GeoHunter
FeaturesPricingAPI DocsAbout
Sign inStart free
← Back to Home

GDPR & Data Protection Compliance

Last updated: March 24, 2026

1. Introduction

This document outlines the commitment of Socrat Tech Inc. to data protection and provides an overview of our compliance framework with key global regulations, including the EU General Data Protection Regulation (GDPR), Turkey's Law on the Protection of Personal Data (KVKK), and the California Consumer Privacy Act (CCPA).

2. Data Controller & Data Protection Officer (DPO)

  • Data Controller: Socrat Tech Inc.
  • Contact Email: privacy@geohunter.ai
  • Data Protection Officer (DPO): We have appointed a DPO to oversee our data protection strategy. They can be reached at dpo@geohunter.ai.

3. Record of Processing Activities (ROPA) Summary

In accordance with Article 30 of the GDPR, we maintain a comprehensive record of our data processing activities. A summary is provided below:

Processing ActivityData SubjectsPersonal DataPurposeLegal BasisTransfers
User Account Management & AuthenticationRegistered UsersName, email, hashed password, IP address, auth tokensProvide, manage, and secure user accountsArt. 6(1)(b) - ContractBased on server location
Core Service Provision (AI Analysis)Registered UsersUser-uploaded imagesPerform AI-powered geolocation analysisArt. 6(1)(b) - ContractYes (USA) - SCCs
Payment & Subscription ManagementSubscribersName, email, subscription data (payments via Stripe)Process payments and manage subscriptionsArt. 6(1)(b) - ContractYes (USA) - SCCs, DPF
Platform Security & MonitoringAll UsersIP addresses, access logs, device identifiersPrevent fraud, protect against attacksArt. 6(1)(f) - Legitimate InterestBased on server location
Website AnalyticsAll VisitorsAnonymous client ID, pages visited, session duration, general geo region (via cookies: _ga, _ga_*)Understand usage patterns, improve Platform experienceArt. 6(1)(f) - Legitimate InterestYes (USA) - Google Analytics, SCCs

4. Data Protection Impact Assessment (DPIA) Summary

Due to the use of new technologies (AI APIs) for processing personal data (user-uploaded images) on a potentially large scale, we have conducted a Data Protection Impact Assessment (DPIA).

Identified Risks

  1. Data breach at a third-party AI provider leading to unauthorized access to images.
  2. Misuse of data by sub-processors.
  3. Potential for re-identification from analyzed images if shared improperly.

Mitigation Measures Implemented

  1. Contractual Safeguards: We have entered into robust Data Processing Addendums (DPAs) with all AI providers, which include the latest Standard Contractual Clauses (SCCs).
  2. Data Minimization: We only send the image data required for the analysis and do not transmit other user-identifying information in the API call.
  3. User Control: Users have the right and ability to delete their images and search history from our Platform.
  4. Security: We enforce strict access controls and encryption for all data in transit and at rest.

The DPIA concludes that with these measures in place, the residual risk is acceptable.

5. Data Breach Notification Procedure

In the event of a personal data breach, GeoHunter will follow a strict incident response plan:

  1. Identification and Assessment: Immediately upon discovery, our security team will assess the scope and impact of the breach.
  2. Containment: We will take immediate steps to contain the breach and mitigate any ongoing risk.
  3. Notification to Supervisory Authority: If the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant Data Protection Authority without undue delay, and where feasible, not later than 72 hours after having become aware of it.
  4. Notification to Data Subjects: If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will communicate the breach to the affected data subjects without undue delay.

6. International Transfer Mechanisms

GeoHunter provides a global service, which requires the international transfer of data. Our primary transfer mechanism for data sent from the EEA, UK, or Switzerland to countries without an adequacy decision (such as the United States) is the Standard Contractual Clauses (SCCs) as approved by the European Commission. We conduct Transfer Impact Assessments (TIAs) to ensure that the data remains adequately protected in the destination country and supplement these transfers with additional technical and organizational measures where necessary.

Google Analytics: We use Google Analytics 4 to collect anonymous usage statistics. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF) and processes analytics data under its own Privacy Policy. No personally identifiable information is transmitted. Users can opt out via the Google Analytics Opt-out Browser Add-on.

7. Specific Compliance Notes

7.1. KVKK Compliance (Turkey)

GeoHunter is committed to complying with Turkey's Law on Protection of Personal Data No. 6698 (KVKK).

  • Our legal bases for processing align with the conditions outlined in Articles 5 and 6 of the KVKK.
  • We fully support the rights of data subjects as detailed in Article 11 and provide clear channels for exercising these rights.
  • For data transfers abroad, we rely on explicit consent or other mechanisms permitted under KVKK where applicable.
  • We will fulfill our obligation to register with the Data Controllers' Registry (VERBIS) if and when we meet the required thresholds.

7.2. CCPA / CPRA Compliance (California)

GeoHunter respects the privacy rights of California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

  • No Sale or Sharing: We confirm that we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA. Therefore, an “opt-out” mechanism is not required.
  • Notice at Collection: Our Privacy Policy serves as our notice at collection, detailing the categories of personal information collected and the purposes for which they are used.
  • Honoring User Rights: We have established procedures to efficiently respond to verifiable consumer requests to know, delete, and correct personal information.
  • Data Processing Agreements: Our contracts with our service providers prohibit them from retaining, using, or disclosing personal information for any purpose other than for the specific business purpose specified in the contract.

8. Contact Us

For any questions or concerns about our data protection practices, please contact our Data Protection Officer at: dpo@geohunter.ai or privacy@geohunter.ai.

Privacy PolicyCookie PolicyTerms of Service

Product

  • Features
  • Pricing
  • API Docs

Resources

  • Earthquake Risk Analysis
  • Disaster Preparedness
  • Image Location Search
  • AI Photo Analysis

Company

  • About
  • Solutions
  • Careers
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • GDPR

Geohunter is a proprietary platform owned and operated by Socrat Tech Inc., a corporation organized under the laws of the State of Delaware, USA.

© 2026 Socrat Tech Inc. All rights reserved.