Privacy
Privacy notice
Draft for counsel review · 31 August 2026
Data we expect to process
Business contact information, verified asset identifiers, authorization records, assessment configuration, security findings, remediation evidence, audit events, and support communications.
What we do not request
The commercial SaaS does not request wallet seed phrases, customer private keys, payment-card PINs, or production secrets. Credentials required for authenticated assessment must use a dedicated, least-privilege method defined in the written scope.
Purpose and legal basis
Data is used to provide authorized security services, protect the platform, document consent, support customers, meet contractual duties, and comply with law.
Retention and deletion
Evidence retention follows the customer plan and signed agreement. Account, legal, and security records may be retained longer where required for fraud prevention, dispute handling, or law.
Sharing
Data is shared only with approved service providers, professional advisers, authorities when legally required, and customer-authorized recipients. We do not sell security findings or customer contact data.
Security
Production uses encrypted transport, access controls, separation of duties, audit logging, monitored secrets, and documented incident response. No public claim promises absolute security.
Contact
Privacy requests: office@globalconnect.sbs.
A final notice must name subprocessors, international transfer safeguards, retention periods, controller details, and applicable privacy rights before launch.