Privacy Policy

Learn how GNR Research collects, uses, and protects your personal data. We are committed to GDPR compliance, ESOMAR standards, and the highest levels of data security.

  • Home
  • Privacy Policy
Effective Date: January 1, 2025
Last Updated: September 1, 2025
Version: 2.0

1. Overview

GNR Research ("we," "our," or "us") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, visit our website, or interact with us as a research panelist, client, or website visitor.

We are fully compliant with the EU General Data Protection Regulation (GDPR), ESOMAR Code of Conduct, and UAE Data Protection Law. Our data processing operations are certified under ISO 27001.

2. Information We Collect

2.1 Personal Information

  • Identity Data: Full name, username, date of birth, government-issued ID numbers
  • Contact Data: Email address, phone number, postal address, country of residence
  • Demographic Data: Age, gender, nationality, education level, employment status, income bracket
  • Financial Data: Bank account details, payment information for panelist rewards and compensation
  • Technical Data: IP address, browser type, device information, operating system, screen resolution

2.2 Research Data

  • Survey responses and opinions provided during research studies
  • Behavioral data collected through online research activities
  • Purchase history and brand usage data shared voluntarily
  • Audio recordings from CATI (Computer-Assisted Telephone Interviewing) sessions
  • Qualitative feedback from focus groups and in-depth interviews

2.3 Information Collected Automatically

  • Website usage data through cookies and similar tracking technologies
  • Log data including access times, pages viewed, and referring URLs
  • Geolocation data (country/region level) for research segmentation

3. How We Use Your Information

We use the collected information for the following purposes:

  • Research Services: Conducting market research studies, surveys, and data analysis on behalf of our clients
  • Panelist Management: Managing your panel membership, matching you with relevant surveys, and distributing rewards
  • Quality Assurance: Validating data quality, detecting fraudulent responses, and ensuring research integrity
  • Service Improvement: Enhancing our platforms, methodologies, and user experience
  • Communication: Sending survey invitations, research updates, and administrative notifications
  • Legal Compliance: Fulfilling regulatory obligations under GDPR, ESOMAR, and local data protection laws
  • Business Operations: Processing payments, generating anonymized reports, and managing client relationships

4. Data Sharing & Disclosure

We do not sell your personal data. We share information only in the following circumstances:

  • Clients (Aggregated Only): Research findings are shared with clients in aggregated, anonymized form. Individual identities are never disclosed in research reports.
  • Service Providers: Trusted third-party vendors who assist in data collection, processing, or hosting, bound by strict confidentiality agreements.
  • Legal Requirements: When required by law, court order, or governmental regulation.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected individuals.

All data shared with clients is fully anonymized and aggregated. Individual respondent identities are never disclosed in any research deliverables.

5. Data Security

We implement industry-leading security measures to protect your data:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • ISO 27001 certified Information Security Management System (ISMS)
  • Regular penetration testing and vulnerability assessments
  • Role-based access control with multi-factor authentication
  • Secure data centers with 24/7 monitoring and redundancy
  • Employee data protection training and confidentiality agreements
  • Incident response plan with 72-hour breach notification protocol

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Panelist Accounts: Retained for the duration of active membership plus 2 years
  • Research Data: Retained for 5 years after project completion (or as required by client contracts)
  • Website Analytics: Retained for 26 months
  • Financial Records: Retained for 7 years as required by tax regulations
  • Communication Logs: Retained for 3 years

After the retention period, data is securely deleted or anonymized for statistical purposes.

7. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation on how we use your data
  • Right to Data Portability: Request transfer of your data to another service
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing

To exercise any of these rights, email us at privacy@gnrresearch.com or write to our Data Protection Officer. We respond to all requests within 30 days.

8. Cookies & Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience. For detailed information, please refer to our Cookie Policy.

9. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us immediately at privacy@gnrresearch.com and we will delete the information promptly.

10. International Data Transfers

As we operate across 33+ countries in the MENA region, your data may be transferred to and processed in countries outside your country of residence. We ensure all transfers comply with applicable data protection laws through Standard Contractual Clauses (SCCs), adequacy decisions, or other approved transfer mechanisms.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated through our website with an updated "Last Updated" date. We encourage you to review this policy periodically.

12. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

  • Data Protection Officer: dpo@gnrresearch.com
  • General Privacy Inquiries: privacy@gnrresearch.com
  • Phone: +971 50 123 4567
  • Address: GNR Research, Dubai, United Arab Emirates

Have Questions About Our Policies?

Our team is here to help. Contact us for any clarifications regarding our privacy practices, terms of service, or panelist policies.

We'd Love to Hear From You!

Have a question about our market research services? Send us a message and our team will respond within 24 hours.

Your data is secure. We never share it with third parties.