Trust centre

Marketing spend data deserves financial-grade handling.

We describe only the controls we actually operate. Globaltong does not hold SOC 2, ISO or NDPR certification, and we will not claim otherwise.

Data security

Data is encrypted in transit over TLS and at rest by our infrastructure provider. Access to production data is limited to authorised operators.

Access control

Every workspace is isolated by row-level security. Users only read records belonging to their own account, and operator functions require an explicit admin role.

Audit logs

Approvals, invoice issuance, payment confirmation and catalogue changes record the acting user and timestamp.

Consent

Audience profiles carry a consent state. Segments intended for activation are built from consented records, and consent can be withdrawn.

Data retention and deletion

Clients can request export or deletion of their workspace data. Deletion removes profiles, segments and associated records.

Backups

Databases are backed up by our managed infrastructure provider with point-in-time recovery.

Incident response

Suspected incidents are triaged by the engineering team, contained, and reported to affected customers with the facts we have established.

Subprocessors

We use managed infrastructure, database and AI providers to deliver the service. A current subprocessor list is available on request.

Data processing agreements

A data processing agreement is available for customers who require one. Contact us to request the current version.

Security contact

Report a vulnerability or ask a security question through our contact page and mark the topic as Security.

Have a security or procurement review?

Send us your questionnaire and we will answer it against the controls we actually operate.