Skip to main content

Privacy Policy

Last updated: 28 July 2026

Controller

Evgen Bodunov, an individual entrepreneur registered in Poland and operating the Globus service, is the controller of personal data described in this Privacy Policy ("Globus", "we", "us").

For privacy questions or requests, contact [email protected].

Globus is a business-to-business service. This Policy primarily applies to people who create or use an account on behalf of a customer, visit our website, or communicate with us.

Data We Collect

Depending on how you use Globus, we collect:

  • Account data: email address, authentication data, account status, and account identifiers.
  • Customer and billing data: organization name, billing name and address, country, tax identifiers, and invoice details.
  • Application and usage data: registered applications, application identifiers, API and SDK usage counts, applicable pricing tiers, and related billing records.
  • Technical and security data: IP address, request time, device and browser information, SDK or API version, diagnostic events, security events, and service logs.
  • Payment metadata: Stripe customer and payment identifiers, payment status, and transaction references. Full card details are provided directly to Stripe and are not received or stored by us.
  • Communications: messages, support requests, billing questions, and other information you send to us.
  • Website analytics: interaction and device data collected through PostHog to understand website performance and usage.

How We Use Personal Data

We use personal data to:

  • create and administer accounts and registered applications;
  • provide APIs, SDK access, documentation, support, and security;
  • measure usage, apply free allowances and pricing tiers, issue invoices, and process payments;
  • detect abuse, investigate incidents, and protect accounts and infrastructure;
  • communicate about the Services, including operational, billing, security, and legal notices;
  • comply with accounting, tax, and other legal obligations; and
  • understand and improve the website and Services.

Where the GDPR applies, we process personal data on the following bases:

  • Contract and pre-contractual steps: to create an account and provide, support, and bill for the Services.
  • Legal obligations: including tax, accounting, fraud-prevention, and lawful authority requirements.
  • Legitimate interests: to secure and operate the Services, prevent abuse, support customers, collect amounts due, and improve reliability and usability.
  • Consent: where we specifically request it for an optional activity. Consent may be withdrawn at any time without affecting earlier lawful processing.

Service Providers and Recipients

We disclose personal data only where necessary to operate the business or comply with law. Recipients may include:

  • infrastructure, hosting, database, authentication, monitoring, and support providers;
  • Stripe and related payment and invoicing providers;
  • PostHog for website analytics;
  • professional advisers, including accountants, tax advisers, and legal advisers; and
  • public authorities where disclosure is legally required.

These providers may process data only for the relevant service and under applicable contractual and legal safeguards.

International Transfers

Some service providers may process data outside the European Economic Area. Where required, we use an adequacy decision, standard contractual clauses, or another lawful transfer mechanism.

Retention

We retain personal data only for as long as needed for the purposes described above:

  • account and application data is generally retained while the account is active and for a reasonable period after closure;
  • usage, invoice, payment, and tax records are retained for the periods required by applicable accounting and tax law;
  • technical and security logs are retained according to operational, diagnostic, and security needs; and
  • support communications are retained while needed to resolve the request and maintain an appropriate business record.

We may retain limited data for longer where necessary to establish, exercise, or defend legal claims, prevent fraud or abuse, or comply with law. Data is deleted or anonymized when it is no longer required.

Security

We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or loss. No internet service can guarantee absolute security. Customers are responsible for protecting their passwords, API keys, and account access.

Your Rights

Subject to applicable law, you may have the right to:

  • access and receive a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests;
  • receive data you provided in a portable format;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority, including the President of the Polish Personal Data Protection Office (UODO).

To exercise a right, contact [email protected]. We may need to verify your identity and authority to act for an account before completing a request.

Automated Decisions

We do not use personal data for solely automated decisions that produce legal or similarly significant effects on individuals.

Changes to This Policy

We may update this Privacy Policy to reflect changes in the Services, our providers, or applicable law. We will update the date above and provide additional notice where a change is material.