GOSRAGlobal Online Scam
Recovery Agency
HomePrivacy Policy

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: January 2025

The Global Online Scam Recovery Agency (“GOSRA”, “we”, “our”, or “us”) is committed to protecting the privacy of scam victims and all visitors to gosra.org. This policy explains how we handle your personal data.

1. Data Controller

The data controller is the Global Online Scam Recovery Agency, operating from 100 Financial District, New York, NY 10005, United States. Contact our Data Protection Officer at privacy@gosra.org.

2. Information We Collect

2.1 Information you provide

  • Contact details (name, email, phone number)
  • Company and position (if applicable)
  • Case details including summaries of the scam experienced
  • Supporting documentation you choose to share

2.2 Information collected automatically

  • IP address and approximate geographic location
  • Browser type and device information
  • Pages visited and time spent on pages
  • Referring website or link

3. How We Use Your Information

We use your personal data to:

  • Assess and progress your scam recovery case
  • Communicate with you about your case and our services
  • Comply with legal and regulatory obligations
  • Improve our website and services
  • Detect and prevent fraud and abuse of our services

4. Data Sharing

We never sell your data. We only share information with trusted third parties where strictly necessary for your case (e.g., legal partners in relevant jurisdictions, law enforcement when appropriate, and financial institutions during recovery). All sharing is governed by strict confidentiality agreements.

5. International Transfers

Because online scam recovery is inherently global, your data may be transferred to and processed in countries outside your home jurisdiction. We ensure all transfers comply with applicable data protection laws and use Standard Contractual Clauses where required.

6. Data Retention

We retain case files for a minimum of 7 years after case closure to comply with professional regulatory requirements. Contact information is retained for 3 years after last contact unless you request earlier deletion.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal obligations)
  • Object to or restrict processing
  • Data portability
  • Withdraw consent where processing is based on consent

To exercise your rights, contact privacy@gosra.org.

8. Security

We implement bank-grade security including AES-256 encryption at rest, TLS 1.3 in transit, multi-factor access controls, 24/7 monitoring, and ISO 27001-aligned processes. Staff undergo annual security training and background checks.

9. Cookies

Our use of cookies is detailed in our Cookie Policy.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. Continued use of our services after changes constitutes acceptance.

11. Contact

Questions about this policy? Email privacy@gosra.org or write to us at 100 Financial District, New York, NY 10005, USA.