Data Processing Agreement
The Review Pals — Last updated: 16 August 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between The Review Pals (company number 16505574), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("Processor", "we", "us") and the client identified at sign-up ("Controller", "you"). It applies whenever we process personal data on your behalf and on your instructions in connection with the Service, in particular your customers' contact details used to send review requests. This DPA is intended to meet the requirements of Article 28 of the UK GDPR and the Data Protection Act 2018. Capitalised terms not defined here have the meaning given in UK GDPR.
1. Roles of the Parties
You are the Controller in respect of your customers' personal data. We are the Processor, and we process that personal data only on your documented instructions, as set out in this DPA and the Terms, except where we are required to do otherwise by UK or EU law (in which case we will inform you before processing, unless the law prohibits this).
2. Subject Matter, Duration, and Purpose
The subject matter of the processing is our provision of the Service to you, including sending review requests and related communications, drafting review responses, monitoring reviews, and generating reports on your behalf. Processing continues for the duration of your subscription and any period afterwards required to fulfil our obligations under this DPA (such as data deletion).
3. Nature and Purpose of Processing
We process personal data to: send plain service/review request messages by SMS, email, and/or WhatsApp on your behalf to your existing customers; generate personalised images accompanying those requests; draft suggested responses to reviews; monitor and report on your review activity; and integrate with third-party platforms you connect (such as your Google Business Profile, CRM, booking system, or accounting software) for these purposes.
You may provide customer contact details to us either via a direct platform/CRM integration, or by sending us a file (for example by email or WhatsApp) containing your customers' names and contact details. Where files are received this way, they may be formatted or organised using Google Drive before being imported into our platform. Where you send data by email or WhatsApp, you are responsible for ensuring you are authorised to transmit that data to us by those means, and we will handle any file received — including any intermediate formatting in Google Drive — in line with the security measures set out in Annex 2, including prompt import into our platform and deletion of the original file once processed.
The Service is designed for customer care communications, not marketing. You are responsible for ensuring messages sent through the Service do not contain promotional content and that you hold a valid lawful basis (typically legitimate interest, as an existing customer relationship) for contacting each data subject, as set out in the Terms and Conditions.
4. Categories of Data Subjects
Your customers and prospective customers whose contact details you upload to, or connect via integration with, the Service.
5. Types of Personal Data
Typically: full name, email address, phone number, and details of the transaction or interaction that triggered the review request (such as service date or invoice reference). We do not require, and you should not upload, special category data (such as health data) unless strictly necessary and agreed with us in writing, with appropriate safeguards.
6. Our Obligations as Processor
We will:
- Process personal data only on your documented instructions, including with regard to international transfers, unless required otherwise by law;
- Ensure that persons authorised to process personal data are subject to confidentiality obligations;
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Annex 2);
- Not engage another processor (sub-processor) without your prior general authorisation (see Section 7), and impose data protection obligations on any sub-processor equivalent to those in this DPA;
- Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as reasonably possible, to respond to requests from data subjects exercising their rights under UK GDPR;
- Assist you in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and consultation with the ICO, taking into account the nature of processing and information available to us;
- At your choice, delete or return all personal data to you at the end of the provision of services, and delete existing copies unless UK or EU law requires storage;
- Make available to you all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to reasonable audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice and confidentiality.
7. Sub-Processors
You provide general authorisation for us to engage sub-processors to support delivery of the Service, provided we impose data protection terms on them consistent with this DPA and remain liable to you for their performance. Our current sub-processors include categories such as: cloud hosting providers; Google Drive, used to format and organise customer files before import; SMS, email, and WhatsApp message delivery providers; payment processing (Stripe); and customer support and analytics tools. A current list of named sub-processors is available on request by emailing info@thereviewpals.com.
We will notify you of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable data protection grounds within 14 days. If you object and we cannot resolve the concern, either party may terminate the affected part of the Service.
8. International Transfers
Where any processing involves a transfer of personal data outside the UK, we will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement (IDTA), an EU Standard Contractual Clauses arrangement with the UK Addendum, or a UK adequacy decision, in accordance with UK GDPR Chapter V.
9. Personal Data Breach
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your data, providing sufficient information to allow you to meet your own breach notification obligations, and will cooperate with you and take reasonable steps to assist in investigating, mitigating, and remediating the breach.
10. Data Subject Rights
If we receive a request directly from a data subject to exercise their rights (such as access, erasure, or objection) in relation to data we process on your behalf, we will promptly forward it to you and will not respond directly, unless legally required to do so, since you remain the Controller responsible for responding.
11. Deletion or Return of Data
On termination or expiry of the Service, we will, at your election, delete or return all personal data processed on your behalf within a reasonable period (typically 30 days), and delete existing copies unless applicable law requires us to retain some or all of the data, in which case we will isolate and protect that data from further processing.
12. Liability
Liability under this DPA is subject to the limitations of liability set out in the Terms and Conditions between the parties, save that nothing in this DPA limits either party's liability for infringements of data subjects' rights under UK GDPR to the extent such liability cannot lawfully be limited.
13. Term
This DPA takes effect on the date you begin using the Service and continues for as long as we process personal data on your behalf under the Terms.
Annex 1 — Details of Processing
- Controller: You, the client business identified at sign-up.
- Processor: The Review Pals (company number 16505574), 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
- Subject matter: Provision of the review management and automation Service.
- Duration: For the term of the Service agreement, plus any agreed post-termination period for data return/deletion.
- Nature and purpose: Sending review requests and related communications; AI-assisted drafting of review responses; review monitoring, reporting, and analytics; integration with connected third-party platforms.
- Categories of data subjects: Controller's customers and prospective customers.
- Types of personal data: Name, email address, phone number, and interaction/transaction details relevant to the review request.
Annex 2 — Technical and Organisational Security Measures
- Encryption of personal data in transit (TLS) and at rest where supported by our infrastructure providers;
- Access controls restricting personal data access to authorised personnel on a need-to-know basis;
- Use of reputable cloud infrastructure providers with their own recognised security certifications;
- Regular review of access permissions and prompt removal of access for departing staff;
- Secure password policies and, where available, multi-factor authentication for internal systems;
- Processes for detecting, investigating, and responding to security incidents, including breach notification procedures;
- Contractual data protection obligations imposed on sub-processors;
- Regular backups to support data availability and resilience;
- Where customer contact files are received by email or WhatsApp rather than direct integration, prompt import of the file into our secure platform, restricted access to the original file during that process, and deletion of the original file once the data has been imported.
