law requires it.
Children
GTME is a business service. This site isn’t meant for anyone under 18, and we don’t knowingly collect data about children.
Changes to this notice
We’ll update this notice when what we do with data changes. The version and date at the top of the page change with it, and we keep every earlier version.
Our records store which version was live when you sent a form. If a change affects how we use data we already hold about you, we’ll tell you by email first.
This notice is in English. If you’re in India, you can ask for it in a language from the Eighth Schedule of the Constitution of India. Just email privacy@gtme.consulting.