Rvply

Deze pagina is op dit moment alleen in het Engels beschikbaar. De Nederlandse versie volgt. Vragen? info@shipitdigital.nl

Data Processing Agreement

Rvply Version 1.0, effective 3 August 2026


1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between:

It forms part of the Terms of Service and is accepted when you create an account. It applies to all processing of personal data we carry out on your behalf. Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of data protection.

Terms such as "personal data", "processing", "data subject", "controller" and "processor" have the meaning given in the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").

2. Roles

You determine the purposes and means of the processing. We process personal data only on your behalf and on your documented instructions.

Your instructions to us are: the Terms of Service, this DPA, and the settings you configure in the application, including which locations you connect, your reply mode, your delay settings, and your brand voice configuration. Changing a setting is a change of instruction.

If we consider an instruction to infringe the GDPR or other data protection law, we will inform you without delay and may suspend the processing concerned.

Note on our other role: for the personal data of your own users, such as their name, email address and billing data, we act as controller, not processor. That processing is described in our Privacy Policy and falls outside this DPA.

3. Subject matter, duration, nature and purpose

Full details are in Annex I.

4. Categories of data subjects and personal data

4.1 Data subjects

4.2 Personal data

CategorySource
Reviewer display name as shown publicly on GoogleGoogle Business Profile API
Review text, star rating, dateGoogle Business Profile API
Any personal data the reviewer chose to include in their review textGoogle Business Profile API
Language, sentiment and topic derived from the reviewGenerated by us
Draft and published reply textGenerated by us, edited by you
Identity of the user who approved a reply, and the timestampGenerated by us

4.3 Special categories of personal data

Review text is free text written by a member of the public. It may unintentionally contain special category data under Art. 9 GDPR, for example a reference to illness ("I was sick after eating here"), disability ("the wheelchair access was poor"), dietary requirements connected to religion, or health conditions ("as a coeliac").

Neither party solicits this data. We handle it as follows:

5. Our obligations

We will:

6. Sub-processors

You give us general authorisation to engage the sub-processors listed below.

Sub-processorPurposeLocation
Hetzner Online GmbHApplication server, database and backupsNuremberg, Germany (EU)
HostArmada (Managed Hosting Ltd)The public website at rvply.nlFrankfurt, Germany (EU)
Anthropic PBCGenerating draft repliesUnited States (SCCs)
Resend, Inc.Transactional emailUnited States (SCCs)

The current list is maintained at https://rvply.nl/subprocessors.

We will notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service and receive a refund of prepaid fees for the unused period.

We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

7. Data subject rights

Given the nature of the processing, you are the party a data subject will normally contact.

8. Personal data breach

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting personal data processed on your behalf. Our notification will describe, as far as known:

We will assist you in meeting your own obligations under Art. 33 and 34 GDPR. We will not notify a supervisory authority or a data subject on your behalf unless you instruct us to.

9. Audits

We will make available all information reasonably necessary to demonstrate compliance with Art. 28 GDPR.

You may audit our compliance once per twelve-month period, or more often following a personal data breach affecting you. Audits will be:

We may satisfy an audit request by providing a current third-party certification or audit report where one covers the matters in question.

10. International transfers

Primary storage of your data is within the European Union.

Where a sub-processor is established outside the EEA, the transfer is based on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor), supplemented by technical measures including encryption in transit and at rest. Where required, we have carried out a transfer impact assessment.

You authorise us to enter into Standard Contractual Clauses with sub-processors on your behalf for this purpose.

11. Retention, deletion and return

DataRetention
Reviews and replies24 months from the review date, then automatic deletion
Audit log12 months
Google OAuth refresh tokenDeleted immediately when you disconnect the account
All data, on account deletionPermanently deleted within 30 days

Before deletion you may export your data in a machine-readable format from the application.

We may retain data for longer only where required by EU or Member State law, and only for as long as that law requires. In that case we will inform you and continue to protect the data under this DPA.

Backups follow their own rotation and are overwritten within 35 days. Data in a backup is not restored to production after a deletion request.

12. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by Art. 82 GDPR.

13. Term

This DPA takes effect when you create an account and remains in force for as long as we process personal data on your behalf.

14. Governing law

This DPA is governed by the law of the Netherlands. Disputes will be brought before the competent court in Amsterdam.


Annex I: Details of processing

Subject matterProvision of the Rvply review management service
DurationTerm of the account, plus the retention periods in section 11
NatureCollection, storage, structuring, analysis, generation of derived text, disclosure by publication to Google, erasure
PurposeEnabling the controller to read and respond to public reviews of its own business locations, in the language the review was written in
Data subjectsReviewers who left a public Google review; users invited into the controller's account
Personal dataReviewer display name, review text, rating, date; language, sentiment and topic derived from the review; draft and published reply text; approver identity and timestamp
Special categoriesNot solicited. May be incidentally present in free-text reviews. Handled per section 4.3
FrequencyContinuous, triggered by new reviews
ControllerYou
ProcessorShipIt Digital

Annex II: Technical and organisational measures

Access control

Encryption

Pseudonymisation and minimisation

Availability and resilience

Integrity and traceability

Organisational