Data Processing Agreement (DPA)

Version 2026-09-09.1

Part of the Geosed contract

This DPA applies where Geosed processes personal data on behalf of a business customer. It forms part of the contract when the Terms are accepted.

1. Parties and application

The instructing party is the business identified in the Geosed account, order or individual offer (“Customer”). The processor is Avaroq alkan, Switzerland, UID CHE-183.558.613, email info@geosed.com (“Geosed”). This DPA supplements the Terms. The Customer may act as a controller or as a processor; Geosed acts accordingly as its processor or sub-processor.

2. Subject matter, purpose and duration

Geosed provides a platform for measuring and improving visibility in AI search systems. Processing includes storing, organising, retrieving, transmitting, evaluating, backing up and deleting account, project, measurement and support data to the extent it contains personal data. Processing continues during the contract and until the agreed deletion or return of the data.

3. Data subjects and data types

Data subjects may include employees, representatives, customers, prospects, competitors, website operators and other persons whose information the Customer lawfully submits to Geosed. Data may include identity and contact details, professional information, account and permission data, domains, questions, publicly available website content, AI inputs and outputs, sources, usage, log and support data.

Sensitive personal data may be submitted only where necessary, lawful and expressly agreed with Geosed in advance.

4. Instructions and Customer duties

  • The Terms, selected features, project settings and documented support instructions constitute the Customer's instructions.
  • The Customer is responsible for the lawfulness, accuracy, transparency and required legal bases for its data and instructions.
  • Geosed will inform the Customer if it believes an instruction breaches applicable data protection law and may suspend it pending clarification.

5. Geosed duties

  • Geosed processes Customer Data only to provide the agreed services, on documented instructions or where mandatory law requires it.
  • Authorised persons are bound to confidentiality and receive only the access needed for their duties.
  • Geosed reasonably assists with data subject requests, security incidents, impact assessments and compliance evidence.
  • Geosed does not use Customer Data to train its own general-purpose AI models.

6. Security

Geosed maintains technical and organisational measures appropriate to the risk, including TLS encryption in transit, password hashing, encryption of stored API keys, role-based access, tenant separation, security-event logging, backups, controlled deployment and security updates. Measures are developed in line with risk and the state of the art.

7. Sub-processors

The Customer generally authorises the following sub-processors. Geosed will normally notify registered customers of planned material additions or replacements at least 14 days in advance by email or in the account. The Customer may object on substantiated data-protection grounds. If no reasonable solution is available, the affected service may be terminated.

ProcessorPurposeProcessing locationsSafeguard
Hostinger International Ltd.Hosting, database and backupsFrankfurt, Germany; support may involve other locationsHostinger DPA; SCCs where required
Plus Five Five, Inc. (Resend)Transactional emailUnited StatesResend DPA; EU SCCs adapted for Switzerland
OpenAI Ireland Ltd. and affiliatesChatGPT measurements and evaluationEEA, United States and other disclosed locationsOpenAI DPA; applicable transfer safeguards
Perplexity AI, Inc.Perplexity measurements and web searchUnited StatesPerplexity DPA; SCCs
Anthropic, PBCClaude measurementsUnited StatesAnthropic DPA; SCCs
Google Ireland Ltd., Google LLC and affiliatesGemini measurementsEEA, United States and other disclosed locationsGoogle data processing terms; SCCs where required
Stripe Payments Europe, Ltd. and affiliatesCheckout, subscriptions, invoices and payment eventsIreland and global Stripe infrastructureStripe DPA and Data Transfers Addendum

OpenStreetMap Nominatim is used only for a location search initiated by the user. Personal or confidential information must not be submitted there; the public service does not act as Geosed's contractual sub-processor in this respect.

8. International transfers

Processing in countries without recognised adequate protection is safeguarded, where required, by recognised Standard Contractual Clauses adapted for Swiss law, a recognised adequacy mechanism or another lawful basis. Geosed considers supplementary technical and organisational safeguards.

9. Security incidents

Geosed will notify the Customer without undue delay of a confirmed personal data breach affecting Customer Data and provide reasonably available information for statutory assessment and notification duties. Geosed will take appropriate containment and remediation measures.

10. Return and deletion

After contract termination, Geosed generally deletes or anonymises Customer Data within 30 days or, if requested beforehand, returns it to the Customer in an available format, unless retention is required by law or for legal claims. Remaining backup copies are overwritten or deleted in the regular backup cycle and remain protected and unavailable for productive use until then.

11. Evidence and audits

On reasonable request, Geosed provides information needed to demonstrate compliance. Reviews first use available documents and evidence. Further audits may take place on reasonable notice, during normal business hours and subject to security, confidentiality and other customers' rights. The Customer bears avoidable additional costs unless the audit identifies a material breach by Geosed.

12. Priority, liability and contact

For processing on behalf of the Customer, this DPA prevails over conflicting Terms. Otherwise, the main contract's liability and duration provisions apply. Send questions and data protection instructions to info@geosed.com.