Legal

Data Processing Agreement

Last updated: 3 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer") and [LEGAL ENTITY] ("GeoVerdict"). It applies whenever the Customer submits personal data to the GeoVerdict API or widget, and it is entered into by using the service; no signature is required. If the parties have signed a separate data processing agreement, that agreement prevails.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Customer Data" means personal data the Customer submits to the service, in particular address data sent to the validation and autocomplete endpoints.

2. Roles

For Customer Data, the Customer is the controller (or a processor acting on behalf of another controller) and GeoVerdict is the processor. For account, billing and website data, GeoVerdict is an independent controller as described in the Privacy Policy.

3. Details of the processing

Subject matterValidation, standardization and autocompletion of postal addresses via an HTTP API and embeddable widget
DurationThe term of the Customer's account, plus the deletion period in section 10
Nature and purposeReceiving address queries, forwarding them to the geocoding data sources configured for the request, scoring and returning results, caching results where permitted, and recording usage logs for billing, troubleshooting and the Customer's own analytics
Categories of personal dataPostal address components and free-text address queries; optional request labels chosen by the Customer
Categories of data subjectsPersons whose addresses the Customer submits, such as the Customer's customers, users, employees or contacts
Special categoriesNone. The Customer must not submit special categories of personal data (Art. 9 GDPR) to the service

4. Instructions

GeoVerdict processes Customer Data only on the Customer's documented instructions, unless required to do otherwise by EU or member state law, in which case GeoVerdict informs the Customer before processing unless the law prohibits it. The Customer instructs GeoVerdict to process Customer Data as necessary to provide the service as documented, which includes forwarding queries to the configured geocoding data sources, caching, and retaining request logs that the Customer can inspect in the console. GeoVerdict will inform the Customer if, in its opinion, an instruction infringes the GDPR.

5. Confidentiality

GeoVerdict ensures that persons authorized to process Customer Data are bound by confidentiality obligations, contractual or statutory.

6. Security

GeoVerdict implements appropriate technical and organizational measures within the meaning of Art. 32 GDPR, taking into account the nature of the data and the risks of the processing. The current measures are described on the security page, including encrypted transport, hashed credentials, encrypted storage of secrets, and EU data storage. GeoVerdict may update these measures provided the overall level of protection is not reduced.

7. Subprocessors

The Customer grants a general authorization to engage the subprocessors listed at geoverdict.com/subprocessors, including the geocoding data sources described there. Geocoding data sources receive only the address query, never the identity of the Customer or the data subject. GeoVerdict will update that page before adding or replacing a subprocessor and, where reasonably possible, give account holders advance notice of material changes. If the Customer objects to a new subprocessor on reasonable data protection grounds and no workaround is available, the Customer may terminate the affected service.

GeoVerdict imposes data protection obligations on its subprocessors comparable to those in this DPA and remains responsible for their performance.

8. Assistance

Taking into account the nature of the processing, GeoVerdict assists the Customer with appropriate technical and organizational measures in fulfilling the Customer's obligations to respond to data subject requests (Art. 12-23 GDPR), and with the Customer's obligations under Art. 32-36 GDPR (security, breach notification, data protection impact assessments), insofar as the information is available to GeoVerdict. The console gives the Customer direct access to the request logs containing their submitted data.

9. Personal data breach

GeoVerdict notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, providing the information reasonably available to it: the nature of the breach, the categories and approximate volumes concerned, likely consequences, and measures taken or proposed.

10. Deletion and return

During the term, the Customer can review Customer Data in the console and export results through the API. Upon account closure, GeoVerdict deletes Customer Data, including request logs, within 30 days of the Customer's request, unless EU or Dutch law requires further retention (for example billing records). Cached geocoding responses expire automatically within one hour.

11. International transfers

Customer Data is stored on infrastructure in the EU (Western Europe region, Amsterdam). Where a subprocessor processes personal data outside the EEA, or is part of a group headquartered outside the EEA, the transfer is covered by an adequacy decision (such as the EU-US Data Privacy Framework) or standard contractual clauses. Details per subprocessor are on the subprocessors page.

12. Audit

GeoVerdict makes available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR, starting with this DPA and the security and subprocessors pages. The Customer may, at most once per year and on at least 30 days' notice, conduct an audit limited to GeoVerdict's compliance with this DPA, at the Customer's cost, in a manner that does not endanger the confidentiality or availability of the service or other customers' data. Where possible, audits are satisfied through written information.

13. Liability and precedence

Liability under this DPA is governed by the limitations in the Terms of Service, to the extent permitted by law. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.

14. Governing law

This DPA is governed by Dutch law, with the same venue as the Terms of Service.