Data Processing Addendum

Last updated: 6 July 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ReputeMap (“ReputeMap”, “we”, “us”, the “Processor”) and the customer that accepts those Terms (“Customer”, “you”, the “Controller”). It applies where ReputeMap processes Personal Data on your behalf in providing the Service. By accepting the Terms of Service you accept this DPA. A countersigned copy is available on request at yaro@reputemap.com.

1. Definitions

Personal Data”, “Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Processing” and “Supervisory Authority” have the meanings given in the EU General Data Protection Regulation 2016/679 (“GDPR”) and, where applicable, equivalent terms under the UK GDPR and the California Consumer Privacy Act (“CCPA”). “Data Protection Laws” means all privacy and data-protection laws applicable to a party’s processing under this DPA.

2. Roles of the parties

For Personal Data you submit to, or that ReputeMap accesses on your behalf through, the Service — including your clients’ Google Business Profile data, reviewer names, review content, and the contacts you upload for review requests — you are the Controller (or a processor acting for your own client) and ReputeMap is the Processor. ReputeMap is the Controller only for its own account, billing and website-analytics data, which is governed by our Privacy Policy. Under the CCPA, ReputeMap acts as a service provider and does not sell or share Personal Data.

3. Scope of processing

  • Subject matter & duration: processing for the term of the Terms of Service and until deletion under Section 9.
  • Nature & purpose: to provide the Service — syncing and displaying reviews, publishing replies you author, sending the alerts, review requests and reports you configure, and generating audits and analytics you request.
  • Types of Personal Data: names and email addresses of your users, team members and contacts; reviewer display names and review text; business location and rating data; and any content you choose to submit.
  • Categories of Data Subjects: your staff and team members, your clients’ customers/reviewers, and the recipients of review requests.

4. Processor obligations

ReputeMap will:

  • Process Personal Data only on your documented instructions (including this DPA and your use of the Service), unless required by law, in which case we will inform you unless legally prohibited.
  • Ensure persons authorised to process Personal Data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (Section 6).
  • Taking into account the nature of processing, assist you by appropriate measures in fulfilling your obligation to respond to Data Subject requests (access, correction, deletion, portability, objection).
  • Assist you with security, breach notification, data-protection impact assessments and prior consultation, taking into account the information available to us.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits under Section 8.

5. Sub-processors

You provide general authorisation for ReputeMap to engage Sub-processors to provide the Service. Each Sub-processor is bound by data protection obligations no less protective than this DPA, and ReputeMap remains responsible for their performance. Our current Sub-processors are listed in the “Service providers (subprocessors)” section of our Privacy Policy — currently Google (Business Profile API), Stripe (payments), Amazon Web Services / SES (email), Anthropic (AI reply drafts), DigitalOcean (hosting) and Google Analytics (aggregate analytics). We will give you notice of any intended addition or replacement of a Sub-processor by updating that list; if you reasonably object on data-protection grounds, you may terminate the affected part of the Service.

6. Security

ReputeMap maintains technical and organisational measures appropriate to the risk, including: encryption of data in transit (HTTPS/TLS) and encryption of OAuth tokens at rest; role-based access controls and tenant isolation; least-privilege access to production systems; structured audit logging of sensitive operations; and secured, access-controlled infrastructure. Card data is handled entirely by Stripe; ReputeMap does not store full card numbers.

7. Personal data breach

ReputeMap will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and will provide information reasonably available to help you meet your notification obligations under Data Protection Laws.

8. Audits

On reasonable prior written request, and no more than once per year (unless required by a Supervisory Authority or following a breach), ReputeMap will make available information necessary to demonstrate compliance with this DPA. Audits are subject to confidentiality and must not unreasonably disrupt ReputeMap’s operations.

9. Return and deletion

On termination of the Service, or on your written request, ReputeMap will delete or return your Personal Data and delete existing copies within a reasonable period, except where retention is required by law. You may also delete your account and associated Personal Data at any time from within the app or by contacting us. Disconnecting a Google account revokes our access to that account’s Google Business Profile data.

10. International transfers

Where processing involves transferring Personal Data outside the EEA, UK or other regulated region to a country without an adequacy decision, ReputeMap and its Sub-processors rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference for such transfers.

11. Google user data

ReputeMap’s access to and use of Google Business Profile data is additionally governed by the Limited Use requirements of the Google API Services User Data Policy, as described in our Privacy Policy. We do not use Google user data for advertising, do not sell it, and do not use it other than to provide the features you request.

12. Liability & order of precedence

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.

13. Contact

Data-protection questions, Data Subject requests, or to request a countersigned copy of this DPA: yaro@reputemap.com. See also our Privacy Policy and Terms of Service.