Loading…
Loading…
Our obligations as a data processor on behalf of customers under GDPR and equivalent laws.
Last updated: May 15, 2026
This Data Processing Agreement ("DPA") forms part of the GlobiGuard Terms of Service between Globi Explore, Inc. ("GlobiGuard," "Processor") and the Customer ("Controller"). It governs the processing of Personal Data by GlobiGuard on behalf of the Customer.
Customers who require a countersigned DPA for regulatory purposes should contact [email protected].
GlobiGuard processes Personal Data solely to provide the services: inspecting data flowing through Customer AI workflows, applying Customer-configured enforcement policies, generating audit records, and routing decisions to human reviewers.
GlobiGuard does not process Personal Data for its own commercial purposes, sell or share it with third parties, use it to train its own AI models, or retain raw Personal Data beyond what is necessary to provide the contracted service, configured review workflow, or audit record.
GlobiGuard's sidecar intercepts data payloads before they reach AI models. When a payload contains fields classified as Personal Data:
[GG-7f3a]) before the payload proceeds.Raw values of BLOCKED fields are never persistently stored. Tokens for MODIFIED fields are retained only until detokenisation is complete, then purged per the Customer's configured retention policy.
Audit records contain: timestamp, workflow ID, field type, enforcement decision, policy applied, and confidence score. They do not contain raw values of BLOCKED or MODIFIED fields. Retention period: 12 months by default, with longer retention windows available where specified in the applicable order form, enterprise agreement, or customer-configured retention settings.
| Category | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ for all API communication |
| Encryption at rest | AES-256 for all stored audit data |
| Access control | Role-based, least-privilege |
| Authentication | Administrative authentication controls, which may include MFA depending on deployment and environment |
| Audit logging | All administrative access is logged |
| Security testing | Performed according to internal release practices and customer or partner requirements |
| Breach notification | In accordance with applicable law and the governing contract |
| Information security management | Security controls aligned with ISO 27001 principles |
Where Customer Data is processed in connection with AI systems subject to the EU AI Act, GlobiGuard's processing activities are designed to support the data governance and record-keeping requirements of that regulation. Customers deploying high-risk AI systems remain responsible for ensuring that all data processing — including processing performed by GlobiGuard on their behalf — meets the requirements of Article 10 (data and data governance) and Article 12 (record-keeping) of the EU AI Act.
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting the control plane and database |
| Message queue | Delivering enforcement and human-review events |
| Transactional email | Compliance notifications and alerts |
| Analytics (anonymised) | Aggregate platform performance monitoring |
Named sub-processors are available on request at [email protected]. We provide 30 days' notice before adding a new sub-processor that processes Personal Data. If you object and we cannot resolve it, you may terminate the affected services.
The Customer is the primary party responsible for responding to Data Subject requests. GlobiGuard will provide reasonable assistance, including export of audit logs, confirmation of enforcement decisions, and deletion of audit records on Customer instruction (subject to legal retention obligations).
GlobiGuard will notify the Customer of any Personal Data breach involving Customer Data in accordance with applicable law and the governing contract or DPA, including the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed.
Transfers from the EEA or UK to third countries are conducted under Standard Contractual Clauses (SCCs) or equivalent lawful mechanisms. By accepting the Terms of Service, Customer authorises GlobiGuard to execute SCCs with sub-processors located outside the EEA on its behalf where applicable.
On termination, GlobiGuard will provide return, export, deletion, or handoff assistance for Customer Data according to the governing order form, deployment model, and any applicable legal retention obligations. If no specific timeline is stated in the governing agreement, GlobiGuard will use commercially reasonable efforts to complete the applicable return or deletion process promptly after verified Customer instruction. Anonymised aggregate statistics that do not relate to identifiable individuals may be retained.
With 30 days' advance notice, Customers may audit GlobiGuard's processing activities to verify DPA compliance, once per calendar year (more frequently if a breach has occurred). GlobiGuard may satisfy an audit request by providing a recent independent security or compliance report, supporting controls documentation, or another evidence package where available, in lieu of direct inspection.
[email protected]
GlobiGuard — Globi Explore, Inc. · Georgia, United States