← Home

Data Processing Agreement

00Parties

01Definitions

Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given in the GDPR. “Sub-processor” means any processor engaged by Usereviews to process personal data on the Customer’s behalf. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to Commission Implementing Decision (EU) 2021/914.

02Roles and Scope

2.1 The Customer is the Controller and Usereviews is the Processor with respect to the personal data described in Annex 1.

2.2 Usereviews processes personal data only for the purpose of providing the Service and only in accordance with the Customer’s documented instructions, including as set out in the Agreement, this DPA, and the Customer’s use of the Service’s features and settings. The Agreement and this DPA constitute the Customer’s complete and final instructions.

2.3 Usereviews will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, unless legally prohibited from doing so.

2.4 Each party will comply with its respective obligations under applicable data protection law. The Customer is responsible for ensuring it has a lawful basis and any necessary notices or consents to provide the personal data to Usereviews for processing under this DPA.

03Processor Obligations

Usereviews shall:

3.1 Instructions. Process personal data only on documented instructions from the Customer, including with regard to transfers to a third country, unless required to do otherwise by EU or Member State law; in which case Usereviews will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.2 Confidentiality. Ensure that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality.

3.3 Security. Implement the technical and organisational measures set out in Annex 2 to ensure a level of security appropriate to the risk, taking into account Article 32 GDPR.

3.4 Sub-processing. Engage sub-processors only in accordance with Section 5.

3.5 Data subject requests. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under the GDPR. Where a data subject contacts Usereviews directly, Usereviews will (unless legally prohibited) forward the request to the Customer and not respond substantively itself except to confirm the request has been passed on.

3.6 Assistance. Taking into account the nature of processing and the information available to it, assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation).

3.7 Breach notification. Notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer’s personal data, and provide the Customer with sufficient information to meet any obligations to report the breach to a supervisory authority or data subjects.

3.8 Deletion or return. At the Customer’s choice, delete or return all personal data to the Customer after the end of the provision of the Service, and delete existing copies unless EU or Member State law requires storage. Personal data is deleted within 30 days of account termination unless the law requires otherwise. The Customer may also export or delete personal data at any time through the Service’s features.

3.9 Audits and information. Make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Usereviews may satisfy this obligation by providing relevant documentation, certifications, or third-party audit reports where available. Audits are limited to once per twelve-month period (unless required by a supervisory authority or following a personal data breach), on reasonable prior notice, during business hours, and subject to confidentiality.

04Customer Obligations

4.1 The Customer warrants that it has, and will maintain throughout the term, a valid lawful basis for the processing instructed under this DPA, and has provided all notices and obtained all consents required for Usereviews to process the personal data as contemplated by the Agreement.

4.2 The Customer is solely responsible for the accuracy, quality, and legality of the personal data it provides and the means by which it acquired that personal data, including reviews aggregated from third-party platforms and contacts uploaded to the Service.

05Sub-processors

5.1 The Customer provides general authorisation for Usereviews to engage the sub-processors listed in Annex 3 to process personal data on the Customer’s behalf.

5.2 Usereviews will impose on each sub-processor, by contract, data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

5.3 Usereviews will inform the Customer of any intended addition or replacement of a sub-processor, giving the Customer a reasonable opportunity to object on reasonable data protection grounds. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.

06International Transfers

6.1 Usereviews may transfer personal data to, and process it in, countries outside the European Economic Area, including through the sub-processors in Annex 3.

6.2 Where personal data is transferred outside the EEA to a country not covered by an adequacy decision, such transfer is governed by the Standard Contractual Clauses (module three, processor-to-processor, where applicable), which are incorporated into this DPA by reference and completed by reference to the details in the Annexes. Where the UK GDPR applies, the UK International Data Transfer Addendum applies in the same manner.

07Liability and Term

7.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

7.2 This DPA takes effect on the date the Customer accepts the Agreement (or, if later, this DPA) and continues for as long as Usereviews processes personal data on the Customer’s behalf. Sections that by their nature should survive termination (including confidentiality and deletion) survive.

7.3 This DPA is governed by the laws of Luxembourg, without prejudice to the SCCs, which are governed as provided therein.

A1Annex 1 — Details of Processing

A2Annex 2 — Technical and Organisational Measures

Usereviews maintains measures appropriate to the risk, including:

  • Encryption — personal data encrypted in transit (TLS) and at rest by the underlying infrastructure providers.
  • Access control — role-based access, least-privilege principles, and unique credentials for personnel; production access restricted to authorised personnel.
  • Secrets management — third-party credentials and integration secrets stored in a dedicated secrets vault, not in application code or plaintext configuration.
  • Authentication — customer authentication managed through the identity provider; support for strong credentials.
  • Segregation — logical separation of Customer data on a multi-tenant basis with per-organisation scoping.
  • Resilience — managed, backed-up database infrastructure with provider-level redundancy.
  • Sub-processor diligence — reliance on reputable infrastructure and AI providers offering their own security certifications and data protection terms.
  • Incident response — procedures to detect, investigate, and notify personal data breaches in accordance with Section 3.7.

A3Annex 3 — Sub-processors

Sub-processorPurposeLocation
CloudflareApplication hosting and edge computeEU / US
SupabaseDatabase, authentication, and storageEU / US
ResendTransactional and notification emailUS
Google (Gemini)AI processing of review contentUS
AnthropicAI processing of review contentUS
Bright DataRetrieval of publicly available review-page contentUS