§Parties
This Data Processing Agreement ("DPA") is entered into between:
Controller
The business entity that has agreed to Strong Reviews' Terms of Service ("Client", "Controller", "you").
Processor
INFUSION AI, trading as Strong Reviews, of 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom ("Strong Reviews", "Processor", "we").
This DPA forms part of and is incorporated into the Terms of Service between the parties. In the event of any conflict between this DPA and the Terms of Service, this DPA shall take precedence in matters relating to data protection.
01Definitions
In this DPA:
- "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018
- "Personal Data" has the meaning given in the UK GDPR
- "Processing" has the meaning given in the UK GDPR
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed
- "Sub-processor" means any third party engaged by Strong Reviews to process Personal Data on behalf of the Client
- "Services" means the review management platform and associated services provided by Strong Reviews under the Terms of Service
- "Controller Data" means any Personal Data provided by or on behalf of the Client to Strong Reviews for processing under this DPA
- "IDTA" means the UK International Data Transfer Agreement issued by the ICO
- "UK Addendum" means the UK Addendum to the EU Standard Contractual Clauses issued by the ICO
02Roles and Responsibilities
2.1 Controller
The Client is the data controller in respect of Controller Data. The Client determines the purposes and means of processing Personal Data relating to its own customers and contacts uploaded into or managed via the Strong Reviews platform.
2.2 Processor
Strong Reviews is the data processor in respect of Controller Data. Strong Reviews processes Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service.
2.3 Independent Controller
Strong Reviews acts as an independent data controller in respect of:
- Platform account and billing data of Client users
- Website visitor data
- Data processed for Strong Reviews' own operational, security, and marketing purposes
This DPA does not apply to data for which Strong Reviews is an independent controller (which is covered by the Strong Reviews Privacy Policy).
03Details of Processing
| Element | Details |
|---|---|
| Subject matter | Review request management, customer contact data, review content, and AI-assisted reply generation |
| Duration | For the term of the Client's subscription plus any retention period set out in Section 8 |
| Nature of processing | Collection, storage, transmission via SMS and WhatsApp, retrieval, use for AI analysis, deletion |
| Purpose | Sending review requests to the Client's customers via SMS and WhatsApp; importing and displaying Google reviews; generating AI-drafted reply suggestions |
| Categories of Personal Data | Names; mobile phone numbers; WhatsApp-registered numbers; review text and ratings; review request history; message delivery and interaction status; opt-out and suppression status; Google Business Profile review identifiers; business or customer reference identifiers; metadata including timestamps |
| Categories of Data Subjects | End customers of the Client who receive review requests via SMS or WhatsApp, or whose reviews are imported from Google |
Note: The Services do not currently support email review requests. Email addresses are not processed as Controller Data under this DPA. The Client must not upload email addresses for review request purposes unless Strong Reviews has expressly confirmed support for email in writing.
04Processor Obligations
Strong Reviews shall:
4.1 Instructions
Process Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service, unless required to do so by UK law. If Strong Reviews is required by law to process data outside of the Client's instructions, it will notify the Client before processing (unless prohibited by law from doing so).
4.2 Confidentiality
Ensure that all personnel authorised to process Controller Data are subject to appropriate confidentiality obligations.
4.3 Security
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The specific measures in place are set out in Schedule C.
4.4 Platform Access by Strong Reviews Personnel
Strong Reviews personnel may access Controller Data only where strictly necessary to provide technical support, troubleshoot platform issues, maintain security, prevent abuse, or deliver the Services. Such access is limited to authorised personnel who are subject to confidentiality obligations. Strong Reviews will not access Controller Data for any other purpose.
4.5 Sub-processors
Not engage any new Sub-processor without giving the Client prior written notice of at least 30 days, allowing the Client to object on reasonable data protection grounds. The current list of approved Sub-processors is set out in Schedule A.
Strong Reviews shall ensure that any Sub-processor is bound by data protection obligations no less protective than those set out in this DPA, including the requirement to implement appropriate security measures.
4.6 Data Subject Rights
Assist the Client, by appropriate technical and organisational measures, to fulfil its obligations to respond to Data Subject requests under Articles 15–22 of the UK GDPR. Where a Data Subject contacts Strong Reviews directly in relation to Controller Data, Strong Reviews will promptly refer that request to the Client.
4.7 Article 32–36 Assistance
Assist the Client in ensuring compliance with the Client's obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, DPIAs, and prior consultation with the ICO), taking into account the nature of the processing and the information available to Strong Reviews.
4.8 Data Protection Impact Assessments
Provide reasonable assistance to the Client where required to carry out a Data Protection Impact Assessment (DPIA) or prior consultation with the ICO, to the extent such assistance relates to Strong Reviews' processing activities.
4.9 Breach Notification
Notify the Client without undue delay (and in any event within 48 hours) of becoming aware of a Personal Data breach affecting Controller Data. Such notification will include, to the extent known at the time:
- The nature of the breach, including categories and approximate number of Data Subjects affected
- The name and contact details of the relevant point of contact at Strong Reviews
- The likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its effects
4.10 Audit
Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Client or a mandated third-party auditor, subject to reasonable prior written notice and confidentiality arrangements. Strong Reviews may satisfy audit requests by providing relevant certifications or third-party audit reports where available and appropriate.
4.11 End of Contract
Upon termination or expiry of the Terms of Service, Strong Reviews will (at the Client's written request) delete or return all Controller Data within 30 days. Confirmation of deletion will be provided in writing on request.
Strong Reviews does not currently maintain customer-accessible or user-managed automated database backups for Controller Data. Controller Data is deleted from the live production database upon request within the timeframe set out above. Strong Reviews does not intentionally retain separate backup copies of Controller Data. Where limited provider-level logs, caching, replication, or resilience mechanisms exist, these are managed by the relevant infrastructure provider and are not used by Strong Reviews except as necessary for security, reliability, or legal compliance.
05Controller Obligations
The Client warrants and confirms that it:
- Has a valid lawful basis under UK GDPR for the processing of Controller Data as described in this DPA
- Has provided all required privacy information to its own customers (Data Subjects) prior to uploading their contact details into the Strong Reviews platform
- Is responsible for ensuring that each review request sent via the platform complies with UK GDPR, the Privacy and Electronic Communications Regulations 2003 (PECR), and any applicable direct marketing rules — including obtaining consent or satisfying the soft opt-in conditions where required, and ensuring that appropriate opt-out mechanisms are included in review request messages where required by applicable law
- Has ensured that customers have a reasonable expectation of receiving review requests via SMS or WhatsApp, or has otherwise satisfied the requirements of applicable law
- Will only upload contact data that it is lawfully entitled to process for the purposes of the Services
- Maintains and honours opt-out and suppression records for its customers, and will promptly notify Strong Reviews where a customer has opted out of further contact
- Will not upload special category data, criminal offence data, or other sensitive personal data to the Services unless expressly agreed in writing with Strong Reviews in advance
- Will not knowingly upload children's personal data (data relating to individuals under the age of 16) to the Services unless expressly agreed in writing with Strong Reviews in advance
- Will promptly notify Strong Reviews of any Data Subject request, complaint, or regulatory inquiry relating to Controller Data that the Client receives
06AI-Assisted Reply Generation
The Client acknowledges that the Strong Reviews platform uses OpenAI's API to analyse review content and generate suggested reply text. The Client agrees that:
- Review text, star rating, business name, and (where available) the reviewer's first name may be transmitted to OpenAI's API solely for the purpose of generating a suggested public reply. No additional personal identifiers are transmitted.
- According to OpenAI's API data controls, inputs and outputs submitted via the API are not used to train or improve OpenAI's models. Strong Reviews will not opt in to any such training for Controller Data.
- This processing is carried out on the Client's instructions as part of the Services
- All AI-generated replies are suggestions only and must be reviewed and approved by a human (the Client or their authorised team member) before publication
- This processing does not constitute solely automated decision-making with legal or similarly significant effects on Data Subjects
OpenAI is listed as an approved Sub-processor in Schedule A.
07International Data Transfers
The Client acknowledges that Strong Reviews uses Sub-processors located outside the UK (see Schedule A). Strong Reviews warrants that all such restricted transfers are subject to appropriate safeguards, being one or more of:
- The UK International Data Transfer Agreement (IDTA)
- The UK Addendum to the EU Standard Contractual Clauses
- An adequacy regulation made by the UK Secretary of State
Details of the specific transfer safeguard in place for each Sub-processor are set out in Schedule A. Further information is available on request from hello@infusion-ai.net.
08Retention and Deletion
Controller Data will be retained for the duration of the Client's subscription. Following termination:
- Review request contact data will be deleted within 30 days of termination, or earlier on written request
- Review content and interaction data will be deleted within 30 days of termination
- Opt-out and suppression records may be retained for a further 12 months to prevent inadvertent re-contact, after which they will be permanently deleted
- Anonymised or aggregated analytics data (which cannot identify individuals) may be retained indefinitely
Strong Reviews does not currently maintain user-managed automated database backups for Controller Data. Controller Data is deleted from the live production database upon request or at contract termination within the timeframe set out above.
09Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited by applicable law.
10Governing Law
This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
11Updates to This DPA
Strong Reviews may update this DPA from time to time to reflect changes in law, regulation, or its processing activities. Material changes will be notified to Clients with at least 30 days' notice by email or in-platform notification.
If a Client reasonably objects to a material change that adversely affects its data protection position, the parties will work in good faith to resolve the objection within 30 days. If no resolution is reached, the Client may terminate the Services on written notice without penalty.
§Schedule A — Approved Sub-processors
The following Sub-processors are approved as at the date of this DPA. Strong Reviews will provide at least 30 days' notice of any additions or material changes.
| Sub-processor | Purpose | Data Processed | Location | Safeguard |
|---|---|---|---|---|
| Supabase | Database and primary data storage | All Controller Data | London, UK (eu-west-2) | UK-based — no restricted transfer |
| Vercel | Frontend application hosting and delivery | Technical logs, IP addresses, and request metadata only — no Controller Data | USA | IDTA / UK Addendum |
| Stripe | Client subscription billing and payment processing | Client billing data only — not end-customer Controller Data | USA | IDTA / UK Addendum |
| Twilio | SMS and WhatsApp message delivery | Mobile numbers, message content | USA | IDTA / UK Addendum |
| Meta / WhatsApp | WhatsApp messaging infrastructure (routed via Twilio) | Mobile numbers, message content | USA | IDTA / UK Addendum |
| Review data import via Google Business Profile API | Review text, ratings, reviewer names, Google review identifiers | USA | IDTA / UK Addendum | |
| OpenAI | AI-assisted review reply generation | Review text, star rating, business name, reviewer first name only | USA | IDTA / UK Addendum |
§Schedule B — Contact Details
For all DPA and data protection enquiries:
Email: hello@infusion-ai.net
Address: 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom
§Schedule C — Technical & Organisational Security Measures
The following technical and organisational measures are implemented by Strong Reviews to protect Controller Data:
Encryption
- All data transmitted between users and the platform is encrypted in transit using TLS 1.2 or higher
- All Controller Data stored in the Supabase database is encrypted at rest using industry-standard encryption
Access Controls
- Role-based access controls (RBAC) are in place, limiting access to Controller Data to authorised personnel only
- Least-privilege principles are applied — staff access only the data necessary for their role
- Platform administrator access requires strong authentication
Infrastructure Security
- Primary database hosted in Supabase (London, UK — eu-west-2), a managed cloud database provider with SOC 2 Type II certification
- Frontend application hosted on Vercel. Vercel does not process customer names, mobile numbers, review text, ratings, or review request history, but may process limited technical logs, IP addresses, and request metadata
- Network-level security controls and firewall policies are maintained by Supabase
Application Security
- Input validation and output encoding applied throughout the application
- Regular dependency and vulnerability checks performed
- Separation of production and development environments
Monitoring and Logging
- Access and activity logs maintained for security monitoring purposes
- Anomalous access patterns reviewed by authorised personnel
Incident Response
- A defined process is in place for detecting, reporting, and responding to Personal Data breaches
- Clients are notified within 48 hours of a confirmed breach affecting their Controller Data (see Section 4.9)
Personnel
- All personnel with access to Controller Data are subject to confidentiality obligations
- Awareness of data protection responsibilities is maintained across the team
Deletion
- Controller Data is deleted from the live database upon request or at contract termination within 30 days (see Section 4.11)
- Strong Reviews does not currently maintain user-managed automated database backups for Controller Data. Deletion is applied to the live production database within the timeframe set out above
Sub-processor Management
- All Sub-processors are reviewed prior to engagement and bound by data processing agreements
- Sub-processor changes are communicated to Clients with at least 30 days' notice
This DPA should be read alongside the Strong Reviews Privacy Policy and Terms of Service.