Data Processing Terms
Last updated: 08/16/2026
This page explains, in plain language, how GEO & SEO Checker processes data on your behalf and which sub-processors we use to run the service. It's written to be read by a real person doing a vendor review, not as a substitute for legal counsel. If your procurement process requires a formal, signed Data Processing Agreement, see the request section below.
1. What "Processing" Means Here
When you use GEO & SEO Checker, we process the data described in our Privacy Policy — your account details, the URLs and pages you submit for audits, and the resulting audit data — in order to run audits, store results, bill your plan, and send account-related notifications. We act as the processor of that data on your behalf; you (or your organization) are the controller of what you submit for auditing.
2. Sub-processors We Use
These are the third parties (and self-hosted services) that data passes through as part of running GEO & SEO Checker. This list reflects what's actually wired into the product today, not a generic boilerplate list.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase (self-hosted) | Database, authentication, and file storage | Account profile, audit jobs and results, billing status flags |
| Stripe | Payment processing and subscription billing | Email address, plan/subscription status; card details are entered directly on Stripe's hosted page and never touch our servers |
| Resend | Transactional email — audit alerts, weekly digests, welcome and contact emails | Recipient email address and the content of the specific notification being sent |
| AI provider (OpenAI or Anthropic) | Generating AI-written fix suggestions and executive summaries for an audit | The audited URL and the SEO issues found on it; not your account details or page HTML |
| Google sign-in (OAuth), optional Search Console integration, and public entity lookups used during an audit | Email/profile info from Google sign-in; Search Console query and page data if you connect it; the audited domain and organization name for entity lookups |
The AI provider is configurable on our side between OpenAI and Anthropic — whichever is active at a given time, only the audited URL and its findings are sent, never your account credentials or unrelated page content. The Google Search Console integration only sends data if you explicitly connect your Search Console account; if you don't connect it, no data flows to that part of Google's API.
3. Data Location
As described in our Security page, GEO & SEO Checker runs on infrastructure we operate ourselves rather than a shared third-party platform's default multi-tenant environment. We haven't published the exact physical data center location, and we'd rather say that plainly than claim a region we can't back up. Sub-processors listed above (Stripe, Resend, the AI provider, and Google) process data under their own respective infrastructure and terms.
4. Security Measures
See our Security page for the current, honest state of our technical safeguards — including database-level row-level security, authentication handling, and encryption in transit — and what we haven't built yet.
5. Sub-processor Changes
If we add or replace a sub-processor that handles customer data, we'll update the table above. We don't currently run a formal advance-notice subscription for sub-processor changes; if your organization needs to be notified directly, mention that when you request a signed DPA below.
6. Requesting a Signed DPA
We don't yet have a formal, lawyer-drafted DPA template published on this site (see our Security page's "What We Don't Have Yet" section). If your legal or procurement team requires a signed DPA to complete a vendor review, contact us and we'll work with you directly on one.
Fastento OU
Laeva 1, Tallinn, 10111, Estonia