This addendum applies where you send Geoverio personal data belonging to your own users. In that processing you are the controller and Geoverio is the processor, as those terms are used in the GDPR and the UK GDPR.
Last updated: 28 July 2026
1. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Geoverio APIs |
| Duration | For as long as your account is active, plus the retention periods in the Privacy Policy |
| Nature and purpose | Receiving an API request, computing a response, caching results, metering usage and preventing abuse |
| Categories of data subject | Your end users and customers whose data you submit |
| Categories of personal data | Postal addresses (Sales Tax, Address Autocomplete) and IP addresses (IP Lookup), plus request metadata |
| Special category data | None. Do not send special category data to these endpoints. |
2. Our obligations
- We process personal data only on your documented instructions — which, for this service, are the API requests you send — unless a law we are subject to requires otherwise.
- Everyone with access is bound by confidentiality obligations.
- We implement the technical and organisational measures set out in section 4 and in our Security page.
- We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with supervisory authorities.
- On termination we delete or return personal data, except where we must keep it by law.
- We make available the information you need to demonstrate compliance.
3. Subprocessors
You give general authorisation for the subprocessors listed in the Privacy Policy. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds.
Each subprocessor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
4. Security measures
- TLS in transit for every endpoint, with HSTS on our web properties.
- Passwords hashed with Argon2id and a server-side pepper. API keys stored only as hashes and shown to you once.
- Optional two-factor authentication by authenticator app or emailed one-time code; recovery codes stored hashed.
- Per-account rate limiting and quota enforcement; per-IP throttling on authentication.
- Content Security Policy with per-request nonces,
X-Frame-Options: DENY, and a strict referrer policy. - An audit log of security-relevant account actions.
- Least-privilege access to production, reviewed when roles change.
5. Personal data breach
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own notification obligations, and we will keep you updated as we learn more.
Report a suspected vulnerability or breach to [email protected].
6. International transfers
Where personal data leaves the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with any supplementary measures the circumstances require.
7. Audit
On reasonable notice, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to demonstrate compliance with this addendum and cooperate with audits carried out by you or an auditor you appoint, subject to confidentiality and to not compromising other customers' security.
8. Order of precedence
If this addendum conflicts with the Terms of Service, this addendum governs for the processing of personal data.