Data Processing Agreement
Last updated: 3 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between GeoScale and the customer using the GeoScale Services ("Customer") where GeoScale processes personal data on behalf of Customer.
This DPA is intended to satisfy the requirements applicable to processor agreements under Article 28 of Regulation (EU) 2016/679 (the "GDPR").
1. Parties and roles
Customer is the controller of Customer Personal Data and GeoScale is the processor of Customer Personal Data, except where applicable law determines otherwise for a particular processing activity.
"Customer Personal Data" means personal data processed by GeoScale on behalf of Customer in connection with the Services.
"Controller", "Processor", "Personal Data", "Data Subject", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given to them in the GDPR.
2. Scope and duration
This DPA applies to GeoScale's processing of Customer Personal Data where such processing is performed on behalf of Customer in connection with the Services.
The processing continues for as long as GeoScale processes Customer Personal Data on behalf of Customer, including any limited period following termination that is reasonably necessary to complete deletion or comply with applicable law.
3. Nature and purpose of processing
GeoScale processes Customer Personal Data as necessary to provide geographic-data and address services requested by Customer, including to:
- Receive and process address-search requests
- Return address autocomplete results
- Retrieve addresses by GeoScale identifier
- Route and deliver API requests and responses
- Apply security and rate-limiting controls
- Diagnose technical problems
- Provide support requested by Customer
- Otherwise carry out Customer's documented instructions consistent with the Services
4. Types of Customer Personal Data
Depending on how Customer uses the Services, Customer Personal Data may include:
- Partial or complete address-search queries
- Street names
- House numbers and additions
- Postal codes
- Localities and municipalities
- Address identifiers
- Geographic coordinates
- Technical request information, including IP addresses where applicable
- Other information Customer chooses to submit in connection with a support request
The Services are not designed for the intentional submission of special categories of personal data under Article 9 GDPR, criminal-conviction or offence data, passwords, payment-card information, government identity documents, or similarly sensitive information.
5. Categories of Data Subjects
Depending on Customer's use of the Services, Data Subjects may include:
- Customer's customers and prospective customers
- Users of Customer's websites or applications
- Ecommerce customers
- Delivery recipients
- Customer personnel
- Persons associated with addresses submitted through the Services
6. Customer instructions
GeoScale will process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of personal data outside the European Economic Area, unless processing is required by applicable European Union or Member State law.
The agreement governing the Services, this DPA, Customer's use and configuration of the Services, and other written instructions accepted by GeoScale constitute Customer's documented instructions.
If applicable law requires GeoScale to process Customer Personal Data otherwise than on Customer's instructions, GeoScale will inform Customer before carrying out that processing unless the law prohibits such notification.
GeoScale will inform Customer if, in GeoScale's reasonable opinion, an instruction infringes the GDPR or other applicable European data-protection law.
7. Customer responsibilities
Customer is responsible for:
- Complying with applicable data-protection law in its use of the Services
- Providing any required privacy information to Data Subjects
- Establishing an appropriate legal basis for processing Customer Personal Data
- Ensuring its instructions to GeoScale are lawful
- Limiting Customer Personal Data submitted to what is reasonably necessary for the intended purpose
- Responding to Data Subjects in its capacity as controller
8. Confidentiality
GeoScale will ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
Access to Customer Personal Data will be limited to persons and service providers that require access for legitimate purposes connected with providing, securing, maintaining, or supporting the Services.
9. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of the processing, GeoScale will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures used by GeoScale include, as appropriate:
- Encrypted transmission using HTTPS/TLS
- Authentication and API credential controls
- Access controls and restricted administrative access
- Network and infrastructure security controls
- Rate limiting and abuse-prevention mechanisms
- Operational logging and monitoring where appropriate
- Software and dependency maintenance
- Backup or recovery mechanisms for relevant mutable service data
- Incident-response procedures
Customer acknowledges that no internet-based service can provide absolute security and that appropriate security measures may evolve over time.
10. Data minimization and query retention
GeoScale does not ordinarily persist the content of address queries in its application databases. Address-query content is processed transiently as necessary to provide the requested API response.
Request information, including address-query content, may temporarily appear in operational infrastructure logs where it is included in a request URL or otherwise processed by infrastructure providers.
GeoScale may also retain Customer Personal Data supplied voluntarily in support correspondence for as long as reasonably necessary to investigate and resolve the relevant support matter and maintain appropriate business records.
11. Subprocessors
Customer grants GeoScale general written authorization to engage subprocessors where reasonably necessary to provide the Services.
GeoScale maintains its current subprocessors and their relevant processing activities on the Subprocessor List.
GeoScale will enter into a written agreement with each subprocessor requiring data-protection obligations that provide protection appropriate to the processing and are no less protective than the obligations applicable to GeoScale under this DPA to the extent required by Article 28 GDPR.
GeoScale remains responsible to Customer for the performance of its subprocessors' data-protection obligations as required by applicable law.
12. Changes to subprocessors
GeoScale will provide Customer with at least 14 days' advance notice by email before a new or replacement subprocessor begins processing Customer Personal Data.
Where an urgent change is reasonably necessary to protect the security or availability of the Services, comply with law, or respond to circumstances outside GeoScale's reasonable control, GeoScale may appoint a subprocessor on shorter notice and will inform Customer as soon as reasonably practicable.
Customer may object to a new subprocessor during the notice period where it has reasonable grounds relating to the protection of Customer Personal Data.
GeoScale and Customer will make reasonable efforts to resolve the objection. If no reasonable solution is available, Customer may stop using and terminate the part of the Services that requires the relevant subprocessor before that subprocessor begins processing Customer Personal Data.
13. International transfers
GeoScale will ensure that transfers of Customer Personal Data outside the European Economic Area are made only where permitted under Chapter V of the GDPR.
Where required, GeoScale or the relevant subprocessor will rely on an appropriate transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another legally permitted safeguard.
14. Data Subject requests
Taking into account the nature of the processing, GeoScale will provide reasonable assistance to Customer through appropriate technical and organizational measures, insofar as reasonably possible, to enable Customer to respond to requests from Data Subjects exercising their rights under the GDPR.
If GeoScale receives a Data Subject request that relates primarily to Customer Personal Data processed on behalf of Customer, GeoScale will ordinarily refer the requester to Customer and will not independently respond to the substance of the request unless required by applicable law.
15. Security and regulatory assistance
Taking into account the nature of the processing and the information available to GeoScale, GeoScale will provide reasonable assistance to Customer concerning Customer's obligations under Articles 32 to 36 GDPR.
Such assistance may include information reasonably necessary for security assessments, Personal Data Breach notifications, data protection impact assessments, and consultation with Supervisory Authorities where relevant to GeoScale's processing.
16. Personal Data Breaches
GeoScale will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, GeoScale will provide information concerning:
- The nature of the Personal Data Breach
- The categories and approximate number of affected Data Subjects and records, where known
- The likely consequences of the Personal Data Breach
- Measures taken or proposed to address or mitigate the Personal Data Breach
- Other information reasonably available to GeoScale that Customer needs to meet its notification obligations
GeoScale may provide this information in phases where all relevant information is not available at the same time.
Notification of a Personal Data Breach does not constitute an admission of fault or liability by GeoScale.
17. Return and deletion
At the end of the Services involving processing of Customer Personal Data, GeoScale will, at Customer's choice, delete or return Customer Personal Data to the extent it remains under GeoScale's control, unless applicable law requires continued storage.
Customer acknowledges that address-query content is ordinarily processed transiently rather than stored in GeoScale's application databases and therefore may already have been deleted by the time the Services end.
Residual Customer Personal Data in operational logs, support records, or backups may remain until removed in accordance with the applicable retention cycle, provided that it remains protected in accordance with this DPA and is not used for another purpose.
GeoScale may retain information where and for as long as required by applicable law.
18. Information and audits
GeoScale will make available to Customer information reasonably necessary to demonstrate compliance with the obligations applicable to GeoScale under Article 28 GDPR.
Where reasonably sufficient, Customer will first use documentation, written responses, security information, or remote review to verify GeoScale's compliance.
If such information is not reasonably sufficient, Customer may conduct an audit or appoint an independent auditor to do so, subject to reasonable advance notice and appropriate confidentiality obligations.
Unless required by a Supervisory Authority or applicable law, or reasonably justified by a Personal Data Breach or credible evidence of material non-compliance, Customer may exercise this audit right no more than once in any 12-month period.
Audits must be conducted during normal business hours, must not unreasonably interfere with GeoScale's operations or security, and must not provide access to information concerning other customers except where legally required.
Each party will bear its own costs associated with an ordinary audit unless otherwise required by applicable law or agreed between the parties.
19. Records and Supervisory Authorities
GeoScale will maintain records of processing activities where required by applicable law and will cooperate with competent Supervisory Authorities as legally required.
20. Liability
Liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the GeoScale Terms of Service or other agreement governing Customer's use of the Services, to the extent permitted by applicable law.
21. Priority
If this DPA conflicts with the Terms of Service concerning the processing of Customer Personal Data on behalf of Customer, this DPA prevails to the extent of that conflict.
Mandatory data-protection law prevails over this DPA where it imposes an obligation that cannot lawfully be varied by agreement.
22. Governing law and disputes
This DPA is governed by the same governing-law and dispute-resolution provisions that apply under the agreement governing Customer's use of the Services.
23. Contact
Questions or requests relating to this DPA may be sent to support@geoscale.io.