Data processing agreement

Last updated 8 October 2026. Part of the terms of service; it applies automatically when you use AIvisible. If you need a signed copy, email support@aivisible.dk.

1. Parties and roles

The customer is the data controller and Go-IT ApS, Poppel Alle 71, 3500 Værløse, Denmark, CVR 30819985 ("AIvisible") is the data processor for personal data the customer uploads or enters into AIvisible. This agreement follows article 28 of the General Data Protection Regulation (GDPR). For data about the customer's own users (accounts, billing, logins), AIvisible is the controller; see the privacy policy.

2. What is processed

  • Purpose: measuring the customer's visibility in AI answers: storing keywords, turning them into prompts, asking AI providers, reading the answers, and making reports.
  • Data: keyword lists, Search Console exports and Google Ads search-term reports, competitor and brand names, prompts and AI answers. These can occasionally contain personal data, such as names people searched for. The customer must not upload sensitive personal data (GDPR art. 9 and 10).
  • Data subjects: people whose searches or names appear in the uploaded data.
  • Duration: as long as the customer uses AIvisible, plus the deletion period below.

3. AIvisible's obligations

  • Process the data only on the customer's documented instructions, which are these terms and the customer's use of the service, unless the law requires otherwise. AIvisible tells the customer if it believes an instruction breaks the law.
  • Ensure that people with access are bound by confidentiality.
  • Keep appropriate technical and organisational security measures (GDPR art. 32): hosting in the EU, encrypted connections, passwordless login, access limited to what's needed, separate data per workspace, and backups.
  • Help the customer, as far as reasonable, answer requests from data subjects and meet its obligations under GDPR articles 32–36.
  • Notify the customer without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting the customer's data.
  • Give the customer the information needed to show compliance, and allow audits by the customer or an auditor it appoints, at the customer's cost, with reasonable notice and at most once a year unless there's been a breach.

4. Sub-processors

The customer gives general authorisation to the sub-processors below. AIvisible gives at least 30 days' notice by email before adding or replacing one; the customer can object, and if we can't find a solution, close the account before the change. AIvisible imposes the same data protection obligations on each sub-processor and remains responsible for them.

Sub-processorServiceDataLocation and transfer basis
Render Services, Inc.Hosting, database, backupsAll customer data Frankfurt, Germany (EU)
OpenAI, L.L.C. / OpenAI Ireland Ltd.AI answers (ChatGPT)Prompts and answers US; EU–US Data Privacy Framework and SCCs
Google Ireland Ltd. / Google LLCAI answers (Gemini)Prompts and answers EU/US; EU–US Data Privacy Framework and SCCs
Anthropic, PBCAI answers (Claude); reading answers, checking keywords and drafting prompts Prompts, answers, keyword listsUS; SCCs
Stripe Payments Europe, Ltd.PaymentsNo uploaded data (billing data only) Ireland (EU); US transfers under the Data Privacy Framework and SCCs
Resend (Plus Five Five, Inc.)EmailsNo uploaded data (email addresses only) Ireland sending region; US company, SCCs

AI providers are used through their business APIs, which under their current terms don't use the data to train models and keep it only for a limited period for abuse monitoring.

5. Transfers outside the EU

Data is only transferred outside the EU/EEA when there's a valid transfer basis under GDPR chapter V, such as the EU–US Data Privacy Framework or the EU Commission's standard contractual clauses (SCCs).

6. End of processing

When the customer closes the account, AIvisible deletes the customer's data within 30 days, and from backups within 30 more days, unless the law requires it to be kept. The customer can download reports and prompts before that.

7. Liability and order of documents

The liability rules in the terms of service apply to this agreement, except where GDPR doesn't allow it. If this agreement and the terms conflict on data protection, this agreement wins.

Go-IT ApS · Poppel Alle 71, 3500 Værløse, Denmark · CVR 30819985 · support@aivisible.dk

© AIvisible · Go-IT ApSTermsPrivacyData processing