GlobalGov Inc. ("GlobalGov," "we," "us," or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect information in connection with the GlobalGov platform and website (collectively, the "Service"). It also describes your rights under applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.
1. Data Controller
The data controller responsible for your personal data is:
GlobalGov Inc.
Tampa, Florida, United States
privacy@globalgov.io
For users in the European Economic Area (EEA) or United Kingdom, GlobalGov maintains an EU/UK representative. EU data subjects may contact our representative by emailing eu-rep@globalgov.io. Our Data Protection Officer may be reached at dpo@globalgov.io.
2. Data We Collect
We collect the following categories of personal data:
Account data: When you register, we collect your name, work email address, job title, company name, country, and password (stored as a salted hash). If you accept an invitation from a team administrator, we receive the email address the invitation was sent to.
Usage data: We automatically collect information about how you interact with the Service, including pages viewed, features used, search queries submitted, timestamps, IP address, browser type, operating system, and referral URLs. We use PostHog, a product analytics service, to collect these usage events and to record session replays of platform use in which all form inputs are masked, including email address fields. PostHog is loaded only after you accept analytics through our consent banner.
Pipeline and opportunity data: Content you voluntarily enter into the platform, such as opportunity tracking notes, bid/no-bid assessments, teaming contacts, capture plan details, and imported procurement records.
Payment information: Billing details are collected and processed directly by our payment processor, Stripe. GlobalGov does not store full credit card numbers, CVV codes, or other sensitive cardholder data. We retain only the last four digits of card numbers and billing address for record-keeping.
Translation requests: Documents and text you submit for translation within the platform. Depending on the source language and content type, this content is transmitted to one or more of our translation providers, Anthropic (Claude), DeepL, and Google Cloud Translation, which process it on our behalf to return the translation.
Search history: Records of procurement searches performed within the platform, used to power saved searches, alerts, and personalized recommendations.
Communications: Emails, support requests, and other correspondence you send to us.
3. Legal Basis for Processing (GDPR Article 6)
For users in the EEA and UK, we process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you have subscribed to, including account management, platform functionality, and customer support.
- Legitimate interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, such as fraud prevention, platform security, usage analytics for product improvement, and direct marketing of related services to existing customers, where these interests are not overridden by your rights.
- Consent (Art. 6(1)(a)): Where we rely on your consent, such as for certain marketing communications or optional cookies, you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, such as financial record-keeping and responding to lawful requests from public authorities.
4. How We Use Your Data
We use the data we collect to:
- Provide, operate, maintain, and improve the Service.
- Process transactions and manage your subscription through our payment processor.
- Send transactional emails (account confirmations, billing receipts, security alerts) and, where permitted, product updates and marketing communications.
- Respond to your support requests, questions, and feedback.
- Monitor platform security, detect fraud, and enforce our Terms of Service.
- Conduct aggregate analytics to understand usage patterns and improve platform features.
- Comply with applicable legal obligations and respond to lawful governmental or regulatory requests.
5. Data Sharing and Disclosure
We do not sell your personal data. Ever. We do not share your data with advertising networks or data brokers. We share data only in the following limited circumstances:
- Stripe: Our payment processor handles billing transactions. Stripe's privacy policy is available at stripe.com/privacy. Stripe processes payment data as an independent data controller.
- Postmark: Our transactional email provider delivers account-related emails on our behalf. Postmark receives recipient email addresses and email content necessary for delivery.
- Translation providers (Anthropic, DeepL, Google): Translation features send the content to be translated to Anthropic's Claude API, DeepL, or Google Cloud Translation, which process it on our behalf to return the translation.
- PostHog: Our product analytics provider processes usage data, including the usage events and session replays described in Section 2, to help us understand and improve how the Service is used.
- Cloud infrastructure providers: We host the Service on cloud infrastructure, currently provided by Vultr, for hosting, storage, and computing. These providers process data on our behalf.
- Legal compliance: We may disclose data where required by law, subpoena, court order, or other legal process, or to protect the rights, property, or safety of GlobalGov, our users, or others.
- Business transfers: In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred to the successor entity. We will notify you in advance and provide opt-out rights where required by law.
6. International Data Transfers
GlobalGov is headquartered in the United States. If you access the Service from the EEA, UK, or other regions with data protection laws that differ from those in the U.S., your personal data may be transferred to and processed in the United States.
For transfers of personal data from the EEA and UK to the United States or other third countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the lawful transfer mechanism. Copies of the applicable SCCs are available on request by contacting privacy@globalgov.io. We also maintain a Data Processing Agreement (DPA) for enterprise customers. See our GDPR Information page for details.
7. Data Retention
- Active subscriptions: We retain your personal data for as long as your account remains active or as needed to provide the Service.
- Post-deletion: Upon account deletion, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
- Legal and financial records: Certain transaction records and financial data may be retained for up to 7 years to comply with tax, accounting, and legal obligations.
- Aggregated data: We may retain anonymized, aggregated usage data indefinitely for analytical purposes.
8. Your Rights Under GDPR (Articles 15–22)
If you are located in the EEA or UK, you have the following rights with respect to your personal data. To exercise any of these rights, please submit a request to privacy@globalgov.io. We will respond within 30 days. We may need to verify your identity before processing your request.
- Right of access (Art. 15): You have the right to request a copy of the personal data we hold about you and information about how we process it.
- Right to rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to erasure / "right to be forgotten" (Art. 17): You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent, subject to legal retention requirements.
- Right to data portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller where technically feasible.
- Right to restriction of processing (Art. 18): You have the right to request that we restrict processing of your data in certain circumstances, such as while you contest its accuracy.
- Right to object (Art. 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds.
- Rights related to automated decision-making (Art. 22): We do not make fully automated decisions that produce significant legal effects. AI-assisted features are informational tools, with final decisions always made by you.
You also have the right to lodge a complaint with your local supervisory authority. In the EU, this is your national data protection authority. In the UK, this is the Information Commissioner's Office (ICO).
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and its amendment, the CPRA:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which it is used, and the categories of third parties with whom it is shared.
- Right to delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to opt out of sale or sharing: We do not sell personal information and do not share personal information for cross-context behavioral advertising. This right therefore does not apply, but you may still submit a request if you have concerns.
- Right to correct: You may request correction of inaccurate personal information.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, or provide a different level of service based on your exercise of these rights.
To submit a CCPA rights request, please email privacy@globalgov.io with the subject line "California Privacy Rights Request."
10. Children's Privacy
GlobalGov is a professional B2B platform and is not directed to individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will promptly delete it. If you believe we may have collected such data, please contact us at privacy@globalgov.io.
11. Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, loss, alteration, or disclosure. These include TLS 1.3 encryption in transit, AES-256 encryption at rest, JWT-based authentication with short-lived tokens, role-based access controls, and regular security testing. For a detailed overview, see our Security page.
No transmission of data over the internet or storage system can be guaranteed to be 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately at security@globalgov.io.
12. Cookies
We use cookies and similar technologies, including browser local storage, for authentication, security, remembering your preferences, and the product analytics described in Section 2. A consent banner lets you accept or decline non-essential cookies, and analytics tools are not loaded unless you accept. We also honor the Global Privacy Control (GPC) browser signal and treat it as a decline for analytics. Please see our Cookie Policy for detailed information about the technologies we use and how to manage them.
13. GlobalGov API & MCP Connector
When you connect via our API or an MCP connector (e.g. from Claude, ChatGPT, or another AI assistant): the connector only queries GlobalGov's own database of government procurement information and does not access, read, or store any data or files from your device or your AI assistant.
You authenticate with a GlobalGov API key tied to your paid account; we store it securely and use it only to authenticate requests and enforce your plan's limits.
We log request metadata (endpoint, timestamp, parameters, response size) to operate the service, enforce rate limits, bill usage, and prevent abuse, retained for 12 months.
If you connect through a third-party AI assistant, that provider handles your data under their own privacy terms; GlobalGov only receives the queries your assistant sends.
We do not sell your API usage data.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or by prominent notice within the platform at least 30 days before the changes take effect. The "last updated" date at the top of this page indicates when the policy was last revised.
15. Contact Us
For privacy-related questions, to exercise your rights, or to contact our DPO:
Email:privacy@globalgov.io
DPO:dpo@globalgov.io
EU Representative:eu-rep@globalgov.io
We aim to respond to all inquiries within 30 days. For complex requests, we may extend this period by an additional 60 days and will notify you accordingly.