Neobora
Book a demoTry for free
Legal

Data processing agreement

Last updated: 30 July 2026

Data Processing Agreement between the Customer, as controller, and Innovageo Software SLU, as processor, for the processing of the personal data that the Customer processes through the Neobora platform. Entered into in accordance with Article 28 of the GDPR (EU) 2016/679 and Spanish Organic Law 3/2018.

This page is an automatic translation for informational purposes only. In case of doubt or discrepancy with the original content, the Spanish-language version of this document shall prevail. View the Spanish version

01Subject matter and scope

This Data Processing Agreement (hereinafter, the "Agreement") governs the processing of personal data that Innovageo Software SLU, with tax ID CIF B70993019 and registered office at Plaza Vicente Andrés Estellés nº2 Bajo, 46950 Xirivella (Spain) (hereinafter, "Innovageo Software" or the "Processor"), carries out on behalf of the Customer (hereinafter, the "Controller") in connection with the provision of the services of the neobora.ai application.

This Agreement forms an integral part of the Terms of Service and is entered into in compliance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights. Acceptance of the Terms of Service constitutes acceptance of this Agreement.

This Agreement applies only to the personal data that the Controller processes through the Application on its own behalf, that is, to data contained in the data and content that it uploads to the Application cloud. It does not apply to the Customer’s own account and billing data, in respect of which Innovageo Software acts as data controller in accordance with its Privacy Policy, nor to files that the user opens only locally with the Desktop Application, which Innovageo Software does not access.

02Description of the processing

In accordance with Article 28.3 of the GDPR, the processing entrusted is described as follows:

Element
Description
Subject matter
Hosting, storage, processing, visualisation and publication of geospatial data on behalf of the Controller, through the features of the Application.
Purpose
Solely the provision of the services contracted by the Controller, in accordance with its instructions.
Nature of the operations
Collection, recording, storage, organisation, retrieval, consultation, disclosure by transmission, dissemination, alignment, interconnection, restriction and erasure.
Type of personal data
That which the Controller decides to incorporate into its Projects. Generally: identifying and contact data of the users the Controller invites to its Projects, and any personal data that may be contained in the geospatial data, images or documents that the Controller uploads (among others, images in which persons, vehicles, dwellings or identifiable features may appear, and data associated with cadastral references or addresses).
Categories of data subjects
Those determined by the Controller. Generally: users authorised by the Controller and persons who may be identifiable from the data the Controller processes through the Application.
Duration
The term of the Terms of Service, plus the retention periods set out in the "Erasure and return of the data" clause.

It is the Controller’s exclusive responsibility to determine which personal data it incorporates into the Application. Innovageo Software takes no part in that decision and does not carry out any prior examination of the content of the data the Controller uploads.

03Controller’s instructions

Innovageo Software shall process the personal data only in accordance with the Controller’s documented instructions. This Agreement, the Terms of Service and the instructions that the Controller issues through the configuration and use of the Application’s features constitute documented instructions.

Innovageo Software shall not use the personal data for its own purposes, shall not disclose it to third parties save in the cases provided for in this Agreement or by legal obligation, and shall not take decisions on its processing other than those necessary to provide the services.

If Innovageo Software considers that an instruction from the Controller infringes data protection legislation, it shall inform the Controller without undue delay, and shall be entitled to suspend the execution of that instruction until the Controller confirms or amends it.

The Controller warrants that it has the legal basis necessary for the processing it entrusts, that it has informed data subjects in accordance with Articles 13 and 14 of the GDPR, and that it has assessed, where applicable, the need to carry out a data protection impact assessment. The Controller shall be liable to Innovageo Software for the consequences of any breach of these warranties.

04Confidentiality and authorised personnel

Innovageo Software shall maintain the confidentiality of the personal data to which it gains access in connection with the processing entrusted, an obligation that shall subsist after the end of the relationship.

Access to the personal data shall be limited to personnel who need to know it in order to provide the services. Innovageo Software warrants that such personnel have been informed of their obligations and are bound by a duty of confidentiality of a contractual or statutory nature.

05Security measures

Innovageo Software shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

Those measures include, among others, access control through individual authentication and per-Project permission management, encryption of communications, logical segregation of each customer’s information, logging of relevant activity, and the performance of backups on the terms set out in the Terms of Service.

The security measures may evolve in line with the state of the art and the evolution of the services. Innovageo Software shall not reduce them in a way that lowers the level of protection of the data. This Agreement does not entail any obligation to maintain specific certifications or to adhere to particular certification schemes or codes of conduct.

It is the Controller’s responsibility to configure the permissions of its Projects and the public or restricted nature of the geoportals it publishes appropriately, and to assess in advance whether it is appropriate to publish data that may contain personal information. Innovageo Software is not liable for the consequences of a visibility configuration decided by the Controller.

06Sub-processors

The Controller grants Innovageo Software general authorisation to engage other processors (sub-processors) for the provision of the services. Innovageo Software shall impose on those sub-processors, by contract, data protection obligations equivalent to those set out in this Agreement, and shall be liable for their acts on the terms of Article 28.4 of the GDPR.

As at the date of this Agreement, the sub-processors are as follows:

Sub-processor
Service provided
Location of processing
Amazon Web Services EMEA SARL
Hosting, storage, database, asynchronous processing, identity and activity logging infrastructure for the platform.
Region selected by the Controller (European Union or United States)
Stripe Payments Europe Ltd.
Management of subscriptions and handling of payments and billing.
European Union, with possible transfers to the United States

Innovageo Software shall notify the Controller, by notice sent to the email address associated with the Account or by notification within the Application, of any addition or replacement of sub-processors, with at least thirty (30) calendar days’ notice. During that period the Controller may object on reasonable grounds relating to data protection; if no solution is reached, the Controller may terminate the Terms of Service without penalty, with a refund of the proportionate part of the amounts paid and not consumed, which shall constitute its sole remedy on this ground.

07Location of the data and international transfers

The Controller selects, when creating its account, the region in which it wishes the data of its Projects to be hosted. Innovageo Software shall not move the hosted data to a region other than the one selected without first notifying the Controller.

Where the region selected by the Controller is within the European Economic Area, the processing shall take place in that territory, without prejudice to occasional remote technical support access necessary for the provision of the service.

If the Controller selects a region located outside the European Economic Area, the resulting international transfer shall be based on the Standard Contractual Clauses approved by the European Commission by Implementing Decision (EU) 2021/914, or on such adequate safeguard mechanism as may be applicable at any given time, including an adequacy decision of the European Commission. The choice of a region outside the European Economic Area is a decision of the Controller, who is responsible for assessing its suitability for the processing it intends to carry out.

08Assistance to the Controller

Data subjects’ rights. It is the Controller’s responsibility to handle the requests to exercise rights that it receives from data subjects. Innovageo Software shall make available to it the features of the Application that allow the hosted data to be accessed, rectified, exported and erased. If a data subject addresses its request directly to Innovageo Software, Innovageo Software shall forward it to the Controller without undue delay, without handling it on its own account.

Innovageo Software shall provide the Controller, taking into account the nature of the processing and the information available to it, with such reasonable assistance as the Controller may request for the fulfilment of its obligations regarding security, notification of personal data breaches, impact assessments and prior consultations with the supervisory authority. Where such assistance goes beyond making available the information and features already existing in the Application, Innovageo Software may pass on to the Controller a reasonable cost, notified and accepted in advance.

09Personal data breaches

Innovageo Software shall notify the Controller, without undue delay from becoming actually aware of it, of any breach of the security of the personal data processed on behalf of the Controller, by notice to the email address associated with the Account.

The notification shall include the information available to Innovageo Software at that time regarding the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects. Where it is not possible to provide that information at the same time, it shall be provided in phases without undue further delay.

It is the Controller’s responsibility to assess whether the breach must be notified to the supervisory authority and to data subjects in accordance with Articles 33 and 34 of the GDPR, and to make those notifications where applicable. Innovageo Software’s notification to the Controller does not in itself constitute an acknowledgement of liability or fault.

10Information and audit

Innovageo Software shall make available to the Controller the information reasonably necessary to demonstrate compliance with the obligations of Article 28 of the GDPR, by means of documentation describing its technical and organisational measures and, where available, the reports or certifications it holds in respect of its infrastructure and its sub-processors.

The Controller’s right of audit shall be deemed satisfied by the provision of the above documentation. Only where that documentation is objectively insufficient, or where a competent supervisory authority so requires, may the Controller carry out an audit, which shall be subject to the following conditions: minimum notice of thirty (30) calendar days; a single audit per calendar year, save at the requirement of the supervisory authority or following a demonstrated security breach; scope limited to the processing covered by this Agreement; performance during business hours and without affecting the availability of the service or the confidentiality of other customers’ information; the audit personnel being bound by a duty of confidentiality; and the Controller bearing its own costs and the reasonable costs that the audit generates for Innovageo Software.

11Erasure and return of the data

On termination of the provision of the services, Innovageo Software shall erase the personal data processed on behalf of the Controller, in accordance with the periods set out in the Terms of Service: for thirty (30) calendar days following the end of the last billing period the data shall be retained in read-only mode, so that the Controller may download or export it using the features of the Application, and after that period it shall be permanently deleted.

Existing backups shall be deleted in accordance with their ordinary rotation cycle, within the following thirty (30) calendar days, and Innovageo Software shall not carry out selective deletions within those backups.

Notwithstanding the foregoing, Innovageo Software may retain such personal data as is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims, duly blocked and for the limitation period applicable to the relevant actions.

12Liability

The liability of the Parties under this Agreement is governed by Article 82 of the GDPR and, as regards the contractual relationship between them, by the limits and exclusions set out in the "Warranties and liability" clause of the Terms of Service, which apply jointly and in the aggregate to the Terms of Service and to this Agreement.

Each Party shall be liable for the fines and compensation imposed on it for causes attributable exclusively to it.

13Term, modification and precedence

This Agreement enters into force upon acceptance of the Terms of Service and shall remain in force for as long as Innovageo Software processes personal data on behalf of the Controller.

Innovageo Software may modify this Agreement in order to adapt it to regulatory developments, to decisions of the supervisory authorities or to changes in the services, giving at least thirty (30) calendar days’ notice in accordance with the procedure set out in the Terms of Service.

In the event of any conflict between this Agreement and the Terms of Service on matters of personal data protection, the provisions of this Agreement shall prevail. In respect of matters not expressly provided for, the provisions of the Terms of Service shall apply.

Questions?

For any query about this document, write to us at support@neobora.ai or by post to the address indicated.

Innovageo Software SL
Plaza Vicente Andrés Estellés nº2 Bajo · 46950 Xirivella, España
We use our own cookies, necessary for the site to work, and, if you accept them, external services (reCAPTCHA and the subscription and contact forms) that involve loading third-party resources. You can accept them, reject them, or read more in our cookie policy.