11. Data Processing, Privacy, GDPR
11.1 Roles of the Parties
a) For Content that you submit for analysis (e.g., URLs, brand assets, website data), you are the Data Controller and GEOReport acts as your Data Processor.
b) For Account Data (e.g., registration details, billing records, support communications, product telemetry), GEOReport acts as the Data Controller.
11.2 Types of Data Processed
GEOReport may collect, process, and store the following categories of data:
a) Content Data: URLs, brand data, analytics inputs, and other information you upload or connect for auditing.
b) Account Data: Names, email addresses, login credentials, subscription details, billing records, and support interactions.
c) Technical Data: Log files, telemetry, device/browser information, and usage statistics.
d) Report Outputs: GEO Health Scores, diagnostics, benchmarking data, and related insights generated by the Services.
11.3 Lawful Bases for Processing
Processing of Personal Data is carried out under the following lawful bases (as applicable under GDPR or equivalent laws):
a) Performance of a contract (providing the Services);
b) Compliance with legal obligations (e.g., tax or accounting records);
c) Legitimate interests (e.g., improving Services, ensuring security, preventing misuse);
d) Consent (for specific optional features, such as certain marketing or beta programs).
11.4 Data Retention
a) Account and billing data: Retained for as long as required by tax, financial, or legal obligations.
b) Content and Reports: Retained for the duration of the Subscription Term, and deleted within 30 days after termination or expiration, unless longer retention is required by law.
c) Technical and telemetry data: Retained up to 12 months for service improvement and diagnostics.
d) Backups: Securely overwritten on rolling cycles, generally within 90 days.
11.5 Data Subject Rights
Users have the right to exercise the following GDPR rights (or equivalent under local laws):
a) Right of access (request a copy of your data);
b) Right to rectification (correct inaccuracies);
c) Right to erasure (“right to be forgotten”);
d) Right to restrict or object to processing;
e) Right to data portability;
f) Right to withdraw consent (where applicable).
Requests may be submitted via https://discord.gg/GPBkUjcs, and GEOReport will respond within 30 days unless extensions are permitted by law.
11.6 Deletion and Export Procedure
l Deletion Requests: Verified requests will result in deletion of live system data within 30 days, with backups purged by natural rotation (≤90 days).
l Export Requests: Data will be provided in machine-readable formats (CSV, JSON, or PDF) within 30 days.
l Verification: GEOReport reserves the right to request proof of identity or authority before fulfilling requests.
11.7 Data Hosting and Transfers
l By default, GEOReport hosts and processes data in the European Union.
l If data must be transferred outside the EU/EEA, GEOReport will implement Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent safeguards to ensure compliance with GDPR.
11.8 Sub-Processors
l GEOReport may use trusted infrastructure or service providers (e.g., EU-based cloud hosting).
l GEOReport will maintain an updated list of sub-processors and provide notice before engaging new ones.
l Each sub-processor is bound by written agreements ensuring GDPR-level safeguards.
11.9 Security Measures
GEOReport implements appropriate technical and organizational measures to protect Personal Data, including encryption (in transit and at rest), access controls, monitoring, vulnerability management, and periodic audits. Further details are described in Section 12 (Security).
11.10 Data Protection Addendum (DPA)
For Users requiring a formal agreement under GDPR, GEOReport offers a Data Processing Addendum (DPA) incorporating standard GDPR clauses. In case of conflict, the DPA prevails over this Section.
11.11 Aggregated and Anonymized Data
GEOReport may use aggregated, pseudonymized, or anonymized data (that cannot reasonably identify you or any individual) for statistical analysis, product improvement, and industry research.
Last updated
