Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement (“DPA”) supplements our Privacy Policy and sets out the terms under which The Geopolitics Report processes personal data on behalf of its users and in connection with the operation of its website.

Definitions

  • Controller: The Geopolitics Report, as the entity that determines the purposes and means of processing personal data collected through its website.
  • Processor: Any third-party service provider engaged by The Geopolitics Report to process personal data on its behalf.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data, including collection, storage, use, and deletion.

Scope

This DPA applies to all personal data processed by The Geopolitics Report through its website, including data collected via newsletter subscriptions, contact forms, and analytics.

Our Role

The Geopolitics Report acts as the Controller of personal data collected through our website. We determine why and how personal data is processed.

Third-Party Processors

We engage the following categories of processors to operate our website:

  • Cloudflare — website hosting, content delivery, and security services
  • Email service provider — newsletter delivery
  • Analytics provider — anonymised website usage statistics

Each processor is bound by contractual obligations to:

  1. Process personal data only on our documented instructions
  2. Ensure that persons authorised to process personal data are bound by confidentiality obligations
  3. Implement appropriate technical and organisational security measures
  4. Not engage sub-processors without our prior authorisation
  5. Assist us in responding to data subject rights requests
  6. Delete or return all personal data upon termination of the service
  7. Make available all information necessary to demonstrate compliance

Security Measures

We require all processors to implement appropriate security measures, including:

  • Encryption of personal data in transit and at rest
  • Regular security assessments
  • Access controls limiting who can access personal data
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach, our processors are required to notify us without undue delay. We will in turn notify affected individuals and relevant authorities as required by applicable data protection laws.

International Transfers

Where personal data is transferred outside the jurisdiction of the data subject, we ensure that appropriate safeguards are in place, such as standard contractual clauses or equivalent mechanisms recognised under applicable law.

Data Subject Rights

We support the exercise of data subject rights as outlined in our Privacy Policy, including access, rectification, erasure, restriction, portability, and objection.

Duration

This DPA remains in effect for as long as we process personal data. Upon cessation of processing, personal data will be deleted or returned in accordance with our data retention policies.

Contact

For questions about this Data Processing Agreement, please contact privacy@thegeopoliticsreport.com.