Privacy Policy
Last updated: 13/07/2026
1. Who We Are
Website: https://geia.ai
GEIA.AI is operated by GEIA Systems Inc., a company incorporated in the United States.
GEIA Systems Inc. is the data controller responsible for your personal data.
Where required by applicable data protection laws, including the EU General Data Protection Regulation (EU GDPR) and UK GDPR, GEIA.AI may appoint appropriate representatives or comply with additional obligations applicable to users in those jurisdictions.
For privacy-related requests, please contact us through the GEIA.AI website.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- The GEIA.AI website
- The GEIA.AI web and mobile applications (“the App”)
- IoT devices and gateways connected to the GEIA.AI platform
- APIs, MQTT connections, and integrations provided by GEIA.AI
- Webshop, billing, and partner services
3. Personal Data We Collect
3.1 Website & Account Data
- Name
- Email address
- Username
- City, state, or country (optional)
- Login and account metadata
3.2 App, IoT & Platform Data
- Sensor data (e.g. temperature, humidity, light, EC, pH)
- Relay and actuator states
- User-defined configurations and automation rules
- Plant data, journals, logs, and notes
- System usage and performance data
3.3 Webshop & Billing Data
- Billing name and address
- Invoice details
- Transaction references
3.4 Partner & Business User Data
- Business contact details
- Service descriptions
- Optional public listings or references (with consent)
4. Separation of Data Domains
Application and IoT data are logically separated from webshop, billing, and accounting data.
A common user identifier may be used to link accounts, but each data domain is processed independently and for distinct purposes.
5. How We Use Your Data
We process data for the following purposes:
- Providing and operating the GEIA.AI platform
- Monitoring and controlling connected environments
- Customer support and communication
- Billing, invoicing, and accounting
- Improving system performance and user experience
- Machine learning and system optimization
6. AI and Machine Learning
GEIA.AI uses data to improve automation, system reliability, and platform functionality.
Machine learning processes are designed to support operational intelligence and optimization and do not produce legal or similarly significant effects on users without human involvement.
Where applicable, data used for model improvement is processed in aggregated or anonymized form.
Users retain control over what data is shared or used beyond core system functionality.
7. User-Controlled Data Sharing
Users can explicitly choose to mark specific data, settings, or configurations as public or shared.
- Only data marked as public is visible to other users
- API and MQTT access return only authorized and consented data
- Sharing permissions can be changed or revoked at any time
8. Community & Knowledge Sharing
GEIA.AI may offer optional community features allowing users to share configurations,
strategies, or anonymized insights (e.g. “top grower” features). Participation is voluntary
and requires explicit user consent.
9. Cookies & Analytics
Cookies
We use essential cookies for authentication and functionality. Optional cookies may be used for analytics and usability improvements.
Analytics & Session Tools
We may use third-party analytics and session tools to understand aggregate usage patterns and improve usability.
These tools are configured to avoid identifying individual users where possible.
10. Payments & Invoicing
Payment processing is handled by third-party providers such as Stripe and PayPal. GEIA.AI does not store full payment card details.
Billing and transaction records may be retained for periods required by applicable accounting, tax, financial, and legal obligations.
11. Data Retention
- Account data: retained while the account is active
- IoT and app data: retained in accordance with user settings and system requirements, and deleted upon account removal where applicable
- Invoice data: retained for legal and accounting purposes
Some data may be retained for a limited period where required for security, legal compliance, or dispute resolution.
12. Your Rights
You have the right to:
- Access your personal data
- Download your data
- Correct inaccurate data
- Request deletion or erasure of personal data (‘right to be forgotten’)
- Withdraw consent for optional processing
Some data may be retained where legally required.
13. Security & Encryption
We implement industry-standard security measures, including:
- Encryption in transit (TLS)
- Encryption at rest where appropriate
- Role-based access control
- Logical isolation between users
Further details about our security practices and vulnerability reporting process are available on our Security & Responsible Disclosure page.
14. Data Processing Architecture
GEIA.AI processes data using modern infrastructure designed for reliability, security, and isolation between users.
This does not affect users’ legal rights, ownership, or control over their data.
15. Data Breach Procedures
In the event of a data breach, we will notify affected users and relevant authorities in accordance with applicable laws.
16. Third Parties
We may share data with trusted service providers strictly for providing our services, legal compliance, security, infrastructure operation, analytics, payments, and customer support. We do not sell personal data.
17. Regulatory Compliance
GEIA.AI is committed to protecting user privacy and complying with applicable data protection laws.
Depending on your location, this may include:
- The California Consumer Privacy Act (CCPA)
- The California Privacy Rights Act (CPRA)
- The European Union General Data Protection Regulation (EU GDPR)
- The United Kingdom General Data Protection Regulation (UK GDPR)
- The UK Data Protection Act 2018
- Applicable United States privacy laws, including state-specific privacy regulations where applicable
GEIA.AI applies privacy-by-design principles, including data minimization, user-controlled sharing, security protections, and transparency regarding data processing.
18. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with certain rights regarding your personal information.
Your Rights
California residents may have the right to:
- Know what personal information we collect, use, disclose, or sell
- Request access to personal information collected about them
- Request deletion of personal information, subject to legal exceptions
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of personal information
- Limit the use and disclosure of sensitive personal information where applicable
- Not receive discriminatory treatment for exercising privacy rights
Categories of Personal Information Collected
- Identifiers (such as name, email address, username)
- Internet or network activity information (such as account activity and usage data)
- Geolocation information where voluntarily provided
- User-generated content and configurations
- IoT and environmental data generated through connected devices
- Business contact information for partner accounts
Sale or Sharing of Personal Information
GEIA.AI does not sell personal information.
GEIA.AI does not share personal information for cross-context behavioral advertising purposes.
Exercising California Privacy Rights
California residents may submit privacy requests through our website.
Requests may require verification to protect account security.
19. International Data Transfers
GEIA.AI may process personal data in countries outside your country of residence, including the United States.
Where personal data is transferred internationally, GEIA.AI uses appropriate safeguards as required by applicable data protection laws, such as contractual protections or recognized transfer mechanisms.
20. Contact
For privacy-related questions or requests, please contact us via the website.




