For legal teams, procurement officers, and compliance departments evaluating Global Search for enterprise use.
Summary for busy compliance teams: Global Search is registered in Austria and fully subject to the GDPR. We sign Data Processing Agreements for enterprise clients. All processing occurs within the EU/EEA. We retain client query logs for 90 days then delete them. DPA requests: [email protected].
Global Search is a data intelligence platform registered and operating in Austria, a member state of the European Union. As such, we are directly subject to Regulation (EU) 2016/679 (the General Data Protection Regulation) and the Austrian Datenschutzgesetz (DSG).
Our platform serves B2B clients — law firms, corporate compliance teams, financial institutions, and licensed investigators. The platform aggregates information from public records and licensed data sources. When enterprise clients use Global Search, two separate data processing relationships apply:
We do not sell client data to third parties. We do not use client query content for advertising or profiling.
Global Search offers a fully executed Data Processing Agreement to enterprise clients. The DPA covers:
To request a DPA, contact us at [email protected]. We typically return a countersigned DPA within 5 business days.
The following categories of personal data are processed in connection with operating client accounts:
| Data category | Purpose | Retention |
|---|---|---|
| Account data Name, email, organisation |
Account creation, authentication, billing, and support communications | Duration of contract + 3 years for legal compliance |
| Query logs IP address, timestamp, query type (not result content) |
Abuse prevention, rate limiting, service integrity monitoring | 90 days, then automatically deleted |
| Billing records Transaction IDs, amounts, payment method type |
Invoicing, tax compliance, dispute resolution | 7 years (Austrian tax law requirement) |
| Support communications Email correspondence |
Customer support | 2 years from last interaction |
What we do not log: The content of search results returned to clients is not stored on our servers after delivery. Query logs record the type and timestamp of a query but not the results themselves.
Under the GDPR, individuals have the following rights with respect to their personal data processed by Global Search. Submit requests to [email protected]. We respond within 30 calendar days; complex requests may be extended by a further 60 days with notification.
You may request a copy of the personal data we hold about you and information about how it is processed.
You may request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data where there is no overriding legal basis for continued processing. Note that certain data (e.g. billing records) must be retained to meet legal obligations.
You may request your account data in a structured, machine-readable format (JSON or CSV).
You may request that processing of your data be restricted while a complaint or accuracy dispute is being resolved.
You may object to processing carried out under legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
If you believe your rights have not been respected, you have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde): www.dsb.gv.at.
Global Search uses the following sub-processors. We maintain Data Processing Agreements with all of them and conduct due diligence on their GDPR compliance status.
| Sub-processor | Role | Location |
|---|---|---|
| Stripe | Payment processing. Processes billing name, card details (tokenised), transaction records. Full cardholder data never reaches our servers. | EU data residency (Ireland) |
| EU-based infrastructure provider | Cloud hosting and compute. Server infrastructure on which the platform runs. | EU/EEA |
No tracking or marketing SDKs: We do not load Google Analytics, Meta Pixel, HubSpot, Segment, Intercom, or any similar third-party marketing or analytics tools on our platform. There are no third-party cookies. No client behaviour data is shared with advertising networks.
All personal data processed by Global Search is stored and processed within the EU/EEA. We do not transfer personal data to third countries (outside the EU/EEA) as a matter of ordinary operation.
In the event that a future business requirement necessitates a third-country transfer (for example, engaging a sub-processor headquartered outside the EEA), we will implement appropriate safeguards in advance — specifically Standard Contractual Clauses (SCCs) as approved by the European Commission, supplemented by a Transfer Impact Assessment where required.
Stripe's EU data residency option is selected, ensuring payment data remains within the EEA.
Global Search implements the following technical and organisational measures (TOMs) to protect personal data:
We rely on the following legal bases under GDPR Article 6:
For privacy-related enquiries, data subject rights requests, or to discuss a Data Processing Agreement: