This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer") and [LEGAL ENTITY] ("GeoVerdict"). It applies whenever the Customer submits personal data to the GeoVerdict API or widget, and it is entered into by using the service; no signature is required. If the parties have signed a separate data processing agreement, that agreement prevails.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Customer Data" means personal data the Customer submits to the service, in particular address data sent to the validation and autocomplete endpoints.
2. Roles
For Customer Data, the Customer is the controller (or a processor acting on behalf of another controller) and GeoVerdict is the processor. For account, billing and website data, GeoVerdict is an independent controller as described in the Privacy Policy.
3. Details of the processing
| Subject matter | Validation, standardization and autocompletion of postal addresses via an HTTP API and embeddable widget |
|---|---|
| Duration | The term of the Customer's account, plus the deletion period in section 10 |
| Nature and purpose | Receiving address queries, forwarding them to the geocoding data sources configured for the request, scoring and returning results, caching results where permitted, and recording usage logs for billing, troubleshooting and the Customer's own analytics |
| Categories of personal data | Postal address components and free-text address queries; optional request labels chosen by the Customer |
| Categories of data subjects | Persons whose addresses the Customer submits, such as the Customer's customers, users, employees or contacts |
| Special categories | None. The Customer must not submit special categories of personal data (Art. 9 GDPR) to the service |
4. Instructions
GeoVerdict processes Customer Data only on the Customer's documented instructions, unless required to do otherwise by EU or member state law, in which case GeoVerdict informs the Customer before processing unless the law prohibits it. The Customer instructs GeoVerdict to process Customer Data as necessary to provide the service as documented, which includes forwarding queries to the configured geocoding data sources, caching, and retaining request logs that the Customer can inspect in the console. GeoVerdict will inform the Customer if, in its opinion, an instruction infringes the GDPR.
5. Confidentiality
GeoVerdict ensures that persons authorized to process Customer Data are bound by confidentiality obligations, contractual or statutory.
6. Security
GeoVerdict implements appropriate technical and organizational measures within the meaning of Art. 32 GDPR, taking into account the nature of the data and the risks of the processing. The current measures are described on the security page, including encrypted transport, hashed credentials, encrypted storage of secrets, and EU data storage. GeoVerdict may update these measures provided the overall level of protection is not reduced.
7. Subprocessors
The Customer grants a general authorization to engage the subprocessors listed at geoverdict.com/subprocessors, including the geocoding data sources described there. Geocoding data sources receive only the address query, never the identity of the Customer or the data subject. GeoVerdict will update that page before adding or replacing a subprocessor and, where reasonably possible, give account holders advance notice of material changes. If the Customer objects to a new subprocessor on reasonable data protection grounds and no workaround is available, the Customer may terminate the affected service.
GeoVerdict imposes data protection obligations on its subprocessors comparable to those in this DPA and remains responsible for their performance.
8. Assistance
Taking into account the nature of the processing, GeoVerdict assists the Customer with appropriate technical and organizational measures in fulfilling the Customer's obligations to respond to data subject requests (Art. 12-23 GDPR), and with the Customer's obligations under Art. 32-36 GDPR (security, breach notification, data protection impact assessments), insofar as the information is available to GeoVerdict. The console gives the Customer direct access to the request logs containing their submitted data.
9. Personal data breach
GeoVerdict notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available to it: the nature of the breach, the categories and approximate volumes concerned, likely consequences, and measures taken or proposed.
10. Deletion and return
During the term, the Customer can review Customer Data in the console and export results through the API. Upon account closure, GeoVerdict deletes Customer Data, including request logs, within 30 days of the Customer's request, unless EU or Dutch law requires further retention (for example billing records). Cached geocoding responses expire automatically within one hour.
11. International transfers
Customer Data is stored on infrastructure in the EU (Western Europe region, Amsterdam). Where a subprocessor processes personal data outside the EEA, or is part of a group headquartered outside the EEA, the transfer is covered by an adequacy decision (such as the EU-US Data Privacy Framework) or standard contractual clauses. Details per subprocessor are on the subprocessors page.
12. Audit
GeoVerdict makes available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR, starting with this DPA and the security and subprocessors pages. The Customer may, at most once per year and on at least 30 days' notice, conduct an audit limited to GeoVerdict's compliance with this DPA, at the Customer's cost, in a manner that does not endanger the confidentiality or availability of the service or other customers' data. Where possible, audits are satisfied through written information.
13. Liability and precedence
Liability under this DPA is governed by the limitations in the Terms of Service, to the extent permitted by law. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
14. Governing law
This DPA is governed by Dutch law, with the same venue as the Terms of Service.