ALIGN is still under construction. Create your account to join the beta:Get started โ†’

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the ALIGNTerms of Service (the "Agreement") between GEO NOVA SRL ("ALIGN", "we", "processor") and the customer entity accepting the Agreement ("Customer", "you", "controller"). It applies whenever you use the Service to process personal data relating to third parties.

If you use ALIGN solely to process your own personal data, this DPA does not apply to you โ€” our Privacy Policygoverns that relationship instead.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them in Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means personal data that we process on your behalf under the Agreement.

2. Roles of the parties

You act as controller and determine the purposes and means of processing Customer Personal Data. We act as processor and process it only on your behalf. Where you act as a processor for another controller, you confirm that you have the authority to appoint us as a sub-processor on that controller's instructions, and this DPA applies accordingly.

We remain an independent controller for the data described in ourPrivacy Policy โ€” your account details, billing records, and the technical and usage data we need to operate and secure the Service. That processing is not governed by this DPA.

3. Scope and duration of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out inAnnex A below. Processing lasts for the term of the Agreement, plus the limited period described in section 11.

4. Our instructions

We process Customer Personal Data only on your documented instructions, including with regard to transfers, unless required otherwise by Union or Member State law. Your use of the Service, your configuration choices, and the Agreement together constitute your documented instructions.

If we believe an instruction infringes the GDPR or other Union or Member State data protection law, we will inform you without undue delay. We may suspend the affected processing until the instruction is confirmed, amended or withdrawn.

We do not sell Customer Personal Data, and we do not use it for our own purposes, for advertising, or to train machine learning models.

5. Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to perform the Agreement.

6. Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. Those measures are described inAnnex 2 โ€” Technical and Organisational Measuresand incorporated into this DPA.

We may update those measures over time, provided the level of protection is not reduced.

7. Sub-processors

You give us general written authorisation to engage sub-processors. Our current sub-processors are listed inAnnex 1 โ€” Sub-processorsand incorporated into this DPA.

Before we add or replace a sub-processor, we will update that list and notify you at least thirty (30) days in advance, by email to the Owner of your organisation. If you have a reasonable objection on data protection grounds, you may raise it within that period; we will work with you in good faith to find a solution, and if none is found, you may terminate the affected part of the Service without penalty for the remainder of its term.

We impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance. Where a provider is listed in Annex 1 without a data processing agreement in place, Annex 1 says so on that provider's row.

8. AI model providers

The Service includes AI features. When you use them, the prompts and the context you supply โ€” which may contain Customer Personal Data if you choose to include it โ€” are transmitted to the AI model provider you select for that request. Those providers act as our sub-processors and are listed in Annex 1, together with the country in which they process data and the safeguard relied upon for any transfer outside the European Economic Area.

You choose the provider on a per-request basis. An administrator of your organisation may restrict which providers are available to its users, and providers established outside the EEA are disabled by defaultfor an organisation until an administrator enables them.

You are responsible for deciding whether to include personal data in a prompt, and for selecting a provider whose location and safeguards are compatible with your own obligations.

9. Assistance to you

Taking into account the nature of the processing and the information available to us, we will assist you:

If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance; we will refer them to you and inform you without undue delay.

10. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notification will describe the nature of the breach, its likely consequences, the measures taken or proposed, and a point of contact, to the extent that information is available to us at the time, with further information supplied as it becomes available.

You remain responsible for notifying your supervisory authority and, where required, the data subjects.

11. Deletion and return

On termination of the Agreement, and at your choice, we will delete or return Customer Personal Data, and delete existing copies, unless Union or Member State law requires us to retain it.

You may export Customer Personal Data in open formats at any time during the term, using the features of the Service. After termination, you havethirty (30) days to export it, after which we delete it. Until deletion is complete across all our systems, the data remains protected by this DPA and is not accessed.

12. Audits and information

We will make available to you the information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or another auditor you mandate.

In practice, we will first provide our published documentation, our security measures, and, when available, the reports of any third-party certification we hold. Where that is not sufficient for your obligations, you may request an audit, on reasonable prior notice, no more than once per twelve-month period unless a personal data breach or a supervisory authority requires otherwise, during business hours, and subject to confidentiality. Each party bears its own costs.

13. International transfers

We aim to process Customer Personal Data within the European Economic Area. Where a sub-processor processes it outside the EEA, we rely on an appropriate safeguard under Chapter V GDPR โ€” an adequacy decision, or the European Commission's Standard Contractual Clauses supplemented, where necessary, by additional measures.

Annex 1 states, for each sub-processor, the country of processing and the safeguard relied upon. Where you select an AI provider established outside the EEA, section 8 applies.

14. Annexes and precedence

The following annexes are incorporated into this DPA and are maintained as separate, versioned documents:

In case of conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

15. Liability and governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by Belgian law, and the courts of Brussels have jurisdiction, without prejudice to the competence of supervisory authorities.

Annex A โ€” Details of the processing

Subject matter. Provision of the ALIGN platform: creating, storing, processing, hosting and publishing geospatial data, web maps and GIS applications, including AI-assisted features.

Duration. The term of the Agreement, plus the period described in section 11.

Nature and purpose. Storage, hosting, structuring, conversion, spatial analysis, indexing, transmission, publication and deletion of the data you upload or create, and processing of the prompts you submit to AI features, in each case to provide the Service to you.

Types of personal data. Determined by you. Typically: identifiers and contact details of the users you invite to your organisation; and any personal data contained in the geospatial datasets, attribute tables, files, code or prompts you choose to upload or submit โ€” which may include addresses, parcel or building references, and any attribute you associate with an identified or identifiable person.

Categories of data subjects. Determined by you. Typically: your staff and the members of your organisation; and the individuals to whom the data you process relates, such as residents, applicants, customers or survey respondents.

Special categories. The Service is not designed for the processing of special categories of personal data within the meaning of Article 9 GDPR, or data relating to criminal convictions and offences under Article 10. If you intend to process such data, you must inform us in advance so that we can assess whether additional measures are required.

Contact

For any question about this agreement, a countersigned copy, or your processing records: contact@geonova.be. All our legal documents are listed on our legal page.