Data Processing Agreement
This Data Processing Agreement (DPA) sets out how ReviewCatcher processes personal data on behalf of a client, in line with Article 28 GDPR. Every client receives a completed copy of this agreement — with your business's details added — to sign as part of onboarding, before we begin processing any of your customers' data on your behalf. It forms part of, and is governed by, your service agreement with us; where the two conflict on data protection, this Agreement prevails.
Parties
You — the business named in your service agreement with us — act as the Controller of your customers' personal data. ReviewCatcher (RBN — registration pending, of Rush, Co. Dublin, Ireland) acts as the Processor.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Data Protection Law" means the GDPR and the Irish Data Protection Acts 2018. "Personal Data", "Controller", "Processor", "Processing", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by the Processor to process Personal Data.
2. Roles and scope
The Controller is the controller and the Processor is the processor of the Personal Data described in Annex A. The Processor will process Personal Data only to provide the services in the Principal Agreement and only as set out in this Agreement.
3. Processor obligations
The Processor shall:
- Process only on instructions — process the Personal Data only on the Controller's documented instructions (including as set out in Annex A), unless required by law, in which case it will inform the Controller first where legally permitted.
- Confidentiality — ensure that anyone authorised to process the Personal Data is bound by an appropriate duty of confidentiality.
- Security — implement the technical and organisational measures in Annex C to ensure a level of security appropriate to the risk (Article 32 GDPR).
- Sub-processors — not engage a Sub-processor without the Controller's prior authorisation (see clause 4), and impose data protection terms on any Sub-processor equivalent to those in this Agreement.
- Assist with data subject requests — taking into account the nature of the processing, assist the Controller by appropriate measures to respond to requests from Data Subjects exercising their rights.
- Assist with compliance — assist the Controller in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to the Processor.
- Breach notification — notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach, with the information the Controller needs to meet its own notification duties.
- Deletion or return — at the Controller's choice, delete or return all Personal Data at the end of the services and delete existing copies, unless law requires storage.
- Demonstrate compliance — make available to the Controller the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, on reasonable notice.
4. Sub-processors
The Controller gives general authorisation for the Processor to use the Sub-processors listed in Annex B. The Processor will inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object on reasonable data protection grounds. The Processor remains liable for its Sub-processors' performance of these obligations.
5. International transfers
The Processor will not transfer Personal Data outside the EEA unless it has taken measures required by Data Protection Law — such as relying on an adequacy decision or putting Standard Contractual Clauses in place. Relevant transfers are noted in Annex B.
6. Liability and term
This Agreement takes effect on the date of signature and continues for the duration of the processing under the Principal Agreement. Liability is governed by the Principal Agreement.
7. Governing law
This Agreement is governed by the laws of Ireland, and the parties submit to the jurisdiction of the Irish courts.
Both parties sign a completed copy of this agreement before your data is processed — you'll receive yours during onboarding, alongside the request for your customer list and confirmation of your lawful basis to contact them.
Annex A — Details of Processing
- Subject matter: provision of an automated Google review-generation and review-response service.
- Duration: for the term of the Principal Agreement.
- Nature and purpose: sending review-request and reminder messages to the Controller's customers on the Controller's behalf; running an initial re-engagement campaign to the Controller's existing customers; drafting and posting responses to reviews.
- Types of personal data: customer name; mobile phone number; email address (if provided); details of the service/visit (e.g. date, job type); review content.
- Categories of data subjects: the Controller's customers and prospective customers.
- Controller instructions: the Processor processes the above data solely to deliver the services and for no other purpose.
Annex B — Authorised Sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| n8n (automation platform) | Workflow automation — sending requests, reminders, reactivation campaigns | TODO — confirm n8n Cloud data-hosting region | TODO |
| Google Workspace | Business email | US / EU (Google Cloud) | EU–US Data Privacy Framework / SCCs |
| TODO — SMS delivery provider | Sending SMS review requests | TODO | TODO |
| TODO — AI provider | Drafting review responses | TODO | TODO |
Annex C — Technical & Organisational Security Measures
- Access to Personal Data restricted to authorised personnel on a need-to-know basis, protected by strong authentication.
- Personal Data encrypted in transit; stored in access-controlled systems.
- Sub-processors selected for appropriate security and bound by contract.
- Regular review of access rights; prompt removal of access when no longer needed.
- Data minimisation — only the data needed to deliver the service is collected and held.
- Deletion or return of Personal Data on termination.
- A process for detecting, reporting and responding to Personal Data Breaches.