Compliance & Governance
GGNomad inherits governance and privacy-aligned data handling from the Burdenoff platform, so the same controls apply uniformly across GGNomad and every other Burdenoff product. Travel involves PII and payment data, so the platform treats data protection, scoped access, and audit as foundations rather than add-ons.
GGNomad makes no claim to formal certifications. Compliance evidence and attestations remain on the roadmap.
Privacy alignment
GDPR / CCPA-aligned handling Data protection is built into the platform:
- Data minimization and purpose limitation across the booking lifecycle
- Support for data-subject rights (access, correction, deletion)
- Consent handling where required
- Retention and deletion policies inherited from the platform
PII & payment data Traveler and payment data are protected by design:
- Encryption in transit and at rest
- Scoped, least-privilege access
- Field-level controls on sensitive data
- Secrets held in managed, per-environment secret storage
Governance framework
Policy & roles Governance is expressed through roles and RBAC, not bolt-on tooling:
- Roles and permissions scope every action
- Multi-tenant isolation keeps workspaces separate
- The listing verification lifecycle gates quality before inventory goes live
- Transparent, itemized totals so bookings are explained before they confirm
Data governance The platform manages how data is held and tracked:
- Per-workspace data isolation
- Retention and deletion policies
- Scoped access controls
- Audit logging on every mutation
Audit & accountability
Activity & audit log Every action is attributable:
- Searchable, exportable activity timeline
- Actor, target, and result recorded for every mutation
- Audit fields stamped on every write (
createdBy,onBehalfOf,updatedBy) - Per-action quota enforcement — no after-the-fact surprises
Operational signal Governance is backed by operational visibility:
- Structured logging and tracing
- Health checks and alerting
- Usage metering per billing plan
Roadmap
Governance capabilities aimed at managed and enterprise travel are committed direction, marked as such so the vision and current reality are never confused:
- Enterprise policy guardrails and approval flows for managed travel — roadmap
- Formal compliance evidence and attestations as the platform matures past launch — roadmap
Getting started
Understand and apply the governance model:
- Review the Security Overview and Authentication & Access Control
- Scope roles to least privilege for your team and integrations
- Use the activity log to track and review actions
- Verify listings through the verification lifecycle before they go live
For compliance questions, contact the GGNomad team at [email protected].