Data Processing Addendum
Last updated: 8 September 2026 · Version 1.1
This Data Processing Addendum (“DPA”) supplements the agreement between a customer (“Customer”) and Bigdoor Ai Labs Pte. Ltd. (“MonitorMyGEO”) when MonitorMyGEO processes personal data on Customer's behalf in providing the service.
1. Roles and instructions
Where Customer determines the purposes and means of processing Customer Personal Data, Customer acts as controller/business and MonitorMyGEO acts as processor/service provider to the extent required by applicable law. MonitorMyGEO processes Customer Personal Data to provide, secure, support and administer the contracted service on documented instructions, unless law requires otherwise.
1A. Aggregated research and separate purposes
The processor obligations in this DPA apply to Customer Personal Data that MonitorMyGEO processes on Customer's behalf. The Terms and Privacy Policy separately describe eligible creation and use of aggregated, statistical and de-identified service measurements for benchmarking, product improvement and research. MonitorMyGEO does not rely on this DPA alone as permission to publish identifiable Customer Personal Data for its own marketing.
The internal benchmark layer is designed to exclude raw prompts, raw AI-provider responses, direct user/contact identifiers, customer names, domains and billing identifiers. Where an internal research key remains linkable to a customer, it is treated as protected pseudonymous data and subject to access and publication controls. Named customer publicity remains subject to separate authorisation. An enterprise order or other written agreement may set a workspace to private-only research mode.
2. Processing details
- Subject matter: operation of AI visibility monitoring, AI Readiness, competitor intelligence, reports, exports, support, authentication and related contracted features.
- Duration: for the term of the applicable service plus limited retention required for deletion, backup rotation, security, disputes or law.
- Categories of data: account/contact data, workspace and organisation data, prompts/business context, support inputs, service usage/security metadata and personal data Customer elects to include.
- Data subjects may include Customer users, representatives, employees, contractors, customers or other persons whose data Customer lawfully submits.
3. Customer obligations
Customer is responsible for the lawfulness of its instructions, notices, permissions and legal bases, and for avoiding unnecessary sensitive or special-category personal data unless an approved use case and appropriate safeguards apply.
4. Confidentiality and personnel
MonitorMyGEO limits access to personal data to personnel and systems that require it for authorised purposes and requires appropriate confidentiality obligations for persons authorised to process it.
5. Security
MonitorMyGEO maintains technical and organisational measures appropriate to the service and risk, including authenticated access, tenant-scoped authorization, server-side credential handling, transport security provided by the deployed platform, rate limiting for sensitive routes, privileged admin separation, webhook verification for billing, secret management expectations, vulnerability/dependency controls and incident procedures.
6. Subprocessors
Customer provides general authorisation for MonitorMyGEO to use subprocessors necessary to provide the service. MonitorMyGEO remains responsible for imposing applicable data-protection obligations on subprocessors as required by law and contract. The current public Subprocessors page identifies material integrations represented by the production design.
7. Data-subject requests
Taking into account the nature of processing, MonitorMyGEO provides reasonable assistance for access, correction, deletion, restriction, objection and portability requests where required. Customer remains responsible for responding where Customer is the controller unless law requires MonitorMyGEO to respond directly.
8. Security incidents
MonitorMyGEO will investigate confirmed personal-data incidents and provide information reasonably necessary for Customer to meet applicable notification obligations, subject to law and the information available. Notification is not an admission of fault or liability.
9. DPIAs and regulatory assistance
Taking into account the nature of processing and information available, MonitorMyGEO will provide reasonable assistance with data-protection impact assessments and regulator consultations where legally required and relevant to the service.
10. International transfers
Personal data may be processed in countries where authorised service providers operate. The parties will use safeguards required by applicable transfer law. Where a restricted transfer requires a recognised contractual transfer mechanism, the applicable mechanism will be incorporated or executed as required.
11. Return and deletion
At termination or upon a valid instruction, MonitorMyGEO will delete or return Customer Personal Data as required by applicable law and the agreement, subject to lawful retention exceptions. Live application data is handled through privacy/deletion operations; immutable backups expire through the infrastructure backup-retention cycle.
12. Information and audits
MonitorMyGEO will make information reasonably necessary to demonstrate applicable processor obligations available to Customer, subject to confidentiality, security and proportionality. Audit requests should first use available documentation and evidence.
13. Conflict and contact
If this DPA conflicts with the agreement on processing of Customer Personal Data, this DPA controls to the extent of that conflict. Contract and privacy enquiries may be sent to support@monitormygeo.com.