Deze pagina is op dit moment alleen in het Engels beschikbaar. De Nederlandse versie volgt. Vragen? info@shipitdigital.nl
Data Processing Agreement
Rvply Version 1.0, effective 3 August 2026
1. Parties and scope
This Data Processing Agreement ("DPA") is entered into between:
- You, the business using Rvply, acting as controller; and
- ShipIt Digital, KvK 85945579, Torresstraat 50, 1056 RV Amsterdam, Nederland, acting as processor ("we", "us").
It forms part of the Terms of Service and is accepted when you create an account. It applies to all processing of personal data we carry out on your behalf. Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of data protection.
Terms such as "personal data", "processing", "data subject", "controller" and "processor" have the meaning given in the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").
2. Roles
You determine the purposes and means of the processing. We process personal data only on your behalf and on your documented instructions.
Your instructions to us are: the Terms of Service, this DPA, and the settings you configure in the application, including which locations you connect, your reply mode, your delay settings, and your brand voice configuration. Changing a setting is a change of instruction.
If we consider an instruction to infringe the GDPR or other data protection law, we will inform you without delay and may suspend the processing concerned.
Note on our other role: for the personal data of your own users, such as their name, email address and billing data, we act as controller, not processor. That processing is described in our Privacy Policy and falls outside this DPA.
3. Subject matter, duration, nature and purpose
- Subject matter: provision of the Rvply review management service.
- Duration: for as long as you have an account, plus the retention periods in section 11.
- Nature and purpose: reading reviews from your Google Business Profile locations, displaying them to you, generating draft replies using artificial intelligence, and publishing replies you have authorised.
Full details are in Annex I.
4. Categories of data subjects and personal data
4.1 Data subjects
- Reviewers. People who have left a public Google review on one of your locations. This is the primary category and deserves attention: these people never entered into a relationship with us, and in most cases are not aware that Rvply exists.
- Your users. The employees and agency staff you invite into your account.
4.2 Personal data
| Category | Source |
|---|---|
| Reviewer display name as shown publicly on Google | Google Business Profile API |
| Review text, star rating, date | Google Business Profile API |
| Any personal data the reviewer chose to include in their review text | Google Business Profile API |
| Language, sentiment and topic derived from the review | Generated by us |
| Draft and published reply text | Generated by us, edited by you |
| Identity of the user who approved a reply, and the timestamp | Generated by us |
4.3 Special categories of personal data
Review text is free text written by a member of the public. It may unintentionally contain special category data under Art. 9 GDPR, for example a reference to illness ("I was sick after eating here"), disability ("the wheelchair access was poor"), dietary requirements connected to religion, or health conditions ("as a coeliac").
Neither party solicits this data. We handle it as follows:
- We do not index, filter, profile or search on special category data.
- We do not use it to build any profile of a reviewer.
- Our safety checks flag reviews mentioning illness or food safety so that they always require human approval, and we instruct the AI model never to confirm, deny or discuss an individual's health in a public reply.
- You must not configure the service, or edit a reply, in a way that publicly confirms or discusses a reviewer's health, disability or other special category data. Doing so is your processing decision and your responsibility as controller.
5. Our obligations
We will:
- Process personal data only on your documented instructions, including for transfers to a third country, unless required otherwise by EU or Member State law. In that case we will inform you before processing, unless the law prohibits it.
- Ensure that everyone authorised to process personal data is bound by an appropriate duty of confidentiality.
- Implement the technical and organisational measures in Annex II.
- Respect the conditions in section 6 for engaging a sub-processor.
- Assist you, taking into account the nature of the processing, in responding to requests from data subjects (section 7).
- Assist you in complying with Art. 32 to 36 GDPR, including security, breach notification and data protection impact assessments.
- Delete or return personal data at the end of the service, as set out in section 11.
- Make available the information necessary to demonstrate compliance and allow for audits, as set out in section 9.
6. Sub-processors
You give us general authorisation to engage the sub-processors listed below.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application server, database and backups | Nuremberg, Germany (EU) |
| HostArmada (Managed Hosting Ltd) | The public website at rvply.nl | Frankfurt, Germany (EU) |
| Anthropic PBC | Generating draft replies | United States (SCCs) |
| Resend, Inc. | Transactional email | United States (SCCs) |
The current list is maintained at https://rvply.nl/subprocessors.
We will notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service and receive a refund of prepaid fees for the unused period.
We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Data subject rights
Given the nature of the processing, you are the party a data subject will normally contact.
- If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will forward the request to you without undue delay and tell the data subject that you are the controller.
- We will assist you with appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond. The application provides export and deletion functions for this purpose.
- A specific point on reviews: the review itself is published on Google and remains under Google's control. If a reviewer wants their review removed from Google, neither you nor we can do that, they must approach Google. We can delete our copy.
8. Personal data breach
We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting personal data processed on your behalf. Our notification will describe, as far as known:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects;
- a contact point for further information.
We will assist you in meeting your own obligations under Art. 33 and 34 GDPR. We will not notify a supervisory authority or a data subject on your behalf unless you instruct us to.
9. Audits
We will make available all information reasonably necessary to demonstrate compliance with Art. 28 GDPR.
You may audit our compliance once per twelve-month period, or more often following a personal data breach affecting you. Audits will be:
- announced at least 30 days in advance;
- conducted during normal business hours;
- conducted so as not to unreasonably disrupt our operations;
- subject to confidentiality obligations;
- at your cost, unless the audit reveals a material breach on our side.
We may satisfy an audit request by providing a current third-party certification or audit report where one covers the matters in question.
10. International transfers
Primary storage of your data is within the European Union.
Where a sub-processor is established outside the EEA, the transfer is based on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor), supplemented by technical measures including encryption in transit and at rest. Where required, we have carried out a transfer impact assessment.
You authorise us to enter into Standard Contractual Clauses with sub-processors on your behalf for this purpose.
11. Retention, deletion and return
| Data | Retention |
|---|---|
| Reviews and replies | 24 months from the review date, then automatic deletion |
| Audit log | 12 months |
| Google OAuth refresh token | Deleted immediately when you disconnect the account |
| All data, on account deletion | Permanently deleted within 30 days |
Before deletion you may export your data in a machine-readable format from the application.
We may retain data for longer only where required by EU or Member State law, and only for as long as that law requires. In that case we will inform you and continue to protect the data under this DPA.
Backups follow their own rotation and are overwritten within 35 days. Data in a backup is not restored to production after a deletion request.
12. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by Art. 82 GDPR.
13. Term
This DPA takes effect when you create an account and remains in force for as long as we process personal data on your behalf.
14. Governing law
This DPA is governed by the law of the Netherlands. Disputes will be brought before the competent court in Amsterdam.
Annex I: Details of processing
| Subject matter | Provision of the Rvply review management service |
| Duration | Term of the account, plus the retention periods in section 11 |
| Nature | Collection, storage, structuring, analysis, generation of derived text, disclosure by publication to Google, erasure |
| Purpose | Enabling the controller to read and respond to public reviews of its own business locations, in the language the review was written in |
| Data subjects | Reviewers who left a public Google review; users invited into the controller's account |
| Personal data | Reviewer display name, review text, rating, date; language, sentiment and topic derived from the review; draft and published reply text; approver identity and timestamp |
| Special categories | Not solicited. May be incidentally present in free-text reviews. Handled per section 4.3 |
| Frequency | Continuous, triggered by new reviews |
| Controller | You |
| Processor | ShipIt Digital |
Annex II: Technical and organisational measures
Access control
- Multi-factor authentication required for all access to production systems
- Access limited to named personnel on a need-to-know basis, reviewed quarterly
- Role-based access control within the application (owner, admin, editor, viewer)
- Every tenant's data is isolated by organisation identifier, enforced at the data access layer
Encryption
- TLS 1.2 or higher for all data in transit
- Encryption at rest for the database and backups
- Google OAuth refresh tokens encrypted separately with AES-256-GCM, with the key held outside the database in a secrets manager
Pseudonymisation and minimisation
- We collect only the review fields required to display a review and generate a reply. We do not request access to posts, messages, questions and answers, photos, or performance data
- Reviewer data is never aggregated across controllers
- Reviewer data is never used to train machine learning models, and this is contractually enforced with our AI sub-processor
Availability and resilience
- Daily automated backups, retained 35 days
- Restore procedure tested at least annually
- Monitoring and alerting on availability and error rates
Integrity and traceability
- Append-only audit log recording who approved and published each reply, and when
- Application-level logging of access to personal data
- Change management: all code changes reviewed before deployment
Organisational
- Confidentiality obligations in every employment and contractor agreement
- Data protection instruction for anyone with production access
- Documented personal data breach procedure with a 24-hour notification commitment
- Sub-processor due diligence before engagement, and a data processing agreement with each