01 · Governance  ·  ACTIVE FRAMEWORK

Trust is not a feature.
It is the floor.

Cross-border mobility is governed by some of the most consequential regulation in the global economy. Every interaction with the glomotec platform happens inside a framework of regulatory alignment, operational integrity, and institutional governance that is non-negotiable.

This page sets out how glomotec operates, the frameworks that govern it, and how it handles the information entrusted to it.

00 · Corporate structure

Corporate structure

The platform is operated by glomotec, Inc., a corporation incorporated in the State of Delaware, United States of America, with registered office at 131 Continental Drive, Suite 305, Newark, DE 19713, United States, together with its affiliates (collectively, “glomotec”).

The affiliates of glomotec, Inc., which operate as regional licensees of the platform, are:

Global Mobility Technologies LLC, a limited liability company organised under the laws of the State of Wyoming, United States of America, with registered office at 1309 Coffeen Avenue, STE 15705, Sheridan, WY 82801, and principal place of business at 809 Cuesta Drive, Suite B PMB 1177, Mountain View, CA 94040.

GLOMOTEC LTD, a private limited company registered in England and Wales under Companies House registration number 13211798, with registered office at Suite 116, Lovell House, Birchwood Park, Warrington, Cheshire WA3 6FW, United Kingdom.

RM Project Management Services Co. LLC, a limited liability company licensed in the Emirate of Dubai, United Arab Emirates under Department of Economy and Tourism licence number 1158581, with offices at 114 Al Fajer Complex, Umm Hurair Road, Dubai, United Arab Emirates.

References on this page to “glomotec” mean glomotec, Inc. and its affiliates, except where the context requires otherwise. Each presence is registered, operational, and regulated in its home jurisdiction.

02 · Regulatory Frameworks

Operating inside the regulation,
not around it.

Data protection

GDPR and UK GDPR compliance for data subjects in the European Economic Area and United Kingdom. UAE Personal Data Protection Law (PDPL) compliance for data subjects in the United Arab Emirates. US state privacy law compliance including CCPA, VCDPA, and applicable state frameworks.

Cross-border

Standard Contractual Clauses for international data transfers. Adequacy decisions respected where issued. Data residency options available for institutional clients with jurisdictional requirements.

Sector

Cross-border mobility, visa, residency, and investment migration programmes operate under jurisdiction-specific regulation. glomotec monitors and adapts to regulatory change across every jurisdiction it operates in.

Financial

AML and KYC obligations met through dedicated compliance workflows. Source-of-funds verification where required by jurisdiction or programme. Sanctions screening against current global lists.

03 · Jurisdictions

Three jurisdictions.
One platform.

glomotec operates across three principal jurisdictions. Each presence is registered, operational, and regulated in its home jurisdiction.

United States

Client engagement and contracting are handled through glomotec, a United States company. US operations govern platform infrastructure, commercial terms, and the contractual relationship with institutional and corporate clients.

United Kingdom

European presence is established through glomotec Ltd, a UK-registered company operating as the platform's European hub. UK operations extend access across the European regulatory environment and support institutional counterparties based in or connected to the region.

United Arab Emirates

Regional operations across the Middle East are conducted from the United Arab Emirates, where the platform's physical infrastructure, processing teams, and systems are based.

04 · Data & Security

Audit-grade
from the first byte.

Every action taken on the platform is recorded, attributable, and auditable. Security is not a layer applied after the fact. It is built into the infrastructure.

Infrastructure

Platform data is stored on enterprise-grade managed infrastructure with row-level security, encryption at rest, and encryption in transit. Access is governed by least-privilege policies enforced at the database layer.

Access control

Authenticated access only. Role-based permissions across every module. Multi-factor authentication available across client and partner portals. Session controls and audit logging enforced at the application and infrastructure layers.

Audit trail

Every significant platform event is logged with actor, timestamp, and context. Logs are retained in accordance with regulatory requirement and available for institutional audit on request.

Retention

Personal data is retained only for as long as necessary for the purposes for which it was collected, or as required by law. Retention policies are documented in the Privacy Policy and reviewed annually.

05 · Engagement

Governance inquiries.

Institutional counterparties, auditors, regulators, and partners conducting due diligence may request the governance pack directly. It includes entity registrations, regulatory alignment documentation, data handling specifications, and the operating model across jurisdictions.

For governance inquiries, data subject requests under GDPR, UK GDPR, or PDPL, or to exercise any rights set out in the Privacy Policy, write to governance@glomotec.com.