Data Privacy
Your data, your control. GLBNXT is committed to protecting personal and organizational data in full compliance with the General Data Protection Regulation (GDPR) and applicable EU data protection laws.
Privacy Principles
We operate under core principles of data minimization, purpose limitation, transparency, and security by design. This means we collect only the data necessary to deliver our services, process it exclusively for specified legitimate purposes, communicate clearly about how we handle your data, and build privacy and security into our platform architecture from the ground up.
Data Ownership & Control
You retain full ownership of all data and model outputs created on our platform. GLBNXT acts solely as a data processor under GDPR when handling customer data, which means we process your data only according to your instructions and never for our own purposes.We provide you with complete control over what data is processed through the platform, which AI models access your data, how long data is retained, and the ability to export or delete your data at any time.
Data Processing
GLBNXT processes customer data exclusively for platform operation and service delivery, technical support and troubleshooting, system monitoring and security, and service improvement using only aggregated, anonymized data. We do not use customer data to train or fine-tune AI models, sell or monetize customer data, process data for marketing purposes without explicit consent, or share data with third parties except as detailed in this policy and our comprehensive Privacy Policy.
Data Residency & International Transfers
Sovereign Deployments: All data in sovereign deployments is hosted and processed exclusively within the European Union, specifically in GLBNXT-managed infrastructure in the Netherlands.
Standard Deployments: Customer data remains within the EU unless explicitly agreed otherwise. When customers request access to non-EU AI models such as certain OpenAI or Anthropic services, data transfers are governed by Standard Contractual Clauses approved by the European Commission, Data Processing Agreements with adequate safeguards, and explicit customer authorization for each external model provider.
Customers have full geographic control and can restrict all data processing to EU-only models and infrastructure, specific EU member states, or private self-hosted models with no external data transfer whatsoever.
Data Subject Rights
GLBNXT supports the full range of GDPR data subject rights. You have the right to access copies of your personal data, rectify inaccurate information, request erasure of your data (subject to legal exceptions), restrict how we process your data, receive your data in a portable machine-readable format, object to specific processing activities, and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated.
Data subject rights requests can be submitted to contact@glbnxt.com and are processed within 30 days as required by GDPR. For organizational customers, we provide tools within the platform to facilitate end-user rights management and help you meet your own obligations as a data controller.
Data Retention
We retain customer data only for the duration necessary to deliver our services. Active customer data is retained for the duration of the service agreement, backups are kept for 14 days for disaster recovery purposes, and audit logs are maintained for 90 days for security and compliance. Upon receiving a deletion request, we purge data from all systems including backups within 30 days. When a contract terminates, all customer data is deleted within 30 days unless longer retention is required by law (such as tax legislation requiring 7-year retention) or explicitly requested by the customer for transition purposes.
Third-Party Data Sharing
GLBNXT shares customer data only in limited, clearly defined circumstances. We work with carefully vetted EU-based sub-processors for infrastructure and platform operations, with a current list maintained at [link to sub-processors page]. When customers explicitly request external AI model providers such as OpenAI, Anthropic, or Mistral, we share data only under contractual prohibitions against using that data for training purposes. We may also share data when required by EU law or valid legal process, and will notify customers unless prohibited by law. We never sell customer data to third parties under any circumstances.
Data Processing Agreement
GLBNXT provides a comprehensive Data Processing Agreement (DPA) that includes detailed processing terms and purposes, our sub-processor list and notification procedures, security measures and audit rights, data breach notification procedures, and Standard Contractual Clauses for any international transfers. Our DPA is available for review and execution with all enterprise customers upon request.
Security Incidents & Breach Notification
In the event of a personal data breach, GLBNXT will notify affected customers within 72 hours of becoming aware of the incident. We provide detailed information about the nature and scope of the breach, describe measures taken to address it, and assist customers in meeting their own notification obligations to supervisory authorities and data subjects where required.