Data Processing Addendum (DPA)
How to execute. This is the standard GEO Tracker AI Data Processing Addendum ("DPA") offered to customers who require a written processor agreement under Article 28 GDPR or analogous laws. To execute, fill in the customer details in Section 1 and the data summary in Annex 1 below, sign the page, and e-mail a counter-signed copy to legal@geotrackerai.com. We will counter-sign and return the executed PDF. The DPA enters into force on the latest signature date and applies as of the date you accepted the Terms of Service.
1. Parties
Processor: Ing. Petra Vlčková, OSVČ, IČO 10881263, Zahradní 302, 267 51 Zdice, Czech Republic, operating GEO Tracker AI (the Provider).
Controller: the entity that has accepted the Terms of Service of the Service or executed an order form with the Provider (the Customer).
Customer details to be filled in upon execution: legal name, registered address, registration number / VAT ID, authorized signatory, signatory e-mail.
2. Definitions
Capitalized terms not defined in this DPA have the meaning given in the Terms of Service and the Privacy Policy. "Applicable Data Protection Law" means Regulation (EU) 2016/679 (GDPR), the UK Data Protection Act 2018 and the UK GDPR, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other comprehensive data-protection laws to the extent they apply to the processing under this DPA. "Customer Personal Data" means personal data that the Provider processes on behalf of the Customer in connection with the Service.
3. Roles and Scope of Processing
3.1 The Customer acts as controller (or, where applicable, processor for its own customer) of Customer Personal Data. The Provider acts as processor (or sub-processor) and processes Customer Personal Data only for the documented purposes set out in Annex 1 and on documented instructions from the Customer.
3.2 The Customer's instructions are: (a) the Terms of Service; (b) the Privacy Policy; (c) this DPA; (d) the Customer's configuration of the Service (e.g., domains added, queries stored, alert webhooks configured); (e) any additional written instructions agreed in advance.
3.3 The Provider will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Provider Obligations (Article 28(3) GDPR)
The Provider will:
- process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or member-state law (in which case the Provider will inform the Customer of the legal requirement before processing, unless prohibited by law);
- ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- implement the technical and organizational measures described in Annex 2;
- use sub-processors only in accordance with Section 6;
- taking into account the nature of the processing, assist the Customer through appropriate technical and organizational measures, insofar as possible, in fulfilling its obligation to respond to requests from data subjects exercising rights under Chapter III GDPR;
- assist the Customer in complying with Articles 32–36 GDPR, taking into account the nature of the processing and the information available to the Provider;
- at the Customer's choice, delete or return all Customer Personal Data after the end of the provision of services relating to processing, and delete existing copies, unless Applicable Data Protection Law requires storage of the personal data;
- make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer (Section 8).
5. Data Subject Requests
5.1 The Provider will, where reasonably practicable, promptly forward to the Customer any data-subject request received in connection with the processing of Customer Personal Data.
5.2 Where the Service offers self-service mechanisms for data-subject requests (e.g., account deletion in Settings, CSV/JSON export endpoints for Pro and Business users), the Provider may direct the Customer or the data subject to those mechanisms.
5.3 Beyond the assistance described above and in Section 4, the Customer is responsible for handling requests addressed to it.
6. Sub-processors
6.1 General authorization. The Customer grants the Provider a general authorization to engage sub-processors for the provision of the Service. The current sub-processor list is published in the Privacy Policy and is incorporated into this DPA by reference.
6.2 Notice of changes. The Provider will notify the Customer of intended additions or replacements of sub-processors at least thirty (30) days before the change takes effect, by e-mail to the Customer's account address or by an in-product notification. The Customer may object on reasonable grounds related to data protection within fifteen (15) days of notice. The Provider will use good faith efforts to address the objection; if not resolved, the Customer may terminate the affected portion of the Service for cause without further liability beyond accrued fees.
6.3 Sub-processor obligations. The Provider will impose on each sub-processor data-protection obligations no less protective than those in this DPA.
7. International Data Transfers
7.1 Where the processing involves a transfer of Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a third country that does not provide an adequate level of protection, the parties agree that:
- the EU Standard Contractual Clauses (Module 2 controller-to- processor or Module 3 processor-to-sub-processor, as applicable, of Decision (EU) 2021/914) are hereby incorporated by reference and apply, with the Customer as data exporter and the Provider as data importer; the docking clause (Clause 7) is not used; option in Clause 9(a) is option 2 (general written authorization for sub-processors with 30-day notice); the optional language in Clause 11 is not selected; the supervisory authority is the Czech Office for Personal Data Protection (ÚOOÚ); the governing law is Czech law; the courts are those of the Czech Republic, save as required by Clause 18;
- for transfers subject to UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner;
- for transfers from Switzerland, the parties apply the EU SCCs with the modifications recommended by the Swiss FDPIC.
7.2 Where the recipient sub-processor is self-certified under the EU-U.S. Data Privacy Framework (and, as applicable, the UK Extension and the Swiss-U.S. Framework), reliance on that framework satisfies Article 45 GDPR and the corresponding transfer requirement.
8. Audits
8.1 The Provider will make available to the Customer, upon reasonable written request, the information necessary to demonstrate compliance with this DPA, including responses to standard security questionnaires (e.g., a SIG Lite, CAIQ, or equivalent) and copies of relevant third-party certifications/audit summaries of sub-processors where available.
8.2 An on-site audit may be conducted no more than once per year, on at least sixty (60) days' advance written notice, during business hours, with reasonable scope, by the Customer or a mutually agreed third-party auditor that is not a competitor of the Provider and that signs an appropriate confidentiality agreement. The Customer bears the cost of the audit unless the audit reveals material non-compliance, in which case the Provider bears its own costs and reasonable audit costs.
8.3 Audits must not unreasonably interfere with the Provider's operations and must not jeopardize the security or confidentiality of other customers' data.
9. Personal Data Breach
9.1 The Provider will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and in any event, where reasonably practicable, within seventy-two (72) hours.
9.2 The notification will include, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed.
9.3 The Provider will reasonably cooperate with the Customer in investigating, mitigating, and remedying the breach and in fulfilling any notification obligations the Customer may have under Articles 33–34 GDPR or analogous laws.
10. Return or Deletion of Data
On termination of the Service or upon the Customer's written request, the Provider will, at the Customer's choice, delete or return Customer Personal Data, except for copies required to be retained by Applicable Data Protection Law or other applicable laws (e.g., Czech tax / accounting records up to ten (10) years; backup rotation up to thirty-five (35) days; alert idempotency log up to twelve (12) months; fraud-prevention records up to twenty-four (24) months for the Free GEO Snapshot). The Provider will continue to apply this DPA to any retained copies until they are deleted.
11. Liability and Conflict
11.1 The liability provisions in the Terms of Service govern this DPA, save that nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Law.
11.2 In the event of conflict between this DPA and the Terms of Service, this DPA prevails as to the processing of personal data; in the event of conflict between this DPA and the EU SCCs, the EU SCCs prevail.
12. Term and Survival
This DPA enters into force on the date of last signature and continues for as long as the Provider processes Customer Personal Data in connection with the Service. Sections 4 (return/deletion), 8 (audits, for a period of one (1) year after termination), 9 (breach), 10 (deletion), 11 (liability), and 13 (governing law) survive termination.
13. Governing Law
This DPA is governed by Czech law. The courts of the Czech Republic have exclusive jurisdiction, subject to the EU SCCs (Clause 18) and to mandatory consumer-protection rights.
Annex 1 — Description of Processing (Article 28(3) GDPR)
- Subject matter and duration: provision of the Service for the duration of the Customer's subscription, including any post-termination tail described in Section 10.
- Nature and purpose of the processing: hosting; authentication; running AI visibility scans against third-party AI providers; collecting, fetching, classifying, and enriching public-web citation data (CSI); auditing the Customer's domain (Crawlability, Content Audit, Discovery Readiness); generating the Customer's GEO Score and competitor / loss-analysis insights; sending transactional, weekly report, and alert e-mails; (where configured) posting alert mirrors to a Customer-controlled Slack Incoming Webhook; running the optional CSV/JSON export endpoints; technical support; security monitoring and anti-abuse.
- Categories of data subjects: primarily the Customer's authorized end users (account holders) and personnel; rarely, individuals whose names or e-mails appear inside Customer Inputs the Customer chooses to store. The Service is not designed to process personal data of large external populations.
- Categories of personal data: identification and contact data (e-mail, account name); authentication data; subscription and billing metadata; IP addresses (for the Customer this is hashed for the public Free GEO Snapshot only); usage logs; configuration data; Customer Inputs; AI-generated outputs (which may incidentally include personal data appearing in third-party content cited by AI systems).
- Special-category or criminal-data processing: none intended; the Customer must not knowingly submit such data.
- Frequency: continuous, for the duration of the Service.
- Sub-processors: see the list in the Privacy Policy (Section 5).
Annex 2 — Technical and Organizational Measures (Article 32 GDPR)
- Pseudonymization and encryption: TLS 1.2+ in transit; provider-managed encryption at rest; SHA-256 IP hashing on the public Free GEO Snapshot with a per-deployment salt; password hashing handled by Supabase Auth.
- Confidentiality, integrity, availability, resilience: row-level security in PostgreSQL; service-role keys restricted to the server; signed Stripe webhooks (HMAC); anti-SSRF host validation on outbound webhooks (e.g., Slack); isolation of admin tooling; provider-managed regional redundancy and backups via Supabase and Vercel.
- Restoration after incident: routine backups with rotation up to ~35 days managed by Supabase; runbook and incident-response procedures maintained by the Provider.
- Regular testing and evaluation: automated test suite (unit + integration), structured logging and alerting, classifier-failure logs, billing-audit events, cron-run heartbeats; periodic review of access controls and dependencies.
- Access controls: least-privilege access, password rotation guidance, separate admin login with optional session-secret rotation; vendor-managed MFA enforced for personnel with admin access.
- Vendor management: each sub-processor is contractually bound by a published DPA or equivalent; transfers are governed by EU SCCs / UK IDTA / EU-U.S. DPF where applicable.
- Logging and monitoring: structured logs (component, level, event, status, run-id, duration); error stacks; billing-audit and alert-dispatch logs; cron-run heartbeats.
- Personnel: processing is performed by the Provider directly; contractors, if any, are bound by appropriate confidentiality and data-protection clauses.
Signatures
For the Provider: Ing. Petra Vlčková — signed on file upon counter-signature.
For the Customer: ____________________________________ (printed name and title), ____________________________________ (signature), date: ____________.
Questions or to request a counter-signed copy: legal@geotrackerai.com. This DPA is offered alongside our Terms of Service and Privacy Policy.