G-P Privacy & Security Center

Welcome to G-P Privacy & Security Center

G-P’s rigorous security, privacy, compliance, and transparency standards let you focus on your business with confidence.

Icon Transparency Privacy

Transparency.

We’re open and honest about how we use personal data so you aren’t left guessing what we do with it.
Icon Control Privacy

Control.

We give you choices about how we use your data and protect access to sensitive data and workflows with authorization levels and security standards built into G-P’s products.
Icon Security Privacy

Security.

We use strong safeguards to keep your data confidential and secure every step of the way.
Privacy Support

Privacy resources.

At G-P, we take the privacy and security of our Customers’ and Professionals’ data seriously. Explore the links below for more information on G-P’s thorough approach to privacy and data protection.

Privacy statements.

At G-P, we value, protect, and defend privacy. We believe in transparency, so that people and organizations can control their data and have meaningful choices in how it is used.

Sub-processor list.

Where G-P acts as a processor in providing you with products or services, we may engage third party sub-processors to assist us. A list of our sub-processors is available for your review.

Cookies.

In order to provide you with more relevant offers and optimize your experience on our website, we use different types of cookies and advertising technologies. Learn about how we engage you and update your preferences.

Security and compliance

 

Security information.

 

At G-P we believe you have a right to understand how we protect customer data. G-P applies security best practices and manages security to allow customers to focus primarily on their business. G-P identifies security risks and puts controls in place to manage or eliminate those risks and assure stakeholders and customers that data processed is protected and available.

Platform Security

Platform security.

Our Global Employment Platform has been designed and built following the highest security and compliance standards in the industry — keeping all your workforce data safe.

Owasp

OWASP secure coding practices.

During the design, implementation, and maintenance of G-P products and services, G-P follows a branching strategy workflow for source control and uses the principles outlined in the OWASP secure coding practices to defend against the OWASP top 10 security vulnerabilities.

Soc 2

Certified with SOC 2 standards.

G-P has implemented a formal information security program designed to protect the confidentiality, integrity, and availability of our systems and customer data. G-P has been certified and attested to confirm compliance with SOC 2 standards by independent auditors. Service Organization Controls (SOC) reports demonstrate our commitment to securing customer data.

ISO 27001

Certified with the ISO 27001 standard.

The provision of G-P’s services through the G-P Platform is certified to be compliant with the ISO 27001 standard, a key international standard governing information security management. Adherence to this standard assures that data and services are protected to the fullest extent possible.

Aws

Amazon Web Services secure and certified data centers.

AWS data centers have multiple layers of operational and physical security to ensure the integrity and safety of data. The data center is manned and supported 24 hours a day, 7 days a week and 365 days a year.

Armanino Certified

Artificial Intelligence Management Systems certified.

G-P maintains a rigorous, third-party audited compliance program. We hold certifications for ISO/IEC 27001 (Information Security), ISO/IEC 27017 (Cloud Security), ISO/IEC 27018 (Cloud Privacy), and ISO/IEC 42001 (Artificial Intelligence Management).

Security and compliance

Security portal.

To learn more and access G-P security and compliance posture, please reference our security and compliance overview page. Our latest reports are available to customers under NDA and can be accessed by contacting your account manager.

Privacy & Support FAQ

Your Privacy & Security questions, answered.

These frequently asked questions are designed to assist you in understanding G-P’s approach to privacy and security.

How does G-P collect personal data?

G-P collects personal data:

  • Directly from you when you access various parts of our Services, including when you communicate with us via email or other channels;

  • From other sources, for instance, including your company and your company’s third parties who may send us your personal data on your or your Company’s behalf; and

  • From the network of websites and applications accessible through or utilized by our Services and our company, including third party suppliers (e.g. recruiting agencies) and our G-P related companies, affiliates, subsidiaries, partners and subcontractors. This includes personal data we collect automatically through our websites and applications, for instance by using cookies and similar technologies.

How does G-P protect Customers’ personal data?

G-P employs appropriate technical and organizational security measures to ensure a level of security appropriate to the risk and to protect personal data against loss, unauthorized access, disclosure, alteration, and destruction, and against other forms of unlawful or abusive treatment. To learn more and access to G-P security and compliance posture, please reference our

How does G-P meet its obligations under data protection laws?

G-P has a comprehensive global privacy program which includes policies, procedures, standards, and controls focusing on compliance with global data protection laws, including GDPR. This program is managed and monitored by a global privacy and data protection team. G-P’s comprehensive program includes policies, procedures, standards, and controls around:

  • Data Governance;

  • Data Mapping;

  • Incident Response;

  • International Data Transfers;

  • Notice and Consent;

  • Privacy Impact Assessment (and DPIAs);

  • Privacy By Design and Default;

  • Third Party Management;

  • Security of Data;

  • Recordkeeping;

  • Confidentiality; and

  • Training and Awareness of our team members.

G-P’s Privacy Policy explains how and why G-P collects, uses, stores, and discloses personal data / information from individuals who interact with us. You may consult it here

Is G-P a Data Controller or a Data Processor?

G-P is both a data controller and a data processor.

G-P collects and uses the Professional’s human resources data during the course the employment relationship. With regard to that information, G-P is a data controller. In the context of the employment relationship with the Professionals, G-P is not a processor on behalf of the Customer. To the extent Customers also collect and use the Professional’s personal data for the Customer’s own purposes, Customers are also data controllers with independent privacy obligations. Therefore, the exchange / sharing of Professionals’ Personal data between G-P and the Customer is under an independent Controller-to-Controller relationship.

On the other hand, through our SaaS-based platform (“G-P Platform”), we help Customers to find, hire, onboard, pay, and manage team members, quickly and compliantly, to expand growth opportunities for everyone, everywhere – without the hassle of setting up local subsidiaries or branch offices. By providing Customers with access to G-P Platform, G-P is a data processor for any personal data uploaded to the G-P Platform by Customer concerning the authorized users of the G-P Platform appointed by the Customer. G-P processes the account related date belonging to such authorized users of the GP Platform.

Those relationships between Customer and G-P are addressed in G-P Data Protection Addendum incorporated in the Master Agreement executed between the parties.

Does G-P transfer personal data across borders?

G-P disrupted the rules of international business by enabling organizations to hire anyone, anywhere in the world within minutes. Therefore, transferring personal data internationally is necessary for the provision of our Services. When sharing with or disclosing personal data to other parties, including to G-P’s related companies, affiliates, subsidiaries, partners and subcontractors who provide Services, personal data may be transferred to countries with data protection laws providing a lower standard of protection for your personal data than your country.

We will transfer your personal data in compliance with applicable data protection laws, including having adequate mechanisms in place to protect your personal data when it is transferred internationally (e.g. Standard Contractual Clauses, data processing agreements).

Is G-P obliged to provide or give access to personal data to third parties on the basis of national laws?

G-P protects the privacy of its Customers and Professionals and G-P not voluntarily provide third party. G-P has never received a request under U.S. surveillance laws to provide personal data to the U.S. government.

How does G-P manage and monitor its AI technologies safely and compliantly?

G-P has achieved ISO/IEC 42001 certification, the world’s most rigorous standard dedicated to Artificial Intelligence Management Systems (AIMS). This independently audited framework validates G-P's ability to responsibly develop, deploy and monitor AI technologies.

  • Comprehensive Risk Mitigation: Continuous identification and evaluation of AI-specific operational and security risks.

  • Data Governance & Integrity: Establishing strict parameters for AI data provenance and quality, ensuring data utilized by AI models is handled ethically and in alignment with global privacy principles.

  • Algorithmic Transparency: Ensuring AI system deployment features clear traceability and logging, allowing for meaningful human oversight and accountability.

  • Systemic Accountability: Establishing clear corporate governance and institutional responsibility for all AI outputs and lifecycles.

Does G-P give Professionals a privacy notice?

Yes, G-P issues a Privacy Notice to Professionals at the time their data is collected.

This means that:

Our privacy notice ensures that Professionals are aware of the way their personal data is processed, helping them understand what data is being collected, why and how it’s being used, with whom will be shared, how it is secured and how long it will be kept.

How does G-P use cookies?

When you visit our websites, we may use cookies or similar technologies to deliver a more personalized experience. Cookies help us better understand your interests, tell us which parts of our website you’ve visited, and show how you’re interacting with our online ads and web searches. For more information on our cookies settings, and how to manage your preferences, visit our COOKIES SETTINGS in our website.

Privacy Contact
Contact us

Reach out to our privacy team.

For any further questions, comments or help managing your privacy options, please don’t hesitate to get in touch. You can send us an email at privacy@globalization-partners.com

Globalization Partners, LLC
Global Data Privacy Office
175 Federal Street, 17th Floor,
Boston, MA 02110 USA