GDPR Compliance

For legal teams, procurement officers, and compliance departments evaluating Global Search for enterprise use.

Last updated: July 2026  ·  Questions? [email protected]

Summary for busy compliance teams: Global Search is registered in Austria and fully subject to the GDPR. We sign Data Processing Agreements for enterprise clients. All processing occurs within the EU/EEA. We retain client query logs for 90 days then delete them. DPA requests: [email protected].

1. Our Commitment

Global Search is a data intelligence platform registered and operating in Austria, a member state of the European Union. As such, we are directly subject to Regulation (EU) 2016/679 (the General Data Protection Regulation) and the Austrian Datenschutzgesetz (DSG).

Our platform serves B2B clients — law firms, corporate compliance teams, financial institutions, and licensed investigators. The platform aggregates information from public records and licensed data sources. When enterprise clients use Global Search, two separate data processing relationships apply:

We do not sell client data to third parties. We do not use client query content for advertising or profiling.

2. Data Processing Agreement (DPA)

Global Search offers a fully executed Data Processing Agreement to enterprise clients. The DPA covers:

To request a DPA, contact us at [email protected]. We typically return a countersigned DPA within 5 business days.

3. What We Process — Client Data

The following categories of personal data are processed in connection with operating client accounts:

Data categoryPurposeRetention
Account data
Name, email, organisation
Account creation, authentication, billing, and support communications Duration of contract + 3 years for legal compliance
Query logs
IP address, timestamp, query type (not result content)
Abuse prevention, rate limiting, service integrity monitoring 90 days, then automatically deleted
Billing records
Transaction IDs, amounts, payment method type
Invoicing, tax compliance, dispute resolution 7 years (Austrian tax law requirement)
Support communications
Email correspondence
Customer support 2 years from last interaction

What we do not log: The content of search results returned to clients is not stored on our servers after delivery. Query logs record the type and timestamp of a query but not the results themselves.

4. Data Subject Rights

Under the GDPR, individuals have the following rights with respect to their personal data processed by Global Search. Submit requests to [email protected]. We respond within 30 calendar days; complex requests may be extended by a further 60 days with notification.

Right of Access Art. 15

You may request a copy of the personal data we hold about you and information about how it is processed.

Right to Rectification Art. 16

You may request correction of inaccurate or incomplete personal data.

Right to Erasure Art. 17

You may request deletion of your personal data where there is no overriding legal basis for continued processing. Note that certain data (e.g. billing records) must be retained to meet legal obligations.

Right to Data Portability Art. 20

You may request your account data in a structured, machine-readable format (JSON or CSV).

Right to Restriction Art. 18

You may request that processing of your data be restricted while a complaint or accuracy dispute is being resolved.

Right to Object Art. 21

You may object to processing carried out under legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to Lodge a Complaint

If you believe your rights have not been respected, you have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): www.dsb.gv.at.

5. Sub-Processors

Global Search uses the following sub-processors. We maintain Data Processing Agreements with all of them and conduct due diligence on their GDPR compliance status.

Sub-processorRoleLocation
Stripe Payment processing. Processes billing name, card details (tokenised), transaction records. Full cardholder data never reaches our servers. EU data residency (Ireland)
EU-based infrastructure provider Cloud hosting and compute. Server infrastructure on which the platform runs. EU/EEA

No tracking or marketing SDKs: We do not load Google Analytics, Meta Pixel, HubSpot, Segment, Intercom, or any similar third-party marketing or analytics tools on our platform. There are no third-party cookies. No client behaviour data is shared with advertising networks.

6. International Data Transfers

All personal data processed by Global Search is stored and processed within the EU/EEA. We do not transfer personal data to third countries (outside the EU/EEA) as a matter of ordinary operation.

In the event that a future business requirement necessitates a third-country transfer (for example, engaging a sub-processor headquartered outside the EEA), we will implement appropriate safeguards in advance — specifically Standard Contractual Clauses (SCCs) as approved by the European Commission, supplemented by a Transfer Impact Assessment where required.

Stripe's EU data residency option is selected, ensuring payment data remains within the EEA.

7. Security Measures

Global Search implements the following technical and organisational measures (TOMs) to protect personal data:

Encryption

Access Controls

Monitoring and Audit Logs

Incident Response

8. Legal Basis for Processing

We rely on the following legal bases under GDPR Article 6:

9. Contact and DPO

For privacy-related enquiries, data subject rights requests, or to discuss a Data Processing Agreement:

Request a DPA