Privacy Policy

    GeoGenie Inc.

    Effective date: Sep 1st 2026

    At a glance

    This summary is for convenience only. The full Policy below governs.

    Who we areGeoGenie Inc., a Delaware corporation. We operate the GeoGenie AI-search visibility platform at geogenie.ai.
    Two different rolesFor our website, marketing and account data we are a controller. For the Customer Content our business customers put into the platform we are a processor, acting on their instructions under the Data Processing Agreement in Annex B.
    Do we sell personal data?No. We do not sell personal data and we do not share it for cross-context behavioural advertising or targeted advertising.
    Do we train AI models on your data?No. We do not use Customer Content to train generative AI models, and we require our AI providers not to train on what we send them. See Section 12.
    What do we send to the AI engines?Prompts, brand and topic terms, and publicly available web content. We do not send Customer Content containing personal data to them. Publicly available web content that we retrieve for analysis can itself contain personal data — for example the name of an article's author. See Section 12.2.
    Where is data hosted?The United States. Transfers out of the EEA, UK and Switzerland are covered by Standard Contractual Clauses. See Section 8.
    Google Search Console and GA4If you connect them, we use that data only to produce your reports inside GeoGenie — never for advertising and never to train models. Our use adheres to the Google API Services User Data Policy, including its Limited Use requirements. See Section 18.
    Sub-processorsPublished in full in Annex A, with 30 days' advance notice of changes and a right to object.
    Data Processing AgreementAnnex B. It applies automatically to every customer — you do not need to sign it or ask for it.
    Contactprivacy@geogenie.ai

    Table of contents

    1. Scope and our role
    2. Definitions
    3. Personal data we collect
    4. Customer Content and how the platform works
    5. Why we process personal data and our legal bases
    6. How we share personal data
    7. Sub-processors
    8. International data transfers
    9. How long we keep data
    10. Security
    11. Cookies and similar technologies
    12. Artificial intelligence: what we do and do not do
    13. Automated decision-making and profiling
    14. Your rights — EEA, United Kingdom and Switzerland
    15. Your rights — United States
    16. How to exercise your rights
    17. Children
    18. Connected integrations, Google API Services and third-party links
    19. Changes to this Policy
    20. How to contact us

    Annex A — Sub-processor list

    Annex B — Data Processing Agreement

    1. Scope and our role

    This Privacy Policy ("Policy") explains how GeoGenie Inc. ("GeoGenie", "we", "us", "our") collects, uses, discloses and protects personal data.

    It covers:

    • the GeoGenie platform and applications, including ContextGenie, PromptsGenie, MonitoringGenie, CitationsGenie, ActionsGenie, SiteGenie and Agent Analytics (together, the "Services");
    • our websites at geogenie.ai and its subdomains;
    • our sales, marketing, event and support activities; and
    • our advisory and managed-service engagements.

    1.1 We act in two distinct roles

    Most questions about a specific piece of data are answered by working out which of these two roles applies to it.

    We are a controller when we decide why and how personal data is processed. This applies to:

    • data about people who visit our websites, request a demo, subscribe to our communications or attend our events;
    • data about the individual users and administrators of a customer account — names, work email addresses, authentication data;
    • billing and contract data about our customers; and
    • data we process for our own security, fraud prevention, accounting and legal-compliance purposes.

    We are a processor when we process Customer Content on behalf of a business customer. Our customer is the controller; we act only on their documented instructions. This applies to any personal data a customer chooses to submit into the platform — for example, personal data appearing inside content assets uploaded for analysis, or contact records carried in by an integration the customer connects.

    Where we act as a processor, our processing is governed by the Data Processing Agreement at Annex B. If you are an individual whose personal data was submitted to us by one of our customers, please direct your privacy request to that customer in the first instance; we will refer such requests to them and assist them in responding.

    1.2 The Services are for business use

    The Services are offered to businesses and their personnel. They are not directed at consumers and not directed at children. See Section 17.

    2. Definitions

    Capitalised terms used but not defined here have the meaning given in the GeoGenie Terms and Conditions at geogenie.ai/terms.

    TermMeaning
    Customer ContentAny data, information, text, files, URLs, brand assets, prompts or other content that a customer or its Users submit to the Services.
    Generated ContentReports, visibility scores, analyses, briefs, recommendations and other output the Services produce from Customer Content and inputs.
    Personal dataInformation relating to an identified or identifiable natural person. Where a US state privacy law applies, this includes "personal information" as defined by that law.
    Controller / ProcessorAs defined in the EU GDPR and UK GDPR. Under CCPA/CPRA, "controller" corresponds broadly to "business" and "processor" to "service provider".
    Sub-processorA third party engaged by us to process personal data on our behalf in providing the Services.
    EU GDPRRegulation (EU) 2016/679.
    UK GDPRThe EU GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.
    FADPThe Swiss Federal Act on Data Protection, as revised with effect from 1 September 2023.
    SCCsThe Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
    UK AddendumThe International Data Transfer Addendum to the EU SCCs (version B1.0) issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.

    3. Personal data we collect

    3.1 Data you give us

    CategoryExamplesSource
    Account dataName, work email address, password hash or single sign-on identifier, job title, company name, account role and permissions, workspace and project namesYou, or an administrator of your organisation
    Billing dataBilling contact, billing address, VAT or tax identification number, purchase order references, plan and subscription details, card brand and last four digitsYou. Full card numbers are collected and processed by Stripe directly through its hosted payment components and do not pass through GeoGenie's systems
    Communications dataThe content of emails, support tickets, chat messages, demo requests, survey responses and notes we take during calls; scheduling preferencesYou
    Marketing dataContact details submitted through forms, gated content downloads, webinar and event registrations, communication preferences and consent recordsYou, or the event organiser
    Recruitment dataCV, cover letter, work history and other application materialsYou, or a recruitment platform on your behalf

    Is providing this data required? Account data and billing data are necessary for us to enter into and perform a contract with you. If you do not provide them we cannot create your account, give you access to the Services or bill you. Everything else is optional: you are free not to give it, and the only consequence is that we cannot provide the corresponding feature — for example, we cannot answer a support request you do not send, or register you for an event without a registration. No provision of personal data to us is required by statute.

    Calls and meetings. We do not record calls or meetings unless we tell you at the start of the call and, where the law of your jurisdiction requires it, obtain your consent. Where you decline, we take written notes instead.

    Account credentials. Log-in credentials are treated as "sensitive personal information" under the CPRA. We use them solely to authenticate you and to secure your account. We do not use or disclose them for any purpose that would give rise to a right to limit their use under §1798.121 CPRA.

    3.2 Data we collect automatically

    CategoryExamplesNotes
    Device and connection dataIP address, browser type and version, operating system, device type, language, screen dimensions
    Usage and product telemetryPages and screens viewed, features used, buttons clicked, reports run, session duration, timestamps, referring URLCollected through PostHog, and only after consent where consent is required. See Section 11
    Approximate locationCountry, region and city inferred from IP addressWe do not collect precise GPS or device-level location data
    Log and security dataAccess logs, authentication events, API request metadata, error traces, rate-limit and abuse signals
    Cookie and consent dataCookie identifiers, consent choices and their timestampsSee Section 11

    3.3 Data we obtain from third parties

    SourceWhat we receive
    Google Search Console and Google Analytics 4If you connect these accounts, we receive search performance data (clicks, impressions, queries, pages) and user behaviour metrics. Our access is limited to the scopes you approve on the Google OAuth consent screen, and our use of that data is governed by Section 18
    Other integrations you connectWhere you connect another third-party service — a CDN log source, a CMS, a CRM — we receive the data that integration is configured to share, in accordance with your settings and that provider's terms
    Payment processorTransaction status, subscription state and limited billing metadata from Stripe
    Business contact data providersBusiness contact details (name, job title, employer, work email, professional profile links) about prospective business customers. The providers we use are named in Annex A. Where we obtain your details this way we will tell you, at the latest in our first communication with you, which provider we obtained them from and how to object
    Publicly available sourcesCompany information, website content and public professional profiles, used for prospect research and for the competitive and citation analysis the Services perform

    We do not knowingly collect special categories of personal data (Article 9 EU GDPR). Other than the account credentials described in Section 3.1, we do not collect "sensitive personal information" as defined by the CPRA, and we do not process any personal data in order to infer sensitive characteristics about individuals or to build behavioural profiles of them. Customers must not submit special-category data through the Services unless expressly agreed with us in writing.

    3.4 Further processing

    If we ever intend to process your personal data for a purpose other than the one it was collected for, we will inform you of that purpose and give you the information required by Article 13(3) EU GDPR before we begin.

    4. Customer Content and how the platform works

    Understanding what GeoGenie actually processes explains why the privacy footprint of the Services is narrow.

    The Services measure and improve how a brand appears in generative AI engines and AI-powered search. To do that, we process:

    • Prompts and query sets — the natural-language questions we run against AI engines on a customer's behalf. These are designed to be about brands, products, categories and topics. Customers write and edit their own prompts, so a customer could in principle include personal data in one; we ask that they do not.
    • Brand, competitor and topic terms — supplied by the customer or derived from public sources.
    • Publicly available web content — pages, articles, listings and citation sources that we crawl or retrieve to analyse how AI engines source their answers. Public web pages routinely contain personal data such as author names and quoted individuals, and that data is processed as an unavoidable part of analysing the page.
    • AI engine responses — the answers and cited sources returned by third-party AI platforms in response to our queries.
    • Site and technical audit data — structured data, schema markup, robots directives and crawlability signals for a customer's domains.
    • Connected Google Search Console and Google Analytics 4 data — where a customer connects those accounts, search performance and traffic metrics for the customer's own properties, used to produce that customer's reports. See Section 18.
    • AI agent and bot traffic logs — where a customer connects CDN or server logs to Agent Analytics, we process request records to classify AI bot visits. These logs can contain IP addresses and user-agent strings. IP addresses are truncated or pseudonymised on ingestion, and we do not use them to identify individual human visitors.
    • Generated Content — the briefs, reports and recommendations the Services produce.

    The Services are not designed to process personal data about individuals as their subject matter. In the ordinary course, the only personal data a customer deliberately places in the platform is the business contact data of its own Users. A customer may nonetheless choose to submit more — by uploading a content asset containing personal data, or connecting an integration that carries contact records. Where that happens we act as a processor under Annex B, and the customer remains responsible for the lawfulness of that submission.

    6. How we share personal data

    We disclose personal data only in the circumstances set out below.

    Sub-processors and service providers. We use the third parties listed in Annex A to help us operate the Services and our business. Each is bound by a written data-processing agreement imposing confidentiality and security obligations materially equivalent to those in Annex B, and processes personal data only on our documented instructions and for the purposes we specify. Annex A identifies the small number of providers that act as independent controllers for part of their processing — principally payment providers meeting their own regulatory obligations — for which this instruction-only description does not apply.

    Professional advisers. Lawyers, accountants, auditors and insurers, bound by professional confidentiality obligations.

    Legal and regulatory disclosure. We may disclose personal data where required by applicable law, court order, subpoena or binding regulatory request, or where disclosure is necessary to establish, exercise or defend legal claims, to enforce our Terms and Conditions, or to protect the rights, property or safety of GeoGenie, our customers or the public. We will challenge any request we consider unlawful or overbroad. Where we act as a processor and receive a demand for Customer Content, we will, unless legally prohibited, notify the customer before disclosing and will seek to redirect the requesting authority to the customer.

    Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to the counterparty and its advisers subject to confidentiality obligations, and may be transferred as part of the transaction. We will notify affected customers of any resulting change of controller.

    At your direction. Where you instruct us to share data — for example by enabling an integration or sharing a report externally.

    6.1 What we do not do

    • We do not sell personal data. We have not sold personal data in the preceding twelve months.
    • We do not share personal data for cross-context behavioural advertising or targeted advertising, as those terms are defined under the CPRA and other US state privacy laws.
    • We do not disclose personal data to third parties for their own direct marketing purposes (California Civil Code § 1798.83).
    • We do not permit the providers we send data to, to use it to train their general-purpose or foundation models.

    7. Sub-processors

    The current list of our sub-processors is published in Annex A to this Policy. You do not need to email us for it.

    Notice of changes. Before we engage a new sub-processor or replace an existing one, we will give at least 30 days' advance notice by updating Annex A and notifying account administrators by email. Customers may subscribe to sub-processor change notifications at privacy@geogenie.ai.

    Right to object. A customer may object to a new sub-processor on reasonable data-protection grounds by writing to privacy@geogenie.ai within the notice period, setting out those grounds. We will work in good faith to make a commercially reasonable change that avoids the objection. If we cannot do so within 30 days, the customer may terminate the affected Services without penalty and receive a refund of prepaid, unused fees for the terminated portion of the then-current term. This right, and the process for exercising it, are set out in full in clause 6 of Annex B, which prevails in the event of any difference.

    8. International data transfers

    Where data is hosted. GeoGenie is a United States company and hosts the Services in the United States. EU-region hosting is not currently available. Personal data we collect — including Customer Content — is transferred to and processed in the United States, and may be accessed by our sub-processors and by our personnel and contractors in the locations listed in Annex A.

    If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data is transferred to a country that has not received an adequacy decision covering all recipients. We apply the following safeguards.

    OriginTransfer mechanism
    EEAThe EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, incorporated into Annex B and into our agreements with each sub-processor
    United KingdomThe UK International Data Transfer Addendum (version B1.0) to the EU SCCs, issued by the Information Commissioner, as completed in clause 12.3 of Annex B
    SwitzerlandThe EU SCCs with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner, as set out in clause 12.4 of Annex B
    ElsewhereStandard contractual clauses, adequacy findings or other lawful mechanisms recognised in the relevant jurisdiction

    Obtaining a copy. You may obtain a copy of the Standard Contractual Clauses and the UK Addendum as we have entered into them, with commercially confidential terms redacted, by writing to privacy@geogenie.ai. This is available to any individual, not only to our customers.

    Onward transfers to sub-processors. Where a US sub-processor transfers personal data onward, that transfer is governed by Clause 8.8 of the SCCs and by the terms of our agreement with that sub-processor. Where a sub-processor is self-certified under the EU–U.S. Data Privacy Framework and its UK Extension and Swiss–U.S. counterpart, we may rely on that certification as an additional safeguard for transfers to that provider. GeoGenie itself is not currently certified under the Data Privacy Framework and does not rely on it for transfers to GeoGenie. Current certification status for any provider can be verified at dataprivacyframework.gov.

    Supplementary measures. In addition to the contractual safeguards above, we apply the technical and organisational measures described in Section 10 and in Annex II to Annex B, including encryption in transit and at rest, strict access controls and data minimisation. We have carried out transfer impact assessments for the transfers described in this Section; a summary is available on request at privacy@geogenie.ai.

    Government access requests. We will challenge any government or law-enforcement request for personal data that we consider unlawful or overbroad, and will notify the affected customer wherever we are legally permitted to do so.

    9. How long we keep data

    We keep personal data only as long as we need it for the purpose it was collected for, plus any period required by law.

    DataRetention period
    Account dataFor the life of the account, then deleted within 90 days of account closure
    Customer Content and Generated ContentFor the life of the subscription. On termination, available for export for 30 days, then returned or deleted at the customer's choice, in accordance with clause 10 of Annex B
    Free trial dataDeleted within 30 days of the end of the trial period if the trial does not convert
    Billing, invoicing and tax records7 years from the end of the relevant tax year, or longer where a local statutory retention period requires it
    Contracts and order formsTerm of the contract plus 6 years
    Product usage and telemetry24 months in identifiable or pseudonymised form; aggregated statistics may be kept indefinitely
    Server, access and security logs12 months, or longer where needed for an active security or fraud investigation
    AI agent and bot traffic logs13 months, with IP addresses truncated or pseudonymised on ingestion
    AI visibility, crawl and citation data24 months, or the period specified in the customer's order form
    Google Search Console and Google Analytics 4 dataCached only for as long as the integration is connected. Purged when you disconnect the integration or delete your account, and in any event within 30 days of disconnection
    Support tickets and correspondence3 years from the last interaction
    Marketing contact recordsUntil you unsubscribe or object, after which we keep a minimal suppression record indefinitely so that we can continue to honour your opt-out
    Consent and cookie preference records3 years from the date of the record, as evidence of consent
    Recruitment data6 months after the hiring decision, unless you consent to a longer period
    BackupsBackups are encrypted and expire on a rolling 35-day cycle. Data deleted from production is removed from backups within that cycle

    Where we are required to retain data for legal, tax, accounting or dispute-resolution purposes, we restrict processing of that data to those purposes only.

    10. Security

    We maintain administrative, technical and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss and destruction. The full set is at Annex II to Annex B; this is the summary.

    • Encryption. TLS 1.2 or higher for data in transit between you and the Services and between our production systems. AES-256 or equivalent for data at rest, including backups.
    • Access control. Role-based access on a least-privilege, need-to-know basis. Multi-factor authentication for personnel access to production systems, managed through a central identity provider. Access is reviewed on a defined cycle and revoked promptly on role change or departure.
    • Network and infrastructure. Production environments segregated from development and staging, firewalled, with no direct public access to data stores, and centralised logging and monitoring.
    • Secure development. Peer code review before merge, dependency and vulnerability scanning in the build pipeline, secrets management.
    • Resilience. Encrypted backups, restoration tested on a defined cycle, infrastructure deployed across multiple availability zones.
    • Personnel. Written confidentiality undertakings for everyone with access to personal data, security and data-protection training, and documented joining and leaving procedures.
    • Vendor management. Data-protection and security review before we engage a sub-processor, and a written data-processing agreement in every case.
    • Incident response. A documented plan with defined roles, severity classification, escalation paths and post-incident review.

    Current maturity. We are transparent about where we are. GeoGenie does not currently hold an ISO 27001 or SOC 2 certification of its own; independent penetration testing and formal certification are on our security roadmap. Our infrastructure providers hold those certifications for the facilities and platforms they operate. Current status, and our latest security documentation, are available to customers and prospects at security@geogenie.ai.

    Breach notification. Where we become aware of a personal data breach affecting Customer Content, we will notify the affected customer without undue delay and in any event within 72 hours of confirming that a breach has occurred, with the information required by Article 33(3) EU GDPR to the extent available to us at the time. Where information is not all available at once we will provide it in phases. Where we are a controller, we will notify the competent supervisory authority and, where the breach is likely to result in a high risk to individuals, the affected individuals, as required by applicable law.

    No system can be guaranteed completely secure. You are responsible for the security of your own credentials, devices and networks, and for configuring access within your account appropriately.

    11. Cookies and similar technologies

    In the EEA, the United Kingdom and Switzerland we store or read information on your device only where that is strictly necessary to provide a service you have requested, or where you have consented through our banner. Our banner offers "reject all" as prominently as "accept all" at the first layer, and you can change or withdraw your choices at any time through the cookie preferences link in our website footer. Withdrawing consent is as easy as giving it.

    CategoryPurposeProviderConsent required
    Strictly necessaryAuthentication, session management, load balancing, security and fraud prevention, remembering your cookie choicesGeoGenie (first party)No
    FunctionalRemembering interface preferences such as language and layoutGeoGenie (first party)Yes, in the EEA, UK and Switzerland
    AnalyticsUnderstanding how the Services and websites are used, so we can improve themPostHogYes, in the EEA, UK and Switzerland
    Marketing and attributionMeasuring the effectiveness of our campaigns and attributing sign-ups to their source[TO BE COMPLETED — name each provider, or delete this row if attribution is first-party only]Yes, in the EEA, UK and Switzerland

    A detailed list of the individual cookies we set, including their names, providers, purposes, durations and whether they are first- or third-party, is available in our cookie preference centre and is updated whenever it changes.

    You can also control cookies through your browser settings, though blocking strictly necessary cookies will prevent parts of the Services from working.

    Global Privacy Control. Where your browser sends a Global Privacy Control (GPC) signal, we treat it as a valid opt-out of the sale or sharing of personal information and of targeted advertising, as required by applicable US state law. As stated in Section 6.1 we do not sell or share personal information, so we honour GPC as a precaution rather than because any such activity takes place.

    Do Not Track. There is no common industry standard for responding to browser Do Not Track signals and our websites do not respond to them. We do respond to GPC as described above.

    12. Artificial intelligence: what we do and do not do

    The Services use artificial intelligence, including large language models supplied by third-party providers. This section explains precisely what that means for personal data.

    12.1 We do not train models on your data

    We do not use Customer Content to train generative AI models or foundation models. We may use aggregated, de-identified data derived from use of the Services — which does not identify you, your Users or your Customer Content — to operate, improve and develop the Services. Where data has been aggregated and de-identified we commit to maintain that de-identification, not to attempt to re-identify it, and to require the same of any recipient.

    Our agreements and the applicable API terms with the AI providers listed in Annex A prohibit them from using the content we send them to train their own general-purpose or foundation models. We impose an equivalent restriction on every sub-processor we engage.

    Data received from Google APIs is never used to train, retrain or improve any AI model, and is never sent to a third-party AI provider. See Section 18.1.

    12.2 What we send to third-party AI providers

    We send the following to third-party AI providers such as OpenAI and Anthropic:

    • prompts and query sets;
    • brand, competitor, product and topic terms;
    • publicly available web content retrieved for analysis; and
    • instructions for generating briefs, summaries and recommendations.

    We design the Services so that Customer Content containing personal data is not sent to third-party AI providers, and our contractual terms prohibit customers from submitting special-category or other sensitive personal data. Two honest qualifications:

    • Publicly available web content can contain personal data. When we retrieve a public article, listing or profile page to analyse how AI engines cite it, that page may name its author or quote named individuals, and that text forms part of what is analysed. This is inherent to analysing public web content and is not something we can strip without destroying the analysis.
    • Customers control their own inputs. Customers write their own prompts and choose what to upload. If a customer places personal data into a prompt or an uploaded asset that is then processed by an AI provider, that data reaches the provider. We ask customers not to do this, and clause 3.5 of Annex B prohibits it for sensitive categories, but we cannot technically prevent it.

    If we introduce a feature that requires personal data to be processed by an AI provider by design, we will update Annex A and this Section and give notice under Sections 7 and 19 before the change takes effect.

    12.3 Accuracy of AI output

    Generated Content is produced with the assistance of AI systems and reflects the output of third-party AI engines, which are outside our control. It may be inaccurate, incomplete, out of date, biased or unsuitable for a particular purpose, and may include fabricated statements. You are responsible for reviewing Generated Content before relying on it. We do not warrant that any particular AI visibility, ranking, mention or citation result will be achieved.

    13. Automated decision-making and profiling

    We do not carry out automated decision-making, including profiling, that produces legal effects concerning individuals or similarly significantly affects them, within the meaning of Article 22 EU GDPR.

    The Services generate scores, rankings and classifications — visibility scores, share of voice, citation rates, bot classifications — but these relate to brands, domains, prompts and content, not to individuals, and they are presented to human users for review rather than used to make decisions about people.

    14. Your rights — EEA, United Kingdom and Switzerland

    If you are in the EEA, the United Kingdom or Switzerland, you have the following rights in relation to personal data for which we are the controller.

    RightWhat it means
    AccessObtain confirmation of whether we process your personal data and, if so, a copy of it and information about how it is processed
    RectificationHave inaccurate personal data corrected and incomplete data completed
    ErasureHave your personal data deleted where one of the grounds in Article 17 applies
    RestrictionHave processing restricted in the circumstances set out in Article 18
    PortabilityReceive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible
    ObjectionObject to processing based on our legitimate interests, and object at any time and without qualification to direct marketing
    Withdraw consentWithdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
    Automated decisionsNot be subject to a decision based solely on automated processing with legal or similarly significant effects. We do not make such decisions — see Section 13
    ComplainLodge a complaint with a supervisory authority

    14.1 Where to complain

    • EEA: the supervisory authority of the Member State where you live, where you work, or where the alleged infringement occurred. A list is at edpb.europa.eu.
    • Germany: the data protection authority of your federal state (Landesdatenschutzbehörde), or the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
    • United Kingdom: the Information Commissioner's Office — ico.org.uk, 0303 123 1113.
    • Switzerland: the Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch.

    We would appreciate the chance to address your concern before you approach a regulator. Please write to privacy@geogenie.ai first.

    15. Your rights — United States

    15.1 California

    If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and not be discriminated against for exercising any of them.

    We do not sell personal information and we do not share it for cross-context behavioural advertising.

    Categories of personal information collected in the preceding twelve months:

    CCPA categoryCollectedSoldShared for cross-context behavioural advertisingDisclosed for a business purpose
    Identifiers (name, email, IP address, account ID)YesNoNoYes — to sub-processors
    Customer records (Cal. Civ. Code § 1798.80)YesNoNoYes — to sub-processors
    Commercial information (subscriptions, transactions)YesNoNoYes — to sub-processors
    Internet or network activity (usage, telemetry, logs)YesNoNoYes — to sub-processors
    Geolocation data (approximate, IP-derived)YesNoNoYes — to sub-processors
    Professional or employment information (job title, employer)YesNoNoYes — to sub-processors
    Sensitive personal information — account log-in credentials onlyYesNoNoYes — to our authentication and hosting sub-processors
    Sensitive personal information — all other subcategoriesNoNoNoNo
    InferencesNoNoNoNo
    Biometric informationNoNoNoNo
    Audio, electronic or visual informationOnly where we have told you a call is being recorded and, where required, obtained consentNoNoYes — to sub-processors
    Education informationNoNoNoNo

    The sources, business purposes and retention periods for each category are described in Sections 3, 5 and 9.

    Limiting the use of sensitive personal information. The only sensitive personal information we collect is your account log-in credentials, which we use solely to authenticate you and secure your account. Because we do not use or disclose sensitive personal information for any purpose beyond those permitted by §1798.121(a) CPRA, the right to limit does not apply to our processing. We will honour a request to limit as a matter of course if you make one.

    Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.

    Authorised agents. You may use an authorised agent to submit a request. We will require written proof of authorisation and may require you to verify your own identity directly.

    15.2 Other US states

    If you are a resident of a US state with a comprehensive consumer privacy law that applies to us — currently including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — you have the rights that law gives you, which generally include confirming and accessing your personal data, correcting it, deleting it, obtaining a portable copy, and opting out of targeted advertising, sale and certain profiling. Not every state grants every right; where a right exists under your state's law, we will honour it.

    We do not engage in targeted advertising, sale, or profiling with legal or similarly significant effects.

    Appeals. Where your state's law gives you a right to appeal a decision we make on your request, you may appeal by replying to our decision or writing to privacy@geogenie.ai with the subject line PRIVACY APPEAL. We will respond within the period your state's law allows — 45 days in most states, 60 in some — and will tell you which applies. If we deny your appeal, we will tell you how to contact your state Attorney General.

    16. How to exercise your rights

    Email privacy@geogenie.ai with the subject line DATA PROTECTION REQUEST (or CALIFORNIA PRIVACY REQUEST or PRIVACY APPEAL, as applicable). Tell us which right you wish to exercise and give us enough detail to locate your data.

    Verification. We will take reasonable steps to verify your identity before acting, which may mean asking you to respond from the email address associated with your data or to provide additional information. Information provided for verification is used for that purpose only and then deleted.

    Timing. We respond within one month for requests under the EU GDPR, UK GDPR or FADP, extendable by two further months for complex or numerous requests, and within the period allowed by the applicable state law for US requests — typically 45 days, extendable once where reasonably necessary. We will tell you if we need an extension and why.

    Cost. Free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and will explain why.

    Requests about Customer Content. If your request concerns personal data that one of our customers submitted to the Services, we act as a processor. We will forward your request to that customer without undue delay and assist them in responding, but we cannot action it directly.

    17. Children

    The Services are intended for business use by individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18, and the Services are not directed at children.

    If you believe a person under 18 has provided us with personal data, contact privacy@geogenie.ai and we will delete it promptly.

    19. Changes to this Policy

    We may update this Policy to reflect changes in our practices, our sub-processors, technology or the law.

    • The version number and effective date at the top of this Policy always identify the current version.
    • For material changes — a new category of personal data, a new purpose, a new sub-processor, or a change to international transfer arrangements — we will give at least 30 days' notice before the change takes effect, by email to account administrators and by prominent notice on our website.
    • We keep an archive of previous versions. Request one at privacy@geogenie.ai.

    Where a change requires your consent under applicable law, we will obtain it before the change applies to you.

    Annex B is not changed unilaterally. Annex B is a contract between GeoGenie and each customer. Nothing in this Section allows us to amend Annex B, the Standard Contractual Clauses, or the technical and organisational measures in Annex II other than as clause 5.2 of Annex B permits. Changes to Annex B are made in accordance with the amendment provisions of the Agreement. The only part of Annex B we maintain unilaterally is the sub-processor list at Annex III, and only through the notice-and-objection process in clause 6.

    20. How to contact us

    GeoGenie Inc.
    251 Little Falls Drive
    Wilmington, New Castle County
    Delaware 19808
    United States

    PurposeContact
    Privacy questions, data subject requests, sub-processor notificationsprivacy@geogenie.ai
    Legal noticeslegal@geogenie.ai
    Billingbilling@geogenie.ai
    Customer supportcs@geogenie.ai
    Security questions and vulnerability reportssecurity@geogenie.ai

    Privacy matters at GeoGenie are handled by our privacy team, reachable at privacy@geogenie.ai. We are not required to designate a data protection officer under Article 37 EU GDPR and have not done so; if that changes, we will name them here.

    Governing law. This Section applies to this Policy only and does not apply to Annex B, which is governed by clause 14.3 of Annex B, nor to the Standard Contractual Clauses and the UK Addendum, which are governed by clauses 12.2 and 12.3 of Annex B.

    This Policy is governed by the laws of the State of Delaware, without regard to its conflict of law principles. Nothing in this paragraph limits any mandatory right you have under the law of your country of residence — including your right under Article 79 EU GDPR to bring proceedings before the courts of the Member State where you reside or where we have an establishment, and your right to complain to your local supervisory authority.

    Annex A — Sub-processor list

    Last updated: September 1, 2026

    These are the sub-processors GeoGenie engages as at the date above. See Section 7 for how we notify customers of changes and how to object. Annex III to Annex B incorporates this list by reference.

    A.1 Sub-processors that may process Customer Content

    Sub-processorEntity and locationPurposeData processedRetentionTransfer mechanism
    Amazon Web ServicesAmazon Web Services, Inc. — United StatesCloud infrastructure: compute, storage, database and networking for the platformAll Customer Content; account data; log dataFor the term of the Agreement, then per Section 9EU SCCs (Modules 2 and 3) + UK Addendum, under the AWS GDPR Data Processing Addendum
    Google CloudGoogle LLC, with Google Cloud EMEA Limited (Ireland) as contracting entity where applicable — United StatesCloud infrastructure and services supporting the platformCustomer Content; account data; log dataFor the term of the Agreement, then per Section 9EU SCCs (Modules 2 and 3) + UK Addendum; EU–U.S. Data Privacy Framework where certified
    OpenAIOpenAI, L.L.C. — United StatesLarge language model API used to generate and analyse prompts, briefs and summariesPrompts, brand and topic terms, publicly available web content retrieved for analysis. Not used for model trainingPer OpenAI's API retention terms; no training on inputsEU SCCs + UK Addendum; contractual prohibition on training
    AnthropicAnthropic, PBC — United StatesLarge language model API used to generate and analyse prompts, briefs and summariesPrompts, brand and topic terms, publicly available web content retrieved for analysis. Not used for model trainingPer Anthropic's API retention terms; no training on inputsEU SCCs + UK Addendum; contractual prohibition on training

    A.2 Sub-processors processing data for which GeoGenie is the controller

    These providers support our own operations. They do not have access to Customer Content.

    Sub-processorEntity and locationPurposeData processedRetentionTransfer mechanism
    PostHogPostHog, Inc. — United StatesProduct analytics and usage telemetry; feature-adoption analysisAccount identifiers, usage and telemetry data, IP address, device data24 months, per Section 9EU SCCs + UK Addendum
    Google WorkspaceGoogle LLC, contracting through Google Ireland Limited — United States, IrelandCorporate email, calendar, documents, meetings and file storageCommunications data, marketing data, contract documentsPer Section 9EU SCCs + UK Addendum; EU–U.S. Data Privacy Framework where certified
    Twilio-SendgridEmail delivery and marketing communicationsMarketing data, communications data

    A.3 Independent controllers

    ProviderEntity and locationRolePurpose
    StripeStripe, Inc. / Stripe Payments Europe, Ltd. — United States, IrelandProcessor for payment processing on our instructions; independent controller for fraud prevention, anti-money-laundering and its own regulatory compliancePayment processing, subscription billing, invoicing, tax calculation. Full card data is collected by Stripe directly through its hosted payment components and does not pass through GeoGenie's systems. Stripe's own privacy policy governs its controller-role processing

    A.4 Personnel and contractors

    GeoGenie personnel and contractors located in the following countries may access personal data, including Customer Content, in the course of providing and supporting the Services:

    [TO BE COMPLETED — list every country in which employees or contractors with access to personal data are located, e.g. United States, Türkiye]

    All are bound by written confidentiality obligations and by data-transfer terms incorporating the SCCs where required. GeoGenie has no subsidiaries or affiliates.

    A.5 Changes

    Any sub-processor we engage in future will be added to this Annex at least 30 days before it begins processing, and account administrators will be notified by email.

    Annex B — Data Processing Agreement

    Version: 2.1 · Effective: September 1, 2026

    This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the GeoGenie Terms and Conditions or other written agreement between GeoGenie Inc. ("GeoGenie", "Processor") and the customer ("Customer", "Controller") governing the Customer's use of the Services (the "Agreement").

    This DPA applies automatically. No signature or countersignature is required. A Customer that requires a separately executed copy, or wishes to negotiate an alternative form of DPA, may request one at privacy@geogenie.ai.

    Order of precedence. In the event of a conflict, the following order applies: (1) the Standard Contractual Clauses and the UK Addendum incorporated by clause 12; (2) this DPA; (3) the Agreement; (4) the Privacy Policy.

    1. Definitions

    Terms not defined here have the meaning given in the Agreement, in Section 2 of the Privacy Policy, or in applicable Data Protection Law.

    "Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR, the FADP, the CCPA as amended by the CPRA, and other US state privacy laws.

    "Customer Personal Data" means Personal Data contained within Customer Content that GeoGenie processes on the Customer's behalf under the Agreement.

    "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

    2. Roles and scope

    2.1 The Customer is the Controller and GeoGenie is the Processor in respect of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, GeoGenie is a sub-processor and the Customer warrants that it has the authority of that controller to enter into this DPA.

    2.2 GeoGenie is an independent controller in respect of the data identified as controller data in Section 1.1 of the Privacy Policy — account administration data, billing data, security and abuse-prevention data, and its own marketing, recruitment and compliance records. That processing is governed by the Privacy Policy, not by this DPA. Product usage telemetry generated by the Customer's Users is processed by GeoGenie as a controller for the purposes of securing, operating and improving the Services; the Customer may object to that characterisation and, on request, GeoGenie will process such telemetry as a processor under this DPA for that Customer, subject to any resulting limitation in analytics functionality.

    2.3 This DPA applies for as long as GeoGenie processes Customer Personal Data.

    3. Processing instructions

    3.1 GeoGenie will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which GeoGenie is subject. Where such a legal requirement applies, GeoGenie will inform the Customer before processing, unless the law prohibits it on important grounds of public interest.

    3.2 The Agreement, this DPA, the Documentation, and the Customer's use and configuration of the Services constitute the Customer's complete documented instructions as at the effective date. Additional instructions require written agreement and may be subject to reasonable charges. For the avoidance of doubt, an amendment GeoGenie makes to the Privacy Policy does not alter the Customer's instructions or this DPA.

    3.3 GeoGenie will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. GeoGenie may suspend performance of an instruction it reasonably believes to be unlawful until the instruction is confirmed or amended.

    3.4 The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all required notices and obtained all required consents, and that its instructions comply with Data Protection Law. The Customer is responsible for the accuracy, quality and legality of Customer Personal Data.

    3.5 The Customer will not submit special categories of personal data (Article 9 EU GDPR), sensitive personal information as defined by the CPRA, government identification numbers, financial account numbers, or personal data of children, through the Services, unless expressly agreed with GeoGenie in writing.

    4. Confidentiality

    GeoGenie will ensure that any person authorised to process Customer Personal Data is subject to a written obligation of confidentiality that survives the end of their engagement, has been informed of the confidential nature of the data, and receives appropriate data-protection training.

    5. Security

    5.1 GeoGenie will implement and maintain the technical and organisational measures set out in Annex II to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 EU GDPR.

    5.2 GeoGenie may update those measures from time to time provided that the level of protection is not materially reduced. GeoGenie will notify the Customer of any material change.

    6. Sub-processors

    6.1 The Customer grants GeoGenie general written authorisation to engage the Sub-processors listed in Annex III, within the meaning of Clause 9(a) Option 2 of the SCCs.

    6.2 Before engaging a new Sub-processor or replacing an existing one, GeoGenie will give the Customer at least 30 days' notice by updating Annex III and notifying account administrators by email. This applies to every Sub-processor, whether or not it processes Customer Personal Data.

    6.3 The Customer may object to a new Sub-processor on reasonable data-protection grounds by written notice to privacy@geogenie.ai within the notice period, stating those grounds. The parties will work together in good faith to find a commercially reasonable alternative. If none can be found within 30 days of the objection, the Customer may terminate the affected Services on written notice and GeoGenie will refund prepaid, unused fees for the terminated portion of the then-current term.

    6.4 GeoGenie will impose on each Sub-processor, by written contract, data-protection obligations that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor's performance of those obligations as if it were GeoGenie's own, subject to clause 14.1.

    7. Assistance with data subject requests

    7.1 Taking into account the nature of the processing, GeoGenie will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject requests under Chapter III EU GDPR and equivalent provisions of other Data Protection Law.

    7.2 The Services provide self-service functionality allowing the Customer to access, export, correct and delete Customer Personal Data. Where the Customer cannot fulfil a request through the Services, GeoGenie will provide reasonable assistance; GeoGenie may charge for assistance that requires more than de minimis effort, at rates notified in advance.

    7.3 If GeoGenie receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively but will forward the request to the Customer without undue delay.

    8. Assistance with compliance obligations

    Taking into account the nature of processing and the information available to it, GeoGenie will provide reasonable assistance to the Customer with:

    • data protection impact assessments (Article 35 EU GDPR);
    • prior consultation with a supervisory authority (Article 36);
    • security of processing (Article 32); and
    • notification of Personal Data Breaches to authorities and Data Subjects (Articles 33 and 34).

    9. Personal data breach notification

    9.1 GeoGenie will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of confirming that such a breach has occurred.

    9.2 The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the information is not all available at once, GeoGenie will provide it in phases without undue further delay.

    9.3 GeoGenie will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's reasonable requests in connection with the Customer's own notification obligations.

    9.4 GeoGenie's notification is not an acknowledgement of fault or liability.

    10. Return and deletion

    10.1 On termination or expiry of the Agreement, the Customer may export Customer Personal Data through the Services for 30 days.

    10.2 At the Customer's choice, GeoGenie will either return Customer Personal Data to the Customer or delete it. The Customer may notify its choice at any time up to the end of the export period in clause 10.1. If the Customer does not notify a choice, GeoGenie will delete. GeoGenie will give effect to the Customer's choice within 90 days of termination, and will delete all existing copies, except:

    • data GeoGenie is required to retain by law, for the period so required and no longer; and
    • data held in encrypted backups, which expires on a rolling 35-day cycle.

    10.3 GeoGenie will not substitute de-identification for deletion where the Customer has instructed deletion.

    10.4 Data retained under clause 10.2 remains subject to this DPA and is processed only for the purpose that requires its retention.

    10.5 GeoGenie will certify return or deletion in writing on the Customer's request.

    11. Audit and monitoring

    11.1 GeoGenie will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 EU GDPR, including its current security documentation and any third-party audit reports, penetration test summaries or certifications it holds at the time of the request. GeoGenie's current certification status is stated in Section 10 of the Privacy Policy and in Annex II, item 6.

    11.2 Where that information is insufficient, the Customer may carry out an audit, including an inspection, of GeoGenie's processing, subject to the following: audits take place no more than once in any twelve-month period, except following a Personal Data Breach or where required by a supervisory authority; on at least 30 days' written notice; during normal business hours; without unreasonably disrupting GeoGenie's operations; subject to confidentiality obligations; scoped to GeoGenie's processing of that Customer's Personal Data; and at the Customer's expense.

    11.3 The Customer may appoint an independent third-party auditor, provided that auditor is not a competitor of GeoGenie and is bound by confidentiality obligations.

    11.4 Clauses 11.1 to 11.3 are the mechanism by which the Customer may take reasonable and appropriate steps to ensure that GeoGenie uses Personal Data in a manner consistent with the Customer's obligations under the CPRA, for the purposes of §1798.100(d) and §7051(a)(5) of the CCPA Regulations.

    12. International transfers

    12.1 The Customer authorises GeoGenie to transfer Customer Personal Data to the United States and to the Sub-processor locations listed in Annex III, subject to this clause.

    12.2 EEA transfers — Standard Contractual Clauses

    Where GeoGenie processes Customer Personal Data subject to the EU GDPR and transfers it outside the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA and form part of it, with the following elections:

    SCC provisionElection
    ModuleModule Two (controller to processor) where the Customer is a controller; Module Three (processor to processor) where the Customer is a processor
    Clause 7 (docking clause)Applies
    Clause 9 (sub-processors)Option 2, general written authorisation, with the 30-day notice period in clause 6.2 above
    Clause 11(a) (independent dispute resolution)The optional wording does not apply
    Clause 13 / competent supervisory authorityAs stated in Annex I.C
    Clause 17 (governing law)Option 1 — the law of Ireland
    Clause 18(b) (choice of forum)The courts of Ireland
    Annex IAnnex I to this DPA
    Annex IIAnnex II to this DPA
    Annex III (list of sub-processors)Annex III to this DPA

    12.3 UK transfers — UK International Data Transfer Addendum

    Where GeoGenie processes Customer Personal Data subject to the UK GDPR and transfers it outside the United Kingdom to a country without UK adequacy regulations, the UK Addendum (version B1.0) is incorporated into this DPA and forms part of it, completed as follows. The Mandatory Clauses of the UK Addendum apply, and where they conflict with clause 12.2, the Mandatory Clauses prevail — including in relation to governing law and courts, which for UK transfers are those of England and Wales.

    Table 1: Parties

    ExporterImporter
    Start dateThe effective date of the AgreementThe effective date of the Agreement
    Parties' detailsThe Customer, as identified in the AgreementGeoGenie Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States
    Key contactThe Customer's account administrator or designated privacy contactPrivacy Team, privacy@geogenie.ai

    Table 2: Selected SCCs, Modules and Selected Clauses

    The Addendum is appended to the EU SCCs as incorporated by clause 12.2 above, including the Appendix Information, with Module Two or Module Three applying as set out in clause 12.2, Clause 7 applying, Clause 9 Option 2 with a 30-day notice period, and Clause 11(a) optional wording not applying.

    Table 3: Appendix Information

    AppendixLocation
    Annex 1A — List of PartiesAnnex I.A to this DPA
    Annex 1B — Description of TransferAnnex I.B to this DPA
    Annex II — Technical and organisational measuresAnnex II to this DPA
    Annex III — List of Sub-processorsAnnex III to this DPA

    Table 4: Ending this Addendum when the Approved Addendum changes

    Which Parties may end this Addendum as set out in Section 19: neither Party.

    12.4 Swiss transfers

    Where GeoGenie processes Customer Personal Data subject to the FADP and transfers it outside Switzerland, the SCCs as incorporated by clause 12.2 apply with the following amendments, consistent with the FDPIC's recognition of the SCCs:

    • references to the GDPR are read as references to the FADP where the FADP applies;
    • the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
    • the term "Member State" is not to be interpreted so as to exclude Data Subjects in Switzerland from bringing proceedings in Switzerland in accordance with Clause 18(c); and
    • references to personal data are to the personal data of natural persons, the revised FADP in force since 1 September 2023 no longer extending to the data of legal entities.

    12.5 Alternative mechanisms

    GeoGenie may rely on an alternative transfer mechanism recognised under Data Protection Law in place of the SCCs or the UK Addendum only where the Customer has agreed in writing, or where the alternative mechanism provides a level of protection at least equivalent to the mechanism it replaces and GeoGenie has given the Customer 30 days' prior notice. GeoGenie is not currently self-certified under the EU–U.S. Data Privacy Framework and does not rely on it for transfers from the Customer to GeoGenie. Onward transfers by Sub-processors are governed by Clause 8.8 of the SCCs.

    12.6 Inability to comply

    GeoGenie will notify the Customer if it becomes unable to comply with the SCCs or the UK Addendum and, if it cannot remedy the position, the Customer may suspend the affected transfers or terminate the affected Services.

    13. US state privacy law terms

    13.1 This clause applies where the Customer is a "business" and GeoGenie a "service provider", "processor" or equivalent under the CCPA as amended by the CPRA, or under another US state privacy law. The Customer discloses Customer Personal Data to GeoGenie only for the following limited and specified business purposes, and for no other purpose:

    • providing, operating, hosting, maintaining and supporting the GeoGenie AI-search visibility platform under the Agreement, including the ContextGenie, PromptsGenie, MonitoringGenie, CitationsGenie, ActionsGenie, SiteGenie and Agent Analytics products;
    • authenticating and administering Users and account access;
    • generating reports, briefs, analyses and recommendations from Customer Content at the Customer's direction;
    • providing technical support and responding to Customer requests;
    • detecting, preventing and investigating security incidents, fraud and unauthorised activity affecting the Services;
    • debugging and repairing errors that impair the intended functionality of the Services; and
    • complying with legal obligations to which GeoGenie is subject.

    13.2 GeoGenie will not:

    • sell or share Customer Personal Data as those terms are defined in the CPRA;
    • retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in clause 13.1, or as otherwise expressly permitted by the CPRA;
    • retain, use or disclose Customer Personal Data outside the direct business relationship between the parties; or
    • combine Customer Personal Data with personal information received from another source, except as permitted by §7050(b) of the CCPA Regulations.

    13.3 GeoGenie will comply with its obligations under the CPRA and will provide the same level of privacy protection as the CPRA requires of a business. GeoGenie will notify the Customer promptly if it determines it can no longer meet those obligations. The Customer has the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data; and the right, exercisable through clause 11, to take reasonable and appropriate steps to ensure that GeoGenie uses Customer Personal Data in a manner consistent with the Customer's obligations under the CPRA.

    13.4 Where another US state privacy law applies, clauses 3 to 11 of this DPA apply for the purposes of that law's mandatory processor-contract requirements, including the Customer's right under clause 10 to direct deletion or return of Customer Personal Data.

    13.5 GeoGenie certifies that it understands and will comply with the restrictions in this clause 13.

    14. Liability and general

    14.1 Each party's liability under this DPA, including under clause 6.4, is subject to the exclusions and limitations of liability in the Agreement. This does not limit either party's liability to Data Subjects under the SCCs or the UK Addendum, or any liability that Data Protection Law prohibits limiting.

    14.2 If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force.

    14.3 This DPA is governed by the law stated in the Agreement, except that clause 12.2 and the SCCs are governed by the law of Ireland, and clause 12.3 and the UK Addendum are governed by the law of England and Wales.

    Annex I to the DPA — Description of processing

    A. List of parties

    Data exporter (Controller, or Processor where clause 2.1 applies)

    Name and addressThe Customer, as identified in the Agreement
    Contact personThe Customer's account administrator, or the privacy contact designated by the Customer in its account settings
    Activities relevant to the data transferredProcuring and using the GeoGenie AI-search visibility platform to measure and improve the visibility of the Customer's brand in generative AI engines and AI-powered search; administering its account and Users; submitting Customer Content for analysis
    RoleController (or Processor, where clause 2.1 applies)
    Signature and dateBy entering into the Agreement, the Customer is treated as having signed this Annex on the effective date of the Agreement

    Data importer (Processor)

    Name and addressGeoGenie Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States
    Contact personPrivacy Team — privacy@geogenie.ai
    Activities relevant to the data transferredProviding, hosting, maintaining, securing and supporting the GeoGenie AI-search visibility platform and related services under the Agreement
    RoleProcessor
    Signature and dateBy making the Services available under the Agreement, GeoGenie is treated as having signed this Annex on the effective date of the Agreement

    B. Description of transfer

    Categories of Data SubjectsThe Customer's employees, contractors and other authorised Users of the Services; the Customer's own personnel and business contacts, and any other individuals, whose personal data the Customer chooses to include in Customer Content
    Categories of Personal DataName, work email address, job title, employer, user and account identifiers, authentication data, access and usage logs, IP address, device and browser data; and any Personal Data the Customer chooses to include within Customer Content
    Sensitive dataNone is intended or permitted to be transferred. The Customer is contractually prohibited by clause 3.5 from submitting special-category data, sensitive personal information, government identifiers, financial account numbers or children's data without prior written agreement. Where such data is nonetheless submitted, GeoGenie applies the measures in Annex II without distinction
    Frequency of transferContinuous, for the duration of the Agreement
    Nature of processingCollection, recording, organisation, structuring, storage, retrieval, analysis, generation of derived reports and recommendations, transmission, restriction, erasure and destruction
    Purpose of processingProviding, maintaining, securing and supporting the Services in accordance with the Agreement; measuring and improving the Customer's brand visibility in generative AI engines and AI-powered search
    Retention periodFor the duration of the Agreement, plus the periods set out in clause 10 of this DPA and Section 9 of the Privacy Policy
    Sub-processors — subject matter, nature and durationAs listed in Annex III, which states the subject matter and nature of each Sub-processor's processing. Each Sub-processor processes for the duration of the Agreement plus the retention periods stated in Annex A to the Privacy Policy, after which processing ceases in accordance with clause 10

    C. Competent supervisory authority

    The competent supervisory authority under Clause 13 of the SCCs is determined as follows:

    • where the data exporter is established in an EEA Member State, the supervisory authority of that Member State;
    • where the data exporter is not established in an EEA Member State but has designated a representative under Article 27(1) EU GDPR, the supervisory authority of the Member State in which that representative is established; and
    • where the data exporter is not established in an EEA Member State and is not required to designate a representative, the supervisory authority of the Member State in which the Data Subjects whose personal data is transferred are located.

    For transfers subject to the UK GDPR, the competent authority is the Information Commissioner's Office. For transfers subject to the FADP, it is the Swiss Federal Data Protection and Information Commissioner.

    Annex II to the DPA — Technical and organisational measures

    GeoGenie implements and maintains at least the following measures. GeoGenie may update them under clause 5.2 provided the level of protection is not materially reduced.

    1. Pseudonymisation and encryption Data in transit between the Customer and the Services, and between GeoGenie's production systems, is encrypted using TLS 1.2 or higher. Data at rest, including backups, is encrypted using AES-256 or an equivalent standard. Encryption keys are managed through a dedicated key-management service with restricted access. IP addresses in AI bot traffic logs are truncated or pseudonymised on ingestion.

    2. Confidentiality — access control Role-based access control on least-privilege principles. Multi-factor authentication for personnel access to production systems and to the corporate identity provider. Production access is limited to named personnel with a documented business need. Break-glass and automated service-account access paths are individually documented, restricted and logged. Access is reviewed at least quarterly and revoked promptly on role change or departure. Administrative actions are logged.

    3. Confidentiality — system and physical access Production environments are logically segregated from development and staging. Network access is restricted by firewall and security-group policy, with no direct public access to data stores. Physical security of the data-centre facilities is provided by Amazon Web Services and Google Cloud under their own certifications, which include ISO 27001 and SOC 2. These are the infrastructure providers' certifications; GeoGenie's own certification status is stated in item 6 below.

    4. Integrity Input validation and output encoding. Change management with peer code review before merge. Static analysis and dependency vulnerability scanning in the build pipeline. Separation of duties between development and deployment. Centralised, tamper-resistant audit logging of security-relevant events.

    5. Availability and resilience Automated, encrypted backups on a rolling 35-day cycle. Recovery point and recovery time objectives are defined and are available to customers on request at security@geogenie.ai. Backup restoration is tested at least annually. Infrastructure is deployed across multiple availability zones. Monitoring and alerting on availability and error rates.

    6. Regular testing and evaluation Periodic internal security review and continuous automated vulnerability scanning of infrastructure and dependencies. GeoGenie does not currently hold an ISO 27001 or SOC 2 certification of its own; independent penetration testing and formal certification are on GeoGenie's security roadmap. Current status is available at security@geogenie.ai.

    7. Data minimisation and purpose limitation Only data necessary for the Services is collected. Retention periods are defined and enforced as set out in Section 9 of the Privacy Policy. The Services are designed so that Customer Content containing personal data is not transmitted to third-party AI providers, subject to the two qualifications stated in Section 12.2 of the Privacy Policy (personal data appearing in publicly available web content retrieved for analysis, and personal data a Customer chooses to place in its own prompts or uploads).

    8. Personnel Written confidentiality undertakings for all personnel with access to personal data. Security and data-protection training on onboarding and at least annually thereafter. Documented onboarding and offboarding procedures including prompt access revocation.

    9. Sub-processor governance Data-protection and security review before engagement. A written data-processing agreement in every case, with obligations no less protective than this DPA. Periodic review of the sub-processor list.

    10. Incident management A documented incident-response plan with defined roles, severity classification, escalation paths, customer-notification procedures meeting clause 9, and a documented post-incident review.

    Annex III to the DPA — Authorised sub-processors

    The authorised Sub-processors are those listed in Annex A to the Privacy Policy, which is incorporated here by reference and maintained as the current list under clause 6.2. As at the effective date of this DPA:

    Sub-processorLocationSubject matter and nature of processing
    Amazon Web Services, Inc.United StatesCloud infrastructure — compute, storage, database and networking. Hosts Customer Personal Data
    Google LLC (Google Cloud)United StatesCloud infrastructure and platform services. May host and process Customer Personal Data
    OpenAI, L.L.C.United StatesLarge language model API. Processes prompts and publicly available web content; not used for model training
    Anthropic, PBCUnited StatesLarge language model API. Processes prompts and publicly available web content; not used for model training
    PostHog, Inc.United StatesProduct analytics and usage telemetry. Processes account identifiers, usage data, IP address and device data
    Google LLC / Google Ireland Limited (Google Workspace)United States, IrelandCorporate email, calendar, documents and file storage. Processes communications and contract data
    Stripe, Inc. / Stripe Payments Europe, Ltd.United States, IrelandPayment processing and subscription billing. Acts as an independent controller for fraud prevention and its own regulatory compliance

    Each Sub-processor processes for the duration of the Agreement plus the retention period stated for it in Annex A to the Privacy Policy.

    End of Privacy Policy, Annex A and Annex B.