本法律文件以英文为准,以下为英文原文(详见文末语言条款)。如需协助或翻译,请联系 privacy@globalepr.ai。
Effective date: 30 July 2026 · Version 1.0
Global Agentic Holdings Limited ("globalEPR™", "we"), Rm 604-5, 6/F., Easey Comm Building, 253-261 Hennessy Road, Wan Chai, Hong Kong (BR No. 80741226), operates the globalEPR.ai website and platform (the "Service"). We are the data controller unless stated otherwise in Section 8. Contact: privacy@globalepr.ai.
EU Representative (Art. 27 GDPR): Pursuant to Article 27 of Regulation (EU) 2016/679 (GDPR), we have designated the following representative in the European Union for matters relating to the processing of personal data of EEA data subjects:
U. Eggers Minervum 7162A 4817 ZN Breda The Netherlands Email: eu-rep@globalepr.ai · Tel: +31 76 579 4260
Data subjects and supervisory authorities may contact our EU representative directly on all matters relating to processing. Our EU representative is mandated in writing and authorised to be addressed in addition to or instead of us by supervisory authorities and data subjects on all issues related to processing, for the purposes of ensuring compliance with the GDPR.
UK Representative (Art. 27 UK GDPR): We have not appointed a UK representative. We have assessed that we fall within the Article 27(2) UK GDPR exemption: our processing of UK residents' personal data is only occasional, is low-risk, and does not include large-scale processing of special categories of data or criminal-offence data. We keep this assessment under review and will appoint a UK representative if our processing changes.
| Purpose | Legal basis |
|---|---|
| Providing the Service, accounts, support | Contract (6(1)(b)) |
| Billing, invoicing, tax records | Contract + legal obligation (6(1)(b),(c)) |
| Security: authentication, 2FA, audit logs, anomaly detection, abuse prevention | Legitimate interests (6(1)(f)) |
| Product analytics (first-party, aggregate) | Legitimate interests (6(1)(f)) |
| Regulatory deadline alerts, digests, newsletter | Consent (6(1)(a)) — withdraw anytime |
| Transactional emails | Contract / legitimate interests |
| Free-tool lead capture | Consent |
| Legal compliance, defence of claims | Legal obligation / legitimate interests |
Some features use large-language-model providers to answer compliance questions and process documents. We do not permit providers to use your data to train their models under our agreements. Do not include unnecessary personal data in AI prompts.
Provider:
We share personal data only with: (a) processors under data-processing agreements; (b) authorities where legally required; (c) a successor in a merger/asset transfer, under this Policy. We do not sell personal data and do not share it for third-party advertising.
Sub-processor list (kept current at globalepr.ai/legal/subprocessors):
| Sub-processor | Purpose | Data location | Transfer mechanism | Notes |
|---|---|---|---|---|
| Google Cloud Platform (Google LLC), engaged through our US-based managed hosting provider | Application hosting, database, backups | US | SCCs (Module 2) | Primary hosting |
| Cloudflare | CDN, DNS, DDoS protection and Turnstile anti-abuse checks | Global edge network | SCCs (Module 2) for non-EEA edge nodes | Turnstile receives technical and interaction data needed to distinguish humans from automated traffic |
| Stripe | Payments, billing | US | SCCs (Module 2) | Card data never touches our servers |
| SiteGround | Transactional email delivery, business mailboxes | EU (Spain) | No transfer — EU-based | |
| Anthropic | AI features (compliance assistant, document analysis) | US (US API region) | SCCs (2021, Module 2) as incorporated in Anthropic's Data Processing Addendum; TIA on file | No model training on our data |
New sub-processors: 30 days' notice via the sub-processor page + account email, with an objection right per the DPA.
We are established in Hong Kong; primary hosting runs on Google Cloud infrastructure, engaged through our US-based managed hosting provider. Where personal data is transferred outside the EEA/UK (including to the US and Hong Kong), we rely on the EU Standard Contractual Clauses (2021) and UK IDTA/Addendum, supplemented by transfer impact assessments. Copies of relevant safeguards: privacy@globalepr.ai.
China: no sub-processor in mainland China processes personal data. Transfer Impact Assessments covering the Anthropic (US) sub-processor flow and our Hong Kong establishment (TIA-001) are maintained on file and available on request.
Where you upload personal data of third parties as part of your compliance records, you are the controller; we process it on your behalf under the Data Processing Addendum (Part 3), solely to provide the Service.
Subject to applicable law (GDPR/UK GDPR; PDPO in Hong Kong), you may request access, rectification, erasure, restriction, portability, and object to legitimate-interest processing; consent may be withdrawn at any time. Contact privacy@globalepr.ai or our EU representative (§1). You may lodge a complaint with a supervisory authority — in the EU, with the authority of your habitual residence, place of work, or the place of the alleged infringement. Our lead contact point in the EU is the supervisory authority of the member state where our Art. 27 representative is established: Autoriteit Persoonsgegevens (Dutch Data Protection Authority), autoriteitpersoonsgegevens.nl. In the UK: the Information Commissioner's Office (ICO), ico.org.uk. In Hong Kong: the Privacy Commissioner for Personal Data (PCPD), pcpd.org.hk.
The Service uses AI models to organise data, answer questions, generate documents and estimate fees. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. All Service outputs (obligation checks, fee estimates, generated documents, recommendations) are informational aids that you review and act on at your discretion; no output results in an automatic denial of service, automatic contract change, or automatic report to any authority. Anti-abuse systems (CAPTCHA, anti-abuse cookies, rate limits) may automatically restrict access to free public tools to prevent automated abuse; this affects tool access only, not any legal position, and you can contact support@globalepr.ai for human review of any restriction. Should we ever introduce processing within the scope of Art. 22, we will update this Policy first and provide the required information about the logic, significance and consequences, and your right to human intervention.
We do not use third-party advertising or analytics cookies, and we do not use device fingerprinting for advertising. The first-party cookies below are either strictly necessary for the Service or serve first-party anti-abuse and attribution purposes based on our legitimate interests. Public forms also load Cloudflare Turnstile, which may use strictly necessary browser storage or cookies to perform an anti-abuse check; it is not used by us for advertising. You can delete or block cookies in your browser settings, although blocking necessary storage may prevent login or form submission.
| Name | Category | Purpose | Duration | Consent |
|---|---|---|---|---|
| PPWRSESSID | Necessary | Login session and security (CSRF protection is bound to this session) | Session | No |
| gepr_tools_sid | Anti-abuse | Anonymous session id for the free public tools (rate limiting, abuse prevention) | 30 days | No — legitimate interests |
| gepr_tools_uid / gepr_tools_verified | Necessary | Remembers your verified free-tools identity after a magic-link sign-in | 30 days | No |
| ppwr_utm | Attribution | Records which campaign link brought you to the site (set only when you arrive via such a link) | 30 days | No — legitimate interests |
Encryption in transit and at rest for secrets; 2FA for administrative access; role-based access; re-authentication for sensitive actions; session controls; audit logging and anomaly alerting; server-side enforcement of document watermarking and tier limits. No system is 100% secure; report issues to support@globalepr.ai.
Breach notification: for breaches creating risk to rights and freedoms, we notify the relevant supervisory authority without undue delay (within 72 hours where GDPR Art. 33 requires) and affected customers without undue delay, describing nature, likely consequences, and measures. Under the PDPO, notification follows the "real risk of significant harm" standard. Carried into the DPA §4(e).
The Service is for businesses and not directed to children under 16; we do not knowingly collect their data.
Updates posted here; material changes notified to account holders by email. Continued use after the effective date is acceptance.
We have carried out a Data Protection Impact Assessment covering our AI-assisted processing of compliance data, security/anti-abuse processing, and cross-border transfer flows. The DPIA is reviewed on material product changes and at least annually. A summary is available to our EU representative and, on request, to the competent supervisory authority.
We maintain a Record of Processing Activities documenting all processing we carry out as controller and processor. It is made available to supervisory authorities on request per Art. 30(4) GDPR and forms Schedule 1 to our EU representative's mandate agreement. A Data Protection Officer has not been appointed; a threshold assessment under Art. 37 GDPR is on file and identified no mandatory appointment trigger.