GeoGenie Inc.
Effective date: Sep 1st 2026
This summary is for convenience only. The full Policy below governs.
| Who we are | GeoGenie Inc., a Delaware corporation. We operate the GeoGenie AI-search visibility platform at geogenie.ai. |
|---|---|
| Two different roles | For our website, marketing and account data we are a controller. For the Customer Content our business customers put into the platform we are a processor, acting on their instructions under the Data Processing Agreement in Annex B. |
| Do we sell personal data? | No. We do not sell personal data and we do not share it for cross-context behavioural advertising or targeted advertising. |
| Do we train AI models on your data? | No. We do not use Customer Content to train generative AI models, and we require our AI providers not to train on what we send them. See Section 12. |
| What do we send to the AI engines? | Prompts, brand and topic terms, and publicly available web content. We do not send Customer Content containing personal data to them. Publicly available web content that we retrieve for analysis can itself contain personal data — for example the name of an article's author. See Section 12.2. |
| Where is data hosted? | The United States. Transfers out of the EEA, UK and Switzerland are covered by Standard Contractual Clauses. See Section 8. |
| Google Search Console and GA4 | If you connect them, we use that data only to produce your reports inside GeoGenie — never for advertising and never to train models. Our use adheres to the Google API Services User Data Policy, including its Limited Use requirements. See Section 18. |
| Sub-processors | Published in full in Annex A, with 30 days' advance notice of changes and a right to object. |
| Data Processing Agreement | Annex B. It applies automatically to every customer — you do not need to sign it or ask for it. |
| Contact | privacy@geogenie.ai |
This Privacy Policy ("Policy") explains how GeoGenie Inc. ("GeoGenie", "we", "us", "our") collects, uses, discloses and protects personal data.
It covers:
Most questions about a specific piece of data are answered by working out which of these two roles applies to it.
We are a controller when we decide why and how personal data is processed. This applies to:
We are a processor when we process Customer Content on behalf of a business customer. Our customer is the controller; we act only on their documented instructions. This applies to any personal data a customer chooses to submit into the platform — for example, personal data appearing inside content assets uploaded for analysis, or contact records carried in by an integration the customer connects.
Where we act as a processor, our processing is governed by the Data Processing Agreement at Annex B. If you are an individual whose personal data was submitted to us by one of our customers, please direct your privacy request to that customer in the first instance; we will refer such requests to them and assist them in responding.
The Services are offered to businesses and their personnel. They are not directed at consumers and not directed at children. See Section 17.
Capitalised terms used but not defined here have the meaning given in the GeoGenie Terms and Conditions at geogenie.ai/terms.
| Term | Meaning |
|---|---|
| Customer Content | Any data, information, text, files, URLs, brand assets, prompts or other content that a customer or its Users submit to the Services. |
| Generated Content | Reports, visibility scores, analyses, briefs, recommendations and other output the Services produce from Customer Content and inputs. |
| Personal data | Information relating to an identified or identifiable natural person. Where a US state privacy law applies, this includes "personal information" as defined by that law. |
| Controller / Processor | As defined in the EU GDPR and UK GDPR. Under CCPA/CPRA, "controller" corresponds broadly to "business" and "processor" to "service provider". |
| Sub-processor | A third party engaged by us to process personal data on our behalf in providing the Services. |
| EU GDPR | Regulation (EU) 2016/679. |
| UK GDPR | The EU GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018. |
| FADP | The Swiss Federal Act on Data Protection, as revised with effect from 1 September 2023. |
| SCCs | The Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914. |
| UK Addendum | The International Data Transfer Addendum to the EU SCCs (version B1.0) issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018. |
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email address, password hash or single sign-on identifier, job title, company name, account role and permissions, workspace and project names | You, or an administrator of your organisation |
| Billing data | Billing contact, billing address, VAT or tax identification number, purchase order references, plan and subscription details, card brand and last four digits | You. Full card numbers are collected and processed by Stripe directly through its hosted payment components and do not pass through GeoGenie's systems |
| Communications data | The content of emails, support tickets, chat messages, demo requests, survey responses and notes we take during calls; scheduling preferences | You |
| Marketing data | Contact details submitted through forms, gated content downloads, webinar and event registrations, communication preferences and consent records | You, or the event organiser |
| Recruitment data | CV, cover letter, work history and other application materials | You, or a recruitment platform on your behalf |
Is providing this data required? Account data and billing data are necessary for us to enter into and perform a contract with you. If you do not provide them we cannot create your account, give you access to the Services or bill you. Everything else is optional: you are free not to give it, and the only consequence is that we cannot provide the corresponding feature — for example, we cannot answer a support request you do not send, or register you for an event without a registration. No provision of personal data to us is required by statute.
Calls and meetings. We do not record calls or meetings unless we tell you at the start of the call and, where the law of your jurisdiction requires it, obtain your consent. Where you decline, we take written notes instead.
Account credentials. Log-in credentials are treated as "sensitive personal information" under the CPRA. We use them solely to authenticate you and to secure your account. We do not use or disclose them for any purpose that would give rise to a right to limit their use under §1798.121 CPRA.
| Category | Examples | Notes |
|---|---|---|
| Device and connection data | IP address, browser type and version, operating system, device type, language, screen dimensions | |
| Usage and product telemetry | Pages and screens viewed, features used, buttons clicked, reports run, session duration, timestamps, referring URL | Collected through PostHog, and only after consent where consent is required. See Section 11 |
| Approximate location | Country, region and city inferred from IP address | We do not collect precise GPS or device-level location data |
| Log and security data | Access logs, authentication events, API request metadata, error traces, rate-limit and abuse signals | |
| Cookie and consent data | Cookie identifiers, consent choices and their timestamps | See Section 11 |
| Source | What we receive |
|---|---|
| Google Search Console and Google Analytics 4 | If you connect these accounts, we receive search performance data (clicks, impressions, queries, pages) and user behaviour metrics. Our access is limited to the scopes you approve on the Google OAuth consent screen, and our use of that data is governed by Section 18 |
| Other integrations you connect | Where you connect another third-party service — a CDN log source, a CMS, a CRM — we receive the data that integration is configured to share, in accordance with your settings and that provider's terms |
| Payment processor | Transaction status, subscription state and limited billing metadata from Stripe |
| Business contact data providers | Business contact details (name, job title, employer, work email, professional profile links) about prospective business customers. The providers we use are named in Annex A. Where we obtain your details this way we will tell you, at the latest in our first communication with you, which provider we obtained them from and how to object |
| Publicly available sources | Company information, website content and public professional profiles, used for prospect research and for the competitive and citation analysis the Services perform |
We do not knowingly collect special categories of personal data (Article 9 EU GDPR). Other than the account credentials described in Section 3.1, we do not collect "sensitive personal information" as defined by the CPRA, and we do not process any personal data in order to infer sensitive characteristics about individuals or to build behavioural profiles of them. Customers must not submit special-category data through the Services unless expressly agreed with us in writing.
If we ever intend to process your personal data for a purpose other than the one it was collected for, we will inform you of that purpose and give you the information required by Article 13(3) EU GDPR before we begin.
Understanding what GeoGenie actually processes explains why the privacy footprint of the Services is narrow.
The Services measure and improve how a brand appears in generative AI engines and AI-powered search. To do that, we process:
The Services are not designed to process personal data about individuals as their subject matter. In the ordinary course, the only personal data a customer deliberately places in the platform is the business contact data of its own Users. A customer may nonetheless choose to submit more — by uploading a content asset containing personal data, or connecting an integration that carries contact records. Where that happens we act as a processor under Annex B, and the customer remains responsible for the lawfulness of that submission.
Where the EU GDPR, UK GDPR or FADP applies, we rely on the following legal bases. Where more than one is listed, they apply to different aspects of the same activity.
| Purpose | Personal data used | Legal basis |
|---|---|---|
| Creating and administering accounts; authenticating Users | Account data | Contract — Art. 6(1)(b) |
| Providing, maintaining and supporting the Services | Account data, usage data, Customer Content | Contract — Art. 6(1)(b); as processor, on the customer's instructions |
| Retrieving and analysing data from a Google Search Console or Google Analytics 4 account you connect | Google API data for your own properties | Contract — Art. 6(1)(b), performed on the scopes you authorise at the Google OAuth consent screen; as processor, on the customer's instructions. Use is additionally restricted by Section 18.1 |
| Processing payments, invoicing and collections | Billing data | Contract — Art. 6(1)(b) |
| Retaining accounting, tax and corporate records | Billing data, contract data | Legal obligation — Art. 6(1)(c) |
| Responding to support requests and enquiries | Communications data, account data | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) (running an effective support function) |
| Product analytics; measuring feature adoption; improving and developing the Services | Usage and telemetry data | Consent — Art. 6(1)(a), obtained through our consent banner before any information is stored on or read from your device, and relied on for the subsequent analysis of that data |
| Securing the Services; detecting, investigating and preventing fraud, abuse and unauthorised access | Log and security data, account data | Legitimate interests — Art. 6(1)(f) (protecting our systems, our customers and their data); legal obligation — Art. 6(1)(c) where applicable |
| Sending service, security and administrative notices | Account data | Contract — Art. 6(1)(b) |
| Sending marketing communications and newsletters | Marketing data | Consent — Art. 6(1)(a). In the limited case of existing customers receiving information about comparable services, legitimate interests — Art. 6(1)(f), subject to an opt-out in every message |
| Business-to-business prospecting and contact enrichment | Business contact data | Legitimate interests — Art. 6(1)(f) (promoting our Services to relevant businesses), subject to a balancing test and an unconditional right to object. Where we contact a named individual by electronic means, we obtain consent first wherever national law requires it — including Germany (§7(2) UWG) and the United Kingdom (PECR reg. 22) |
| Hosting events and webinars | Marketing data, communications data | Contract — Art. 6(1)(b); consent — Art. 6(1)(a) |
| Recruitment | Recruitment data | Pre-contractual steps — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Producing aggregated, de-identified statistics about platform usage and AI-search trends | De-identified usage data | Legitimate interests — Art. 6(1)(f). Once data has been aggregated and de-identified so that individuals can no longer be singled out, it is no longer personal data |
| Establishing, exercising or defending legal claims; corporate transactions | Any of the above, as relevant | Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
You may object at any time to processing based on legitimate interests. Where you object to direct marketing we will stop without exception. Where you object to other legitimate-interest processing we will stop unless we can demonstrate compelling legitimate grounds that override your interests. You can obtain a summary of the balancing test for any legitimate interest we rely on by writing to privacy@geogenie.ai.
Where we rely on your consent you may withdraw it at any time, and withdrawing is as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The current list of our sub-processors is published in Annex A to this Policy. You do not need to email us for it.
Notice of changes. Before we engage a new sub-processor or replace an existing one, we will give at least 30 days' advance notice by updating Annex A and notifying account administrators by email. Customers may subscribe to sub-processor change notifications at privacy@geogenie.ai.
Right to object. A customer may object to a new sub-processor on reasonable data-protection grounds by writing to privacy@geogenie.ai within the notice period, setting out those grounds. We will work in good faith to make a commercially reasonable change that avoids the objection. If we cannot do so within 30 days, the customer may terminate the affected Services without penalty and receive a refund of prepaid, unused fees for the terminated portion of the then-current term. This right, and the process for exercising it, are set out in full in clause 6 of Annex B, which prevails in the event of any difference.
Where data is hosted. GeoGenie is a United States company and hosts the Services in the United States. EU-region hosting is not currently available. Personal data we collect — including Customer Content — is transferred to and processed in the United States, and may be accessed by our sub-processors and by our personnel and contractors in the locations listed in Annex A.
If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred to a country that has not received an adequacy decision covering all recipients. We apply the following safeguards.
| Origin | Transfer mechanism |
|---|---|
| EEA | The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, incorporated into Annex B and into our agreements with each sub-processor |
| United Kingdom | The UK International Data Transfer Addendum (version B1.0) to the EU SCCs, issued by the Information Commissioner, as completed in clause 12.3 of Annex B |
| Switzerland | The EU SCCs with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner, as set out in clause 12.4 of Annex B |
| Elsewhere | Standard contractual clauses, adequacy findings or other lawful mechanisms recognised in the relevant jurisdiction |
Obtaining a copy. You may obtain a copy of the Standard Contractual Clauses and the UK Addendum as we have entered into them, with commercially confidential terms redacted, by writing to privacy@geogenie.ai. This is available to any individual, not only to our customers.
Onward transfers to sub-processors. Where a US sub-processor transfers personal data onward, that transfer is governed by Clause 8.8 of the SCCs and by the terms of our agreement with that sub-processor. Where a sub-processor is self-certified under the EU–U.S. Data Privacy Framework and its UK Extension and Swiss–U.S. counterpart, we may rely on that certification as an additional safeguard for transfers to that provider. GeoGenie itself is not currently certified under the Data Privacy Framework and does not rely on it for transfers to GeoGenie. Current certification status for any provider can be verified at dataprivacyframework.gov.
Supplementary measures. In addition to the contractual safeguards above, we apply the technical and organisational measures described in Section 10 and in Annex II to Annex B, including encryption in transit and at rest, strict access controls and data minimisation. We have carried out transfer impact assessments for the transfers described in this Section; a summary is available on request at privacy@geogenie.ai.
Government access requests. We will challenge any government or law-enforcement request for personal data that we consider unlawful or overbroad, and will notify the affected customer wherever we are legally permitted to do so.
We keep personal data only as long as we need it for the purpose it was collected for, plus any period required by law.
| Data | Retention period |
|---|---|
| Account data | For the life of the account, then deleted within 90 days of account closure |
| Customer Content and Generated Content | For the life of the subscription. On termination, available for export for 30 days, then returned or deleted at the customer's choice, in accordance with clause 10 of Annex B |
| Free trial data | Deleted within 30 days of the end of the trial period if the trial does not convert |
| Billing, invoicing and tax records | 7 years from the end of the relevant tax year, or longer where a local statutory retention period requires it |
| Contracts and order forms | Term of the contract plus 6 years |
| Product usage and telemetry | 24 months in identifiable or pseudonymised form; aggregated statistics may be kept indefinitely |
| Server, access and security logs | 12 months, or longer where needed for an active security or fraud investigation |
| AI agent and bot traffic logs | 13 months, with IP addresses truncated or pseudonymised on ingestion |
| AI visibility, crawl and citation data | 24 months, or the period specified in the customer's order form |
| Google Search Console and Google Analytics 4 data | Cached only for as long as the integration is connected. Purged when you disconnect the integration or delete your account, and in any event within 30 days of disconnection |
| Support tickets and correspondence | 3 years from the last interaction |
| Marketing contact records | Until you unsubscribe or object, after which we keep a minimal suppression record indefinitely so that we can continue to honour your opt-out |
| Consent and cookie preference records | 3 years from the date of the record, as evidence of consent |
| Recruitment data | 6 months after the hiring decision, unless you consent to a longer period |
| Backups | Backups are encrypted and expire on a rolling 35-day cycle. Data deleted from production is removed from backups within that cycle |
Where we are required to retain data for legal, tax, accounting or dispute-resolution purposes, we restrict processing of that data to those purposes only.
We maintain administrative, technical and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss and destruction. The full set is at Annex II to Annex B; this is the summary.
Current maturity. We are transparent about where we are. GeoGenie does not currently hold an ISO 27001 or SOC 2 certification of its own; independent penetration testing and formal certification are on our security roadmap. Our infrastructure providers hold those certifications for the facilities and platforms they operate. Current status, and our latest security documentation, are available to customers and prospects at security@geogenie.ai.
Breach notification. Where we become aware of a personal data breach affecting Customer Content, we will notify the affected customer without undue delay and in any event within 72 hours of confirming that a breach has occurred, with the information required by Article 33(3) EU GDPR to the extent available to us at the time. Where information is not all available at once we will provide it in phases. Where we are a controller, we will notify the competent supervisory authority and, where the breach is likely to result in a high risk to individuals, the affected individuals, as required by applicable law.
No system can be guaranteed completely secure. You are responsible for the security of your own credentials, devices and networks, and for configuring access within your account appropriately.
The Services use artificial intelligence, including large language models supplied by third-party providers. This section explains precisely what that means for personal data.
We do not use Customer Content to train generative AI models or foundation models. We may use aggregated, de-identified data derived from use of the Services — which does not identify you, your Users or your Customer Content — to operate, improve and develop the Services. Where data has been aggregated and de-identified we commit to maintain that de-identification, not to attempt to re-identify it, and to require the same of any recipient.
Our agreements and the applicable API terms with the AI providers listed in Annex A prohibit them from using the content we send them to train their own general-purpose or foundation models. We impose an equivalent restriction on every sub-processor we engage.
Data received from Google APIs is never used to train, retrain or improve any AI model, and is never sent to a third-party AI provider. See Section 18.1.
We send the following to third-party AI providers such as OpenAI and Anthropic:
We design the Services so that Customer Content containing personal data is not sent to third-party AI providers, and our contractual terms prohibit customers from submitting special-category or other sensitive personal data. Two honest qualifications:
If we introduce a feature that requires personal data to be processed by an AI provider by design, we will update Annex A and this Section and give notice under Sections 7 and 19 before the change takes effect.
Generated Content is produced with the assistance of AI systems and reflects the output of third-party AI engines, which are outside our control. It may be inaccurate, incomplete, out of date, biased or unsuitable for a particular purpose, and may include fabricated statements. You are responsible for reviewing Generated Content before relying on it. We do not warrant that any particular AI visibility, ranking, mention or citation result will be achieved.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning individuals or similarly significantly affects them, within the meaning of Article 22 EU GDPR.
The Services generate scores, rankings and classifications — visibility scores, share of voice, citation rates, bot classifications — but these relate to brands, domains, prompts and content, not to individuals, and they are presented to human users for review rather than used to make decisions about people.
If you are in the EEA, the United Kingdom or Switzerland, you have the following rights in relation to personal data for which we are the controller.
| Right | What it means |
|---|---|
| Access | Obtain confirmation of whether we process your personal data and, if so, a copy of it and information about how it is processed |
| Rectification | Have inaccurate personal data corrected and incomplete data completed |
| Erasure | Have your personal data deleted where one of the grounds in Article 17 applies |
| Restriction | Have processing restricted in the circumstances set out in Article 18 |
| Portability | Receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible |
| Objection | Object to processing based on our legitimate interests, and object at any time and without qualification to direct marketing |
| Withdraw consent | Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing |
| Automated decisions | Not be subject to a decision based solely on automated processing with legal or similarly significant effects. We do not make such decisions — see Section 13 |
| Complain | Lodge a complaint with a supervisory authority |
We would appreciate the chance to address your concern before you approach a regulator. Please write to privacy@geogenie.ai first.
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising any of them.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
Categories of personal information collected in the preceding twelve months:
| CCPA category | Collected | Sold | Shared for cross-context behavioural advertising | Disclosed for a business purpose |
|---|---|---|---|---|
| Identifiers (name, email, IP address, account ID) | Yes | No | No | Yes — to sub-processors |
| Customer records (Cal. Civ. Code § 1798.80) | Yes | No | No | Yes — to sub-processors |
| Commercial information (subscriptions, transactions) | Yes | No | No | Yes — to sub-processors |
| Internet or network activity (usage, telemetry, logs) | Yes | No | No | Yes — to sub-processors |
| Geolocation data (approximate, IP-derived) | Yes | No | No | Yes — to sub-processors |
| Professional or employment information (job title, employer) | Yes | No | No | Yes — to sub-processors |
| Sensitive personal information — account log-in credentials only | Yes | No | No | Yes — to our authentication and hosting sub-processors |
| Sensitive personal information — all other subcategories | No | No | No | No |
| Inferences | No | No | No | No |
| Biometric information | No | No | No | No |
| Audio, electronic or visual information | Only where we have told you a call is being recorded and, where required, obtained consent | No | No | Yes — to sub-processors |
| Education information | No | No | No | No |
The sources, business purposes and retention periods for each category are described in Sections 3, 5 and 9.
Limiting the use of sensitive personal information. The only sensitive personal information we collect is your account log-in credentials, which we use solely to authenticate you and secure your account. Because we do not use or disclose sensitive personal information for any purpose beyond those permitted by §1798.121(a) CPRA, the right to limit does not apply to our processing. We will honour a request to limit as a matter of course if you make one.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
Authorised agents. You may use an authorised agent to submit a request. We will require written proof of authorisation and may require you to verify your own identity directly.
If you are a resident of a US state with a comprehensive consumer privacy law that applies to us — currently including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — you have the rights that law gives you, which generally include confirming and accessing your personal data, correcting it, deleting it, obtaining a portable copy, and opting out of targeted advertising, sale and certain profiling. Not every state grants every right; where a right exists under your state's law, we will honour it.
We do not engage in targeted advertising, sale, or profiling with legal or similarly significant effects.
Appeals. Where your state's law gives you a right to appeal a decision we make on your request, you may appeal by replying to our decision or writing to privacy@geogenie.ai with the subject line PRIVACY APPEAL. We will respond within the period your state's law allows — 45 days in most states, 60 in some — and will tell you which applies. If we deny your appeal, we will tell you how to contact your state Attorney General.
Email privacy@geogenie.ai with the subject line DATA PROTECTION REQUEST (or CALIFORNIA PRIVACY REQUEST or PRIVACY APPEAL, as applicable). Tell us which right you wish to exercise and give us enough detail to locate your data.
Verification. We will take reasonable steps to verify your identity before acting, which may mean asking you to respond from the email address associated with your data or to provide additional information. Information provided for verification is used for that purpose only and then deleted.
Timing. We respond within one month for requests under the EU GDPR, UK GDPR or FADP, extendable by two further months for complex or numerous requests, and within the period allowed by the applicable state law for US requests — typically 45 days, extendable once where reasonably necessary. We will tell you if we need an extension and why.
Cost. Free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will explain why.
Requests about Customer Content. If your request concerns personal data that one of our customers submitted to the Services, we act as a processor. We will forward your request to that customer without undue delay and assist them in responding, but we cannot action it directly.
The Services are intended for business use by individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18, and the Services are not directed at children.
If you believe a person under 18 has provided us with personal data, contact privacy@geogenie.ai and we will delete it promptly.
GeoGenie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
When you connect any other integration, data flows between GeoGenie and that provider according to the permissions you grant, and the provider's own privacy policy governs its handling of that data. Review it before connecting. You can disconnect an integration at any time from your account settings.
The Services and our websites contain links to third-party websites and services that we do not control. This Policy does not apply to them.
We may update this Policy to reflect changes in our practices, our sub-processors, technology or the law.
Where a change requires your consent under applicable law, we will obtain it before the change applies to you.
Annex B is not changed unilaterally. Annex B is a contract between GeoGenie and each customer. Nothing in this Section allows us to amend Annex B, the Standard Contractual Clauses, or the technical and organisational measures in Annex II other than as clause 5.2 of Annex B permits. Changes to Annex B are made in accordance with the amendment provisions of the Agreement. The only part of Annex B we maintain unilaterally is the sub-processor list at Annex III, and only through the notice-and-objection process in clause 6.
GeoGenie Inc.
251 Little Falls Drive
Wilmington, New Castle County
Delaware 19808
United States
| Purpose | Contact |
|---|---|
| Privacy questions, data subject requests, sub-processor notifications | privacy@geogenie.ai |
| Legal notices | legal@geogenie.ai |
| Billing | billing@geogenie.ai |
| Customer support | cs@geogenie.ai |
| Security questions and vulnerability reports | security@geogenie.ai |
Privacy matters at GeoGenie are handled by our privacy team, reachable at privacy@geogenie.ai. We are not required to designate a data protection officer under Article 37 EU GDPR and have not done so; if that changes, we will name them here.
Governing law. This Section applies to this Policy only and does not apply to Annex B, which is governed by clause 14.3 of Annex B, nor to the Standard Contractual Clauses and the UK Addendum, which are governed by clauses 12.2 and 12.3 of Annex B.
This Policy is governed by the laws of the State of Delaware, without regard to its conflict of law principles. Nothing in this paragraph limits any mandatory right you have under the law of your country of residence — including your right under Article 79 EU GDPR to bring proceedings before the courts of the Member State where you reside or where we have an establishment, and your right to complain to your local supervisory authority.
Last updated: September 1, 2026
These are the sub-processors GeoGenie engages as at the date above. See Section 7 for how we notify customers of changes and how to object. Annex III to Annex B incorporates this list by reference.
| Sub-processor | Entity and location | Purpose | Data processed | Retention | Transfer mechanism |
|---|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services, Inc. — United States | Cloud infrastructure: compute, storage, database and networking for the platform | All Customer Content; account data; log data | For the term of the Agreement, then per Section 9 | EU SCCs (Modules 2 and 3) + UK Addendum, under the AWS GDPR Data Processing Addendum |
| Google Cloud | Google LLC, with Google Cloud EMEA Limited (Ireland) as contracting entity where applicable — United States | Cloud infrastructure and services supporting the platform | Customer Content; account data; log data | For the term of the Agreement, then per Section 9 | EU SCCs (Modules 2 and 3) + UK Addendum; EU–U.S. Data Privacy Framework where certified |
| OpenAI | OpenAI, L.L.C. — United States | Large language model API used to generate and analyse prompts, briefs and summaries | Prompts, brand and topic terms, publicly available web content retrieved for analysis. Not used for model training | Per OpenAI's API retention terms; no training on inputs | EU SCCs + UK Addendum; contractual prohibition on training |
| Anthropic | Anthropic, PBC — United States | Large language model API used to generate and analyse prompts, briefs and summaries | Prompts, brand and topic terms, publicly available web content retrieved for analysis. Not used for model training | Per Anthropic's API retention terms; no training on inputs | EU SCCs + UK Addendum; contractual prohibition on training |
These providers support our own operations. They do not have access to Customer Content.
| Sub-processor | Entity and location | Purpose | Data processed | Retention | Transfer mechanism |
|---|---|---|---|---|---|
| PostHog | PostHog, Inc. — United States | Product analytics and usage telemetry; feature-adoption analysis | Account identifiers, usage and telemetry data, IP address, device data | 24 months, per Section 9 | EU SCCs + UK Addendum |
| Google Workspace | Google LLC, contracting through Google Ireland Limited — United States, Ireland | Corporate email, calendar, documents, meetings and file storage | Communications data, marketing data, contract documents | Per Section 9 | EU SCCs + UK Addendum; EU–U.S. Data Privacy Framework where certified |
| Twilio-Sendgrid | Email delivery and marketing communications | Marketing data, communications data |
| Provider | Entity and location | Role | Purpose |
|---|---|---|---|
| Stripe | Stripe, Inc. / Stripe Payments Europe, Ltd. — United States, Ireland | Processor for payment processing on our instructions; independent controller for fraud prevention, anti-money-laundering and its own regulatory compliance | Payment processing, subscription billing, invoicing, tax calculation. Full card data is collected by Stripe directly through its hosted payment components and does not pass through GeoGenie's systems. Stripe's own privacy policy governs its controller-role processing |
GeoGenie personnel and contractors located in the following countries may access personal data, including Customer Content, in the course of providing and supporting the Services:
[TO BE COMPLETED — list every country in which employees or contractors with access to personal data are located, e.g. United States, Türkiye]
All are bound by written confidentiality obligations and by data-transfer terms incorporating the SCCs where required. GeoGenie has no subsidiaries or affiliates.
Any sub-processor we engage in future will be added to this Annex at least 30 days before it begins processing, and account administrators will be notified by email.
Version: 2.1 · Effective: September 1, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the GeoGenie Terms and Conditions or other written agreement between GeoGenie Inc. ("GeoGenie", "Processor") and the customer ("Customer", "Controller") governing the Customer's use of the Services (the "Agreement").
This DPA applies automatically. No signature or countersignature is required. A Customer that requires a separately executed copy, or wishes to negotiate an alternative form of DPA, may request one at privacy@geogenie.ai.
Order of precedence. In the event of a conflict, the following order applies: (1) the Standard Contractual Clauses and the UK Addendum incorporated by clause 12; (2) this DPA; (3) the Agreement; (4) the Privacy Policy.
Terms not defined here have the meaning given in the Agreement, in Section 2 of the Privacy Policy, or in applicable Data Protection Law.
"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR, the FADP, the CCPA as amended by the CPRA, and other US state privacy laws.
"Customer Personal Data" means Personal Data contained within Customer Content that GeoGenie processes on the Customer's behalf under the Agreement.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
2.1 The Customer is the Controller and GeoGenie is the Processor in respect of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, GeoGenie is a sub-processor and the Customer warrants that it has the authority of that controller to enter into this DPA.
2.2 GeoGenie is an independent controller in respect of the data identified as controller data in Section 1.1 of the Privacy Policy — account administration data, billing data, security and abuse-prevention data, and its own marketing, recruitment and compliance records. That processing is governed by the Privacy Policy, not by this DPA. Product usage telemetry generated by the Customer's Users is processed by GeoGenie as a controller for the purposes of securing, operating and improving the Services; the Customer may object to that characterisation and, on request, GeoGenie will process such telemetry as a processor under this DPA for that Customer, subject to any resulting limitation in analytics functionality.
2.3 This DPA applies for as long as GeoGenie processes Customer Personal Data.
3.1 GeoGenie will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which GeoGenie is subject. Where such a legal requirement applies, GeoGenie will inform the Customer before processing, unless the law prohibits it on important grounds of public interest.
3.2 The Agreement, this DPA, the Documentation, and the Customer's use and configuration of the Services constitute the Customer's complete documented instructions as at the effective date. Additional instructions require written agreement and may be subject to reasonable charges. For the avoidance of doubt, an amendment GeoGenie makes to the Privacy Policy does not alter the Customer's instructions or this DPA.
3.3 GeoGenie will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. GeoGenie may suspend performance of an instruction it reasonably believes to be unlawful until the instruction is confirmed or amended.
3.4 The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all required notices and obtained all required consents, and that its instructions comply with Data Protection Law. The Customer is responsible for the accuracy, quality and legality of Customer Personal Data.
3.5 The Customer will not submit special categories of personal data (Article 9 EU GDPR), sensitive personal information as defined by the CPRA, government identification numbers, financial account numbers, or personal data of children, through the Services, unless expressly agreed with GeoGenie in writing.
GeoGenie will ensure that any person authorised to process Customer Personal Data is subject to a written obligation of confidentiality that survives the end of their engagement, has been informed of the confidential nature of the data, and receives appropriate data-protection training.
5.1 GeoGenie will implement and maintain the technical and organisational measures set out in Annex II to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 EU GDPR.
5.2 GeoGenie may update those measures from time to time provided that the level of protection is not materially reduced. GeoGenie will notify the Customer of any material change.
6.1 The Customer grants GeoGenie general written authorisation to engage the Sub-processors listed in Annex III, within the meaning of Clause 9(a) Option 2 of the SCCs.
6.2 Before engaging a new Sub-processor or replacing an existing one, GeoGenie will give the Customer at least 30 days' notice by updating Annex III and notifying account administrators by email. This applies to every Sub-processor, whether or not it processes Customer Personal Data.
6.3 The Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice to privacy@geogenie.ai within the notice period, stating those grounds. The parties will work together in good faith to find a commercially reasonable alternative. If none can be found within 30 days of the objection, the Customer may terminate the affected Services on written notice and GeoGenie will refund prepaid, unused fees for the terminated portion of the then-current term.
6.4 GeoGenie will impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor's performance of those obligations as if it were GeoGenie's own, subject to clause 14.1.
7.1 Taking into account the nature of the processing, GeoGenie will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject requests under Chapter III EU GDPR and equivalent provisions of other Data Protection Law.
7.2 The Services provide self-service functionality allowing the Customer to access, export, correct and delete Customer Personal Data. Where the Customer cannot fulfil a request through the Services, GeoGenie will provide reasonable assistance; GeoGenie may charge for assistance that requires more than de minimis effort, at rates notified in advance.
7.3 If GeoGenie receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively but will forward the request to the Customer without undue delay.
Taking into account the nature of processing and the information available to it, GeoGenie will provide reasonable assistance to the Customer with:
9.1 GeoGenie will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of confirming that such a breach has occurred.
9.2 The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the information is not all available at once, GeoGenie will provide it in phases without undue further delay.
9.3 GeoGenie will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's reasonable requests in connection with the Customer's own notification obligations.
9.4 GeoGenie's notification is not an acknowledgement of fault or liability.
10.1 On termination or expiry of the Agreement, the Customer may export Customer Personal Data through the Services for 30 days.
10.2 At the Customer's choice, GeoGenie will either return Customer Personal Data to the Customer or delete it. The Customer may notify its choice at any time up to the end of the export period in clause 10.1. If the Customer does not notify a choice, GeoGenie will delete. GeoGenie will give effect to the Customer's choice within 90 days of termination, and will delete all existing copies, except:
10.3 GeoGenie will not substitute de-identification for deletion where the Customer has instructed deletion.
10.4 Data retained under clause 10.2 remains subject to this DPA and is processed only for the purpose that requires its retention.
10.5 GeoGenie will certify return or deletion in writing on the Customer's request.
11.1 GeoGenie will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 EU GDPR, including its current security documentation and any third-party audit reports, penetration test summaries or certifications it holds at the time of the request. GeoGenie's current certification status is stated in Section 10 of the Privacy Policy and in Annex II, item 6.
11.2 Where that information is insufficient, the Customer may carry out an audit, including an inspection, of GeoGenie's processing, subject to the following: audits take place no more than once in any twelve-month period, except following a Personal Data Breach or where required by a supervisory authority; on at least 30 days' written notice; during normal business hours; without unreasonably disrupting GeoGenie's operations; subject to confidentiality obligations; scoped to GeoGenie's processing of that Customer's Personal Data; and at the Customer's expense.
11.3 The Customer may appoint an independent third-party auditor, provided that auditor is not a competitor of GeoGenie and is bound by confidentiality obligations.
11.4 Clauses 11.1 to 11.3 are the mechanism by which the Customer may take reasonable and appropriate steps to ensure that GeoGenie uses Personal Data in a manner consistent with the Customer's obligations under the CPRA, for the purposes of §1798.100(d) and §7051(a)(5) of the CCPA Regulations.
12.1 The Customer authorises GeoGenie to transfer Customer Personal Data to the United States and to the Sub-processor locations listed in Annex III, subject to this clause.
Where GeoGenie processes Customer Personal Data subject to the EU GDPR and transfers it outside the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA and form part of it, with the following elections:
| SCC provision | Election |
|---|---|
| Module | Module Two (controller to processor) where the Customer is a controller; Module Three (processor to processor) where the Customer is a processor |
| Clause 7 (docking clause) | Applies |
| Clause 9 (sub-processors) | Option 2, general written authorisation, with the 30-day notice period in clause 6.2 above |
| Clause 11(a) (independent dispute resolution) | The optional wording does not apply |
| Clause 13 / competent supervisory authority | As stated in Annex I.C |
| Clause 17 (governing law) | Option 1 — the law of Ireland |
| Clause 18(b) (choice of forum) | The courts of Ireland |
| Annex I | Annex I to this DPA |
| Annex II | Annex II to this DPA |
| Annex III (list of sub-processors) | Annex III to this DPA |
Where GeoGenie processes Customer Personal Data subject to the UK GDPR and transfers it outside the United Kingdom to a country without UK adequacy regulations, the UK Addendum (version B1.0) is incorporated into this DPA and forms part of it, completed as follows. The Mandatory Clauses of the UK Addendum apply, and where they conflict with clause 12.2, the Mandatory Clauses prevail — including in relation to governing law and courts, which for UK transfers are those of England and Wales.
Table 1: Parties
| Exporter | Importer | |
|---|---|---|
| Start date | The effective date of the Agreement | The effective date of the Agreement |
| Parties' details | The Customer, as identified in the Agreement | GeoGenie Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States |
| Key contact | The Customer's account administrator or designated privacy contact | Privacy Team, privacy@geogenie.ai |
Table 2: Selected SCCs, Modules and Selected Clauses
The Addendum is appended to the EU SCCs as incorporated by clause 12.2 above, including the Appendix Information, with Module Two or Module Three applying as set out in clause 12.2, Clause 7 applying, Clause 9 Option 2 with a 30-day notice period, and Clause 11(a) optional wording not applying.
Table 3: Appendix Information
| Appendix | Location |
|---|---|
| Annex 1A — List of Parties | Annex I.A to this DPA |
| Annex 1B — Description of Transfer | Annex I.B to this DPA |
| Annex II — Technical and organisational measures | Annex II to this DPA |
| Annex III — List of Sub-processors | Annex III to this DPA |
Table 4: Ending this Addendum when the Approved Addendum changes
Which Parties may end this Addendum as set out in Section 19: neither Party.
Where GeoGenie processes Customer Personal Data subject to the FADP and transfers it outside Switzerland, the SCCs as incorporated by clause 12.2 apply with the following amendments, consistent with the FDPIC's recognition of the SCCs:
GeoGenie may rely on an alternative transfer mechanism recognised under Data Protection Law in place of the SCCs or the UK Addendum only where the Customer has agreed in writing, or where the alternative mechanism provides a level of protection at least equivalent to the mechanism it replaces and GeoGenie has given the Customer 30 days' prior notice. GeoGenie is not currently self-certified under the EU–U.S. Data Privacy Framework and does not rely on it for transfers from the Customer to GeoGenie. Onward transfers by Sub-processors are governed by Clause 8.8 of the SCCs.
GeoGenie will notify the Customer if it becomes unable to comply with the SCCs or the UK Addendum and, if it cannot remedy the position, the Customer may suspend the affected transfers or terminate the affected Services.
13.1 This clause applies where the Customer is a "business" and GeoGenie a "service provider", "processor" or equivalent under the CCPA as amended by the CPRA, or under another US state privacy law. The Customer discloses Customer Personal Data to GeoGenie only for the following limited and specified business purposes, and for no other purpose:
13.2 GeoGenie will not:
13.3 GeoGenie will comply with its obligations under the CPRA and will provide the same level of privacy protection as the CPRA requires of a business. GeoGenie will notify the Customer promptly if it determines it can no longer meet those obligations. The Customer has the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data; and the right, exercisable through clause 11, to take reasonable and appropriate steps to ensure that GeoGenie uses Customer Personal Data in a manner consistent with the Customer's obligations under the CPRA.
13.4 Where another US state privacy law applies, clauses 3 to 11 of this DPA apply for the purposes of that law's mandatory processor-contract requirements, including the Customer's right under clause 10 to direct deletion or return of Customer Personal Data.
13.5 GeoGenie certifies that it understands and will comply with the restrictions in this clause 13.
14.1 Each party's liability under this DPA, including under clause 6.4, is subject to the exclusions and limitations of liability in the Agreement. This does not limit either party's liability to Data Subjects under the SCCs or the UK Addendum, or any liability that Data Protection Law prohibits limiting.
14.2 If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force.
14.3 This DPA is governed by the law stated in the Agreement, except that clause 12.2 and the SCCs are governed by the law of Ireland, and clause 12.3 and the UK Addendum are governed by the law of England and Wales.
Data exporter (Controller, or Processor where clause 2.1 applies)
| Name and address | The Customer, as identified in the Agreement |
|---|---|
| Contact person | The Customer's account administrator, or the privacy contact designated by the Customer in its account settings |
| Activities relevant to the data transferred | Procuring and using the GeoGenie AI-search visibility platform to measure and improve the visibility of the Customer's brand in generative AI engines and AI-powered search; administering its account and Users; submitting Customer Content for analysis |
| Role | Controller (or Processor, where clause 2.1 applies) |
| Signature and date | By entering into the Agreement, the Customer is treated as having signed this Annex on the effective date of the Agreement |
Data importer (Processor)
| Name and address | GeoGenie Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States |
|---|---|
| Contact person | Privacy Team — privacy@geogenie.ai |
| Activities relevant to the data transferred | Providing, hosting, maintaining, securing and supporting the GeoGenie AI-search visibility platform and related services under the Agreement |
| Role | Processor |
| Signature and date | By making the Services available under the Agreement, GeoGenie is treated as having signed this Annex on the effective date of the Agreement |
| Categories of Data Subjects | The Customer's employees, contractors and other authorised Users of the Services; the Customer's own personnel and business contacts, and any other individuals, whose personal data the Customer chooses to include in Customer Content |
|---|---|
| Categories of Personal Data | Name, work email address, job title, employer, user and account identifiers, authentication data, access and usage logs, IP address, device and browser data; and any Personal Data the Customer chooses to include within Customer Content |
| Sensitive data | None is intended or permitted to be transferred. The Customer is contractually prohibited by clause 3.5 from submitting special-category data, sensitive personal information, government identifiers, financial account numbers or children's data without prior written agreement. Where such data is nonetheless submitted, GeoGenie applies the measures in Annex II without distinction |
| Frequency of transfer | Continuous, for the duration of the Agreement |
| Nature of processing | Collection, recording, organisation, structuring, storage, retrieval, analysis, generation of derived reports and recommendations, transmission, restriction, erasure and destruction |
| Purpose of processing | Providing, maintaining, securing and supporting the Services in accordance with the Agreement; measuring and improving the Customer's brand visibility in generative AI engines and AI-powered search |
| Retention period | For the duration of the Agreement, plus the periods set out in clause 10 of this DPA and Section 9 of the Privacy Policy |
| Sub-processors — subject matter, nature and duration | As listed in Annex III, which states the subject matter and nature of each Sub-processor's processing. Each Sub-processor processes for the duration of the Agreement plus the retention periods stated in Annex A to the Privacy Policy, after which processing ceases in accordance with clause 10 |
The competent supervisory authority under Clause 13 of the SCCs is determined as follows:
For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office. For transfers subject to the FADP, it is the Swiss Federal Data Protection and Information Commissioner.
GeoGenie implements and maintains at least the following measures. GeoGenie may update them under clause 5.2 provided the level of protection is not materially reduced.
1. Pseudonymisation and encryption Data in transit between the Customer and the Services, and between GeoGenie's production systems, is encrypted using TLS 1.2 or higher. Data at rest, including backups, is encrypted using AES-256 or an equivalent standard. Encryption keys are managed through a dedicated key-management service with restricted access. IP addresses in AI bot traffic logs are truncated or pseudonymised on ingestion.
2. Confidentiality — access control Role-based access control on least-privilege principles. Multi-factor authentication for personnel access to production systems and to the corporate identity provider. Production access is limited to named personnel with a documented business need. Break-glass and automated service-account access paths are individually documented, restricted and logged. Access is reviewed at least quarterly and revoked promptly on role change or departure. Administrative actions are logged.
3. Confidentiality — system and physical access Production environments are logically segregated from development and staging. Network access is restricted by firewall and security-group policy, with no direct public access to data stores. Physical security of the data-centre facilities is provided by Amazon Web Services and Google Cloud under their own certifications, which include ISO 27001 and SOC 2. These are the infrastructure providers' certifications; GeoGenie's own certification status is stated in item 6 below.
4. Integrity Input validation and output encoding. Change management with peer code review before merge. Static analysis and dependency vulnerability scanning in the build pipeline. Separation of duties between development and deployment. Centralised, tamper-resistant audit logging of security-relevant events.
5. Availability and resilience Automated, encrypted backups on a rolling 35-day cycle. Recovery point and recovery time objectives are defined and are available to customers on request at security@geogenie.ai. Backup restoration is tested at least annually. Infrastructure is deployed across multiple availability zones. Monitoring and alerting on availability and error rates.
6. Regular testing and evaluation Periodic internal security review and continuous automated vulnerability scanning of infrastructure and dependencies. GeoGenie does not currently hold an ISO 27001 or SOC 2 certification of its own; independent penetration testing and formal certification are on GeoGenie's security roadmap. Current status is available at security@geogenie.ai.
7. Data minimisation and purpose limitation Only data necessary for the Services is collected. Retention periods are defined and enforced as set out in Section 9 of the Privacy Policy. The Services are designed so that Customer Content containing personal data is not transmitted to third-party AI providers, subject to the two qualifications stated in Section 12.2 of the Privacy Policy (personal data appearing in publicly available web content retrieved for analysis, and personal data a Customer chooses to place in its own prompts or uploads).
8. Personnel Written confidentiality undertakings for all personnel with access to personal data. Security and data-protection training on onboarding and at least annually thereafter. Documented onboarding and offboarding procedures including prompt access revocation.
9. Sub-processor governance Data-protection and security review before engagement. A written data-processing agreement in every case, with obligations no less protective than this DPA. Periodic review of the sub-processor list.
10. Incident management A documented incident-response plan with defined roles, severity classification, escalation paths, customer-notification procedures meeting clause 9, and a documented post-incident review.