Legal

Data Processing Agreement

Strong Reviews  ·  operated by INFUSION AI
Version 1.3
Effective: 1 June 2026
Last updated: 1 June 2026

§Parties

This Data Processing Agreement ("DPA") is entered into between:

Controller

The business entity that has agreed to Strong Reviews' Terms of Service ("Client", "Controller", "you").

Processor

INFUSION AI, trading as Strong Reviews, of 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom ("Strong Reviews", "Processor", "we").

This DPA forms part of and is incorporated into the Terms of Service between the parties. In the event of any conflict between this DPA and the Terms of Service, this DPA shall take precedence in matters relating to data protection.

01Definitions

In this DPA:

  • "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018
  • "Personal Data" has the meaning given in the UK GDPR
  • "Processing" has the meaning given in the UK GDPR
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed
  • "Sub-processor" means any third party engaged by Strong Reviews to process Personal Data on behalf of the Client
  • "Services" means the review management platform and associated services provided by Strong Reviews under the Terms of Service
  • "Controller Data" means any Personal Data provided by or on behalf of the Client to Strong Reviews for processing under this DPA
  • "IDTA" means the UK International Data Transfer Agreement issued by the ICO
  • "UK Addendum" means the UK Addendum to the EU Standard Contractual Clauses issued by the ICO

02Roles and Responsibilities

2.1 Controller

The Client is the data controller in respect of Controller Data. The Client determines the purposes and means of processing Personal Data relating to its own customers and contacts uploaded into or managed via the Strong Reviews platform.

2.2 Processor

Strong Reviews is the data processor in respect of Controller Data. Strong Reviews processes Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service.

2.3 Independent Controller

Strong Reviews acts as an independent data controller in respect of:

  • Platform account and billing data of Client users
  • Website visitor data
  • Data processed for Strong Reviews' own operational, security, and marketing purposes

This DPA does not apply to data for which Strong Reviews is an independent controller (which is covered by the Strong Reviews Privacy Policy).

03Details of Processing

ElementDetails
Subject matterReview request management, customer contact data, review content, and AI-assisted reply generation
DurationFor the term of the Client's subscription plus any retention period set out in Section 8
Nature of processingCollection, storage, transmission via SMS and WhatsApp, retrieval, use for AI analysis, deletion
PurposeSending review requests to the Client's customers via SMS and WhatsApp; importing and displaying Google reviews; generating AI-drafted reply suggestions
Categories of Personal DataNames; mobile phone numbers; WhatsApp-registered numbers; review text and ratings; review request history; message delivery and interaction status; opt-out and suppression status; Google Business Profile review identifiers; business or customer reference identifiers; metadata including timestamps
Categories of Data SubjectsEnd customers of the Client who receive review requests via SMS or WhatsApp, or whose reviews are imported from Google

Note: The Services do not currently support email review requests. Email addresses are not processed as Controller Data under this DPA. The Client must not upload email addresses for review request purposes unless Strong Reviews has expressly confirmed support for email in writing.

04Processor Obligations

Strong Reviews shall:

4.1 Instructions

Process Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service, unless required to do so by UK law. If Strong Reviews is required by law to process data outside of the Client's instructions, it will notify the Client before processing (unless prohibited by law from doing so).

4.2 Confidentiality

Ensure that all personnel authorised to process Controller Data are subject to appropriate confidentiality obligations.

4.3 Security

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The specific measures in place are set out in Schedule C.

4.4 Platform Access by Strong Reviews Personnel

Strong Reviews personnel may access Controller Data only where strictly necessary to provide technical support, troubleshoot platform issues, maintain security, prevent abuse, or deliver the Services. Such access is limited to authorised personnel who are subject to confidentiality obligations. Strong Reviews will not access Controller Data for any other purpose.

4.5 Sub-processors

Not engage any new Sub-processor without giving the Client prior written notice of at least 30 days, allowing the Client to object on reasonable data protection grounds. The current list of approved Sub-processors is set out in Schedule A.

Strong Reviews shall ensure that any Sub-processor is bound by data protection obligations no less protective than those set out in this DPA, including the requirement to implement appropriate security measures.

4.6 Data Subject Rights

Assist the Client, by appropriate technical and organisational measures, to fulfil its obligations to respond to Data Subject requests under Articles 15–22 of the UK GDPR. Where a Data Subject contacts Strong Reviews directly in relation to Controller Data, Strong Reviews will promptly refer that request to the Client.

4.7 Article 32–36 Assistance

Assist the Client in ensuring compliance with the Client's obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, DPIAs, and prior consultation with the ICO), taking into account the nature of the processing and the information available to Strong Reviews.

4.8 Data Protection Impact Assessments

Provide reasonable assistance to the Client where required to carry out a Data Protection Impact Assessment (DPIA) or prior consultation with the ICO, to the extent such assistance relates to Strong Reviews' processing activities.

4.9 Breach Notification

Notify the Client without undue delay (and in any event within 48 hours) of becoming aware of a Personal Data breach affecting Controller Data. Such notification will include, to the extent known at the time:

  • The nature of the breach, including categories and approximate number of Data Subjects affected
  • The name and contact details of the relevant point of contact at Strong Reviews
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects

4.10 Audit

Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Client or a mandated third-party auditor, subject to reasonable prior written notice and confidentiality arrangements. Strong Reviews may satisfy audit requests by providing relevant certifications or third-party audit reports where available and appropriate.

4.11 End of Contract

Upon termination or expiry of the Terms of Service, Strong Reviews will (at the Client's written request) delete or return all Controller Data within 30 days. Confirmation of deletion will be provided in writing on request.

Strong Reviews does not currently maintain customer-accessible or user-managed automated database backups for Controller Data. Controller Data is deleted from the live production database upon request within the timeframe set out above. Strong Reviews does not intentionally retain separate backup copies of Controller Data. Where limited provider-level logs, caching, replication, or resilience mechanisms exist, these are managed by the relevant infrastructure provider and are not used by Strong Reviews except as necessary for security, reliability, or legal compliance.

05Controller Obligations

The Client warrants and confirms that it:

  • Has a valid lawful basis under UK GDPR for the processing of Controller Data as described in this DPA
  • Has provided all required privacy information to its own customers (Data Subjects) prior to uploading their contact details into the Strong Reviews platform
  • Is responsible for ensuring that each review request sent via the platform complies with UK GDPR, the Privacy and Electronic Communications Regulations 2003 (PECR), and any applicable direct marketing rules — including obtaining consent or satisfying the soft opt-in conditions where required, and ensuring that appropriate opt-out mechanisms are included in review request messages where required by applicable law
  • Has ensured that customers have a reasonable expectation of receiving review requests via SMS or WhatsApp, or has otherwise satisfied the requirements of applicable law
  • Will only upload contact data that it is lawfully entitled to process for the purposes of the Services
  • Maintains and honours opt-out and suppression records for its customers, and will promptly notify Strong Reviews where a customer has opted out of further contact
  • Will not upload special category data, criminal offence data, or other sensitive personal data to the Services unless expressly agreed in writing with Strong Reviews in advance
  • Will not knowingly upload children's personal data (data relating to individuals under the age of 16) to the Services unless expressly agreed in writing with Strong Reviews in advance
  • Will promptly notify Strong Reviews of any Data Subject request, complaint, or regulatory inquiry relating to Controller Data that the Client receives

06AI-Assisted Reply Generation

The Client acknowledges that the Strong Reviews platform uses OpenAI's API to analyse review content and generate suggested reply text. The Client agrees that:

  • Review text, star rating, business name, and (where available) the reviewer's first name may be transmitted to OpenAI's API solely for the purpose of generating a suggested public reply. No additional personal identifiers are transmitted.
  • According to OpenAI's API data controls, inputs and outputs submitted via the API are not used to train or improve OpenAI's models. Strong Reviews will not opt in to any such training for Controller Data.
  • This processing is carried out on the Client's instructions as part of the Services
  • All AI-generated replies are suggestions only and must be reviewed and approved by a human (the Client or their authorised team member) before publication
  • This processing does not constitute solely automated decision-making with legal or similarly significant effects on Data Subjects

OpenAI is listed as an approved Sub-processor in Schedule A.

07International Data Transfers

The Client acknowledges that Strong Reviews uses Sub-processors located outside the UK (see Schedule A). Strong Reviews warrants that all such restricted transfers are subject to appropriate safeguards, being one or more of:

  • The UK International Data Transfer Agreement (IDTA)
  • The UK Addendum to the EU Standard Contractual Clauses
  • An adequacy regulation made by the UK Secretary of State

Details of the specific transfer safeguard in place for each Sub-processor are set out in Schedule A. Further information is available on request from hello@infusion-ai.net.

08Retention and Deletion

Controller Data will be retained for the duration of the Client's subscription. Following termination:

  • Review request contact data will be deleted within 30 days of termination, or earlier on written request
  • Review content and interaction data will be deleted within 30 days of termination
  • Opt-out and suppression records may be retained for a further 12 months to prevent inadvertent re-contact, after which they will be permanently deleted
  • Anonymised or aggregated analytics data (which cannot identify individuals) may be retained indefinitely

Strong Reviews does not currently maintain user-managed automated database backups for Controller Data. Controller Data is deleted from the live production database upon request or at contract termination within the timeframe set out above.

09Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited by applicable law.

10Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

11Updates to This DPA

Strong Reviews may update this DPA from time to time to reflect changes in law, regulation, or its processing activities. Material changes will be notified to Clients with at least 30 days' notice by email or in-platform notification.

If a Client reasonably objects to a material change that adversely affects its data protection position, the parties will work in good faith to resolve the objection within 30 days. If no resolution is reached, the Client may terminate the Services on written notice without penalty.

§Schedule A — Approved Sub-processors

The following Sub-processors are approved as at the date of this DPA. Strong Reviews will provide at least 30 days' notice of any additions or material changes.

Sub-processorPurposeData ProcessedLocationSafeguard
SupabaseDatabase and primary data storageAll Controller DataLondon, UK (eu-west-2)UK-based — no restricted transfer
VercelFrontend application hosting and deliveryTechnical logs, IP addresses, and request metadata only — no Controller DataUSAIDTA / UK Addendum
StripeClient subscription billing and payment processingClient billing data only — not end-customer Controller DataUSAIDTA / UK Addendum
TwilioSMS and WhatsApp message deliveryMobile numbers, message contentUSAIDTA / UK Addendum
Meta / WhatsAppWhatsApp messaging infrastructure (routed via Twilio)Mobile numbers, message contentUSAIDTA / UK Addendum
GoogleReview data import via Google Business Profile APIReview text, ratings, reviewer names, Google review identifiersUSAIDTA / UK Addendum
OpenAIAI-assisted review reply generationReview text, star rating, business name, reviewer first name onlyUSAIDTA / UK Addendum

§Schedule B — Contact Details

For all DPA and data protection enquiries:

INFUSION AI (trading as Strong Reviews)

Email: hello@infusion-ai.net

Address: 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom

§Schedule C — Technical & Organisational Security Measures

The following technical and organisational measures are implemented by Strong Reviews to protect Controller Data:

Encryption

  • All data transmitted between users and the platform is encrypted in transit using TLS 1.2 or higher
  • All Controller Data stored in the Supabase database is encrypted at rest using industry-standard encryption

Access Controls

  • Role-based access controls (RBAC) are in place, limiting access to Controller Data to authorised personnel only
  • Least-privilege principles are applied — staff access only the data necessary for their role
  • Platform administrator access requires strong authentication

Infrastructure Security

  • Primary database hosted in Supabase (London, UK — eu-west-2), a managed cloud database provider with SOC 2 Type II certification
  • Frontend application hosted on Vercel. Vercel does not process customer names, mobile numbers, review text, ratings, or review request history, but may process limited technical logs, IP addresses, and request metadata
  • Network-level security controls and firewall policies are maintained by Supabase

Application Security

  • Input validation and output encoding applied throughout the application
  • Regular dependency and vulnerability checks performed
  • Separation of production and development environments

Monitoring and Logging

  • Access and activity logs maintained for security monitoring purposes
  • Anomalous access patterns reviewed by authorised personnel

Incident Response

  • A defined process is in place for detecting, reporting, and responding to Personal Data breaches
  • Clients are notified within 48 hours of a confirmed breach affecting their Controller Data (see Section 4.9)

Personnel

  • All personnel with access to Controller Data are subject to confidentiality obligations
  • Awareness of data protection responsibilities is maintained across the team

Deletion

  • Controller Data is deleted from the live database upon request or at contract termination within 30 days (see Section 4.11)
  • Strong Reviews does not currently maintain user-managed automated database backups for Controller Data. Deletion is applied to the live production database within the timeframe set out above

Sub-processor Management

  • All Sub-processors are reviewed prior to engagement and bound by data processing agreements
  • Sub-processor changes are communicated to Clients with at least 30 days' notice

This DPA should be read alongside the Strong Reviews Privacy Policy and Terms of Service.