Privacy Policy
Effective date: 5 August 2026 — Last updated: 5 August 2026
We keep your data for a very short time, we encrypt it, and we never see your card number. This policy explains exactly how.
1. WHO IS RESPONSIBLE FOR YOUR DATA
The data controller is Global Entry Form LLC, registration number 0008098270, registered office 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States, the United States (State of New Mexico). Privacy contact: info@globalentryform.com This policy applies to maldives-traveller-declaration.com and to the services provided through it.
2. THE SHORT VERSION
* We collect only what is needed to prepare and submit your Maldives TD. * Applicant data is encrypted at rest and in transit and is PERMANENTLY DELETED NO LATER THAN 24 HOURS after the Service is completed. * We never receive or store your full card number, CVV or PIN. Card data goes directly to TailoredPay. * We do not sell, rent or trade your personal data. Ever. * Non-essential cookies only run if you consent, and you can change your mind at any time.
3. WHAT DATA WE COLLECT
3.1 Data you give us to obtain the Maldives TD ("Applicant Data"): - full name, date and place of birth, sex/gender as shown on the travel document, nationality; - travel document type, number, issuing country, issue and expiry dates; - contact details: email address, telephone number; - travel details: arrival and departure dates, flight or carrier details, addresses in the Maldives, purpose of travel; - answers to the declaration questions required by the Authority, which may include customs, biosecurity, goods, criminal-record or health-related questions; - any supporting document you upload.
3.2 Order and billing data: - order reference, product purchased, amount, currency, date and time; - invoicing name and email; - payment status and the transaction reference returned by TailoredPay; - card scheme and last four digits (for identification of a transaction only).
3.3 Technical data: - IP address, user agent, device and browser type, language, referring URL, pages viewed, timestamps; - security and anti-fraud signals; - cookie and consent data (see the Cookie Policy).
3.4 Correspondence: - the content of emails, chat messages or forms you send us.
3.5 WE DO NOT COLLECT: your full payment card number, the CVV/CVC code, the card expiry date in full, your PIN, or your online banking credentials. These are never transmitted to, processed by, or stored on our systems.
4. SENSITIVE DATA
Some declarations required by an Authority include questions that may reveal health information or information about criminal convictions. Where you provide such information, we process it solely to prepare and submit the declaration you have asked us to submit. In the EU/EEA and the UK, this processing is based on your explicit consent under Article 9(2)(a) GDPR and, where applicable, on the establishment, exercise or defence of legal claims under Article 9(2)(f). You may withdraw that consent at any time, although we will then be unable to complete the Service.
5. WHY WE USE YOUR DATA AND ON WHAT LEGAL BASIS
PURPOSE LEGAL BASIS (GDPR Art. 6) ------------------------------------------ -------------------------------- Providing the Service: reviewing, Performance of a contract preparing and submitting your (Art. 6(1)(b)) Maldives TD, and notifying you of the outcome Customer support and correspondence Contract / legitimate interests (Art. 6(1)(b), 6(1)(f)) Taking payment and issuing invoices Contract and legal obligation (Art. 6(1)(b), 6(1)(c)) Keeping accounting and tax records Legal obligation (Art. 6(1)(c)) Fraud prevention, security, abuse Legitimate interests prevention and system integrity (Art. 6(1)(f)) Establishing, exercising or defending Legitimate interests legal claims and handling chargebacks (Art. 6(1)(f)) Analytics, audience measurement and Consent (Art. 6(1)(a)) marketing cookies Optional service emails you opt into Consent (Art. 6(1)(a)) Where we rely on legitimate interests, we have assessed that our interest in running a secure, lawful and functioning service does not override your rights. You may object at any time (see section 11). We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile you for advertising purposes.
6. HOW LONG WE KEEP YOUR DATA — THE 24-HOUR RULE
6.1 APPLICANT DATA. All Applicant Data described in section 3.1 — including your name, date of birth, travel document number, declaration answers and any uploaded document — is retained for a MAXIMUM OF 24 HOURS after the Service is completed (that is, after your Maldives TD has been submitted and the outcome communicated to you, or after the order has been cancelled or refunded).
6.2 Throughout that period the data is held ENCRYPTED AT REST using strong, industry-standard encryption, and is transmitted only over encrypted channels.
6.3 At the end of that period the data is PERMANENTLY AND IRREVERSIBLY DELETED from our production systems by an automated process. Encrypted backups, if any, are rotated and overwritten within 30 days, after which no copy remains.
6.4 NARROW EXCEPTIONS. We retain the following minimum records beyond 24 hours, because the law requires it or because we cannot otherwise defend a legal claim. These records do NOT include your travel document number, your declaration answers or any uploaded document: (a) Invoice and accounting records (billing name, email, amount, currency, date, order and transaction reference) — for the period required by tax and accounting law in the United States (State of New Mexico), typically 5 to 10 years. (b) A minimal transaction log proving that an order was placed and a service delivered (order reference, date, product, status) — up to 24 months, for chargeback and dispute handling. (c) Correspondence with you — up to 12 months, or longer if it relates to an ongoing complaint or claim. (d) Security and server logs — up to 12 months. (e) Consent records for cookies — up to 12 months (see the Cookie Policy). (f) Anything we are ordered to preserve by a court or competent authority.
6.5 Once a retention period ends, data is deleted or irreversibly anonymised.
7. PAYMENTS AND CARD DATA
7.1 Payments are processed by TailoredPay (https://tailoredpay.com) and its acquiring partners. When you pay, your card details are entered into a payment interface controlled by TailoredPay and are transmitted directly to it over an encrypted connection.
7.2 WE NEVER RECEIVE, PROCESS, TRANSMIT OR STORE YOUR FULL CARD NUMBER, CVV/CVC, PIN OR TRACK DATA. There is no point at which cardholder data enters our systems or our databases.
7.3 We receive only a payment result and non-sensitive metadata: an authorisation or transaction reference, the amount, the currency, the status, the card scheme and the last four digits.
7.4 TailoredPay acts as an independent controller in respect of the payment data it collects and processes it under its own privacy policy and under PCI DSS. We recommend you review its privacy notice at https://tailoredpay.com.
8. WHO WE SHARE DATA WITH
8.1 We share the minimum necessary data with: (a) THE COMPETENT AUTHORITY. To submit your Maldives TD we transmit your declaration to Maldives Immigration through its official channels. That Authority then processes your data as an independent controller, under the law of the Maldives, and its processing is outside our control and outside the scope of this policy. (b) OUR PAYMENT PROVIDER, TailoredPay. (c) OUR SERVICE PROVIDERS acting as processors under written data processing agreements: Cloudflare Pages (global edge network) (hosting and infrastructure), our transactional email provider, our customer support tooling, our consent management platform our self-hosted Google Consent Mode v2 platform, and our analytics provider Google Analytics 4 (analytics only where you have consented). (d) PROFESSIONAL ADVISERS — accountants, auditors and lawyers, under a duty of confidentiality. (e) AUTHORITIES, COURTS AND REGULATORS where we are legally required to disclose, or where disclosure is necessary to prevent or investigate fraud or a crime. (f) A BUYER OR SUCCESSOR in the event of a merger, acquisition or sale of assets, subject to equivalent protections.
8.2 WE DO NOT SELL, RENT OR TRADE YOUR PERSONAL DATA, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING.
9. INTERNATIONAL TRANSFERS
9.1 Providing the Service necessarily involves transferring your declaration to the Maldives. Where that country is outside the EEA and is not covered by an adequacy decision, the transfer is necessary for the performance of the contract you have asked us to perform, and, where applicable, is made under Article 49(1) GDPR.
9.2 Where our providers process data outside the EEA or the UK, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with supplementary technical measures including encryption.
9.3 You may request a copy of the relevant safeguards at info@globalentryform.com.
10. HOW WE PROTECT YOUR DATA
We apply technical and organisational measures appropriate to the risk, including: * TLS 1.2 or higher for all data in transit; * strong encryption at rest for all Applicant Data; * automated deletion routines enforcing the 24-hour rule; * strict role-based access control on a need-to-know basis, with multi-factor authentication for administrative access; * network segmentation, firewalling and hardened server configuration; * logging and monitoring of access to personal data; * confidentiality obligations for all staff and contractors; * written data processing agreements with all processors; * a documented personal data breach procedure. Where a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and, where the risk is high, we will notify you. No system is completely secure, and we cannot guarantee absolute security.
11. YOUR RIGHTS
11.1 Subject to applicable law, you have the right to: - ACCESS the personal data we hold about you; - RECTIFICATION of inaccurate or incomplete data; - ERASURE ("right to be forgotten"); - RESTRICTION of processing; - DATA PORTABILITY in a structured, machine-readable format; - OBJECT to processing based on legitimate interests, and to object at any time to direct marketing; - WITHDRAW CONSENT at any time, without affecting the lawfulness of processing before withdrawal; - NOT BE SUBJECT to solely automated decisions with legal or similarly significant effects; - LODGE A COMPLAINT with a supervisory authority.
11.2 HOW TO EXERCISE THEM. Email info@globalentryform.com with enough information for us to identify your record (order reference and the email used). We respond within one month, extendable by two further months for complex requests. We may ask you to verify your identity. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
11.3 PLEASE NOTE THE EFFECT OF THE 24-HOUR RULE. Because we delete Applicant Data within 24 hours of completing the Service, in most cases there will be no Applicant Data left to access, rectify, port or erase by the time a request reaches us. In that situation we will confirm to you that the data has already been deleted and will tell you which limited records under section 6.4 still exist.
11.4 SUPERVISORY AUTHORITIES. EU/EEA residents may complain to the data protection authority of their country of residence, place of work or the place of the alleged infringement. UK residents may complain to the Information Commissioner's Office. Residents elsewhere may contact their national privacy regulator.
12. ADDITIONAL RIGHTS BY REGION
12.1 CALIFORNIA (CCPA/CPRA) AND OTHER US STATES. In the past 12 months we have collected the categories of personal information described in section 3 for the business purposes described in section 5. WE DO NOT SELL PERSONAL INFORMATION AND DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING, including personal information of consumers under 16. You have the right to know, delete, correct, opt out of sale/sharing, limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. Our consent banner honours the Global Privacy Control (GPC) browser signal as a valid opt-out request. Authorised agents may submit requests with proof of authorisation to info@globalentryform.com.
12.2 UNITED KINGDOM. The UK GDPR and the Data Protection Act 2018 apply.
12.3 SWITZERLAND. The revised Federal Act on Data Protection (FADP) applies to Swiss residents, who have equivalent access, rectification and deletion rights.
12.4 BRAZIL (LGPD), CANADA (PIPEDA), AUSTRALIA (Privacy Act) AND NEW ZEALAND (Privacy Act 2020). Residents of these countries have equivalent rights of access, correction and complaint under their national law and may contact info@globalentryform.com.
13. CHILDREN
Our Service is not directed at children and we do not knowingly collect data from children who contact us directly. A parent or legal guardian may submit a declaration on behalf of a minor traveller; in that case the adult is responsible for the data supplied. If you believe a child has provided us with data directly, contact info@globalentryform.com and we will delete it.
14. COOKIES
See our Cookie Policy for full details of the cookies used, their purpose, their duration and how to give or withdraw consent.
15. CHANGES TO THIS POLICY
We may update this policy. The current version is always published on the Website with a revision date. Material changes will be signalled prominently on the Website.
16. CONTACT
Global Entry Form LLC 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States Privacy: info@globalentryform.com — Support: info@globalentryform.com