Data Processing Agreement

Version 1.0  ·  Effective August 2026  ·  GeoScript, Inc.

This Data Processing Agreement ("DPA") is entered into between GeoScript, Inc. ("Processor" or "GeoScript") and the customer entity that has executed a subscription agreement with GeoScript ("Controller" or "Customer"), collectively the "Parties."

This DPA forms part of, and is incorporated into, the GeoScript Terms of Service or any other agreement between the Parties governing use of the GeoScript Services (the "Agreement"). In the event of conflict between this DPA and the Agreement on data processing matters, this DPA controls. This DPA is effective upon the date the Agreement is executed or, where this DPA is incorporated by reference, upon Customer's acceptance of the Agreement.

To request a countersigned copy of this DPA, email hello@geoscript.ai with the subject line "DPA Request."

1. Definitions

Capitalized terms not defined in this DPA have the meanings given to them in the Agreement or in the GDPR. The following terms have the meanings set out below:

  • "Applicable Data Protection Law" means all data protection and privacy legislation applicable to the processing of Customer Personal Data, including: (a) the EU General Data Protection Regulation 2016/679 (EU GDPR) and Member State implementing legislation; (b) the UK Data Protection Act 2018 and UK GDPR; (c) the Swiss Federal Act on Data Protection (Swiss FADP); (d) the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); and (e) any other applicable US state privacy law (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and equivalents as enacted).
  • "Controller" means the Customer, as the entity that determines the purposes and means of processing of Customer Personal Data.
  • "Controller Personal Data" means any personal data processed by Processor on behalf of Controller pursuant to or in connection with the Agreement, as further described in Annex I.
  • "Data Subject" means an identified or identifiable natural person to whom Controller Personal Data relates.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller Personal Data transmitted, stored, or otherwise processed by Processor.
  • "Processing" means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Processor" means GeoScript, Inc., as the entity that processes Controller Personal Data on behalf of Controller.
  • "Restricted Transfer" means a transfer of Controller Personal Data from the EEA, UK, or Switzerland to a country not subject to an adequacy decision by the relevant authority (European Commission, UK Secretary of State, or Swiss FDPIC).
  • "Services" means the GeoScript AI search visibility monitoring and optimization services as described in the Agreement.
  • "Signal Data" means data collected by the GeoScript JavaScript Script from monitored websites, as defined in the Terms of Service. Signal Data is owned by GeoScript (Terms of Service §6.1) and is not Controller Personal Data for purposes of this DPA, except to the extent it contains personal data of website visitors processed on Controller's instructions.
  • "Sub-Processor" means any third-party processor engaged by Processor to process Controller Personal Data on behalf of Controller.
  • "Supervisory Authority" means a public authority responsible for monitoring compliance with Applicable Data Protection Law, including the data protection authorities of EU Member States, the UK Information Commissioner's Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC).

2. Scope and Roles

2.1 Controller and Processor

The Parties acknowledge that, with respect to Controller Personal Data, Customer is the Controller and GeoScript is the Processor. GeoScript processes Controller Personal Data only on behalf of and under the instructions of Controller, except where required to do so by applicable law.

2.2 Signal Data Carve-Out

Signal Data collected by the Script from monitored websites is assigned to and owned by GeoScript pursuant to the Terms of Service (§6.1). To the extent Signal Data contains personal data of website visitors, GeoScript processes it as a Processor under Controller's instructions solely for the purpose of providing the Services. GeoScript's use of aggregated, anonymized Signal Data for dataset and product improvement purposes is conducted by GeoScript as a Controller and is not governed by this DPA.

2.3 Controller Responsibilities

Controller warrants and represents that: (a) it has all necessary rights and legal bases to provide Controller Personal Data to GeoScript for processing under this DPA; (b) its instructions for processing comply with Applicable Data Protection Law; (c) it is responsible for the accuracy, quality, and lawfulness of Controller Personal Data; and (d) where required, it has obtained all necessary consents from Data Subjects for the processing described herein, including consents required for the Script's operation on Controller's or its clients' websites.

3. Processing Instructions

3.1 Documented Instructions

GeoScript processes Controller Personal Data only on documented instructions from Controller. The Agreement and this DPA constitute Controller's primary instructions. Controller may issue additional instructions via email to hello@geoscript.ai that are consistent with the scope of the Agreement. GeoScript has no obligation to follow instructions that would require processing beyond the scope of the Services or in violation of Applicable Data Protection Law.

3.2 Legal Obligation Override

GeoScript may process Controller Personal Data beyond Controller's instructions where required by applicable law. In such cases, GeoScript will notify Controller of the legal requirement before processing unless prohibited by law from doing so.

3.3 Notification of Unlawful Instructions

If GeoScript determines that a Controller instruction would infringe Applicable Data Protection Law, GeoScript will promptly notify Controller in writing. GeoScript may suspend processing under the challenged instruction until Controller provides a revised lawful instruction.

4. Confidentiality of Processing

GeoScript ensures that all personnel and contractors authorized to process Controller Personal Data are bound by enforceable confidentiality obligations that survive termination of their engagement with GeoScript. GeoScript grants access to Controller Personal Data only to personnel who require such access to perform their responsibilities in connection with the Services. GeoScript maintains internal access control policies limiting who may access Controller Personal Data and under what circumstances.

5. Security Measures

5.1 Technical and Organizational Measures

GeoScript implements and maintains appropriate technical and organizational measures (TOMs) designed to protect Controller Personal Data against unauthorized access, disclosure, alteration, loss, or destruction, taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, and the risks to Data Subjects. The current TOMs are set out in Annex II of this DPA.

5.2 Updates to Security Measures

GeoScript may update its security measures from time to time, provided that any update does not materially reduce the overall security level afforded to Controller Personal Data. GeoScript will notify Controller of any material reduction in security measures.

5.3 Audit Rights

GeoScript will make available to Controller, upon written request, all information reasonably necessary to demonstrate compliance with this DPA, including summaries of applicable third-party security assessments (which may be redacted to protect confidential information). Controller may, not more than once per calendar year and upon 30 days' prior written notice, request an on-site or remote audit of GeoScript's data processing practices. The scope, timing, and cost of any such audit will be agreed in writing by both Parties in advance. Controller shall bear the reasonable costs of any such audit. Audit results constitute GeoScript Confidential Information.

6. Personal Data Breach Notification

6.1 Notification Timeline

GeoScript will notify Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Controller Personal Data, to the extent such notification is possible and does not unreasonably delay or impede GeoScript's containment and remediation efforts.

6.2 Notification Content

The breach notification will include, to the extent then known:

  • The nature of the Personal Data Breach;
  • The categories and approximate number of Data Subjects affected;
  • The categories and approximate volume of Controller Personal Data records affected;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach and mitigate its effects;
  • Contact information for GeoScript's point of contact for the breach.

Where all information cannot be provided within 72 hours, GeoScript will provide it in phases as it becomes available.

6.3 Regulatory Notification

Controller is responsible for determining whether and how to notify Supervisory Authorities and Data Subjects of a breach. GeoScript will provide reasonable assistance to Controller in meeting its breach notification obligations under Applicable Data Protection Law.

7. Data Subject Rights

GeoScript will provide Controller with reasonable technical and organizational assistance to enable Controller to fulfill its obligations to respond to Data Subject requests exercising rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection (GDPR Articles 15–22; CCPA/CPRA §§ 1798.100–1798.135).

GeoScript will not respond directly to Data Subject requests concerning Controller Personal Data. If GeoScript receives such a request, it will promptly forward it to Controller. Controller is responsible for responding to Data Subjects within the timeframes required by Applicable Data Protection Law.

GeoScript's ability to assist with erasure requests is subject to the Signal Data provisions in the Terms of Service (§6.1) and Section 2.2 of this DPA. GeoScript cannot identify individual Data Subjects within anonymized or aggregated Signal Data.

8. Sub-Processors

8.1 General Authorization

Controller provides general written authorization for GeoScript to engage Sub-Processors for the processing activities described in this DPA. The current list of approved Sub-Processors is set out in Annex III of this DPA and at geoscript.ai/data-policy#subprocessors.

8.2 Notification of Changes

GeoScript will provide Controller with at least 10 days' prior written notice before adding or replacing a Sub-Processor that will process Controller Personal Data. Notice will be sent to the email address on file for Controller's account.

8.3 Right to Object

Controller may object to the addition or replacement of a Sub-Processor by providing written notice to GeoScript within 10 days of receiving notification. Controller's objection must be based on reasonable grounds relating to data protection. If the Parties cannot resolve the objection within 30 days, either Party may terminate the Agreement on written notice without penalty, with a pro-rata refund of any prepaid fees for the unused portion of the subscription term.

8.4 Sub-Processor Obligations

GeoScript imposes data protection obligations on each Sub-Processor by written contract that are at least as protective as those in this DPA. GeoScript remains fully liable to Controller for the performance of Sub-Processors' data protection obligations.

9. International Data Transfers

9.1 Transfer Mechanisms

Where GeoScript processes Controller Personal Data that originates in the EEA, UK, or Switzerland and transfers it to the United States or other non-adequate countries, GeoScript relies on the following lawful transfer mechanisms:

  • EU Standard Contractual Clauses (SCCs) — Module 2 (Controller to Processor): the SCCs approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which are incorporated into this DPA by reference and supplement the applicable clauses in this Agreement. Where the SCCs require Annex information, such information is set out in Annex I and Annex II of this DPA.
  • UK International Data Transfer Addendum (IDTA): for transfers subject to UK GDPR, GeoScript relies on the UK IDTA issued by the ICO under s.119A of the Data Protection Act 2018, incorporated by reference.
  • EU-U.S. Data Privacy Framework (DPF) / UK Extension: where applicable Sub-Processors are certified under the DPF, GeoScript relies on their DPF certification as an additional or alternative transfer mechanism.

9.2 SCC Precedence

To the extent there is any conflict between the SCCs and this DPA on matters of data protection, the SCCs prevail. Nothing in this DPA contradicts or reduces any rights or obligations of either Party under the SCCs.

9.3 Copies of SCCs

Controller may request a copy of the applicable SCCs and any Transfer Impact Assessment (TIA) by emailing hello@geoscript.ai. GeoScript will provide these within 10 business days.

10. Deletion and Return of Data

Upon termination or expiry of the Agreement, or upon Controller's written request, GeoScript will, at Controller's election:

  • Delete all Controller Personal Data within Controller's account within 60 days, and provide written confirmation of deletion; or
  • Return Controller Personal Data in a portable, machine-readable format (CSV or JSON) within 30 days of the request, after which GeoScript will delete all copies.

GeoScript may retain Controller Personal Data beyond these periods only where required by applicable law (e.g., billing records required for tax compliance) or to the extent it forms part of GeoScript's aggregated, anonymized dataset (Signal Data owned by GeoScript per Terms of Service §6.1), which cannot be disaggregated. GeoScript will notify Controller of any such retained data and the legal basis for retention.

11. CCPA / US State Privacy Laws

To the extent the CCPA/CPRA or other applicable US state privacy laws apply to GeoScript's processing of Controller Personal Data:

  • GeoScript is a "Service Provider" (as defined under CCPA) with respect to Controller Personal Data and processes it solely for the business purpose of providing the Services.
  • GeoScript will not: sell Controller Personal Data; share it for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with Controller; or combine it with personal information from other sources except as permitted by Applicable Data Protection Law or required to provide the Services.
  • GeoScript will comply with applicable obligations under CCPA/CPRA as a Service Provider, including honoring opt-out requests communicated to it by Controller.
  • GeoScript will notify Controller if it determines it can no longer meet its obligations as a Service Provider under Applicable Data Protection Law.

12. Liability

Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service §14). In the event of conflict between the liability provisions of this DPA and the SCCs, the SCCs prevail to the extent required by applicable law. Nothing in this DPA excludes or limits a Party's liability to the extent it cannot be excluded or limited by Applicable Data Protection Law.

Annex I — Description of Processing

Required by GDPR Art. 28(3) and EU SCC Module 2, Annex I.

A. Parties

Data Exporter (Controller)The Customer entity that has executed a GeoScript subscription agreement. Role: Controller. Activity: uses GeoScript to monitor AI search visibility for its own websites and/or its clients' websites.
Data Importer (Processor)GeoScript, Inc., a Delaware corporation. Role: Processor. Activity: provides AI search visibility monitoring and optimization services via the GeoScript platform and JavaScript Script.

B. Description of Transfer / Processing

Subject matterProcessing of personal data in connection with the provision of AI search visibility monitoring and optimization services.
DurationFor the term of the Agreement plus any applicable retention periods set out in this DPA and the Privacy Policy.
Nature and purposeCollection, storage, organization, retrieval, use, and deletion of personal data to: (a) provision and operate Customer's GeoScript account; (b) authenticate and authorize Authorized Users; (c) process billing and subscription management; (d) provide customer support; (e) deliver AI search visibility reports, dashboards, and optimization recommendations based on Script-collected Signal Data.
Types of personal dataAccount data: name, email address, company name, job title, password hash. Billing data: payment method details (tokenized via Stripe; full card numbers not processed by GeoScript), billing address, transaction history. Usage data: IP address (truncated), browser type, platform interactions, feature usage logs. Signal Data (website visitor data): AI crawler bot events, HTTP referrer signals, session source data — no names, emails, or persistent identifiers of website visitors (see Data Policy §2.3).
Categories of data subjects(1) Customer Authorized Users: employees, contractors, or agents of Customer with accounts on the GeoScript platform. (2) Website visitors: individuals visiting websites on which the Script is installed, whose session-level signals (AI referral, bot crawl) are processed — no direct identifiers collected.
Sensitive dataNone. GeoScript does not process special categories of personal data (GDPR Art. 9) or data relating to criminal convictions or offenses (Art. 10).
FrequencyContinuous (real-time Script signal collection); periodic (scheduled visibility query runs, twice monthly or as configured by Customer tier); on-demand (dashboard access, report generation).
RecipientsGeoScript personnel with authorized access; Sub-Processors listed in Annex III.
International transfersController Personal Data is transferred from the EEA/UK/Switzerland to the United States. Transfer mechanism: EU SCCs Module 2 / UK IDTA / DPF as applicable (see §9).

Annex II — Technical and Organizational Security Measures

Required by GDPR Art. 32 and EU SCC Module 2, Annex II.

Pseudonymization and anonymization

Website visitor Signal Data is processed without direct identifiers. IP addresses are used only for geolocation derivation and are not stored in full. Aggregated outputs are anonymized before use in benchmarks.

Encryption in transit

All data transmitted between users, the Script, and GeoScript servers uses TLS 1.2 or higher. Unencrypted HTTP connections are rejected. API endpoints enforce HTTPS.

Encryption at rest

All Controller Personal Data stored in Supabase (PostgreSQL) and associated storage is encrypted at rest using AES-256. Database backups are encrypted.

Confidentiality and access control

Role-based access control (RBAC) restricts access to Controller Personal Data to authorized GeoScript personnel with a documented need. Access logs are maintained.

Integrity and availability

Database replication and daily backups are maintained with a 30-day rolling retention. Backup integrity is tested periodically. Infrastructure uses redundant availability zones.

Authentication

Multi-factor authentication (MFA) is required for all GeoScript administrative and infrastructure access. Customer accounts support MFA via Supabase Auth.

Incident response

GeoScript maintains an internal security incident response plan. Confirmed breaches are escalated immediately; Controller notification is sent within 72 hours of awareness.

Vendor/subprocessor management

All Sub-Processors are assessed for data protection compliance before engagement. Sub-Processor agreements include data protection obligations at least as protective as this DPA.

Physical security

GeoScript operates on cloud infrastructure (AWS via Supabase, Vercel). Physical data center security is managed by those providers, who maintain SOC 2 and ISO 27001 compliance.

Vulnerability and patch management

GeoScript monitors dependencies for known vulnerabilities and applies security patches on a priority basis. Infrastructure is updated regularly.

Annex III — List of Sub-Processors

Current as of August 2026. Updated in the Data Policy whenever Sub-Processors are added or changed. Controller will receive 10 days' advance notice of any addition or replacement.

Sub-ProcessorServicePersonal Data ProcessedLocationTransfer Mechanism
SupabaseDatabase, authentication, storageAccount data, auth tokens, billing records, usage logs, Signal DataUS (AWS us-east-1)SCCs Module 2
StripePayment processingBilling data (name, tokenized card, billing address, transaction history)USDPF certified
PineconeVector databaseAggregated Signal Data (vectorized, no direct identifiers)USSCCs Module 2
VercelHosting, CDN, deploymentIP addresses (transient), request metadata, log dataUS (edge globally)SCCs Module 2
UpstashRedis caching, rate limiting, queuesSession tokens, rate-limit counters, transient query dataUSSCCs Module 2
OpenAIAI engine querying for visibility monitoringBusiness name, city, industry (query construction — no Authorized User personal data)USDPF certified
AnthropicAI engine querying for visibility monitoringBusiness name, city, industry (query construction only)USSCCs Module 2
Perplexity AIAI engine querying for visibility monitoringBusiness name, city, industry (query construction only)USSCCs Module 2
Google (Gemini)AI engine querying for visibility monitoringBusiness name, city, industry (query construction only)USDPF certified

Execution and Contact

This DPA is incorporated into the Agreement upon Customer's acceptance of the Terms of Service. No separate signature is required for standard subscription accounts. Enterprise customers requiring a countersigned DPA should contact:

GeoScript, Inc.
Data Processing Inquiries
hello@geoscript.ai

Related documents: Terms of Service · Privacy Policy · Data Policy

Version 1.0 — Effective August 2026. Prior versions available upon request.