GDPR Notice
This GDPR Notice supplements our Privacy Policy and provides EU and UK users with details required under the General Data Protection Regulation and UK GDPR, including our role as controller, the legal bases we rely on, how we fulfil data subject rights in-app, our retention approach, and how to contact a supervisory authority.
- Version
- v1.0
- Last updated
- 29 July 2026
Georithm, with its registered office at [Business Address], [Country], is the data controller responsible for personal data processed through Georithm.
Where required under Article 27 GDPR or the UK GDPR, we will appoint an EU or UK representative and publish their contact details here. For all data protection queries, contact jerogz@georithm.info or our Data Protection Officer, [Data Protection Officer].
The table below summarizes the main categories of personal data we process and the Article 6 legal basis relied on:
- Account and authentication data (name, email, sign-in method) — processed for performance of a contract (Article 6(1)(b)).
- Usage and interaction data — processed under legitimate interests (Article 6(1)(f)) to secure and improve the service.
- Location and search query data entered into the platform — processed for performance of a contract, to generate the mapping and AI insights you request.
- Billing data — processed for performance of a contract and legal obligation (Article 6(1)(c)) for tax and accounting records.
- Cookie and marketing preferences — processed based on consent (Article 6(1)(a)), which you may withdraw at any time.
- Support communications — processed under legitimate interests to resolve your inquiries.
We do not design Georithm to intentionally collect or process special category data (such as health, biometric, racial or ethnic origin, or political opinion data) as defined under Article 9 GDPR. Please avoid entering special category data into location or search fields, support messages, or account fields. If you believe such data has inadvertently been submitted, contact jerogz@georithm.info so we can review and remediate.
Under the GDPR and UK GDPR, you have the right to:
- Access (Article 15) — obtain confirmation of, and access to, personal data we hold about you.
- Rectification (Article 16) — request correction of inaccurate or incomplete data.
- Erasure (Article 17) — request deletion of your data, subject to legal exceptions.
- Restriction of processing (Article 18) — request that we limit how we use your data.
- Data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format.
- Object to processing (Article 21) — object to processing based on legitimate interests, including profiling.
- Rights related to automated decision-making (Article 22) — safeguards where processing produces legal or similarly significant effects.
- Withdraw consent (Article 7(3)) — where processing relies on consent, at any time.
We have built in-app tools to help you exercise these rights directly:
- Data export as JSON — download a structured export of your account and usage data from account Privacy settings.
- Account deletion — request deletion of your account and associated personal data.
- Correction requests — update account details directly, or submit a correction request for data you cannot edit yourself.
- Consent withdrawal — toggle marketing and non-essential cookie consent at any time.
- Consent history — view a log of your consent choices and when they were made.
For requests that cannot be completed in-app, use the privacy request form at /legal/privacy-request or email jerogz@georithm.info.
We aim to respond to verified data subject requests within one month of receipt, as required by Article 12(3) GDPR. Where a request is complex or we have received multiple requests from you, we may extend this period by a further two months, and we will notify you of any extension and the reasons for the delay within the initial one-month period.
Some of our sub-processors, including our AI model gateway and certain infrastructure providers, may process personal data outside the European Economic Area or the United Kingdom. Where this occurs, we rely on the European Commission's Standard Contractual Clauses and, for transfers from the UK, the UK International Data Transfer Addendum, or other lawful transfer mechanisms recognized under the GDPR and UK GDPR.
We retain personal data according to the following general approach:
- Account data — retained while your account is active, and for a limited period afterward to address legal or operational needs.
- Billing records — retained as required by applicable tax and accounting laws.
- Usage and audit logs — retained for a limited period to support security investigations and service improvement.
- Support communications — retained for a reasonable period to resolve and reference prior inquiries.
Specific retention periods are available on request from jerogz@georithm.info.
For any questions regarding this GDPR Notice, contact:
- Data Protection Officer: [Data Protection Officer]
- Email: jerogz@georithm.info
- Postal address: [Business Address], [Country]
This GDPR Notice should be read alongside our [Privacy Policy](/legal/privacy-policy), which describes the categories of data we collect, our sub-processors, and our security practices in more detail. Where there is a conflict specific to EU or UK processing, this Notice will take precedence.
This document is provided as an original template for Georithm and is maintained by the account owner. It is app-owned editable content and is not legal advice or an independent certification. Replace every bracketed placeholder with your company details and have the final text reviewed by a qualified adviser before relying on it.