← Back to AllSale

AllSale GEO AI

Data Processing Addendum

Effective Date: July 3, 2026 · Version 1.2

This Data Processing Addendum (the "DPA") forms part of, and is incorporated into, the AllSale GEO AI Terms of Service and (where applicable) the Reseller Agreement (collectively, the "Agreement") between Accent Infotech Limited, a company incorporated in New Zealand with registered office at 3/84A Wallace Road, Papatoetoe, Auckland, New Zealand ("AllSale", "Processor") and the customer or reseller entity that accepts the Agreement ("Customer", "Controller"). It applies to all processing of Personal Data carried out by AllSale on behalf of Customer in connection with the Service.

1. Definitions

Capitalised terms not defined here have the meaning given in the Agreement or in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where relevant, the UK Data Protection Act 2018 ("UK GDPR"). "Personal Data", "Processing", "Controller", "Processor", "Sub-Processor", "Data Subject", and "Supervisory Authority" have the meanings given in the GDPR.

2. Roles & Scope

For Personal Data submitted to the Service by Customer or on Customer's behalf ("Customer Personal Data"), Customer is the Controller (or a Processor acting for its own controller customer) and AllSale is the Processor (or Sub-Processor). The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Personal Data are described in Annex 1.

3. Processing Instructions

AllSale shall Process Customer Personal Data only on documented instructions from Customer, including the instructions reflected in the Agreement, the Service configuration chosen by Customer, and Customer's use of the Service. AllSale shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

4. Confidentiality of Personnel

AllSale shall ensure that persons authorised to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality, and are trained on data-protection requirements.

5. Security Measures

AllSale shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including those described in Annex 2.

6. Sub-Processors

Customer grants general authorisation for AllSale to engage Sub-Processors, provided that AllSale:

  • maintains a current list of Sub-Processors at Annex 3;
  • provides at least thirty (30) days' prior notice (by email or in-app notice) before adding or replacing a Sub-Processor;
  • imposes data-protection obligations on each Sub-Processor that are no less protective than those in this DPA;
  • remains liable to Customer for the acts and omissions of its Sub-Processors.

Customer may object to a new Sub-Processor on reasonable data-protection grounds during the notice period; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service on written notice.

7. Data Subject Requests

Taking into account the nature of the Processing, AllSale shall assist Customer by appropriate technical and organisational measures, insofar as possible, to fulfil Customer's obligation to respond to Data Subject requests under Chapter III of the GDPR. If a Data Subject contacts AllSale directly, AllSale shall (a) not respond except as authorised by Customer or required by law, and (b) promptly forward the request to Customer.

8. Personal Data Breach

AllSale shall notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall include, to the extent then known, the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed.

9. Assistance to Controller

AllSale shall assist Customer in ensuring compliance with Articles 32–36 of the GDPR (security, breach notification, data-protection impact assessments, prior consultation), taking into account the nature of the Processing and the information available to AllSale.

10. Audits

AllSale shall make available to Customer information necessary to demonstrate compliance with this DPA. Customer may, no more than once per twelve-month period (and more frequently where required by a Supervisory Authority or after a Personal Data Breach affecting Customer), audit AllSale's compliance, including by accepting AllSale's then-current SOC 2, ISO 27001, or equivalent third-party audit reports under non-disclosure. On-site audits, where strictly necessary, require thirty (30) days' prior written notice and reasonable scope agreement, conducted during normal business hours and without unreasonable disruption.

11. International Transfers & SCCs

Where AllSale Processes Customer Personal Data originating in the EEA, UK, or Switzerland in a country not subject to an adequacy decision, the parties shall comply with Chapter V of the GDPR. The relevant module of the European Commission Standard Contractual Clauses (Decision 2021/914) is hereby incorporated by reference:

  • Where Customer is a Controller and AllSale is a Processor, Module 2 (Controller-to-Processor) applies.
  • Where Customer is itself a Processor for an upstream Controller and AllSale is a Sub-Processor, Module 3 (Processor-to-Processor) applies.

The optional docking clause is selected; the supervisory authority is the lead authority indicated by Customer or, failing that, of the EU country in which Customer's EU representative is established. For UK transfers, the UK International Data Transfer Addendum (Version B1.0) is incorporated; AllSale completes Tables 1–3 by reference to this DPA and Annex 1.

12. Return & Deletion

On termination of the Service and at Customer's choice, AllSale shall delete or return all Customer Personal Data and delete existing copies, except as required by law. Standard production data is deleted within thirty (30) days of termination; encrypted backup copies are deleted within ninety (90) days, after which Customer Personal Data is no longer accessible to AllSale operations.

13. How to Counter-Sign

This DPA is deemed executed and binding as of the Customer's acceptance of the Agreement, with AllSale's signature reflected by publication of this document under AllSale's official domain, in accordance with the New Zealand Electronic Transactions Act 2002. Customers who require a separately signed counterpart for their records may request one by emailing legal@allsalegeo.com; AllSale will provide a PDF copy for counter-signature and return a fully executed version within ten (10) business days.

Annex 1 — Processing Description

Subject matter & purpose

Hosting and delivery of the AllSale GEO AI platform: local-SEO insights, AI-assisted content generation, scheduled publishing, reputation management, billing, and reseller tooling.

Duration

For the term of the Agreement plus any retention period described in the Privacy Policy.

Nature of Processing

Collection, storage, structuring, organisation, retrieval, consultation, use, disclosure to authorised parties (including Sub-Processors), erasure, and destruction.

Categories of Data Subjects

  • Customer's representatives and end users (where Customer is a Reseller, Customer's Sub-Customers and their representatives).
  • Authors and recipients of reviews, comments, or posts processed through the platform.

Categories of Personal Data

  • Identifiers: name, email, phone, business name, user ID.
  • Authentication: hashed password, MFA secrets, session tokens.
  • Billing: billing address, last 4 of card, tax ID (full payment details are held by Stripe, not by AllSale).
  • Business content: location data, reviews, posts, photos, prompts.
  • Technical: IP address, device, browser, log timestamps.

Special Category Data

Not knowingly processed. Customer shall not submit special-category data unless and until specifically agreed in writing.

Annex 2 — Security Measures

AllSale maintains, at minimum, the following measures:

  • Encryption: TLS 1.2+ in transit; AES-256 (or stronger) at rest for primary data stores and backups.
  • Access control: role-based access, least-privilege, mandatory multi-factor authentication for production-system access by personnel.
  • Network & infrastructure: hosted on Google Cloud Platform; private VPC controls, managed firewalls, regular patching.
  • Application security: code review, dependency scanning, automated test coverage, security-aware development practices.
  • Logging & monitoring: audit logs for administrative actions (reseller portal + super-admin), anomaly detection, error monitoring.
  • Backups: encrypted, versioned, periodically tested restore.
  • Personnel: confidentiality undertakings, onboarding training, off-boarding checklist with credential revocation.
  • Incident response: documented procedure with internal escalation, regulator notification, and customer notification within statutory windows.
  • Vendor management: due diligence and contracts with Sub-Processors that impose equivalent obligations.

Annex 3 — Sub-Processors (current list)

Sub-ProcessorPurposeLocation
Google LLC (Cloud Run, Cloud Build, Firestore, Cloud Logging, Firebase Authentication, Firebase Hosting, Google Maps Platform — Places API, Google Business Profile API)application hosting, identity, database, logs, static-asset hosting, business-location data lookup and profile insightsUnited States & global Google regions
Stripe, Inc. and Stripe Payments Europe Ltd.card processing, payouts, Stripe Connect, tax IDsUnited States, Ireland
OpenAI, L.L.C.AI text generation (when AI provider is set to OpenAI)United States
Google LLC — Gemini APIAI text generation (when AI provider is set to Gemini)United States
Resend, Inc.transactional and product email deliveryUnited States
Meta Platforms, Inc.Facebook and Instagram content publishing via the Meta Graph API (only when Customer connects a Meta account)United States, Ireland
Meta Platforms, Inc. — WhatsApp Business Cloud APIWhatsApp templated messaging and broadcast delivery (only when Customer configures WhatsApp Business)United States, Ireland
TikTok Pte. Ltd. / ByteDanceTikTok content publishing and Veo video generation (only when Customer connects a TikTok account)United States, Singapore

The current list is maintained at the URL of this page. Customers will be notified of additions or replacements as set out in section 6.