Data Processing Agreement
The GDPR processor terms between GlobeAPI and its customers — roles, scope of processing, sub-processors, security measures, breach notification and international transfers.
Last updated: August 2, 2026
— 1. Scope, Roles & Definitions
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer and GoGlobe Limited, a private company limited by shares incorporated in Ireland under company registration number 785708, VAT number IE 4403614UH, with its registered address at 46 The Flagsman, Marshall Yards, Dublin 3, D03 H2Y3, Ireland, and applies where GoGlobe processes personal data on the Customer’s behalf. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the GDPR (Regulation (EU) 2016/679).
Roles are split. For personal data that the Customer submits through the Service about its own end users, the Customer is the controller and GoGlobe is the processor. For personal data relating to the Customer’s own account, billing, support and platform usage, GoGlobe is the controller and its Privacy Policy applies, not this DPA. Where GoGlobe uses de-identified and aggregated data to operate, secure and improve the Service, it does so as controller of that aggregated data.
If this DPA conflicts with the Terms of Service on data protection, this DPA prevails.
— 2. Details of Processing
- Subject matter — provision of the GlobeAPI platform and its APIs, widgets and related services.
- Duration — for the term of the Terms of Service, plus the deletion period in Section 10.
- Nature and purpose — receiving, transmitting, storing temporarily, analysing and returning data submitted through the API in order to answer the Customer’s requests; metering and billing that usage; securing the platform.
- Types of personal data — as determined by the Customer, and typically: end-user identifiers and session tokens; free-text queries and chat messages; audio submitted for transcription; images and video submitted for moderation or analysis; location coordinates; and traveller details submitted for booking (name, contact details, date of birth, travel-document details where the supplier requires them).
- Categories of data subject — the Customer’s end users, employees and travellers.
- Special categories — the Service is not intended for special-category data under Art. 9. The Customer must not submit it, save for data unavoidably present in images submitted for content moderation, which is processed solely to produce the moderation result and is not retained beyond that purpose.
— 3. Processor Obligations
— 4. Customer Obligations
— 5. Sub-processors
The Customer grants general authorisation for GoGlobe to engage sub-processors for hosting, infrastructure, edge security, machine-learning inference, payment processing, email delivery, mapping and travel-inventory aggregation. Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than this DPA, and GoGlobe remains fully liable to the Customer for its sub-processors’ performance.
GoGlobe treats sub-processor identity as confidential business information and publishes categories rather than names, as Art. 13(1)(e) GDPR permits. An active business customer may obtain the current named list, with purpose, region and data categories, and the relevant agreements and transfer impact assessments, on request and under a reasonable confidentiality undertaking.
GoGlobe will notify the Customer of an intended addition or replacement of a sub-processor at least 30 days in advance. The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to find an alternative, and if none is available the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
— 6. Security Measures
GoGlobe implements appropriate technical and organisational measures under Art. 32, including: encryption in transit and at rest; hashed, non-recoverable storage of credentials and API keys; role-based least-privilege access with revocable tokens; network segmentation and firewalling; per-request Content Security Policy and hardened security headers; magic-byte and content validation on uploads; rate limiting and anti-abuse controls; audit logging; backup and restoration procedures; and periodic adversarial security testing.
Measures may be updated as threats and technology evolve, provided the level of protection is not reduced. A current summary is available to business customers on request.
— 7. Personal Data Breach
— 8. Assistance to the Customer
— 9. Audit & Compliance Reporting
— 10. Return & Deletion
— 11. International Transfers
— 12. Liability
Questions about this document? Email [email protected].