ip to content

This agreement, together with the Terms of Use defines the terms of use of the Globfone.com website (including all services) between the website publisher and the user.

  • User – any person using the Globfone Services (via Website, subdomain or Application).

  • Services – communication and related services we provide, including sending SMS, VoIP calls, video calls, file transfers, free and Premium services.

  • Website – the service available at https://globfone.com and related subdomains, including premium.globfone.com and auth.globfone.com.

  • Application – the mobile apps "Globfone" or similar, which act mainly as a shortcut/hosted shell for the mobile versions of the Websites and do not contain separate core logic.

  • End User / Recipient – the recipient of an SMS, call or other communication (e.g. owner of a phone number in GSM/PSTN networks).

  • Personal Data – any information relating to an identified or identifiable natural person (e.g. name, email, IP, phone number, identifiers).

  • Data Controller – the entity determining the purposes and means of processing personal data (i-Trends Sp. z o.o. for Globfone).

  • Data Processor – an entity processing personal data on behalf of the Controller (e.g. hosting provider, payment processor, VoIP or SMS gateway).

  • Cookies – small text files stored on your device to support the operation of the Website and for analytics/advertising, as described in the Cookies section.

Account registration and login: email address, first name, last name (if provided), user identifier in the identity system , password or other authentication credentials (stored and managed in the identity provider),

  • email address,
  • first name, last name (if provided),
  • user identifier in the identity system ,
  • password or other authentication credentials (stored and managed in the identity provider),
  • technical tokens (access/refresh tokens) stored as httpOnly cookies on our domains for authentication and security.

password or other authentication credentials (stored and managed in the identity provider),

password or other authentication credentials (stored and managed in the identity provider),

performance of a contract – Art. 6(1)(b) GDPR (sending SMS requested by the User),
legitimate interests – Art. 6(1)(f) GDPR (financing free services with ads, anti-fraud, service quality).

  • Server-based contacts (within the Service): contact name (up to a limited number of characters), phone number (normalised numeric format), link to your User Account.
  • contact name (up to a limited number of characters),
  • phone number (normalised numeric format),
  • link to your User Account.
  • Mobile app device contacts (if you grant permission): access to your address book to allow you to pick recipients directly from contacts.
  • access to your address book to allow you to pick recipients directly from contacts.

consent – Art. 6(1)(a) GDPR (for accessing the address book on your device or adding third-party data),

Stripe customer ID linked to your Account,

basic payment method information accessible to us (card brand, last four digits, expiration month/year),

performance of a contract – Art. 6(1)(b) GDPR (where free recharge is part of the Service offering),

legitimate interests – Art. 6(1)(f) GDPR (protecting the Service from abuse).

blacklists: normalised values such as IP addresses, phone numbers, email addresses or other identifiers,

  • normalised values such as IP addresses, phone numbers, email addresses or other identifiers,
  • hash of the value, human-readable display value, scope (e.g. global, free SMS only), status, validity period,
  • reason, source (manual/automatic), meta-data, ID of admin who created/modified the entry.

normalised values such as IP addresses, phone numbers, email addresses or other identifiers,

normalised values such as IP addresses, phone numbers, email addresses or other identifiers, hash of the value, human-readable display value, scope (e.g. global, free SMS only), status, validity period, reason, source (manual/automatic), meta-data, ID of admin who created/modified the entry.

legitimate interests – Art. 6(1)(f) GDPR (security of networks and information, fraud prevention, service quality),

Analytics and advertising providers – e.g. Google Analytics, Google AdMob, Google Adsense and similar tools used for analytics and displaying ads.

Security and CDN providers – such as Cloudflare, which process certain technical data to improve performance and protect the Service.

Purpose: detect and block messages that may be spam, fraudulent, illegal, offensive, sexually explicit, degrading, threatening or containing prohibited/malicious URLs, and ensure compliance with the Terms of Use.

How it works: the system automatically classifies messages and may decide on sending in certain cases. This decision is automated within the meaning of A.

Account data: stored while your Account is active and for up to 6 years after deletion or last use where necessary to comply with legal obligations (e.g. accounting) or defend/establish legal claims.

Payment and billing information: stored for the period required by tax and accounting law — at least 5–6 years from the end of the year in which the transaction took place.

Communication metadata (calls, SMS, technical logs): stored generally up to 6 years to ensure service provision, security, settlement and legal compliance (e.g. telecom, tax and limitation periods).

Payment and billing information: stored for the period required by tax and accounting laws (often at least 5–6 years from the end of the year in which the transaction took place).

SMS content: stored up to 18 months to ensure delivery, troubleshoot issues and handle complaints, unless a longer period is required by law. After this period, content is securely deleted (e.g. overwritten).

Communication metadata (calls, SMS, technical logs): stored generally up to 6 years unless a longer period is required by law (e.g. certain logs for security or compliance reasons).

Authentication and security logs: stored for a period necessary to ensure security and investigate incidents (for example several months) and then deleted or anonymised. Some aggregated or anonymised data may be kept longer for statistics and security basis.

Account data: stored while your Account is active and for up to 6 years after de-activation or closure, where necessary to comply with legal obligations (e.g. accounting) or to handle disputes.

  • Right of access – to obtain confirmation whether we process your personal data and, if so, to receive a copy and information about that processing (Art. 15 GDPR).
  • Right to rectification – to have inaccurate or incomplete data corrected or completed (Art. 16 GDPR).
  • Right to erasure ("right to be forgotten") – to request deletion of data in cases foreseen by Art. 17 GDPR (e.g. data is no longer needed, processing is unlawful, or consent is withdrawn where consent was the legal basis).
  • Right to restriction – to request that we limit processing in certain situations (Art. 18 GDPR).
  • Right to data portability – to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible (Art. 20 GDPR).
  • Right to object – to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21 GDPR), including profiling. We will stop processing unless we demonstrate compelling legitimate grounds overriding your rights, or the processing is needed to establish or defend legal claims.
  • Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).
  • Right to lodge a complaint – you may lodge a complaint with the competent supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).
  • Right of access – to obtain confirmation whether we process your personal data and, if so, to receive a copy and information about that processing (Art. 15 GDPR).
  • Right to rectification – to have inaccurate or incomplete data corrected or completed (Art. 16 GDPR).
  • Right to erasure ("right to be forgotten") – to request deletion of data in cases foreseen by Art. 17 GDPR (e.g. data is no longer needed, processing is unlawful, or consent is withdrawn where consent was the legal basis).
  • Right to restriction – to request that we limit processing in certain situations (Art. 18 GDPR).
  • Right to data portability – to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object – to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21 GDPR), including profiling. We will stop processing unless we can demonstrate compelling legitimate grounds.
  • Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).
  • Right to lodge a complaint – you may lodge a complaint with the competent supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement.

Right to lodge a complaint – you may lodge a complaint with the competent supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement. In Poland, the authority is the President of the Personal Data Protection Office (UODO).

To exercise any of these rights, you can contact us at support @ globfone.com or by postal mail to our registered address. We will respond without undue delay, and in any event within one month, unless the request is particularly complex (in such case, we may extend this period to three months, informing you about the reasons).

After logging into your User Profile, User may request deletion of Globfone Account by using the "Delete Account" option available in the account profile page. This action initiates the automated process of anonymising and deleting your personal data, subject to the exceptions and time periods described in this Privacy Policy (e.g. data required for legal compliance, to establish or defend legal claims).

We may update this Policy from time to time to reflect changes in our Services, technology or legal requirements. Updated versions will be published on the Website and, where appropriate, within the Application. We encourage you to review the Policy regularly. If changes are significant, we may also notify you via email or within the Service. Continued use of the Service after changes take effect means that you accept the updated Policy.

© Globfone 2026 · All rights reserved.

Powered by Surmado Sites