Scope
This DPA applies when you (the "Customer") use Geo-endpoint and we process personal data on your behalf. In that case, you are the Controller and we are the Processor.
Processing details
- Subject matter: Providing the Service and related support.
- Duration: For the term of the Services, and as needed for legal or security purposes.
- Nature and purpose: Processing Customer Personal Data to deliver API features.
- Categories of data: Data submitted through the Service (for example, addresses or location queries) and related usage metadata.
- Data subjects: Your end users and authorized users.
Processor obligations
We will:
- Process data only on documented instructions from the Customer.
- Ensure authorized personnel are bound by confidentiality.
- Implement appropriate technical and organizational measures to protect data.
- Assist with data subject requests as reasonably practicable.
- Notify the Customer of personal data breaches without undue delay.
- Delete or return Customer Personal Data at the end of the Services, unless retention is required by law.
Subprocessors
We use subprocessors to provide the Service. A current list is available on the Subprocessors page. We will notify Customers of material changes where required.
International transfers
Where transfers outside the EEA/UK are required, we will rely on appropriate safeguards such as Standard Contractual Clauses.
Audits
Upon reasonable request, we will provide information necessary to demonstrate compliance with this DPA.