Exclusively for Marketing Agencies
Exclusively for Marketing Agencies

Data Processing Agreement

Effective Date: 1 June 2026
Parties: GEO Roadmap Limited (“Data Processor”) and the Subscriber (“Data Controller”)
Contact: legal@georoadmap.ai

This Data Processing Agreement (“DPA”) supplements the Terms of Service and governs the processing of personal data by GEO Roadmap Limited on behalf of the Subscriber in connection with the Platform. Where there is any conflict between this DPA and the Terms of Service, this DPA prevails in relation to personal data processing matters.

This DPA is designed to satisfy the requirements of: the New Zealand Privacy Act 2020; the EU General Data Protection Regulation (GDPR) Article 28; the UK GDPR; and equivalent data processing contract requirements in other jurisdictions where Subscribers operate.

1. Roles and Scope

For the purposes of this DPA:

  • The Subscriber acts as the Data Controller in respect of any personal data submitted to the Platform, including personal data embedded in Client Domain inputs or Discovery Session responses.
  • GEO Roadmap Limited acts as the Data Processor, processing that data solely on the Subscriber’s documented instructions and for the purposes described in this DPA.
  • The primary data processed under this DPA relates to: business contact information submitted at registration; and any personal data incidentally present in Discovery Session inputs or Client Domain content (for example, names of key personnel referenced in discovery responses). GEO Roadmap does not systematically collect personal data of end users of Client Domains.

2. GEO Roadmap’s Processing Obligations

As Data Processor, GEO Roadmap will:

  • Process personal data only on the documented instructions of the Subscriber (as set out in the Terms of Service and this DPA) and for no other purpose;
  • Ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations;
  • Implement technical and organisational measures appropriate to the risk, as described in Schedule 1 to this DPA;
  • Not engage sub-processors without the Subscriber’s general authorisation (given by acceptance of these Terms) and, where specific sub-processors are engaged, impose equivalent data protection obligations on them;
  • Assist the Subscriber, to the extent reasonably practicable, in fulfilling obligations to respond to data subject rights requests;
  • Upon termination of the subscription, delete or return personal data in accordance with clause 6 of the Privacy Policy, unless retention is required by law;
  • Make available to the Subscriber all information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits or inspections on reasonable notice.

3. Ring-Fencing of Client Domain Data

This clause reflects a core architectural and contractual commitment of the Platform:

Client Domain data submitted by a Subscriber — including the domain URL, Discovery Session responses, Audit outputs, and Roadmap contents — is processed exclusively for the purpose of generating Platform Outputs for that Subscriber. This data:

  • Is not used to prospect for, solicit, or approach the Client Domain on behalf of any entity other than the Subscriber;
  • Is not shared with other Subscribers;
  • Is not used to generate insights, reports, or intelligence for any third party;
  • Is not accessible to any personnel or contractor except on a need-to-know basis strictly for the purpose of platform operation, support, and improvement;
  • Is not used for competitive intelligence gathering for the benefit of any marketing agency or other business entity.

Operational tools used in the delivery of the Platform — including project management systems, communication platforms, and collaboration tools — are configured to restrict access to Client Domain data to only those personnel whose role requires it. All personnel and contractors with such access are bound by written confidentiality obligations as a condition of their engagement. GEO Roadmap reserves the right to engage advisors, contractors, and service providers as reasonably required to operate the Platform; all such parties are contractually required to comply with the data handling obligations in this DPA.

4. Sub-Processors

The Subscriber provides general authorisation for GEO Roadmap to engage sub-processors for the purposes of operating the Platform. GEO Roadmap will notify Subscribers of any new sub-processor that will process their personal data, with at least 14 days’ notice before the new sub-processor commences processing. Subscribers may object to a new sub-processor on reasonable grounds by written notice to legal@georoadmap.ai.

A current list of approved sub-processors is available on request.

5. Data Subject Rights

Where a Subscriber receives a data subject rights request relating to personal data processed through the Platform, GEO Roadmap will provide reasonable assistance to enable the Subscriber to respond. Subscribers remain the Data Controller and are responsible for responding to data subjects directly.

Where GEO Roadmap receives a data subject rights request directly concerning personal data it holds as Processor, it will promptly notify the Subscriber and await instructions, unless a legal obligation requires immediate action.

6. Security Incident Notification

In the event of a personal data breach affecting data processed under this DPA, GEO Roadmap will notify the Subscriber without undue delay and in any event within 48 hours of becoming aware of the breach. The notification will include, to the extent available: a description of the nature of the breach; categories and approximate number of individuals affected; likely consequences; and measures taken or proposed to address the breach.

GEO Roadmap will cooperate with the Subscriber in any notifications required to be made to supervisory authorities or affected data subjects.

7. International Transfers

Where personal data is transferred to a jurisdiction outside the EEA, UK, or other jurisdiction with transfer restrictions, GEO Roadmap will ensure a lawful transfer mechanism is in place. As a New Zealand entity, GEO Roadmap benefits from the European Commission’s adequacy decision in respect of New Zealand, permitting transfers from the EEA without additional safeguards. For transfers to sub-processors in other jurisdictions, GEO Roadmap relies on EU/UK Standard Contractual Clauses or equivalent mechanisms.

8. Term and Termination

This DPA remains in force for the duration of the Subscriber’s subscription. Upon termination, the data retention and deletion obligations in the Privacy Policy apply.

Free Trial. Agencies Only

A work email from your agency domain is required to access the platform

Contact Us
Country
Country
State/Province
Zip/Postal

FREE TRIAL INCLUDES: