Data Policy
1. Purpose
This Data Policy explains how Geodd handles data, from collection and storage to security and deletion, so you know what we do and don’t do with your information. It covers personal data, technical information, and other data we process as part of delivering our services.
We follow global privacy laws, including:
◾️ GDPR / UK GDPRCCPA / CPRA
◾️ Sri Lanka PDPA
◾️ HIPAA (only if we process healthcare data under a ◾️ signed agreement)
2. What Data We Handle
We process different types of data depending on the service:
◾️ Personal Data: Like your name and email, provided when you sign up or contact us.
◾️ Technical Data: Things like your IP address, browser type, device type, and usage statistics collected automatically.
◾️ AI Inference Data: Inputs (prompts, queries, datasets) and outputs (results, predictions) sent through our AI services.
We do not store inference inputs or outputs. They are processed in-memory only to deliver your results, then discarded immediately.
◾️ Protected Health Information (PHI): Health-related data tied to an individual — processed only if we have a signed Business Associate Agreement (BAA) with a healthcare client.
3. How We Use Your Data.
We only use your data for the purposes we collected it for, such as:
◾️ Running and improving our services
◾️ Responding to support requests
◾️ Securing our systems and preventing fraud
◾️ Meeting legal obligations
◾️ Sending you updates (only if you’ve opted in)
AI commitment: We never use inference inputs or outputs for model training, fine-tuning, or analytics.
HIPAA commitment: If we process PHI for a healthcare client, we follow all HIPAA privacy, security, and breach rules.
4. How We Protect Data
We use a mix of technology and processes to keep data safe, including:
◾️ Encryption in transit (TLS) and at rest (AES-256)
◾️ Role-based access controls and authentication
◾️ Firewalls, intrusion detection, and vulnerability scanning
◾️ Privacy and security training for our team
5. How Long We Keep Data
Account data: While your account is active + 24 months
Technical logs: Up to 2 years
Legal records: Up to 7 years
AI inference data: Never stored
PHI: Only as long as required by HIPAA or our agreement
You can request deletion of your data at any time (unless laws require us to keep it).
6. Sharing Data
We share data only when necessary:
◾️ With trusted service providers like hosting, analytics, email delivery, and security vendors — all bound by strict privacy contracts
◾️ If our business is sold or merged
◾️ When required by law or to protect safety
We do not sell your personal data. We also never share AI inference data because we never store it.
7. Your Rights
Depending on where you live, you may have the right to:
◾️ Access the data we have about you
◾️ Correct wrong or outdated data
◾️ Ask us to delete your data
◾️ Limit or object to how we use your data
◾️ Get a copy of your data
◾️ Opt out of marketing messages
To exercise your rights, email us at support@geodd.io.
8. Changes to This Policy
We may update this Data Policy from time to time. If changes are significant, we’ll let you know before they take effect.
9. Contact Us
Geodd LLC
Registered in Delaware, USA
Email: support@geodd.io
Mailing Address: 1021 E Lincolnway Suite #6661, Cheyenne, Wyoming 82001, United States
Local Data Protection Contact (Sri Lanka PDPA) details available on request via support@geodd.io.