[ Legal ]

Data Processing Agreement

Last modified: September 8, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between: Automagical Technologies Limited, trading as "GEO MarketMap" ("Processor"), and the customer that has accepted the Terms of Service and uses the Services ("Controller"). Together, the "Parties". This DPA is incorporated by reference into the Terms of Service and applies automatically from the moment Controller accepts the Terms. No separate signature is required. Controller may request a countersigned copy by contacting Processor at the address in section 16.

1. Purpose and Scope

This DPA governs Processor's Processing of Personal Data on behalf of Controller in connection with the Services.

It applies where Processor acts as a Processor under applicable data-protection law.

Where Processor acts as an independent Controller (for example, in respect of publicly available search data and competitor information used for its own analytics features), such processing is governed by the Privacy Policy.

2. Definitions

Capitalized terms not defined herein have the meaning given in the Terms of Service.

"Applicable Data Protection Law" means the EU General Data Protection Regulation (GDPR), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Hong Kong Personal Data (Privacy) Ordinance, and any other laws governing Personal Data applicable to the Processing.

"Personal Data", "Processing", "Controller", and "Processor" have the meanings set out in GDPR.

"Sub-processor" means any third party engaged by Processor to Process Personal Data.

3. Processing Details (Article 28(3))

3.1 Subject Matter

Provision of AI-powered market intelligence and analytics Services across AI-powered search platforms and discovery channels.

3.2 Duration

For the term of the Services plus any legally required retention.

3.3 Nature and Purpose

  • hosting and storage;
  • analytics and model execution on publicly available data from AI-powered platforms;
  • customer support;
  • security monitoring;
  • troubleshooting;
  • generation of market intelligence reports and competitive analysis.

3.4 Categories of Data Subjects

  • Controller's employees and contractors;
  • prospects or customers;
  • individuals appearing in publicly available data analyzed by the Services.

3.5 Categories of Personal Data

  • contact details;
  • professional identifiers;
  • account data;
  • communications;
  • brand or domain names;
  • search queries, analysis parameters, and market analysis requests.
  • Google Search Console data for Controller's verified properties, where Controller connects Google Search Console;
  • lists of competitors and social-media accounts monitored at Controller's request.

4. Controller Obligations

Controller represents and warrants that:

  • it has a lawful basis for Processing;
  • notices to data subjects are provided;
  • instructions comply with law;
  • sensitive data is not uploaded unless expressly agreed.

5. Processor Obligations

Processor shall:

a) process Personal Data only on documented instructions;

b) ensure confidentiality of personnel;

c) implement appropriate technical and organizational measures;

d) not sell Personal Data;

e) notify Controller if an instruction violates law.

6. Security Measures

Processor shall maintain security controls including:

  • access restriction;
  • encryption in transit;
  • monitoring and logging;
  • vulnerability management;
  • staff training.

Detailed security schedules may be provided under NDA.

7. Sub-processors

7.1 Authorization

Controller grants general written authorization for Processor to engage the Sub-processors listed in Annex 1, which Processor keeps up to date.

7.2 Notification

Processor shall notify Controller of any intended addition or replacement of a Sub-processor at least 30 days before the change takes effect, by email to the address associated with Controller's account or by a notice in the Services, and by updating Annex 1 of this DPA as published on the Site. Controller may object on reasonable, documented grounds within 30 days of notification. If the Parties cannot resolve the objection, Controller may terminate the affected Services; unused credits are handled in accordance with the Terms of Service.

7.3 Flow-Down

Processor shall impose equivalent obligations on Sub-processors.

8. International Transfers

Where Personal Data is transferred outside the EEA/UK:

  • Processor shall rely on approved safeguards;
  • the EU Standard Contractual Clauses (Commission Decision 2021/914, Module 2 – controller to processor) and, for transfers from the United Kingdom, the UK International Data Transfer Addendum, are incorporated by reference;
  • transfer-impact assessments shall be conducted where required.

Controller acknowledges that Processor is established in Hong Kong and that Sub-processors are located in, among others, the United States and the European Union, as set out in Annex 1.

9. Assistance With Data-Subject Rights

Processor shall assist Controller with:

  • access, deletion, and portability requests;
  • objections or restrictions;
  • regulatory inquiries,

to the extent legally required.

10. Personal-Data Breach

Processor shall:

  • notify Controller without undue delay and, where feasible, within 72 hours after becoming aware of a Personal Data Breach;
  • provide details of the breach;
  • cooperate in remediation.

11. Audits

Upon reasonable notice, Controller may audit Processor's compliance:

  • no more than once annually;
  • subject to confidentiality;
  • via reports or certifications where appropriate.

12. Deletion or Return of Data

Upon termination, Processor shall:

  • delete or return Personal Data at Controller's choice, without undue delay and in any event within the period required by Applicable Data Protection Law;
  • retain data only where legally required;
  • confirm deletion upon request.

13. Confidentiality

All information exchanged under this DPA shall be treated as Confidential Information.

14. Liability

Liability arising from this DPA is subject to the limitations in the Terms of Service, except where prohibited by law.

15. Priority

In case of conflict:

  • 1. this DPA
  • 2. Terms of Service
  • 3. Privacy Policy

shall prevail in that order for Processing activities.

16. Governing Law and Contact

This DPA is governed by the same law and jurisdiction as the Terms of Service, unless mandatory law requires otherwise.

For questions regarding this DPA:

Email: hello@posteam24.com

The domain posteam24.com is operated by Automagical Technologies Limited, the operator of GEO MarketMap.

Postal address:

Automagical Technologies Limited

Office A, 8/F, Kingswell Commercial Tower

171 Lockhart Road, Wan Chai

Hong Kong

Annex 1 – Authorized Sub-processors

Current as of the Effective Date. Processor updates this Annex when Sub-processors change and notifies Controller in accordance with section 7.2.

  • Supabase, Inc. (United States) – application database, authentication and file storage.
  • Lovable Labs Incorporated (Sweden / EU) – application hosting and AI gateway used to generate report analysis.
  • Cloudflare, Inc. (United States) – content delivery network, edge hosting and network security.
  • Stripe, Inc. / Stripe Payments Europe Ltd (United States / Ireland) – payment processing; card details are handled solely by Stripe.
  • DataForSEO (Cyprus / EU) – collection of publicly available AI search and citation data.
  • Google LLC / Google Ireland Ltd (United States / Ireland) – optional Google sign-in, optional Google Search Console connection, and AI models used for report analysis.
  • OpenAI, L.L.C. (United States) – AI assistant queried with the questions Controller tracks, to measure how it answers about Controller's brand.
  • Perplexity AI, Inc. (United States) – AI assistant queried with the questions Controller tracks, to measure how it answers about Controller's brand.
  • Anthropic, PBC (United States) – AI model used to write the drafts and briefs Controller requests.
  • ScrapeCreators – collection of publicly available social-media data for the accounts Controller chooses to monitor.