Data Protection
Data Protection
Global Watch is committed to protecting your privacy and ensuring compliance with global data protection regulations. This document outlines our data protection practices, your rights, and how we handle personal data.
Privacy Principles
Global Watch adheres to core privacy principles:
Data Minimization
We collect only the data necessary for providing our services:
- Essential Data: Information required for account functionality
- Optional Data: Additional data you choose to provide
- No Unnecessary Collection: We don't collect data we don't need
Purpose Limitation
Data is used only for specified purposes:
- Service Delivery: Providing forest management features
- Account Management: Managing your account and subscription
- Communication: Sending necessary notifications
- Improvement: Enhancing our services (with consent)
Transparency
We're transparent about our data practices:
- Clear Policies: Easy-to-understand privacy documentation
- Data Access: You can view all data we hold about you
- Change Notification: We notify you of policy changes
GDPR Compliance
Global Watch complies with the EU General Data Protection Regulation (GDPR).
Legal Basis for Processing
We process personal data under these legal bases:
| Legal Basis | Use Case |
|---|---|
| Contract | Providing services you've subscribed to |
| Legitimate Interest | Security, fraud prevention, service improvement |
| Consent | Marketing communications, analytics |
| Legal Obligation | Tax records, legal compliance |
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Request correction of inaccurate personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Portability
Receive your data in a machine-readable format.
Right to Object
Object to processing based on legitimate interests.
Right to Restrict
Request limitation of processing in certain circumstances.
Exercising Your Rights
To exercise your data protection rights:
- In-App: Navigate to Settings → Privacy → Data Rights
- Email: Contact privacy@global.watch
- Response Time: Within 30 days (as required by GDPR)
LGPD Compliance
Global Watch also complies with Brazil's Lei Geral de Proteção de Dados (LGPD).
LGPD Rights
Brazilian users have additional rights under LGPD:
- Confirmation: Confirm whether we process your data
- Access: Access your personal data
- Correction: Correct incomplete or inaccurate data
- Anonymization: Request anonymization of unnecessary data
- Portability: Transfer data to another service provider
- Deletion: Delete data processed with consent
- Information: Know about sharing with third parties
- Revocation: Revoke consent at any time
PDPL Compliance (UAE)
Global Watch complies with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
PDPL Rights
UAE users have the following rights:
- Access: Request access to personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of data
- Restriction: Limit processing in certain cases
- Portability: Receive data in machine-readable format
- Object: Object to processing based on legitimate interests
Response Time SLA
| Regulation | Required Response | Our SLA |
|---|---|---|
| GDPR | 1 month (extendable to 3) | 15 days |
| LGPD | 15 days | 15 days |
| PDPL | 30 days (extendable to 60) | 15 days |
Global Watch responds to all data subject requests within 15 days, meeting the strictest regulatory requirement.
Data We Collect
Account Data
Information provided during registration:
| Data Type | Purpose | Retention |
|---|---|---|
| Email address | Account identification, communication | Account lifetime |
| Name | Personalization, identification | Account lifetime |
| Password (hashed) | Authentication | Account lifetime |
| Profile photo | Personalization | Until removed |
Usage Data
Information collected during service use:
| Data Type | Purpose | Retention |
|---|---|---|
| Login history | Security, audit | 90 days |
| Feature usage | Service improvement | Aggregated only |
| Error logs | Debugging, support | 30 days |
| API requests | Rate limiting, billing | 90 days |
Project Data
Information you create in Global Watch:
| Data Type | Purpose | Retention |
|---|---|---|
| Project details | Service functionality | Until deleted |
| Geospatial data | Map features, area calculation | Until deleted |
| Asset information | Asset tracking | Until deleted |
| Documents | Document management | Until deleted |
Technical Data
Automatically collected technical information:
| Data Type | Purpose | Retention |
|---|---|---|
| IP address | Security, geolocation | 30 days |
| Browser type | Compatibility, debugging | 30 days |
| Device information | Mobile app functionality | 30 days |
| Cookies | Session management, preferences | Varies |
Data Processing
Sub-Processors
We use trusted sub-processors for specific functions:
| Provider | Purpose | Location | DPA |
|---|---|---|---|
| Cloud Provider | Infrastructure hosting | US/EU | ✅ |
| Email Service | Transactional emails | US | ✅ |
| Payment Processor | Billing and payments | US | ✅ |
| Analytics | Usage analytics | EU | ✅ |
All sub-processors are bound by Data Processing Agreements (DPAs) that ensure GDPR-compliant data handling.
International Transfers
When data is transferred outside the EU/EEA:
- Standard Contractual Clauses: EU-approved transfer mechanisms
- Adequacy Decisions: Transfers to countries with adequate protection
- Supplementary Measures: Additional safeguards where required
Data Security
Technical Measures
Security measures protecting your data:
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Access Control: Role-based access, principle of least privilege
- Monitoring: 24/7 security monitoring and alerting
- Backups: Encrypted backups with tested recovery
Organizational Measures
Policies and procedures for data protection:
- Training: Regular privacy and security training
- Access Reviews: Periodic access permission reviews
- Incident Response: Documented breach response procedures
- Vendor Management: Due diligence on all vendors
Data Retention
Retention Periods
Data is retained only as long as necessary:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Account lifetime + 30 days | Contract |
| Project data | Until deleted by user | Contract |
| Audit logs | 2 years | Legitimate interest |
| Billing records | 7 years | Legal obligation |
| Support tickets | 3 years | Legitimate interest |
Data Deletion
When you delete your account:
- Immediate: Account access revoked
- 30 Days: Personal data deleted from active systems
- 90 Days: Data removed from backups
- Retained: Anonymized data for analytics, legal records
Cookies & Tracking
Cookie Types
Global Watch uses the following cookies:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security | Session |
| Functional | Preferences, settings | 1 year |
| Analytics | Usage statistics (with consent) | 1 year |
Cookie Management
You can manage cookies through:
- Browser Settings: Block or delete cookies
- Cookie Banner: Accept or reject non-essential cookies
- Account Settings: Manage tracking preferences
Do Not Track
Global Watch respects Do Not Track (DNT) browser signals.
Children's Privacy
Global Watch is not intended for children under 16:
- Age Requirement: Users must be 16 or older
- No Intentional Collection: We don't knowingly collect children's data
- Deletion: Children's data will be deleted upon discovery
Privacy by Design
Global Watch implements privacy by design principles:
Default Privacy
- Minimal Collection: Only essential data collected by default
- Private by Default: New projects are private by default
- Opt-In Features: Optional features require explicit consent
Privacy Features
Built-in privacy controls:
- Data Export: Export all your data anytime
- Account Deletion: Self-service account deletion
- Consent Management: Granular consent controls
- Activity Visibility: Control who sees your activity
Data Breach Notification
In the event of a data breach:
Notification Timeline
| Recipient | Timeline | Method |
|---|---|---|
| Supervisory Authority | Within 72 hours | Official notification |
| Affected Users | Without undue delay | Email notification |
| Public | If required | Website notice |
Breach Response
Our breach response includes:
- Containment: Immediate threat containment
- Assessment: Impact and scope evaluation
- Notification: Timely stakeholder notification
- Remediation: Addressing the root cause
- Review: Post-incident improvement
Contact Information
Data Protection Officer
For privacy inquiries:
- Email: dpo@global.watch
- Response Time: Within 5 business days
Privacy Team
For general privacy questions:
- Email: privacy@global.watch
- In-App: Settings → Privacy → Contact
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
Policy Updates
This policy may be updated periodically:
- Notification: Email notification for material changes
- Review: We recommend reviewing this policy regularly
- Effective Date: Changes effective 30 days after notification
Last Updated: January 2025
Related Documentation
- Security - Security measures and practices
- Audit Logs - Activity tracking and reporting