Data processing agreement
Last updated: October 2026
This data processing agreement ("DPA") forms part of the Terms of Service between ReviewTactic LLC and the customer that uses the Service. It applies automatically, with no signature needed. If you need a countersigned copy, email hello@reviewtactic.com.
1. Parties and roles
- Customer (you, the business or agency that holds a ReviewTactic account) is the controller of the personal data it processes through the Service.
- ReviewTactic LLC, 447 Sutter St, Ste 506-1210, San Francisco, CA 94108, United States ("we") is the processor and processes that personal data only on your behalf.
This DPA does not cover data we process as a controller for our own purposes, such as your account and billing details or visits to our website. Those are covered by our privacy policy.
"GDPR" means Regulation (EU) 2016/679 and, where it applies, the UK GDPR and the UK Data Protection Act 2018. Terms such as "personal data", "processing", "controller", "processor" and "personal data breach" have the meaning given in the GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Service: review monitoring, AI reply drafting and publishing, review analysis and reports, competitor and local ranking insights, review removal support and review requests.
- Duration: for as long as you use the Service, plus the deletion period in section 10.
- Nature: collection, storage, analysis, AI processing, transmission (for example publishing a reply to Google, or sending a review request email you trigger) and deletion.
- Purpose: only to provide the Service to you, as described in the Terms and your instructions in the app.
3. Data subjects and categories of personal data
- Reviewers of your business on Google and other review platforms: reviewer name, profile name or photo URL, review text, rating and date, as published on those platforms.
- Your customers you send review requests to: name, email address or phone number you provide.
- Your team members who use the account: name, email address, activity in the app.
- Anyone named in material you upload or type in, such as evidence for review removal, business context documents or insight chat questions.
You should not upload special categories of personal data (Art. 9 GDPR) or data about criminal convictions, unless the Service needs it to handle a specific review and you have a lawful basis to share it.
4. Our obligations as processor
In line with Article 28(3) GDPR, we:
- process the personal data only on your documented instructions, which are the Terms, this DPA and your use of the Service's settings, unless the law requires otherwise; in that case we tell you first unless the law forbids it. If we think an instruction breaks data protection law, we tell you;
- make sure everyone authorised to process the data is bound by confidentiality;
- apply the security measures in Annex 1;
- use subprocessors only as set out in section 6;
- help you, taking into account the nature of the processing, to answer requests from data subjects exercising their rights;
- help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, using the information available to us;
- delete or return the personal data when the Service ends, as set out in section 10;
- make available the information needed to show compliance with this DPA and allow audits as set out in section 9.
5. Your obligations as controller
You are responsible for having a lawful basis for the personal data you bring into the Service, for giving the people concerned the information the law requires (for example before sending them a review request), and for making sure your instructions to us comply with data protection law.
6. Subprocessors
You give general authorisation for us to use the subprocessors listed below. We have a written agreement with each of them that imposes data protection obligations no less protective than this DPA.
We will give you at least 30 days' notice by email, and on this page, before a new subprocessor processes your personal data. You may object on reasonable data protection grounds within that period. If we cannot address your objection, you may end the affected part of the Service before the change takes effect and we will refund any prepaid fees for the unused period. We remain responsible for our subprocessors' performance of their obligations.
List current as of 2026-10-08.
| Provider | Purpose | Personal data | Location |
|---|---|---|---|
| Supabase | Database, sign-in, serverless functions, file storage and backups | Account data, reviews and replies, settings, uploaded removal evidence | UK (London) |
| Netlify | Website and app hosting | Website requests, IP address | US |
| Stripe | Checkout, subscription billing, invoices | Billing name and email, payment history. Card details never reach us. | US |
| Resend | Account, billing, alert and customer email | Email address, name, email content | US |
| Anthropic (Claude API) | AI reply drafting, brand voice, insight chat, reports | Public review text and reviewer names, business context, your chat messages | US |
| Google (Gemini API) | AI analysis, competitor scoring, insights | Public review text, business data | US |
| OpenAI | Text embeddings for searching your business context | Business context text you provide (menu, FAQ, policies) | US |
| Google (Places and Maps API) | Business lookup in the app and free tools | Business name and address, visitor IP address | US |
| Outscraper | Collects public Google reviews for audits | Public reviews and reviewer names | US |
| Zembra | Review monitoring on other platforms (TripAdvisor, Booking.com, Yelp and others) | Public reviews and reviewer names, listing details | US |
| DataForSEO | Local search ranking scans | Business name, address and keywords | EU (Estonia) |
| PostHog | Product analytics | Page views, feature usage, session length, user ID in the app | US |
| Microsoft Clarity | Website heatmaps and session recordings | Clicks, scrolling, page interactions, IP address | US |
| Sentry | App error monitoring | Error details, browser data, IP address | EU (Germany) |
| Cloudflare (Turnstile) | Bot protection on free tools | Browser signals, IP address | US |
| Google Workspace | Our support mailbox | Emails you send us | US |
| Google Fonts | Web fonts in the app | IP address | US |
| Telegram | Internal alerts to our team | Customer email address, business and location names | UAE |
7. International transfers
Our main database is hosted in London, United Kingdom. Some subprocessors process data in the United States or other countries outside the EEA and UK. Where that country has no adequacy decision, the transfer is covered by the EU-US Data Privacy Framework (where the provider is certified) or by the EU Standard Contractual Clauses, with the UK Addendum for UK data, in the provider's data processing agreement.
ReviewTactic LLC is based in the United States. To the extent we receive personal data from you in the EEA or UK, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2, controller to processor) and the UK Addendum are incorporated into this DPA by reference, with this DPA's sections and annexes supplying the information the clauses require. Where the clauses ask for a choice: clause 7 (docking) applies; clause 9 option 2 (general authorisation, with the notice in section 6); clause 11 optional language does not apply; clauses 17 and 18 are governed by and subject to the courts of Ireland. If the clauses conflict with this DPA, the clauses prevail.
8. Personal data breaches
We will notify you by email without undue delay after becoming aware of a personal data breach affecting your personal data. The notice will describe, as far as we know at the time, what happened, the data and people affected, the likely consequences and what we are doing about it, and will name a contact. We will follow up as we learn more.
9. Information and audits
On written request, and no more than once a year unless a supervisory authority requires it or there has been a personal data breach, we will answer reasonable written questions about our compliance with this DPA, and share our security documentation and our subprocessors' published certifications. If that is not enough to show compliance, you, or an independent auditor bound by confidentiality, may carry out an audit on 30 days' notice, during business hours, in a way that does not disrupt our operations or expose other customers' data. You bear the cost of the audit.
10. Deletion and return
You can export your data and delete your account at any time in the app. When your account is deleted or the Service ends, we delete the personal data we process for you within 30 days, including backups and copies held by our subprocessors, unless the law requires us to keep it. Before deletion you may ask us for a copy of your data.
11. California (CCPA)
For personal information covered by the California Consumer Privacy Act, as amended, we act as your service provider. We will not sell or share that personal information, will not keep, use or disclose it for any purpose other than providing the Service or as the CCPA otherwise permits, will not use it outside our direct business relationship with you, and will not combine it with personal information we receive from other sources except as the CCPA permits. We will tell you if we can no longer meet our obligations under the CCPA.
12. Liability, term and order of precedence
Each party's liability under this DPA is subject to the limitation of liability in the Terms, except where the law does not allow it to be limited. This DPA lasts as long as we process personal data for you. If this DPA conflicts with the Terms on data protection, this DPA prevails. We may update this DPA to reflect changes in law or our subprocessors; material changes are notified as set out in the Terms.
Annex 1: Security measures
- Encryption: data is encrypted in transit (HTTPS/TLS) and at rest.
- Access control: row-level security in the database so each customer only sees its own data; staff access limited to the people who need it to run the Service.
- Authentication: email and password, or Google sign-in, which uses your Google account's own 2-step verification. We never see or store your Google password.
- Uploaded evidence: files you upload for review removal are accessible only to you and our operations team, and are deleted within 90 days after the case is resolved.
- Backups: regular database backups held by our hosting provider in the same region.
- Monitoring: application error monitoring and alerting.
- Payments: card details are entered on Stripe's hosted pages and never reach our systems.
- Vendors: each subprocessor is bound by a data processing agreement.
Contact
Questions about this DPA: hello@reviewtactic.com