Skip to content

Data Processing Addendum

In short

Geoverio's data processing addendum covers the case where your API requests contain personal data belonging to your own users — you act as the controller and Geoverio as the processor. It defines what is processed, for how long, the confidentiality obligations, and the sub-processors involved.

Last reviewed 11 September 2026

Key facts

breach notification time
72 hours
password hashing algorithm
Argon2id
subprocessor authorisation
general
special category data
none

This addendum applies where you send Geoverio personal data belonging to your own users. In that processing you are the controller and Geoverio is the processor, as those terms are used in the GDPR and the UK GDPR.

Last updated: 28 July 2026

Need this signed?
Email [email protected] with your entity details and we will return a countersigned copy. Accepting these terms is a condition of using the service; a signature is available when your procurement process requires one.

1. Scope of processing

ItemDetail
Subject matterProvision of the Geoverio APIs
DurationFor as long as your account is active, plus the retention periods in the Privacy Policy
Nature and purposeReceiving an API request, computing a response, caching results, metering usage and preventing abuse
Categories of data subjectYour end users and customers whose data you submit
Categories of personal dataPostal addresses (Sales Tax, Address Autocomplete) and IP addresses (IP Lookup), plus request metadata
Special category dataNone. Do not send special category data to these endpoints.

2. Our obligations

  • We process personal data only on your documented instructions — which, for this service, are the API requests you send — unless a law we are subject to requires otherwise.
  • Everyone with access is bound by confidentiality obligations.
  • We implement the technical and organisational measures set out in section 4 and in our Security page.
  • We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with supervisory authorities.
  • On termination we delete or return personal data, except where we must keep it by law.
  • We make available the information you need to demonstrate compliance.

3. Subprocessors

You give general authorisation for the subprocessors listed in the Privacy Policy. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds.

Each subprocessor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.

4. Security measures

  • TLS in transit for every endpoint, with HSTS on our web properties.
  • Passwords hashed with Argon2id and a server-side pepper. API keys stored only as hashes and shown to you once.
  • Optional two-factor authentication by authenticator app or emailed one-time code; recovery codes stored hashed.
  • Per-account rate limiting and quota enforcement; per-IP throttling on authentication.
  • Content Security Policy with per-request nonces, X-Frame-Options: DENY, and a strict referrer policy.
  • An audit log of security-relevant account actions.
  • Least-privilege access to production, reviewed when roles change.

5. Personal data breach

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own notification obligations, and we will keep you updated as we learn more.

Report a suspected vulnerability or breach to [email protected].

6. International transfers

Where personal data leaves the EEA or the UK, the transfer is made under the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with any supplementary measures the circumstances require.

7. Audit

On reasonable notice, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information needed to demonstrate compliance with this addendum and cooperate with audits carried out by you or an auditor you appoint, subject to confidentiality and to not compromising other customers' security.

8. Order of precedence

If this addendum conflicts with the Terms of Service, this addendum governs for the processing of personal data.

Frequently asked questions

What is the role of Geoverio in data processing?
Geoverio acts as the processor while you serve as the controller when sending personal data.
When must Geoverio notify about a breach?
They will notify within 72 hours of becoming aware of a personal data breach.
Do I need to sign anything to use these APIs?
Accepting these terms is required, but a signature is only needed if your procurement process demands one.
Are special category data supported?
No special category data should be sent to these endpoints as none are supported.