Last Updated: 20/08/2026
1. Introduction
This Privacy Policy explains how GlobeID Limited (“GlobeID”, “we”, “us”, or “our”) collects, uses, stores, discloses, and safeguards personal data in connection with its digital identity and guest registration solutions, including the PassportScan family of products, websites, APIs, and related services (collectively, the “Services”).
PassportScan is a secure digital system that allows accommodation providers (such as hotels, serviced apartments, and similar establishments) to capture, process, and manage guest identity information as part of the guest check-in and regulatory reporting process.
This Policy applies to all personal data processed through the Services, including:
- website visitors
- users of the PassportScan Cloud and on-premise applications
- individuals whose identity documents are scanned or whose data is collected during check-in
- individuals who contact GlobeID via the website or apply for job positions
2. Data Protection Roles
2.1 GlobeID as Data Controller
GlobeID acts as a data controller for personal data it processes for its own internal business purposes, such as managing website inquiries and registrations, enabling user accounts, billing and subscriptions, recruiting and HR processes, and direct communications related to GlobeID’s business.
2.2 GlobeID as Data Processor
When PassportScan is used by accommodation providers to capture guest identity information and comply with legal check-in and reporting obligations, GlobeID acts as a data processor on behalf of the accommodation provider (the data controller in that context). In such cases, PassportScan processes personal data solely on documented instructions from the customer, under the Data Processing Agreement (DPA) entered into with the customer.
2.3 Where guest data comes from
Guest personal data is not collected by GlobeID directly from the data subject: it is captured by, or on the instructions of, the accommodation provider during check-in (Article 14 GDPR). The accommodation provider, as controller, is responsible for informing guests about the processing; PassportScan supports this with in-flow privacy notices and consent capture at check-in.
3. Personal Data Collected
3.1 Identity and Guest Registration Data (Hospitality Use Case)
When used by accommodation providers, PassportScan captures and processes identity information from travellers as part of check-in, including:
- full name and date of birth
- nationality and citizenship
- identity document information (passports, ID cards, visas, driver’s licences)
- digital images and scans of identity documents
- data extracted from documents, including machine-readable zones (MRZ)
This may include data relating to all guests present, including minors, where required for legal compliance.
3.2 Contact and Account Information
When individuals register for Services, contact GlobeID, or request information, GlobeID may collect: name, email address, telephone number, company or organisation name, and billing and subscription information.
3.3 Technical and Usage Data
When visiting the website or using the Services, GlobeID may collect technical and usage data, including IP addresses and device information, browser and operating system details, log and access records, and analytics and cookie data where permitted by the user.
3.4 Consent and Digital Signatures
PassportScan may collect digital signatures and consent records when individuals sign privacy notices, check-in forms, or compliance documents during the check-in process.
3.5 Special Categories of Personal Data
PassportScan does not request or process special categories of personal data (Article 9 GDPR) as such. Scanned identity documents may incidentally contain or reveal such information (for example a photograph or, on some national documents, other attributes); document images are processed exclusively to fulfil the check-in and statutory reporting purposes defined by the accommodation provider, are protected with the security measures described in Section 6, and are never used to infer or profile special-category attributes.
4. Purposes and Legal Bases
| Purpose | Data | Role | Lawful basis |
|---|---|---|---|
| Guest check-in, identity capture and statutory reporting (police, statistics, border control) | Identity and guest registration data (3.1), signatures (3.4) | Processor | Controller’s legal obligation (Art. 6(1)(c)) and the controller’s documented instructions |
| Transfer of guest data to the provider’s Property Management System | Identity and guest registration data (3.1) | Processor | Controller’s contract and instructions (Art. 6(1)(b)) |
| Customer accounts, billing and subscriptions | Contact and account information (3.2) | Controller | Contract performance (Art. 6(1)(b)) |
| Responding to inquiries; service communications | Contact information (3.2) | Controller | Legitimate interest (Art. 6(1)(f)) or pre-contractual steps (Art. 6(1)(b)) |
| Service operation, security, logging and abuse prevention | Technical and usage data (3.3) | Controller | Legitimate interest (Art. 6(1)(f)) |
| Analytics cookies and marketing communications | Technical/usage data (3.3), contact data (3.2) | Controller | Consent (Art. 6(1)(a)), revocable at any time |
| Recruiting and HR processes | Application data | Controller | Pre-contractual steps (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)) |
5. Data Sharing and Disclosure
Processed guest data may be shared with the customer’s internal systems (such as Property Management Systems or reporting interfaces); with governmental and regulatory bodies where legally required (police, immigration authorities, national statistics offices or other authorised public bodies); and with trusted third-party service providers engaged for secure hosting, infrastructure, encryption, and operational support, acting under contractual data protection obligations.
The current list of sub-processors engaged in the processing of customer data is maintained at https://www.passportscan.net/sub-processor/.
Personal data may also be disclosed to comply with legal obligations, respond to lawful requests, or protect GlobeID’s legal rights. PassportScan does not sell personal data to third parties.
6. Data Security
GlobeID implements appropriate technical and organisational safeguards to protect personal data from unauthorised access, loss, alteration, or destruction, including: encryption in transit (TLS 1.2+) and at rest (AES-256), with application-level encryption for sensitive identity data; role-based access control and multi-factor authentication on all critical systems; logging and monitoring; and periodic independent penetration testing. GlobeID operates an information security management system aligned with ISO/IEC 27001:2022.
7. Data Retention
Personal data is retained only as long as necessary for the purposes described in this Policy, according to the following criteria:
| Data category | Retention criterion |
|---|---|
| Guest registration data and document scans (processor role) | As configured by the accommodation provider and for the statutory retention period applicable in the property’s jurisdiction; deleted within 30 days of contract termination (per the DPA), except where law requires longer retention |
| Customer account and billing data | Duration of the contract, then as required by applicable tax and accounting law |
| Website inquiries and correspondence | Up to 24 months after the last interaction |
| Recruitment applications | Up to 12 months after the end of the selection process, unless consent for longer is given |
| Technical logs (access, application, network) | Up to 90 days |
| Backups | Deleted data leaves backup copies through scheduled backup expiry |
8. Cookies and Similar Technologies
The website uses cookies and similar technologies as described in the Cookie Policy. Consent is requested via the consent banner for all non-essential cookies before they are set, and preferences can be changed or withdrawn at any time through the cookie settings.
9. Data Subject Rights
Individuals have the rights of access, rectification, erasure, restriction of processing, objection, data portability, and the right to withdraw consent at any time where processing is based on consent (Articles 15–22 GDPR).
Requests can be addressed to privacy@passportscan.net. We respond within one month of receipt (extendable by two further months for complex requests, with notice). Where PassportScan processes data on behalf of an accommodation provider, GlobeID will route the request to that provider (the controller) and assist in its handling as required by the DPA.
10. Children’s Data
PassportScan may process personal data relating to minors where required by law during guest check-in. Such data is processed solely for legal compliance purposes.
11. International Data Transfers
The Services are hosted in the European Union (AWS, eu-west-1 region, Ireland). Where any ancillary transfer of personal data outside the EU/EEA occurs (for example through a service provider’s support organisation), it is protected by appropriate safeguards under Chapter V GDPR — in particular the European Commission’s Standard Contractual Clauses as incorporated in the provider’s data processing terms (e.g. the AWS Data Processing Addendum) — together with the encryption measures described in Section 6.
12. Automated Decision-Making
GlobeID does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning individuals or similarly significantly affect them (Article 22 GDPR). Automated document capture and data extraction assist the check-in process; the resulting registration and any decisions based on it remain with the accommodation provider and the competent authorities.
13. Changes to This Policy
This Privacy Policy may be updated from time to time. Updated versions will be published on the website with a revised effective date. Material changes are communicated via the website or by email.
14. Contact, Main Establishment and Supervisory Authority
Data controller: GlobeID Limited, The Black Church, St. Mary’s Place, Dublin 7, D07 P4AX, Ireland (CRO 559612).
Privacy contact: privacy@passportscan.net.
Data Protection Officer: reachable at the privacy contact above.
For the purposes of Articles 4(16) and 56 GDPR, GlobeID has designated Spain as its main establishment for data protection decision-making within the European Union. The lead supervisory authority for cross-border processing is:
Spanish Data Protection Agency (AEPD)
C/ Jorge Juan 6
28001 Madrid
Spain
www.aepd.es
Data subjects also have the right to lodge a complaint with their local supervisory authority (Article 77 GDPR).
For contractual matters (including the Terms & Conditions, DPA and SLA), the governing law is Ireland, consistent with GlobeID’s place of incorporation.
