Privacy Policy | Geodd
Last Updated: 9th June, 2026

Privacy Policy

01

Introduction

This Privacy Policy explains how Geodd LLC collects, uses, discloses, retains, and protects personal data in connection with our website, dashboard, communications, and Services.

This Privacy Policy should be read together with Geodd’s Terms of Service, Data Protection Addendum, Subprocessor List, Security Measures page, Cookie Policy, and International Data Transfers page.

For privacy questions or data protection requests, contact: [email protected].
For security questions, contact: [email protected].
For legal notices, contact: [email protected].

02

Who We Are

Geodd LLC is the entity responsible for providing the Services.

Geodd LLC

1007 N Orange St., 4th Floor, Suite #1382

United States

Website: geodd.io

Privacy contact: [email protected]

Security contact: [email protected]

Support contact: [email protected]

Legal notices: [email protected]

For purposes of this Privacy Policy, “Geodd,” “we,” “us,” or “our” means Geodd LLC.

03

Scope of This Privacy Policy

This Privacy Policy applies to personal data that Geodd processes in connection with:

  • Our website
  • Customer account registration
  • Customer dashboard use
  • Sales and contact enquiries
  • Billing and payment administration
  • Support communications
  • Security, fraud prevention, and service operations
  • Marketing communications
  • Use of our Services

This Privacy Policy does not replace any Data Protection Addendum between Geodd and a Customer. Where Geodd processes Customer Personal Data as a processor on behalf of a Customer, Geodd’s processing is governed by the applicable Data Protection Addendum.

Geodd’s Data Protection Addendum is available at: geodd.io/legal/data-protection-addendum

04

Our Role Under Data Protection Laws

Geodd may act as either a controller or a processor depending on the context.

4.1 Geodd as Controller

Geodd acts as an independent controller for personal data processed for our own business purposes, including:

  • Website visitor data
  • Sales and contact enquiries
  • Customer account and administrative data
  • Billing and payment records
  • Usage records
  • Support communications
  • Security logs
  • Legal and compliance records
  • Marketing emails
  • Cookie and analytics data where applicable

4.2 Geodd as Processor

Geodd generally acts as a processor where it processes Customer Personal Data submitted by or on behalf of a Customer through the Services solely to provide the Services under the Customer’s instructions.

This may include Customer-submitted API content and Customer end-user data submitted through the API, if any.

Customers are responsible for ensuring that they have a lawful basis and all required rights, notices, consents, authorizations, and permissions to submit personal data to the Services.

05

Services Covered

Geodd provides AI infrastructure services, including:

  • Inferencing
  • Serverless Inferencing
  • Dedicated Inferencing
  • Dedicated GPU
  • Bare Metal Infrastructure

For EU/EEA and UK customers, Geodd may provide API access to AI models, dedicated managed AI inference endpoints, dedicated GPUs, managed servers, bare metal, and infrastructure services.

06

Personal Data We Collect

Geodd may collect the following categories of personal data.

6.1 Account and Contact Data

  • Name
  • Business email
  • Phone number
  • Company name
  • Job title
  • Login credentials
  • Customer account details

6.2 Billing, Payment, and Legal Data

  • Billing address
  • Payment metadata
  • Invoices
  • Tax IDs
  • Contract details
  • Order form details
  • Billing and financial usage records
  • Legal and compliance records

Geodd does not store full payment card details unless expressly stated. Payment processing may be handled by third-party payment providers.

6.3 Support and Communication Data

  • Support messages
  • Customer enquiries
  • Email communications
  • Service-related messages
  • Administrative communications

6.4 Usage and Technical Data

  • Usage data
  • Model used
  • Timestamp
  • Token count
  • Status code
  • Usage records
  • IP address where applicable
  • Authentication metadata
  • Device type
  • Browser type
  • Pages visited
  • Referral source
  • Session duration
  • Cookie and analytics identifiers

6.5 API and Inferencing Data

For AI model API services, Geodd processes prompts, inputs, outputs, request bodies, and response bodies transiently to provide the requested inference response.

Unless separately agreed in writing, Geodd does not store:

  • API prompts
  • API inputs
  • API outputs
  • Completions
  • API request bodies
  • API response bodies
  • Uploaded files
  • Embeddings
  • Customer datasets
  • Fine-tuning data

Geodd does not use API data for model training and does not conduct human review of prompts or outputs by default.

Geodd may retain limited metadata for billing, usage measurement, security, troubleshooting, service operation, fraud prevention, legal, and compliance purposes.

07

How We Use Personal Data

Geodd uses personal data for the following purposes.

7.1 To Provide and Operate the Services

We use personal data to:

  • Create and manage accounts
  • Authenticate users and API requests
  • Provide access to the Services
  • Process API requests and return responses
  • Provide Serverless Inferencing
  • Provide Dedicated Inferencing
  • Provide Dedicated GPU services
  • Provide Bare Metal Infrastructure
  • Measure usage
  • Generate billing records
  • Provide customer support

7.2 To Secure the Services

We use personal data to:

  • Protect accounts and systems
  • Monitor for abuse, fraud, and unauthorized access
  • Investigate security events
  • Debug and troubleshoot service issues
  • Maintain access logs and security logs
  • Enforce security controls
  • Protect Geodd, Customers, users, and the Services

7.3 To Communicate With Customers

We use personal data to:

  • Respond to enquiries
  • Provide support
  • Send service updates
  • Send administrative notices
  • Send billing notices
  • Provide legal, security, and compliance notices

7.4 For Billing, Legal, and Compliance Purposes

We use personal data to:

  • Process payments
  • Maintain invoices
  • Keep tax records
  • Manage contracts
  • Prevent fraud
  • Resolve disputes
  • Comply with legal obligations
  • Enforce agreements and policies

7.5 For Marketing

Where permitted by law, we may use contact information to send marketing communications about Geodd.

Users can opt out of marketing emails at any time by using the unsubscribe link or contacting [email protected].

Geodd does not use API prompts, inputs, outputs, request bodies, or response bodies for marketing, model training, fine-tuning, or analytics.

08

Legal Bases for Processing

Where GDPR, UK GDPR, or similar laws apply, Geodd relies on one or more of the following legal bases:

  • Contract: to provide the Services, manage accounts, process billing, and provide support.
  • Legitimate interests: to secure the Services, prevent fraud, improve operations, respond to enquiries, and manage business administration.
  • Consent: for certain marketing communications, cookies, analytics, and tracking technologies where required.
  • Legal obligation: to comply with tax, accounting, regulatory, legal, and compliance obligations.
  • Customer instructions: where Geodd acts as processor under a Data Protection Addendum.
09

Sensitive and Regulated Data

Customer is responsible for determining whether personal data submitted to the Services includes sensitive, special category, regulated, or high-risk personal data under applicable data protection laws.

Geodd’s Services are designed to process Customer-submitted data according to Customer’s instructions. Geodd does not require Customers to submit sensitive or regulated data in order to use the Services.

If Customer submits sensitive, special category, regulated, or high-risk personal data to the Services, Customer is responsible for ensuring that it has all required lawful bases, notices, consents, authorizations, permissions, safeguards, and contractual rights necessary for such processing.

Unless expressly agreed in writing, Geodd does not provide Services specifically intended for HIPAA-regulated protected health information, children’s data, biometric identification, criminal offense records, or other legally restricted workloads requiring dedicated contractual or regulatory controls.

Geodd’s Services are intended for users who are at least 18 years old.

10

How We Share Personal Data

Geodd may share personal data with the following categories of recipients.

10.1 Service Providers and Subprocessors

We may share personal data with vendors, service providers, and subprocessors that help us provide, secure, support, and operate the Services.

These may include providers for:

  • Hosting and infrastructure
  • Databases
  • Email delivery
  • Customer relationship management
  • Payment processing
  • Security and CDN services
  • Contract and e-signature services
  • Billing and accounting
  • Support and internal communication

Geodd’s Subprocessor List is available at: geodd.io/legal/subprocessors

10.2 Independent Controllers and Third-Party Platforms

Some third-party services may act as independent controllers depending on how they are used, such as payment providers, analytics providers, or communication platforms.

Their processing may be governed by their own privacy notices and legal terms.

10.3 Legal and Compliance Disclosures

We may disclose personal data where necessary to:

  • Comply with applicable law
  • Respond to lawful requests
  • Protect our rights, users, Customers, systems, and Services
  • Prevent fraud, abuse, or security incidents
  • Enforce agreements and policies
  • Resolve disputes

10.4 Business Transfers

If Geodd is involved in a merger, acquisition, financing, corporate reorganization, sale of assets, or similar transaction, personal data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards.

10.5 No Sale of Personal Data

Geodd does not sell Customer Personal Data.

Geodd does not use Customer Personal Data submitted through the API for targeted advertising, model training, or unrelated commercial purposes.

11

Cookies and Similar Technologies

Geodd uses cookies and similar technologies for website operation, authentication, consent management, analytics, and marketing where applicable.

Cookies may include:

ToolProviderPurposeCategoryDuration
Auth TokenGeoddMaintains logged-in sessionsEssential24 months
Consent PreferenceGeoddStores cookie consent choicesEssential12 months
Google AnalyticsGoogleAnalyzes website traffic and usageAnalytics24 months
GTag ConsentGoogleCommunicates consent status to Google servicesAnalytics / consent managementSession
Meta PixelMetaMarketing and conversion tracking, where enabledMarketingAs configured in the Cookie Policy
LinkedIn PixelLinkedInMarketing and conversion tracking, where enabledMarketingAs configured in the Cookie Policy

For EU/UK users, non-essential cookies and tracking technologies should not load before valid consent is obtained.

Users can manage cookie preferences through Geodd’s cookie banner, cookie settings, or browser settings.

More information is available in Geodd’s Cookie Policy: geodd.io/legal/cookie-policy

12

Security

Geodd uses technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Security measures may include:

  • TLS protection for data in transit
  • Encryption at rest where applicable
  • API key hash storage
  • API authentication using API keys and OAuth where applicable
  • Role-based access controls
  • MFA for administrative access
  • Firewalls and web application firewall protection
  • Private networks where applicable
  • Customer isolation through dedicated endpoints where applicable
  • Access logging
  • Vulnerability management
  • Incident response processes
  • 30-day rolling backups for users and usage data where applicable
  • Staff confidentiality obligations
  • Staff access limited based on job role and operational need

Geodd’s Security Measures page is available at: geodd.io/trust-center/security-measures

No method of transmission or storage is completely secure. Customers are responsible for keeping API keys, credentials, and access permissions secure.

13

Retention

Geodd retains personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Data TypeRetention / Handling
API prompts / inputsNot stored
API outputs / completionsNot stored
API request bodiesNot stored
API response bodiesNot stored
Uploaded filesNot supported / not stored unless separately agreed
EmbeddingsNot stored unless separately agreed
Customer datasetsNot stored unless separately agreed
Fine-tuning dataNot supported unless separately agreed
Limited API metadataRetained as needed for billing, usage measurement, security, troubleshooting, service operation, fraud prevention, legal, and compliance purposes
Billing / financial usage records7 years
Billing / tax records7 years
Security logs12 months unless longer retention is required
Support tickets12 months unless longer retention is required
Marketing recordsUntil unsubscribe plus 2 years
Marketing consent records6 years
Database backups30-day rolling backups
Deleted account dataDeleted within 30 days, except lawful retained records and backup expiry

Billing and financial usage records may be retained for legal, tax, billing, fraud prevention, security, dispute, and compliance reasons.

Backup deletion occurs through normal backup expiry cycles and not by immediate deletion from all backups.

14

Account Deletion

Customers may request deletion of their account by emailing [email protected] or by using any deletion functionality made available in the Services.

Where Customer requests account deletion, Geodd will delete or deactivate the account within a reasonable period and, where applicable, delete associated account data within 30 days, except for records that Geodd is required or permitted to retain for legal, tax, billing, security, fraud prevention, dispute, compliance, or legitimate business purposes.

API prompts, inputs, outputs, completions, request bodies, and response bodies are not available for export, correction, or deletion after processing where Geodd does not store them.

15

International Transfers

Geodd LLC is established in the United States.

For EU customers, API inference is hosted in EU data center infrastructure by default. EU/UK customers may also choose non-EU infrastructure, in which case API requests may be routed outside the EU/UK for inference processing.

Support and administrative access may occur from Geodd operational locations, including Sri Lanka, where necessary for support, security, debugging, service operations, billing, legal, and compliance.

Where personal data is transferred to or accessed from a country that has not been recognized as providing an adequate level of protection, Geodd uses appropriate transfer safeguards as described in its Data Protection Addendum and International Data Transfers page.

These safeguards may include:

  • EU Standard Contractual Clauses
  • UK International Data Transfer Addendum
  • Swiss FADP adaptations where applicable
  • Transfer Impact Assessment support
  • Supplementary technical and organizational measures

Geodd’s International Data Transfers page is available at: geodd.io/legal/international-data-transfers

16

Data Subject Rights

Depending on where you are located and which laws apply, you may have rights to:

  • Access personal data
  • Correct inaccurate personal data
  • Delete personal data
  • Restrict or object to processing
  • Receive a copy of personal data
  • Withdraw consent where processing is based on consent
  • Opt out of marketing communications
  • Lodge a complaint with a supervisory authority

To make a request, contact [email protected].

We may need to verify your identity before responding.

If your request relates to personal data submitted to Geodd by a Customer for processing under that Customer’s instructions, we may redirect your request to the relevant Customer unless legally required to respond directly.

Geodd will respond to rights requests within the timeframe required by applicable law.

17

California Privacy Notice

If California privacy laws apply, California residents may have additional rights, including the right to know, access, correct, delete, and opt out of certain disclosures of personal information.

Geodd does not sell Customer Personal Data.

Geodd does not use Customer Personal Data submitted through the API for cross-context behavioral advertising.

To exercise California privacy rights, contact [email protected].

18

Marketing Communications

Users may opt out of marketing communications at any time by using the unsubscribe link in the email or contacting [email protected].

Even after opting out of marketing communications, users may still receive service, security, legal, billing, or administrative messages.

19

Automated Decision-Making

Geodd does not use Customer Personal Data submitted through the API to make automated decisions that produce legal or similarly significant effects on Data Subjects.

Customers are responsible for determining whether their own use of Geodd’s Services involves automated decision-making under applicable law.

20

Children

Geodd’s Services are intended for users who are at least 18 years old.

Geodd does not knowingly collect personal data from children or provide Services specifically intended for children unless expressly agreed in writing and supported by appropriate legal safeguards.

If you believe a child has provided personal data to Geodd, contact [email protected].

21

EU/UK Representative

Geodd LLC is not currently established in the EU or UK.

Geodd is in the process of appointing an EU representative and assessing or appointing a UK representative where required.

Until representative details are published, privacy-related inquiries may be sent to [email protected].

22

Changes to This Privacy Policy

Geodd may update this Privacy Policy from time to time to reflect changes in law, Services, vendors, security practices, data handling practices, or business operations.

If changes are material, Geodd will provide notice by reasonable means, such as through the website, dashboard, email, or other electronic notice.

The “Last Updated” date shows when this Privacy Policy was last revised.

23

Contact

For privacy questions, data protection requests, or rights requests: [email protected]

For security questions: [email protected]

For support: [email protected]

For legal notices: [email protected]

Geodd LLC

1007 N Orange St., 4th Floor, Suite #1382

United States

Website: geodd.io