PRIVACY POLICY

Effective date: 30 July 2026 · Version 1.0

1. Who we are

Global Agentic Holdings Limited ("globalEPR™", "we"), Rm 604-5, 6/F., Easey Comm Building, 253-261 Hennessy Road, Wan Chai, Hong Kong (BR No. 80741226), operates the globalEPR.ai website and platform (the "Service"). We are the data controller unless stated otherwise in Section 8. Contact: privacy@globalepr.ai.

EU Representative (Art. 27 GDPR): Pursuant to Article 27 of Regulation (EU) 2016/679 (GDPR), we have designated the following representative in the European Union for matters relating to the processing of personal data of EEA data subjects:

U. Eggers Minervum 7162A 4817 ZN Breda The Netherlands Email: eu-rep@globalepr.ai · Tel: +31 76 579 4260

Data subjects and supervisory authorities may contact our EU representative directly on all matters relating to processing. Our EU representative is mandated in writing and authorised to be addressed in addition to or instead of us by supervisory authorities and data subjects on all issues related to processing, for the purposes of ensuring compliance with the GDPR.

UK Representative (Art. 27 UK GDPR): We have not appointed a UK representative. We have assessed that we fall within the Article 27(2) UK GDPR exemption: our processing of UK residents' personal data is only occasional, is low-risk, and does not include large-scale processing of special categories of data or criminal-offence data. We keep this assessment under review and will appoint a UK representative if our processing changes.

2. Data we collect

3. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Providing the Service, accounts, supportContract (6(1)(b))
Billing, invoicing, tax recordsContract + legal obligation (6(1)(b),(c))
Security: authentication, 2FA, audit logs, anomaly detection, abuse preventionLegitimate interests (6(1)(f))
Product analytics (first-party, aggregate)Legitimate interests (6(1)(f))
Regulatory deadline alerts, digests, newsletterConsent (6(1)(a)) — withdraw anytime
Transactional emailsContract / legitimate interests
Free-tool lead captureConsent
Legal compliance, defence of claimsLegal obligation / legitimate interests

4. AI features

Some features use large-language-model providers to answer compliance questions and process documents. We do not permit providers to use your data to train their models under our agreements. Do not include unnecessary personal data in AI prompts.

Provider:

5. Sharing

We share personal data only with: (a) processors under data-processing agreements; (b) authorities where legally required; (c) a successor in a merger/asset transfer, under this Policy. We do not sell personal data and do not share it for third-party advertising.

Sub-processor list (kept current at globalepr.ai/legal/subprocessors):

Sub-processorPurposeData locationTransfer mechanismNotes
Google Cloud Platform (Google LLC), engaged through our US-based managed hosting providerApplication hosting, database, backupsUSSCCs (Module 2)Primary hosting
CloudflareCDN, DNS, DDoS protection and Turnstile anti-abuse checksGlobal edge networkSCCs (Module 2) for non-EEA edge nodesTurnstile receives technical and interaction data needed to distinguish humans from automated traffic
StripePayments, billingUSSCCs (Module 2)Card data never touches our servers
SiteGroundTransactional email delivery, business mailboxesEU (Spain)No transfer — EU-based
AnthropicAI features (compliance assistant, document analysis)US (US API region)SCCs (2021, Module 2) as incorporated in Anthropic's Data Processing Addendum; TIA on fileNo model training on our data

New sub-processors: 30 days' notice via the sub-processor page + account email, with an objection right per the DPA.

6. International transfers

We are established in Hong Kong; primary hosting runs on Google Cloud infrastructure, engaged through our US-based managed hosting provider. Where personal data is transferred outside the EEA/UK (including to the US and Hong Kong), we rely on the EU Standard Contractual Clauses (2021) and UK IDTA/Addendum, supplemented by transfer impact assessments. Copies of relevant safeguards: privacy@globalepr.ai.

China: no sub-processor in mainland China processes personal data. Transfer Impact Assessments covering the Anthropic (US) sub-processor flow and our Hong Kong establishment (TIA-001) are maintained on file and available on request.

7. Retention

8. Your customers' data / controller-processor

Where you upload personal data of third parties as part of your compliance records, you are the controller; we process it on your behalf under the Data Processing Addendum (Part 3), solely to provide the Service.

9. Your rights

Subject to applicable law (GDPR/UK GDPR; PDPO in Hong Kong), you may request access, rectification, erasure, restriction, portability, and object to legitimate-interest processing; consent may be withdrawn at any time. Contact privacy@globalepr.ai or our EU representative (§1). You may lodge a complaint with a supervisory authority — in the EU, with the authority of your habitual residence, place of work, or the place of the alleged infringement. Our lead contact point in the EU is the supervisory authority of the member state where our Art. 27 representative is established: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), autoriteitpersoonsgegevens.nl. In the UK: the Information Commissioner's Office (ICO), ico.org.uk. In Hong Kong: the Privacy Commissioner for Personal Data (PCPD), pcpd.org.hk.

9A. Automated decision-making (Art. 22 GDPR)

The Service uses AI models to organise data, answer questions, generate documents and estimate fees. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. All Service outputs (obligation checks, fee estimates, generated documents, recommendations) are informational aids that you review and act on at your discretion; no output results in an automatic denial of service, automatic contract change, or automatic report to any authority. Anti-abuse systems (CAPTCHA, anti-abuse cookies, rate limits) may automatically restrict access to free public tools to prevent automated abuse; this affects tool access only, not any legal position, and you can contact support@globalepr.ai for human review of any restriction. Should we ever introduce processing within the scope of Art. 22, we will update this Policy first and provide the required information about the logic, significance and consequences, and your right to human intervention.

10. Cookies & similar technologies

We do not use third-party advertising or analytics cookies, and we do not use device fingerprinting for advertising. The first-party cookies below are either strictly necessary for the Service or serve first-party anti-abuse and attribution purposes based on our legitimate interests. Public forms also load Cloudflare Turnstile, which may use strictly necessary browser storage or cookies to perform an anti-abuse check; it is not used by us for advertising. You can delete or block cookies in your browser settings, although blocking necessary storage may prevent login or form submission.

NameCategoryPurposeDurationConsent
PPWRSESSIDNecessaryLogin session and security (CSRF protection is bound to this session)SessionNo
gepr_tools_sidAnti-abuseAnonymous session id for the free public tools (rate limiting, abuse prevention)30 daysNo — legitimate interests
gepr_tools_uid / gepr_tools_verifiedNecessaryRemembers your verified free-tools identity after a magic-link sign-in30 daysNo
ppwr_utmAttributionRecords which campaign link brought you to the site (set only when you arrive via such a link)30 daysNo — legitimate interests

11. Security

Encryption in transit and at rest for secrets; 2FA for administrative access; role-based access; re-authentication for sensitive actions; session controls; audit logging and anomaly alerting; server-side enforcement of document watermarking and tier limits. No system is 100% secure; report issues to support@globalepr.ai.

Breach notification: for breaches creating risk to rights and freedoms, we notify the relevant supervisory authority without undue delay (within 72 hours where GDPR Art. 33 requires) and affected customers without undue delay, describing nature, likely consequences, and measures. Under the PDPO, notification follows the "real risk of significant harm" standard. Carried into the DPA §4(e).

12. Children

The Service is for businesses and not directed to children under 16; we do not knowingly collect their data.

13. Changes

Updates posted here; material changes notified to account holders by email. Continued use after the effective date is acceptance.

14. Data Protection Impact Assessment (Art. 35 GDPR)

We have carried out a Data Protection Impact Assessment covering our AI-assisted processing of compliance data, security/anti-abuse processing, and cross-border transfer flows. The DPIA is reviewed on material product changes and at least annually. A summary is available to our EU representative and, on request, to the competent supervisory authority.

15. Record of Processing Activities (Art. 30 GDPR)

We maintain a Record of Processing Activities documenting all processing we carry out as controller and processor. It is made available to supervisory authorities on request per Art. 30(4) GDPR and forms Schedule 1 to our EU representative's mandate agreement. A Data Protection Officer has not been appointed; a threshold assessment under Art. 37 GDPR is on file and identified no mandatory appointment trigger.