Privacy policy
Last updated: 30 September 2026
This policy explains what personal data Global Data World (https://globaldataworld.com) collects, why, for how long, who helps us process it and the rights you have. We collect as little as the service needs, we do not sell personal data and we use no advertising or analytics cookies.
Who is responsible
The controller of your personal data is Álvaro Linares Cabre, owner of Global Data World, Spain. For anything about your data, write to [email protected].
What we collect
- Account data, when you sign in: your email address, your name and an identifier from the sign-in method you choose (Google, Facebook or a one-time code sent to your email). We never see or store passwords.
- Your analyses: the countries you compare, the language, the price, the dates and the status of each analysis, and the PDF we generate for you.
- Technical data: your IP address, the page or API route requested, the time and the response, in our servers' access logs.
- Emails we send you: your address and whether delivery succeeded.
Exploring the globe needs no account and we do not keep a profile of what you look at.
Why, and on what legal basis
- To create your account, build your analyses, email you the PDF and keep them in your account: performance of our contract with you (art. 6.1.b GDPR).
- To keep the service secure and available, and to detect and stop abuse such as scraping or automated access: our legitimate interest (art. 6.1.f GDPR).
- To keep the records the law requires once payments are taken: legal obligation (art. 6.1.c GDPR).
We do not use your data for advertising, profiling or automated decisions that affect you.
Cookies
We only use cookies that the service needs to work, so no consent banner is shown:
__Host-a360_login: keeps a sign-in in progress secure; deleted after 10 minutes.__Host-a360_idand__Host-a360_rt: keep you signed in; up to 30 days, or until you sign out.
They are HttpOnly (page scripts cannot read them), sent over HTTPS only and never shared with third parties. There are no analytics, advertising or social-media tracking cookies.
Who processes it for us
- Amazon Web Services (Ireland, EU): hosting, database, sign-in (Amazon Cognito), PDF storage and our emails (Amazon SES).
- Cloudflare: delivery of the website and protection against attacks and abusive traffic.
- Google and Meta (Facebook): only if you choose them to sign in; they act as independent controllers under their own policies.
- A payment provider, named at checkout, once payments are available; we never see your card details.
Where a provider processes data outside the European Economic Area, the transfer is covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
Google user data
If you sign in with Google we receive only your email address, name and Google account identifier (the openid, email and profile scopes). We use them only to create and identify your account and to send you your analyses. We do not access your Gmail, contacts, files or any other Google data, we do not share Google user data with anyone except the providers listed above to run the service, and we do not use it for advertising or to train AI models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
- Account data and your analyses: while your account exists; deleted within 30 days after you ask us to close it.
- Generated PDFs: deleted from our storage 30 days after they are made (the copy we email you is yours).
- Access logs: 14 days.
- Payment records, once payments exist: as long as tax law requires.
Your rights
You can ask us to access, correct, delete or export your data, to restrict or object to its processing, and you can withdraw any consent at any time. Write to [email protected] from the address of your account; we answer within one month. If you think we have not handled your data properly you can complain to the Spanish Data Protection Agency (www.aepd.es) or the authority of your country.
Security
Data travels encrypted (HTTPS) and is encrypted at rest; sign-in tokens live in HttpOnly cookies; access to our systems is limited and logged.
Children
Global Data World is not intended for people under 16, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date above, and tell signed-in users by email when the change is significant.