Legal

Data Processing Agreement

The GDPR processor terms between GlobeAPI and its customers — roles, scope of processing, sub-processors, security measures, breach notification and international transfers.

Last updated: August 2, 2026

1. Scope, Roles & Definitions

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer and GoGlobe Limited, a private company limited by shares incorporated in Ireland under company registration number 785708, VAT number IE 4403614UH, with its registered address at 46 The Flagsman, Marshall Yards, Dublin 3, D03 H2Y3, Ireland, and applies where GoGlobe processes personal data on the Customer’s behalf. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the GDPR (Regulation (EU) 2016/679).

Roles are split. For personal data that the Customer submits through the Service about its own end users, the Customer is the controller and GoGlobe is the processor. For personal data relating to the Customer’s own account, billing, support and platform usage, GoGlobe is the controller and its Privacy Policy applies, not this DPA. Where GoGlobe uses de-identified and aggregated data to operate, secure and improve the Service, it does so as controller of that aggregated data.

If this DPA conflicts with the Terms of Service on data protection, this DPA prevails.

2. Details of Processing

  • Subject matter — provision of the GlobeAPI platform and its APIs, widgets and related services.
  • Duration — for the term of the Terms of Service, plus the deletion period in Section 10.
  • Nature and purpose — receiving, transmitting, storing temporarily, analysing and returning data submitted through the API in order to answer the Customer’s requests; metering and billing that usage; securing the platform.
  • Types of personal data — as determined by the Customer, and typically: end-user identifiers and session tokens; free-text queries and chat messages; audio submitted for transcription; images and video submitted for moderation or analysis; location coordinates; and traveller details submitted for booking (name, contact details, date of birth, travel-document details where the supplier requires them).
  • Categories of data subject — the Customer’s end users, employees and travellers.
  • Special categories — the Service is not intended for special-category data under Art. 9. The Customer must not submit it, save for data unavoidably present in images submitted for content moderation, which is processed solely to produce the moderation result and is not retained beyond that purpose.

3. Processor Obligations

GoGlobe processes personal data only on the Customer’s documented instructions, which comprise the Terms of Service, this DPA, and the Customer’s configuration and use of the Service, unless required to process by EU or member-state law, in which case GoGlobe will inform the Customer first unless the law prohibits it. GoGlobe will inform the Customer if, in its opinion, an instruction infringes data-protection law. GoGlobe ensures that persons authorised to process personal data are bound by confidentiality and are trained appropriately, and applies the principle of least privilege.

4. Customer Obligations

The Customer warrants that it has a valid lawful basis, and where required has given notice and obtained consent, for every disclosure of personal data it makes to GoGlobe and for every purpose for which it instructs GoGlobe to process, including automated content scanning and AI processing. The Customer is responsible for the accuracy and legality of the data it submits, for configuring the Service appropriately, and for not submitting data outside the categories described in Section 2.

5. Sub-processors

The Customer grants general authorisation for GoGlobe to engage sub-processors for hosting, infrastructure, edge security, machine-learning inference, payment processing, email delivery, mapping and travel-inventory aggregation. Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than this DPA, and GoGlobe remains fully liable to the Customer for its sub-processors’ performance.

GoGlobe treats sub-processor identity as confidential business information and publishes categories rather than names, as Art. 13(1)(e) GDPR permits. An active business customer may obtain the current named list, with purpose, region and data categories, and the relevant agreements and transfer impact assessments, on request and under a reasonable confidentiality undertaking.

GoGlobe will notify the Customer of an intended addition or replacement of a sub-processor at least 30 days in advance. The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to find an alternative, and if none is available the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.

6. Security Measures

GoGlobe implements appropriate technical and organisational measures under Art. 32, including: encryption in transit and at rest; hashed, non-recoverable storage of credentials and API keys; role-based least-privilege access with revocable tokens; network segmentation and firewalling; per-request Content Security Policy and hardened security headers; magic-byte and content validation on uploads; rate limiting and anti-abuse controls; audit logging; backup and restoration procedures; and periodic adversarial security testing.

Measures may be updated as threats and technology evolve, provided the level of protection is not reduced. A current summary is available to business customers on request.

7. Personal Data Breach

GoGlobe will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf. The notification will describe the nature of the breach, the categories and approximate volume affected, the likely consequences and the measures taken or proposed, to the extent then known, with further information supplied in phases as the investigation progresses. GoGlobe will assist the Customer in meeting its own Art. 33 and Art. 34 obligations. Notification is not an admission of fault or liability.

8. Assistance to the Customer

Taking into account the nature of processing and the information available to it, GoGlobe will assist the Customer with: responding to data subject requests under Chapter III (access, rectification, erasure, restriction, portability and objection), including by providing the technical means for the Customer to retrieve, correct or delete data itself; data protection impact assessments and prior consultation under Arts. 35 and 36; and demonstrating compliance with Art. 32. GoGlobe will promptly forward any request it receives directly from a data subject to the Customer and will not respond to it itself except to confirm that it acts as a processor.

9. Audit & Compliance Reporting

GoGlobe will make available the information necessary to demonstrate compliance with Art. 28. On reasonable written notice of at least 30 days, no more than once in any 12-month period (and additionally following a personal data breach or on the documented instruction of a supervisory authority), the Customer or an independent auditor bound by confidentiality and not a competitor of GoGlobe may audit that compliance. Audits take place during business hours, must not unreasonably disrupt operations, and must not access other customers’ data or GoGlobe’s confidential security detail beyond what is necessary. The Customer bears the cost of the audit unless it reveals material non-compliance. GoGlobe may satisfy an audit request by providing summary compliance reports or third-party assessment results where these reasonably address the request.

10. Return & Deletion

On termination or expiry of the Terms of Service, and at the Customer’s election, GoGlobe will return or delete personal data processed on the Customer’s behalf. Deletion will be completed within 90 days, save for data GoGlobe is required to retain by law and data held in routine backups, which is isolated from active processing and deleted on the ordinary backup rotation. The Customer may export its data through the Service before termination.

11. International Transfers

Processing takes place within the EEA by default. Where personal data is transferred to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), which are incorporated into this DPA by reference with GoGlobe as data importer or exporter as applicable, module selection following the roles in Section 1, supplemented where relevant by the UK International Data Transfer Addendum, and supported by a Transfer Impact Assessment performed in accordance with EDPB post-Schrems II guidance. Where a competent authority invalidates a transfer mechanism, the parties will implement a valid alternative in good faith.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent that limitation is prohibited by the GDPR or other applicable data-protection law. Nothing in this DPA limits a data subject’s rights, or either party’s liability to a supervisory authority or to a data subject under Art. 82 GDPR.

Questions about this document? Email [email protected].