Legal

Data Processing Agreement

Last updated: 03/11/2025

This DPA forms part of the Terms of Service between [Customer Name] ("Customer") and REVIEWHQ ("Processor"). It governs how we process personal data on behalf of the Customer under the GDPR and CCPA.

1. Definitions

  • Data Controller – Determines purposes and means of processing.
  • Data Processor – Processes data on behalf of the controller.
  • Data Subject – Individual whose data is processed.
  • Personal Data – Identifiable information.
  • Processing – Any operation on personal data.
  • Sub-Processor – Third party engaged for processing.

2. Roles and Responsibilities

Customer = Controller. REVIEWHQ = Processor acting only on instructions.

3. Types of Data

End-user data (names, emails, reviews, feedback, videos), customer data (contact details, credentials), usage data (IPs, devices, logs).

4. Purpose

To aggregate, respond, and send review requests, analyze reputation, and automate workflows.

5. Duration

Processing continues for the term of the Agreement unless law requires retention or Customer requests deletion.

6. Processor Obligations

Process only on instructions; ensure confidentiality; maintain security; assist Customer with compliance and breach notifications.

7. Customer Obligations

Provide lawful instructions; inform data subjects; ensure legal basis; handle requests.

8. Sub-Processors

May be engaged under equivalent protections; Customer informed of changes; REVIEWHQ remains liable.

9. International Transfers

Protected by Standard Contractual Clauses or other lawful mechanisms.

10. Security Measures

Encryption, access controls, audits, and incident response.

11. Data Subject Rights

Assistance with access, rectification, erasure, restriction, objection, and portability.

12. Retention and Deletion

Upon termination, data is returned or deleted unless law requires retention.

13. Audit Rights

Customer may request audits with reasonable notice and at own cost.

14. Liability

Follows the limitations set in the main Agreement.

15. Governing Law

Applicable international data protection laws apply.

16. Termination

Effective while REVIEWHQ processes data; obligations continue until deletion.

17. Contact

Questions: