Roles, scope and instructions
Where a customer submits personal data to GeoCore for its own business purposes, the customer acts as controller and GeoCore acts as processor for that Customer Data, except where GeoCore acts independently for its own account, security, legal, billing or service-administration purposes. This DPA forms part of the service agreement.
Processing lasts for the term of the service and any applicable deletion/retention period. It includes hosting, storage, organisation, retrieval, transmission when requested by the customer, support, security, backup and deletion of Customer Data under documented customer instructions and these Terms.
Data and people concerned
Customer Data can include account users, customers, leads, contacts, supplier or project contacts, and other people whose information a customer uploads or enters. Categories may include identification/contact details, business and project information, quotations, communications, documents/photos and other data selected by the customer.
Customers must ensure instructions and data are lawful, documented where required, and within the scope of the service.
Processor commitments
GeoCore will ensure people authorised to process Customer Data are subject to confidentiality obligations, implement appropriate technical and organisational measures, assist reasonably with data-subject requests and security information, and notify the customer of personal-data incidents as required by applicable law.
GeoCore may use subprocessors to provide the service and will maintain the verified subprocessor information page. Customers may raise reasonable concerns through privacy@geocore.one. Subprocessor, transfer and audit terms require professional UK legal review before production publication.
Return, deletion, audits and transfers
On termination, Customer Data is handled through the available export and recoverable deletion process, subject to the retention architecture for billing, security, suppression, audit evidence, backup and legal requirements. The 30-day workspace recovery period is not a promise that every category will be erased at the end of that period.
GeoCore will provide reasonable information needed to demonstrate compliance, subject to security and confidentiality safeguards. International transfers, including any UK GDPR transfer mechanism, depend on provider and customer configuration and are not represented as pre-executed by this DPA.
