CONFIDENTIALITY AND PROTECTION OF PERSONAL DATA
Confidential Information
Confidential information is defined as any information or data, whether in physical, electronic, or any other format, that GlobeToTravel.com (referred to as "GlobeToTravel," "we," or "us") provides to the CLIENT or that the CLIENT has access to, either with or without GlobeToTravel’s knowledge and/or express consent. Such confidential information includes, but is not limited to:
- Proprietary management software, computer system passwords, databases, prototypes, and user information
- Personal data such as email addresses, telephone numbers, or physical addresses
- Business strategies, financial data, development plans, and project information
- Any other supporting documents, data, or materials accessible via the GlobeToTravel website.
Non-Confidential Information
The following will not be considered confidential:
- Information that is publicly available or becomes public through no fault of the CLIENT
- Information disclosed by third parties that have no confidentiality obligation
- Information that must be disclosed by law, by court order, or to governmental bodies for tax or administrative purposes.
Non-Disclosure Agreement
The CLIENT agrees not to disclose any confidential information obtained during the course of the relationship with GlobeToTravel to third parties, whether individuals or organizations. The CLIENT also agrees to ensure that its employees, contractors, and other related parties comply with these confidentiality obligations. Any breach of this confidentiality obligation by the CLIENT or its affiliates will make the CLIENT fully liable for damages or legal claims.
The CLIENT’s confidentiality obligations remain in effect even after the termination of the business relationship with GlobeToTravel. Furthermore, any discoveries, innovations, or intellectual property that the CLIENT or its representatives may develop based on GlobeToTravel’s confidential information must be assigned to GlobeToTravel.
Breach of Confidentiality
In addition to compensating GlobeToTravel for specific damages resulting from a breach, any violation of the confidentiality clauses in this agreement will result in legal action and potential penalties.
Access to Personal Data
If GlobeToTravel requires access to personal data to provide its services, both parties agree to comply with the General Data Protection Regulation (GDPR) and all other applicable data protection laws. The CLIENT guarantees that it has obtained all necessary consents from data subjects (such as end consumers) for the transfer and processing of their personal data by GlobeToTravel.
All personal data collected and processed will be handled in strict compliance with the GDPR, ensuring that the rights of data subjects are fully protected. GlobeToTravel and the CLIENT agree to maintain confidentiality over all personal data, even after the termination of their contractual relationship.
GDPR Compliance
In compliance with GDPR, GlobeToTravel and the CLIENT commit to:
- Storing personal data with appropriate technical and organizational security measures to prevent unauthorized access, loss, alteration, or misuse.
- Using the data solely to fulfill the services requested and not for any other purpose.
- Limiting access to personal data to employees who need the data to perform their tasks, and ensuring that any third parties with access are bound by similar confidentiality agreements.
- Upon completion of the requested services, returning or securely deleting any personal data and ensuring no copies are retained.
Both parties are responsible for any breach of GDPR and agree to be liable for any claims, fines, or damages arising from such breaches.
Personal Data Transfers and Cross-Border Data Flows
In order to provide the services, GlobeToTravel may need to transfer personal data to third parties, including international travel service providers outside the European Economic Area (EEA). Where necessary, GlobeToTravel will implement Standard Contractual Clauses (SCCs) or other appropriate legal mechanisms to ensure the protection of personal data during cross-border transfers.
By using GlobeToTravel’s services, the CLIENT explicitly authorizes the transfer of personal data to service providers located in countries that may not have the same level of data protection as required by GDPR, but only to the extent necessary for the completion of travel bookings.
Rights of Data Subjects
Under GDPR, data subjects (such as end consumers) have the following rights:
- Right to Access: Individuals can request to see the personal data held about them.
- Right to Rectification: Individuals can request corrections to inaccurate or incomplete data.
- Right to Erasure: Individuals can request the deletion of their personal data under certain conditions.
- Right to Restrict Processing: Individuals can request the limitation of data processing under specific circumstances.
- Right to Data Portability: Individuals can request their personal data to be transferred to another organization.
- Right to Object: Individuals can object to the processing of their data for specific purposes.
Requests to exercise any of these rights should be sent to [email protected]. GlobeToTravel will respond within the statutory time frame (one month, with possible extensions in complex cases).
Personal Data Security Measures
GlobeToTravel and the CLIENT agree to implement the necessary technical and organizational measures to protect personal data from unauthorized access, misuse, or loss, in accordance with the state of technology and the level of risk involved. These measures include encryption, pseudonymization, access controls, and secure data storage systems.
Final Consumer Authorization
The CLIENT authorizes GlobeToTravel to disclose the final consumer’s personal data to third parties (such as airlines, hotels, or payment providers) for the sole purpose of completing travel bookings and related administration. Personal data will only be shared with parties directly involved in the travel arrangements, and no data will be shared with unauthorized third parties.
If a breach of personal data protection occurs due to the CLIENT’s failure to comply with GDPR, the CLIENT will bear full responsibility for any resulting claims, fines, or damages, and GlobeToTravel reserves the right to terminate services immediately.
Contact and Data Requests
If the CLIENT wishes to exercise their rights of access, rectification, or erasure under GDPR, they may contact GlobeToTravel at [email protected] or send a written request to GlobeToTravel’s registered address in Amsterdam, Netherlands, along with a copy of their identification for verification purposes.
GlobeToTravel’s designated data protection officer is available to address any data privacy concerns and ensure compliance with GDPR requirements.