Last updated: July 2026 · Effective date: July 1, 2026
1. Introduction & Who We Are
This Privacy Policy describes how Global Search (“we,” “us,” or “our”), an operator of the identity intelligence platform available at global-search.at, processes personal data in connection with the operation of this platform and our relationships with professional subscribers.
Global Search is established in Austria and operates as a business-to-business (B2B) service exclusively. Our platform is designed for and licensed only to verified professional users — including licensed private investigators, legal practitioners, corporate compliance officers, fraud analysts, and accredited journalists — who require access to aggregated identity data records in the lawful performance of their professional duties.
This policy governs our handling of data relating to our platform users (subscribers, account holders, and their authorized personnel). It does not govern the processing of data records held within our search index, which are subject to separate contractual and legal frameworks applicable to our professional subscribers.
We are committed to compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Austrian data protection law (Datenschutzgesetz, DSG).
2. What Data We Collect
2.1 Account and Registration Data
When you apply for or maintain a professional subscription to Global Search, we collect:
Full name and professional title
Business email address and, where provided, direct telephone number
Name and registered address of your employing organization or practice
Proof of professional accreditation or licensing submitted during onboarding verification
Account credentials (password stored as a salted cryptographic hash; we never store plaintext passwords)
2.2 Usage and Query Logs
To maintain platform integrity, detect abuse, fulfill audit obligations, and improve service reliability, we automatically record:
Search queries submitted (terms, field filters, timestamp)
Session identifiers and authentication events (login, logout, failed attempts)
IP address and user-agent string of the connecting client
API request logs including endpoint, response codes, and latency
Report generation and export events
Query log content is treated as confidential professional work product. We do not analyse query content for marketing or profiling purposes.
2.3 Billing and Payment Data
We collect invoicing information including billing contact name, business address, VAT identification number, and payment method details. Payment card data is processed exclusively by our payment service providers (see Section 5) and is not stored on our infrastructure.
2.4 Communications
If you contact us by email or via our support channels, we retain the content of that correspondence and associated metadata for the duration necessary to resolve your inquiry and for up to 12 months thereafter.
2.5 What We Do Not Collect
We do not collect personal data from the subjects of searches conducted on our platform. The data records available through our search index are compiled from licensed commercial data sources, lawfully published public records, and other sources that are contractually governed separately. Those data subjects are not our platform users and are addressed through a distinct legal and operational framework.
3. How We Use Your Data
We use the personal data described above for the following purposes:
Account provisioning and management — creating, authenticating, and maintaining your subscriber account
Service delivery — processing search queries, generating reports, and providing API access as contracted
Billing and invoicing — issuing invoices, processing payments, and maintaining financial records as required by Austrian commercial and tax law
Security and integrity monitoring — detecting unauthorized access, preventing abuse, enforcing our Terms of Service, and maintaining audit trails
Legal compliance — fulfilling obligations under Austrian law, GDPR, and applicable sector regulations; responding to lawful requests from competent authorities
Service communications — sending transactional notifications (account alerts, invoices, critical service updates); we do not send unsolicited marketing communications
Platform improvement — analysing aggregate, anonymized usage patterns to improve performance, reliability, and search quality
4. Legal Basis for Processing (GDPR Article 6)
Every processing activity we conduct rests on one of the following legal bases:
Performance of a contract (Art. 6(1)(b) GDPR) — processing your account, credentials, queries, and usage logs is necessary to deliver the platform services you have contracted for. This is the primary basis for operational processing.
Compliance with a legal obligation (Art. 6(1)(c) GDPR) — retention of invoices and financial records for seven years as required by the Austrian Unternehmensgesetzbuch (UGB) and tax regulations; responses to lawful authority requests.
Legitimate interests (Art. 6(1)(f) GDPR) — security monitoring, fraud and abuse prevention, audit log retention, and aggregate analytics. Our legitimate interests in operating a secure, high-integrity professional platform do not override the rights and freedoms of our professional subscribers, whose reasonable expectations include appropriate logging and audit functions.
Consent (Art. 6(1)(a) GDPR) — where we seek optional consents, for example for participation in product research or beta features, consent is recorded separately and may be withdrawn at any time without affecting your access to core services.
5. Data Sharing and Third Parties
We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
5.1 Service Providers (Data Processors)
We engage vetted third-party processors who act strictly under our documented instructions and are bound by data processing agreements conforming to GDPR Article 28:
Infrastructure and hosting — our servers and data storage infrastructure are operated within the European Union. We do not transfer operational data outside the EEA.
Payment processing — payment transactions are processed by our payment service provider(s) who are independently PCI-DSS compliant. They receive only the billing information necessary to process your payment.
Email delivery — transactional email (account notifications, invoices) is delivered via a third-party mail service operating under a DPA.
5.2 Legal Disclosures
We may disclose data to competent Austrian or EU authorities where we are subject to a binding legal obligation to do so, including court orders, regulatory demands, or obligations under anti-money-laundering legislation. Where permitted by law, we will notify you of such a disclosure.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, subscriber account data may be transferred to the successor entity, subject to equivalent privacy protections and notification to affected subscribers in advance.
6. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected, subject to the following schedules:
Account data — retained for the duration of your active subscription, plus 30 days following closure or termination of your account to allow for reinstatement requests. Thereafter, account records are permanently deleted or anonymized.
Usage and query logs — retained for 90 days from the date of recording, after which logs are purged. Anonymized aggregate statistics derived from logs may be retained indefinitely.
Billing records and invoices — retained for seven years from the end of the fiscal year in which the transaction occurred, as required by Austrian UGB and tax law.
Support correspondence — retained for up to 12 months after the inquiry is closed, unless a longer retention is required for an unresolved dispute.
Security incident records — retained for up to 3 years where relevant to ongoing investigations or legal proceedings.
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights with respect to your personal data processed by Global Search:
Right of access (Art. 15) — you may request a copy of the personal data we hold about you and information about how it is processed.
Right to rectification (Art. 16) — you may request correction of inaccurate or incomplete personal data.
Right to erasure (Art. 17) — you may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to our overriding legal retention obligations.
Right to restriction of processing (Art. 18) — you may request that we limit the processing of your data in specified circumstances, for example while a rectification request is under review.
Right to data portability (Art. 20) — where processing is based on contract or consent and carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21) — you may object to processing based on our legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent (Art. 7(3)) — where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) at www.dsb.gv.at, or with the supervisory authority in your EU member state of habitual residence.
8. Cookies and Session Technology
The Global Search platform uses only strictly necessary session cookies to maintain your authenticated session across page requests. These cookies are:
Created only upon successful login and destroyed upon logout or session expiry
Not used for tracking, behavioural profiling, advertising, or any purpose beyond session management
Not shared with third parties
Not persistent across browser sessions (they expire when you close your browser or when the session token expires server-side)
We do not use analytics cookies, advertising pixels, social media tracking scripts, or any third-party JavaScript that transmits data to external domains. We do not operate a cookie consent banner because we deploy no non-essential cookies that would require one.
9. Security Measures
We implement technical and organizational measures appropriate to the risk profile of a professional identity intelligence platform, including:
All data in transit encrypted via TLS 1.2 or higher; internal service-to-service traffic encrypted where technically feasible
Data at rest encrypted on server infrastructure
Access to production systems restricted to authorized personnel via SSH key authentication and VPN; password-based login disabled on production hosts
Role-based access control ensuring personnel access only the data required for their function
Automated intrusion detection and IP-based rate limiting on authentication endpoints
Regular review of access logs and security alerts
Subscriber passwords stored only as salted bcrypt hashes; we cannot recover plaintext passwords
Incident response procedures including subscriber notification within 72 hours of discovery of a personal data breach that poses a risk to subscriber rights, consistent with GDPR Article 33
No security measure is unconditionally infallible. We encourage subscribers to use strong unique passwords and to report any suspected unauthorized account activity to [email protected] immediately.
10. Contact & Data Protection
For all privacy-related inquiries, requests to exercise your data subject rights, or questions about this policy, please contact:
We aim to acknowledge all privacy inquiries within 5 business days and provide a substantive response within 30 calendar days. For complex requests, we may extend this period by up to 60 additional days, in which case we will notify you of the extension and the reason for it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our processing practices, applicable law, or platform features. When we make material changes, we will notify active subscribers by email at least 14 days before the changes take effect, and will update the “Last updated” date at the top of this document. Your continued use of the platform after the effective date constitutes acceptance of the revised policy. If you do not accept the changes, you may close your account before they take effect.