Skip to main content

Compliance & Governance

GGNomad inherits governance and privacy-aligned data handling from the Burdenoff platform, so the same controls apply uniformly across GGNomad and every other Burdenoff product. Travel involves PII and payment data, so the platform treats data protection, scoped access, and audit as foundations rather than add-ons.

Certifications

GGNomad makes no claim to formal certifications. Compliance evidence and attestations remain on the roadmap.

Privacy alignment

GDPR / CCPA-aligned handling Data protection is built into the platform:

  • Data minimization and purpose limitation across the booking lifecycle
  • Support for data-subject rights (access, correction, deletion)
  • Consent handling where required
  • Retention and deletion policies inherited from the platform

PII & payment data Traveler and payment data are protected by design:

  • Encryption in transit and at rest
  • Scoped, least-privilege access
  • Field-level controls on sensitive data
  • Secrets held in managed, per-environment secret storage

Governance framework

Policy & roles Governance is expressed through roles and RBAC, not bolt-on tooling:

  • Roles and permissions scope every action
  • Multi-tenant isolation keeps workspaces separate
  • The listing verification lifecycle gates quality before inventory goes live
  • Transparent, itemized totals so bookings are explained before they confirm

Data governance The platform manages how data is held and tracked:

  • Per-workspace data isolation
  • Retention and deletion policies
  • Scoped access controls
  • Audit logging on every mutation

Audit & accountability

Activity & audit log Every action is attributable:

  • Searchable, exportable activity timeline
  • Actor, target, and result recorded for every mutation
  • Audit fields stamped on every write (createdBy, onBehalfOf, updatedBy)
  • Per-action quota enforcement — no after-the-fact surprises

Operational signal Governance is backed by operational visibility:

  • Structured logging and tracing
  • Health checks and alerting
  • Usage metering per billing plan

Roadmap

Governance capabilities aimed at managed and enterprise travel are committed direction, marked as such so the vision and current reality are never confused:

  • Enterprise policy guardrails and approval flows for managed travel — roadmap
  • Formal compliance evidence and attestations as the platform matures past launch — roadmap

Getting started

Understand and apply the governance model:

  • Review the Security Overview and Authentication & Access Control
  • Scope roles to least privilege for your team and integrations
  • Use the activity log to track and review actions
  • Verify listings through the verification lifecycle before they go live

For compliance questions, contact the GGNomad team at [email protected].