Data Handling Policies
Last updated: July 30, 2026
This document describes how GEO BUBBLES, located at , handles, processes, and safeguards data within the GEO BUBBLES platform. This policy supplements our Privacy Policy and provides detailed technical and organizational information about our data practices.
1. Data Categories and Processing
1.1 User Account Data
Account data (email, name, company, avatar) is stored in our secure database infrastructure. Passwords are cryptographically hashed using industry-standard algorithms (bcrypt) and are never stored in plaintext. We follow the principle of data minimization.
1.2 Search Console Data
When you connect your Google Search Console account, we retrieve performance data (queries, pages, clicks, impressions, CTR, position) via Google's official APIs using OAuth 2.0. This data is cached in our database to enable analytics and AI-powered insights. We do not share your Search Console data with other users or third parties.
1.3 SERP and SEO Data
When you request SERP analysis through our AI chat, we query the DataForSEO API on your behalf. SERP data is not permanently stored unless it forms part of a saved report or conversation.
1.4 AI Chat Data
Your chat conversations with our AI assistant are stored to maintain conversation history. Chat data is processed by third-party AI models to generate responses. We send only the minimum context necessary. AI providers do not use your data to train their models.
1.5 Support Chat Data (Bubbly)
Conversations with our public AI support assistant "Bubbly" are transcribed and stored as support tickets. We record the message content, the assistant's replies, timestamps, a session identifier, the originating website and page, the email address you provide, and any thumbs up/down rating you give. Signed-in users have their account email attached so the assistant can answer account-specific questions. Transcripts may be reviewed by our support staff and are transmitted to our AI model providers to generate replies; providers do not use them for model training. Use of the chatbot is voluntary β you decide what you disclose, and sensitive data should not be entered into the chat.
2. Data Storage and Infrastructure
2.1 Hosting
Our platform infrastructure is hosted on secure cloud services with data centers in the EU and/or Switzerland. All data at rest is encrypted using AES-256. All data in transit is protected by TLS 1.2 or higher.
2.2 Database Security
Our database employs row-level security (RLS) policies to ensure users can only access their own data. Administrative access is strictly limited and logged. Backups are encrypted.
2.3 Authentication and Access Control
- User authentication via secure, token-based sessions
- OAuth 2.0 for third-party integrations (e.g., Google Search Console)
- API access tokens encrypted at rest with defined expiration
- Role-based access control (RBAC) at the application level
3. Data Retention
We retain data according to the following policies:
- Account data: Retained for account duration plus 30 days after deletion request
- Search Console cached data: Retained while account is active; deleted upon termination
- Chat conversations: Retained while account is active; deleted upon termination
- Support chat transcripts and support tickets: Retained up to 24 months after the conversation is closed
- Usage logs: Retained for 90 days
- Payment records: Retained as required by Swiss law (typically 10 years)
- Contact form submissions: Retained for 2 years unless earlier deletion requested
4. Data Sharing and Sub-Processors
We share data with third parties only as necessary to provide the Service:
- Cloud hosting provider β infrastructure and database hosting (EU/CH region)
- AI model providers β chat and support chatbot responses
- SERP data provider β search results data
- Support infrastructure β support transcript storage and support email delivery
- Google Analytics β website analytics (with consent)
- Stripe β payment processing
All sub-processors are bound by data processing agreements (DPAs) ensuring GDPR and Swiss data protection compliance.
5. Data Transfers
Where data is transferred outside Switzerland or the EEA, we ensure adequate protection through:
- EU adequacy decisions
- Standard Contractual Clauses (SCCs)
- Data processing agreements with appropriate safeguards
6. Data Deletion and Portability
6.1 Account Deletion
You can request deletion of your account and all associated data by contacting privacy@geobubbles.com. Data will be permanently deleted within 30 days, except where retention is required by law.
6.2 Data Export
You have the right to request a copy of your data in a machine-readable format (e.g., JSON or CSV). Contact privacy@geobubbles.com. We will fulfill requests within 30 days.
7. Incident Response
In the event of a data breach:
- Notify the relevant supervisory authority within 72 hours (GDPR)
- Notify affected users without undue delay if high risk
- Document the breach, effects, and remedial actions
- Implement measures to prevent recurrence
8. Security Measures
We implement the following technical and organizational measures:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Regular security assessments and code reviews
- Access logging and monitoring
- Principle of least privilege for all system access
- Regular backups with encrypted off-site storage
- Employee security awareness training
9. Contact
For questions about our data handling practices, contact us at:
GEO BUBBLES
Email: privacy@geobubbles.com