Data Processing Agreement

Template version: July 2026

This Data Processing Agreement (DPA) sets out how ReviewCatcher processes personal data on behalf of a client, in line with Article 28 GDPR. Every client receives a completed copy of this agreement — with your business's details added — to sign as part of onboarding, before we begin processing any of your customers' data on your behalf. It forms part of, and is governed by, your service agreement with us; where the two conflict on data protection, this Agreement prevails.

Parties

You — the business named in your service agreement with us — act as the Controller of your customers' personal data. ReviewCatcher (RBN — registration pending, of Rush, Co. Dublin, Ireland) acts as the Processor.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Data Protection Law" means the GDPR and the Irish Data Protection Acts 2018. "Personal Data", "Controller", "Processor", "Processing", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by the Processor to process Personal Data.

2. Roles and scope

The Controller is the controller and the Processor is the processor of the Personal Data described in Annex A. The Processor will process Personal Data only to provide the services in the Principal Agreement and only as set out in this Agreement.

3. Processor obligations

The Processor shall:

4. Sub-processors

The Controller gives general authorisation for the Processor to use the Sub-processors listed in Annex B. The Processor will inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds. The Processor remains liable for its Sub-processors' performance of these obligations.

5. International transfers

The Processor will not transfer Personal Data outside the EEA unless it has taken measures required by Data Protection Law — such as relying on an adequacy decision or putting Standard Contractual Clauses in place. Relevant transfers are noted in Annex B.

6. Liability and term

This Agreement takes effect on the date of signature and continues for the duration of the processing under the Principal Agreement. Liability is governed by the Principal Agreement.

7. Governing law

This Agreement is governed by the laws of Ireland, and the parties submit to the jurisdiction of the Irish courts.

Both parties sign a completed copy of this agreement before your data is processed — you'll receive yours during onboarding, alongside the request for your customer list and confirmation of your lawful basis to contact them.

Annex A — Details of Processing

Annex B — Authorised Sub-processors

TODO — SMS delivery provider and AI provider (review replies) still need confirming; the two rows below are placeholders, not commitments.

Sub-processorPurposeLocationTransfer safeguard
n8n (automation platform)Workflow automation — sending requests, reminders, reactivation campaignsTODO — confirm n8n Cloud data-hosting regionTODO
Google WorkspaceBusiness emailUS / EU (Google Cloud)EU–US Data Privacy Framework / SCCs
TODO — SMS delivery providerSending SMS review requestsTODOTODO
TODO — AI providerDrafting review responsesTODOTODO

Annex C — Technical & Organisational Security Measures