geony.
Legal

Data Processing Agreement

The core in one paragraph: if you use Geony to process personal data of your own clients or leads, then you are the data controller for that and we are the processor. We do only what is needed to deliver the service, keep everything within the EU, report a data breach within 48 hours and delete everything when you leave. This page spells that out as Article 28 of the GDPR requires.

1. When this applies and between whom

This data processing agreement forms part of the general terms and conditions and applies automatically as soon as you process personal data through Geony for which you are responsible. That is the case with the free check under your own brand, the lead inbox, and with data about contact persons of your clients that you record in the app. A signature is not required; the agreement runs for as long as your account exists.

The processor is Artiq Motion B.V., Heliumstraat 8, 7463 PL Rijssen, KvK 67683428, btw-nummer NL002262657B49, acting under the Geony trademark. The data controller is the organisation in whose name the account is held. Where it concerns your own account data and your own use of Geony, we are the controller ourselves; that is set out in the privacy policy.

2. What it covers

Purpose. Delivering the Geony service to you: carrying out measurements, making reports and work lists, offering the free check under your brand and delivering the leads from it to you. For nothing else.

Which data. From leads that come in via the free check on your domain: name, email address, company name, the message they leave, and the brand, domain, question and competitor they have measured. To prevent misuse of the form we briefly keep a hashed IP address. From team members and clients you invite in the app: name and email address. From contact persons of your clients: whatever you enter yourself in the business context of a project.

From whom. Visitors to your free check, employees of your organisation and of your clients, and contact persons that you record.

How long. For as long as the agreement runs, with the periods from section 8.

3. What we do, and what we do not

We process this data only on your instruction. That instruction is the use of the service as the app offers it; if you want something else, you email us and we agree it. We do not use the data for our own purposes, do not sell it, and do not put leads from your free check on our own newsletter or into our own sales process. If we think an instruction conflicts with the GDPR, we say so immediately.

The questions you have measured go to the AI providers in the app, but those questions contain no personal data of your leads or clients: the question is the question. The AI providers are therefore not a sub-processor under this agreement.

Everyone at our end who has access to the data is bound to confidentiality and gets no more access than is needed for their work.

4. Sub-processors

We engage a small number of parties, each for one task. With each of them we have arrangements that are at least as strict as these:

If we want to add or replace a sub-processor, you will hear about it at least thirty days in advance by email. If you have well-founded objections and we cannot resolve them together, you can cancel the agreement free of charge before the effective date. We remain responsible towards you for what a sub-processor does.

5. Where the data is held

All data is stored and processed within the European Union. We transfer no data to countries outside the European Economic Area. Should a sub-processor nonetheless need this for its service, it happens only on the basis of a legally valid transfer mechanism, such as the standard contractual clauses of the European Commission.

6. Security

We take the measures you may expect from an online service, tailored to the kind of data we process for you:

On request we send you, once a year, a written statement about these measures and about the sub-processors we use, so that you can meet your own accountability obligation. An on-site audit we only do if a regulator requires it or after a data breach that affects you, on working days, after consultation and at your expense.

7. Data breaches and help with rights

If we discover a security breach affecting personal data for which you are responsible, we report it within 48 hours of discovery by email to the owner of your account, or to another address you have given us. We tell you what has happened, which data and which people it affects, what we are doing about it, and we help you with what you have to report to the Data Protection Authority and to data subjects. Whether you report is your decision; we do not report on your behalf.

If a lead or customer of yours asks us for access, rectification or erasure, we forward that request to you within five working days and do not handle it ourselves. Projects and measurement data you can view, export and delete yourself in the app; leads you view in the app, and if a lead has to be deleted or supplied, you email us and we do that within five working days. The same applies to a data protection impact assessment: ask us for what you need about our side of the processing.

8. When it ends

If you cancel or your account is terminated, you can export your measurement data (CSV) until the end of the paid period and request your leads from us as an export. After that we delete the personal data for which you are responsible within thirty days, including the leads from your free check. Backups expire according to the schedule from section 6 and are not used in the meantime to restore deleted data, except to recover from an outage on our side. Only what the law obliges us to keep, such as invoices, stays longer.

9. Liability and the rest

For liability, what is set out in the general terms and conditions states applies. Fines from a regulator are borne by the party to whom the breach is attributable. In the event of a conflict between this page and the terms, for personal data this page prevails. We can amend this agreement in the same way as the terms: thirty days in advance by email, with the option to cancel. Dutch law applies.

Questions about this agreement or about a processing activity can be sent to privacy@geony.ai. That address is also the point of contact for a data breach. On behalf of Artiq Motion B.V..

Version: September 2026.