Data Processing Agreement
Version 1.0 · Also known as a verwerkersovereenkomst
This Agreement applies whenever you use Reviowl to message your own customers. It forms part of our Terms of Service and is entered into between you (the "Controller") and Reviowl (sole proprietorship) (the "Processor", "we"), and governs our processing of personal data on your behalf under Article 28 GDPR.
1. What we process, and why
Subject matter: sending review requests and win-back messages to your customers, on your instructions.
Duration: for as long as your account is active, plus the retention period in clause 8.
Nature and purpose: storing your contact list, generating message wording, and transmitting those messages by email and (where you enable it) SMS.
Categories of data subjects: your customers.
Types of personal data: name, email address, phone number, date of last visit, message history, and opt-out status. We do not ask for and you must not upload special categories of data (health, religion, political opinion and similar).
2. Your instructions
We process personal data only on your documented instructions. Your use of the Service — uploading contacts, configuring campaigns, and approving message content — constitutes those instructions. We will tell you if we believe an instruction breaches the GDPR. We do not sell personal data, and we do not use your contact list for our own purposes, including to market to your customers.
3. Confidentiality
Anyone we authorise to process your data is bound by an obligation of confidentiality. Access is limited to those who need it to run or support the Service.
4. Security (Article 32)
We maintain measures appropriate to the risk, including: encryption in transit (TLS) for all traffic and email delivery; encryption at rest by our hosting providers; row-level security in the database so one customer's data is not reachable from another's account; access to production limited to the account owner and protected by two-factor authentication; secrets held in encrypted environment storage and never in source control; and payment card details handled entirely by Stripe, never seen or stored by us.
5. Sub-processors
You give general written authorisation for us to engage the sub-processors listed in our Privacy Policy, which names each one and where it stores data. We remain responsible for their performance. We will give you reasonable notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds, in which case you may terminate the affected Service.
6. Assisting you with data subject rights
The Service is built so you can handle most requests yourself: you can view, edit, export and delete any contact at any time, and every message carries a one-click unsubscribe that we honour automatically. If a data subject contacts us directly, we will refer them to you and assist you in responding, taking into account the nature of the processing.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations. We will also assist you with data protection impact assessments and prior consultations where required.
8. Deletion and return
You may export or delete your data at any time from within the Service. On termination we delete your contact data within 30 days, unless we are required to keep it by law. Suppression records (opt-outs) are the deliberate exception and are retained indefinitely: they are how we guarantee that someone who unsubscribed is never contacted again, including after a future upload. These records contain only the address and the fact of the opt-out.
9. Demonstrating compliance
We will make available the information reasonably necessary to demonstrate compliance with this Agreement, and allow for and contribute to audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless required by a supervisory authority.
10. International transfers
Contact data is stored and sent within the EU. Where a sub-processor named in the Privacy Policy processes data outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
11. Contact
Data protection questions: support@reviowl.com. Reviowl (sole proprietorship), [your registered business address], the Netherlands.
This agreement is provided in good faith and covers the elements required by Article 28(3) GDPR, but it is not legal advice. If you operate at scale or in a regulated sector, have your own adviser review it.