Data Processing Agreement
This Data Processing Agreement (DPA) template sets out the terms under which Georithm processes personal data on behalf of customers using Georithm. It covers roles and responsibilities, security measures, sub-processors, international transfers, breach notification, and how to execute the agreement.
- Version
- v1.0
- Last updated
- 29 July 2026
In this Data Processing Agreement ("DPA"), capitalized terms not otherwise defined have the meanings below, and terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law, including the GDPR.
- "Agreement" means the underlying terms of service or subscription agreement between Customer and Georithm governing use of Georithm.
- "Customer Data" means personal data submitted to or processed by Georithm on Customer's behalf.
- "Data Protection Laws" means applicable laws relating to the processing of personal data, including the GDPR, UK GDPR, PIPEDA, and the CCPA/CPRA, as applicable.
- "Sub-processor" means a third party engaged by Georithm to process Customer Data.
The parties acknowledge that, with respect to Customer Data, Customer acts as the controller (or business, as applicable) and Georithm acts as the processor (or service provider, as applicable) under Data Protection Laws.
Georithm will process Customer Data only in accordance with Customer's documented instructions, this DPA, and the Agreement, except where otherwise required by applicable law.
Subject matter: the provision of the Georithm location-intelligence platform, including hosting, authentication, mapping, AI-generated insights, and related support services.
Duration: processing continues for the term of the Agreement and for any period thereafter during which Georithm retains Customer Data in accordance with this DPA.
Nature and purpose: collection, storage, organization, retrieval, use, and deletion of Customer Data as necessary to provide the Georithm service, including generating maps, search results, and AI-driven location insights requested by Customer's authorized users.
Categories of data subjects:
- Customer's authorized users (employees, contractors, agents).
- Individuals whose information appears in location, address, or business data entered into the platform by Customer's users.
Categories of personal data:
- Contact and identification data (name, email address, business role).
- Authentication data (sign-in method, account identifiers).
- Usage and query data entered into the platform.
- Billing and account administration data.
Special categories of data: the parties do not intend for special category or sensitive personal data to be submitted to Georithm; Customer is responsible for ensuring it does not submit such data unless separately agreed in writing.
Georithm will:
- Process Customer Data only on documented instructions from Customer, including regarding international transfers, unless required to do otherwise by law.
- Ensure personnel authorized to process Customer Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational measures as described in Annex II.
- Notify Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
- Assist Customer in complying with its obligations relating to the security of processing, data protection impact assessments, and consultation with supervisory authorities, taking into account the nature of processing.
Georithm will ensure that any person authorized to process Customer Data has committed to confidentiality obligations, whether contractual or statutory, and will limit access to Customer Data to personnel who require it to perform their duties in connection with the Agreement.
Georithm maintains technical and organizational measures designed to protect Customer Data, including:
- Encryption of data in transit between clients and Georithm's infrastructure.
- Encryption of data at rest within the Supabase-backed database.
- Secure authentication mechanisms, including email/password and Google sign-in.
- Rate limiting to mitigate abuse and unauthorized access attempts.
- Audit logging of security-relevant and administrative actions.
- Role-based access permissions limiting internal access to Customer Data.
- Segregation of environments and access controls appropriate to the sensitivity of the data processed.
These measures are reviewed and updated periodically but do not constitute a guarantee of uninterrupted or absolute security.
Customer provides general authorization for Georithm to engage the following categories of sub-processors to support delivery of Georithm:
- Hosting and database — Supabase (database hosting and authentication).
- Payments — Stripe (payment processing and billing).
- Mapping — Mapbox (map rendering and geocoding).
- AI model provider — the AI model gateway used to generate location-based insights.
- Email — transactional email delivery provider for account and billing notifications.
Georithm will impose data protection obligations on sub-processors that are substantially similar to those in this DPA. If Georithm intends to add or replace a sub-processor, it will provide notice to Customer, and Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected service in accordance with the Agreement.
Taking into account the nature of processing, Georithm will provide reasonable assistance to Customer, through appropriate technical and organizational measures and in-app tools, to help Customer respond to requests from data subjects seeking to exercise their rights (such as access, correction, deletion, or portability) under applicable Data Protection Laws. Customer remains responsible for responding to data subject requests as the controller.
Georithm will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, providing information reasonably available to Georithm to help Customer meet its own notification obligations under applicable Data Protection Laws. Georithm will cooperate with Customer and take reasonable steps to mitigate the effects of any such breach.
Georithm will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality obligations, and no more than once per year unless otherwise required by a supervisory authority or triggered by a security incident.
Where processing of Customer Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country not deemed to provide an adequate level of protection, the parties agree that such transfers will be governed by the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and will take precedence over conflicting provisions to the extent required to ensure a lawful transfer mechanism is in place.
On termination or expiry of the Agreement, Georithm will, at Customer's election, delete or return all Customer Data, and delete existing copies, within a reasonable period, unless applicable law requires continued storage of some or all of the Customer Data, in which case Georithm will isolate and protect that data from further processing.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, unless applicable Data Protection Laws prohibit such limitation.
In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA will prevail to the extent of the conflict. In the event of a conflict between this DPA and the Standard Contractual Clauses or UK Addendum incorporated under Section 12, the Standard Contractual Clauses or UK Addendum will prevail.
This DPA is intended to form part of the Agreement between Customer and Georithm upon acceptance by both parties. To execute this DPA or request a countersigned copy, contact jerogz@georithm.info. Where required, the parties may complete a signature block or click-through acceptance referencing this DPA and its version and effective date.
This document is provided as an original template for Georithm and is maintained by the account owner. It is app-owned editable content and is not legal advice or an independent certification. Replace every bracketed placeholder with your company details and have the final text reviewed by a qualified adviser before relying on it.