Legal

Data Processing Agreement

Strong Reviews  ·  operated by INFUSION AI
Version 1.4
Effective: 1 June 2026
Last updated: 28 July 2026

§Parties

This Data Processing Agreement ("DPA") is entered into between:

Controller

The business entity that has agreed to Strong Reviews' Terms of Service ("Client", "Controller", "you").

Processor

INFUSION AI, trading as Strong Reviews, of 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom ("Strong Reviews", "Processor", "we").

This DPA forms part of and is incorporated into the Terms of Service between the parties. In the event of any conflict between this DPA and the Terms of Service, this DPA shall take precedence in matters relating to data protection.

01Definitions

In this DPA:

  • "UK GDPR" means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018
  • "Personal Data" has the meaning given in the UK GDPR
  • "Processing" has the meaning given in the UK GDPR
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed
  • "Sub-processor" means any third party engaged by Strong Reviews to process Personal Data on behalf of the Client
  • "Services" means the review management platform and associated services provided by Strong Reviews under the Terms of Service
  • "Controller Data" means any Personal Data provided by or on behalf of the Client to Strong Reviews for processing under this DPA
  • "IDTA" means the UK International Data Transfer Agreement issued by the ICO
  • "UK Addendum" means the UK Addendum to the EU Standard Contractual Clauses issued by the ICO

02Roles and Responsibilities

2.1 Controller

The Client is the data controller in respect of Controller Data. The Client determines the purposes and means of processing Personal Data relating to its own customers and contacts uploaded into or managed via the Strong Reviews platform.

2.2 Processor

Strong Reviews is the data processor in respect of Controller Data. Strong Reviews processes Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service.

2.3 Independent Controller

Strong Reviews acts as an independent data controller in respect of:

  • Platform account and billing data of Client users
  • Website visitor data
  • Data processed for Strong Reviews' own operational, security, and marketing purposes

This DPA does not apply to data for which Strong Reviews is an independent controller (which is covered by the Strong Reviews Privacy Policy).

03Details of Processing

ElementDetails
Subject matterReview request management, customer contact data, review content, and AI-assisted review reply generation and publication
DurationFor the term of the Client's subscription plus any retention period set out in Section 8, subject to the Client's selected contact retention/redaction setting (Never, 7, 14, 30, 60, or 90 days \u2014 see Schedule D)
Nature of processingCollection, storage, transmission via SMS and WhatsApp, retrieval, use for AI analysis and reply generation, publication of replies where authorised, deletion
PurposeSending review requests to the Client's customers via SMS and WhatsApp; importing and displaying Google reviews; generating and, where the Client has authorised automated replies, publishing personalised review replies
Categories of Personal DataNames; mobile phone numbers; WhatsApp-registered numbers; review text and star ratings; date and time of review; reviewer's Google profile information made available through the review; any personal information voluntarily included by the reviewer in the review text; generated reply text and publication status; review request history; message delivery and interaction status; opt-out and suppression status; Google Business Profile and review identifiers; business or customer reference identifiers; metadata including timestamps
Categories of Data SubjectsEnd customers of the Client who receive review requests via SMS or WhatsApp; individuals who publish Google reviews about the Client's business, whose reviews are imported and/or replied to via the Services

Note: The Services do not currently support email review requests. Email addresses are not processed as Controller Data under this DPA. The Client must not upload email addresses for review request purposes unless Strong Reviews has expressly confirmed support for email in writing.

04Processor Obligations

Strong Reviews shall:

4.1 Instructions

Process Controller Data only on the documented instructions of the Client, as set out in this DPA and the Terms of Service, unless required to do so by UK law. If Strong Reviews is required by law to process data outside of the Client's instructions, it will notify the Client before processing (unless prohibited by law from doing so).

4.2 Confidentiality

Ensure that all personnel authorised to process Controller Data are subject to appropriate confidentiality obligations.

4.3 Security

Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The specific measures in place are set out in Schedule C.

4.4 Platform Access by Strong Reviews Personnel

Strong Reviews personnel may access Controller Data only where strictly necessary to provide technical support, troubleshoot platform issues, maintain security, prevent abuse, or deliver the Services. Such access is limited to authorised personnel who are subject to confidentiality obligations. Strong Reviews will not access Controller Data for any other purpose.

4.5 Sub-processors

Not engage any new Sub-processor without giving the Client prior written notice of at least 30 days, allowing the Client to object on reasonable data protection grounds. The current list of approved Sub-processors is set out in Schedule A.

Strong Reviews shall ensure that any Sub-processor is bound by data protection obligations no less protective than those set out in this DPA, including the requirement to implement appropriate security measures.

4.6 Data Subject Rights

Assist the Client, by appropriate technical and organisational measures, to fulfil its obligations to respond to Data Subject requests under Articles 15–22 of the UK GDPR. Where a Data Subject contacts Strong Reviews directly in relation to Controller Data, Strong Reviews will promptly refer that request to the Client.

4.7 Article 32–36 Assistance

Assist the Client in ensuring compliance with the Client's obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, DPIAs, and prior consultation with the ICO), taking into account the nature of the processing and the information available to Strong Reviews.

4.8 Data Protection Impact Assessments

Provide reasonable assistance to the Client where required to carry out a Data Protection Impact Assessment (DPIA) or prior consultation with the ICO, to the extent such assistance relates to Strong Reviews' processing activities.

4.9 Breach Notification

Notify the Client without undue delay (and in any event within 48 hours) of becoming aware of a Personal Data breach affecting Controller Data. Such notification will include, to the extent known at the time:

  • The nature of the breach, including categories and approximate number of Data Subjects affected
  • The name and contact details of the relevant point of contact at Strong Reviews
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its effects

4.10 Audit

Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Client or a mandated third-party auditor, subject to reasonable prior written notice and confidentiality arrangements. Strong Reviews may satisfy audit requests by providing relevant certifications or third-party audit reports where available and appropriate.

4.11 End of Contract

Upon termination or expiry of the Terms of Service, Strong Reviews will delete or return all Controller Data within 30 days. The Client may request earlier deletion at any time where technically and legally possible. Confirmation of deletion will be provided in writing on request.

4.12 Controller Instructions and Deletion Requests

At any time during the term, the Client may instruct Strong Reviews to delete a specific customer record, correct inaccurate data, suppress a mobile number, delete a campaign list, disable further processing, or return available Controller Data. Strong Reviews will comply without undue delay, subject to technical feasibility and its own legal obligations. Data retained after such a request remains subject to the confidentiality and security obligations in this DPA and will not be processed for any new or unrelated purpose.

Strong Reviews does not maintain customer-accessible or user-managed database backups for Controller Data. Deleted Controller Data may remain temporarily within encrypted infrastructure-level backups until the relevant provider's normal backup cycle expires; such backup data is protected by appropriate technical and organisational measures, is not restored or accessed for normal business purposes, and any restored backup will be subject to the original deletion request where technically feasible.

05Controller Obligations

The Client warrants and confirms that it:

  • Has a valid lawful basis under UK GDPR for the processing of Controller Data as described in this DPA
  • Has provided all required privacy information to its own customers (Data Subjects) prior to uploading their contact details into the Strong Reviews platform
  • Is responsible for ensuring that each review request sent via the platform complies with UK GDPR, the Privacy and Electronic Communications Regulations 2003 (PECR), and any applicable direct marketing rules — including obtaining consent or satisfying the soft opt-in conditions where required, and ensuring that appropriate opt-out mechanisms are included in review request messages where required by applicable law
  • Has ensured that customers have a reasonable expectation of receiving review requests via SMS or WhatsApp, or has otherwise satisfied the requirements of applicable law
  • Will only upload contact data that it is lawfully entitled to process for the purposes of the Services
  • Maintains and honours opt-out and suppression records for its customers, and will promptly notify Strong Reviews where a customer has opted out of further contact
  • Will not upload special category data, criminal offence data, or other sensitive personal data to the Services unless expressly agreed in writing with Strong Reviews in advance
  • Will not knowingly upload children's personal data (data relating to individuals under the age of 16) to the Services unless expressly agreed in writing with Strong Reviews in advance
  • Will promptly notify Strong Reviews of any Data Subject request, complaint, or regulatory inquiry relating to Controller Data that the Client receives

06AI-Assisted Reply Generation

Strong Reviews acts as the Client's processor when generating and, where authorised, publishing replies to Google reviews on the Client's behalf, and does so only on the Client's documented instructions as set out below. The Client chooses, for its account, between:

  • Manual replies: the Client writes and publishes all replies itself; Strong Reviews does not generate or publish replies unless the Client enables the option below
  • Automated personalised replies: the Client authorises Strong Reviews to generate and publish personalised replies to new Google reviews on its behalf

The Client acknowledges that, where automated replies are enabled, the Strong Reviews platform uses OpenAI's API to analyse review content and generate a personalised reply. The Client agrees that:

  • The reviewer's name (where available), star rating, review text, the Client's business information, and its chosen tone-of-voice instructions and example replies may be transmitted to OpenAI's API solely for the purpose of generating a personalised reply. No additional personal identifiers are transmitted.
  • According to OpenAI's API data controls, inputs and outputs submitted via the API are not used to train or improve OpenAI's models. Strong Reviews will not opt in to any such training for Controller Data.
  • This processing is carried out on the Client's instructions as part of the Services
  • Where the Client has enabled automated replies, a generated reply may be published to the Client's connected Google Business Profile without individual human approval before each reply; where the Client has not enabled automated replies, no reply is generated or published by Strong Reviews
  • Strong Reviews may hold certain reviews for manual handling, decline to auto-reply, or apply a more cautious response, where a review appears to involve a complaint, legal allegations, threats, discrimination, safeguarding, medical, financial, or other sensitive matter, or another situation where an automated public reply may be inappropriate; the exact rules applied may depend on the Client's selected settings and plan
  • This processing does not constitute solely automated decision-making with legal or similarly significant effects on Data Subjects
  • The Client remains responsible for the accuracy and suitability of the business information, tone instructions, and examples it provides, and may disable automated replies at any time

OpenAI and Google are listed as approved Sub-processors / service providers in Schedule A.

07International Data Transfers

The Client acknowledges that Strong Reviews uses Sub-processors located outside the UK (see Schedule A). Strong Reviews warrants that all such restricted transfers are subject to appropriate safeguards, being one or more of:

  • The UK International Data Transfer Agreement (IDTA)
  • The UK Addendum to the EU Standard Contractual Clauses
  • An adequacy regulation made by the UK Secretary of State

Details of the specific transfer safeguard in place for each Sub-processor are set out in Schedule A. Further information is available on request from hello@infusion-ai.net.

08Retention and Deletion

Controller Data will be retained for the duration of the Client's active subscription or campaign, and for up to 30 days afterwards, unless a longer retention period is required by law, necessary to establish or defend legal claims, required for billing or accounting purposes, or expressly agreed with the Client. After the applicable period, Controller Data will be securely deleted, anonymised, or rendered inaccessible. Following termination:

  • Review request contact data and campaign data will be deleted within 30 days of termination, or earlier on the Client's request under Section 4.12
  • Google review content, generated replies, publication status, and reply history will be deleted within 30 days of termination, unless a shorter or longer period is agreed. Published reviews and replies may remain visible on Google after Strong Reviews deletes its own copy, as Google controls the public platform.
  • Suppression and opt-out records may be retained for a further 12 months after the underlying campaign data is deleted, limited to the minimum information needed to prevent accidental re-contact and evidence compliance with an opt-out request. Suppression data will not be used for marketing, analytics, or any other unrelated purpose.
  • Billing and transaction records will be retained for the period required by applicable UK accounting, taxation, and legal obligations
  • Technical logs and security records will be retained only as long as reasonably necessary for security, fraud prevention, system monitoring, troubleshooting, incident investigation, and legal compliance, in accordance with Strong Reviews' internal retention schedule
  • Anonymised or aggregated analytics data, which cannot identify individuals, may be retained indefinitely

Data retained after termination for the reasons above remains subject to the confidentiality and security obligations of this DPA and will not be processed for any new or unrelated purpose. Sub-processors are required to delete or return Controller Data in accordance with obligations equivalent to those in this Section 8. Deleted Controller Data may remain temporarily in secure backups until the relevant backup cycle expires, as described in Section 4.12. Strong Reviews will provide reasonable confirmation of deletion on request.

Where the Client has selected a contact-level retention/redaction setting under Schedule D, that setting operates alongside — and does not override — this Section 8: the "Never" setting does not prevent deletion at termination or in response to a lawful request, and post-termination deletion applies regardless of the selected setting unless another lawful retention obligation applies.

09Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded or limited by applicable law.

10Governing Law

This DPA is governed by the laws of England and Wales. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

11Updates to This DPA

Strong Reviews may update this DPA from time to time to reflect changes in law, regulation, or its processing activities. Material changes will be notified to Clients with at least 30 days' notice by email or in-platform notification.

If a Client reasonably objects to a material change that adversely affects its data protection position, the parties will work in good faith to resolve the objection within 30 days. If no resolution is reached, the Client may terminate the Services on written notice without penalty.

§Schedule A — Approved Sub-processors

The following Sub-processors are approved as at the date of this DPA. Strong Reviews will provide at least 30 days' notice of any additions or material changes.

Sub-processorPurposeData ProcessedLocationSafeguard
SupabaseDatabase and primary data storageAll Controller DataLondon, UK (eu-west-2)UK-based — no restricted transfer
VercelFrontend application hosting and deliveryTechnical logs, IP addresses, and request metadata only — no Controller DataUSAIDTA / UK Addendum
StripeClient subscription billing and payment processingClient billing data only — not end-customer Controller DataUSAIDTA / UK Addendum
TwilioSMS and WhatsApp message deliveryMobile numbers, message contentUSAIDTA / UK Addendum
Meta / WhatsAppWhatsApp messaging infrastructure (routed via Twilio)Mobile numbers, message contentUSAIDTA / UK Addendum
GoogleReview data import via Google Business Profile API; publication of generated replies to the Client's Google Business Profile where automated replies are authorised. Google processes reviewers' Google account data under its own terms and privacy responsibilities.Review text, ratings, reviewer names, Google review identifiers, published reply textUSAIDTA / UK Addendum
OpenAIAI-assisted review reply generation (sub-processor to Strong Reviews)Review text, star rating, business name, reviewer first name onlyUSAIDTA / UK Addendum

§Schedule B — Contact Details

For all DPA and data protection enquiries:

INFUSION AI (trading as Strong Reviews)

Email: hello@infusion-ai.net

Address: 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom

§Schedule C — Technical & Organisational Security Measures

The following technical and organisational measures are implemented by Strong Reviews to protect Controller Data:

Encryption

  • All data transmitted between users and the platform is encrypted in transit using TLS 1.2 or higher
  • All Controller Data stored in the Supabase database is encrypted at rest using industry-standard encryption

Access Controls

  • Role-based access controls (RBAC) are in place, limiting access to Controller Data to authorised personnel only
  • Least-privilege principles are applied — staff access only the data necessary for their role
  • Platform administrator access requires strong authentication

Infrastructure Security

  • Primary database hosted in Supabase (London, UK — eu-west-2), a managed cloud database provider with SOC 2 Type II certification
  • Frontend application hosted on Vercel. Vercel does not process customer names, mobile numbers, review text, ratings, or review request history, but may process limited technical logs, IP addresses, and request metadata
  • Network-level security controls and firewall policies are maintained by Supabase

Application Security

  • Input validation and output encoding applied throughout the application
  • Regular dependency and vulnerability checks performed
  • Separation of production and development environments

Monitoring and Logging

  • Access and activity logs maintained for security monitoring purposes
  • Anomalous access patterns reviewed by authorised personnel

Incident Response

  • A defined process is in place for detecting, reporting, and responding to Personal Data breaches
  • Clients are notified within 48 hours of a confirmed breach affecting their Controller Data (see Section 4.9)

Personnel

  • All personnel with access to Controller Data are subject to confidentiality obligations
  • Awareness of data protection responsibilities is maintained across the team

Deletion

  • Controller Data is deleted, anonymised, or rendered inaccessible in accordance with the retention periods set out in Section 8
  • The Client may request deletion of a specific record, campaign list, or its full Controller Data at any time under Section 4.12, actioned without undue delay subject to technical feasibility
  • Strong Reviews does not maintain user-managed database backups for Controller Data. Deleted data may remain temporarily within encrypted infrastructure-level backups until the relevant provider's normal backup cycle expires

Sub-processor Management

  • All Sub-processors are reviewed prior to engagement and bound by data processing agreements
  • Sub-processor changes are communicated to Clients with at least 30 days' notice

This DPA should be read alongside the Strong Reviews Privacy Policy and Terms of Service.

§Schedule D — Contact Retention & Redaction

The Client selects, for its account, a contact retention/redaction setting of Never, 7, 14, 30, 60, or 90 days. This setting is a documented processing instruction from the Client as Controller, authorising Strong Reviews to operate the automatic eligibility and redaction process described below.

D.1 Eligibility Events

The selected period begins when Strong Reviews' cleanup process first identifies that a contact is eligible for redaction, triggered by any of: a matched Google review; a contact opt-out; a "Do not contact" mark; completion of the full request/follow-up sequence with nothing further scheduled, queued, or sending; or manual archiving by the Client or an authorised Strong Reviews user. Redaction occurs during the next scheduled cleanup cycle after the period expires.

D.2 Redacted Fields

At redaction, Strong Reviews removes: phone number, job notes, AI personalisation text, and the stored wording of outgoing messages. Request-history reporting is retained, with the displayed contact name replaced by "Anonymised Contact" and stored message content replaced by "[Message removed by retention policy]".

D.3 Retained Fields

Strong Reviews currently continues to retain, after redaction: the contact's display name in the underlying contact record; invoice date; import date and source; contact/campaign status; message delivery statuses, dates, and channel; request/follow-up status; whether a review was matched; aggregate campaign/performance data; and a salted hash derived from the former phone number, where it existed. These retained fields are pseudonymous personal data, not anonymous information, for so long as they can be used to recognise, match, or distinguish an individual, and remain subject to this DPA's confidentiality, security, access-control, and deletion requirements. They must not be reused for any purpose beyond suppression, deduplication, re-contact prevention, and compliance.

D.4 The "Never" Setting

Selecting "Never" means the automatic process will not redact a contact solely because it became eligible. It does not prevent deletion at termination under Section 8, does not override a lawful data-subject request or the Client's own deletion instruction, and does not amount to indefinite retention without review — the Client remains responsible for periodically reviewing whether continued retention is still necessary.

D.5 Assistance with Deletion and Objection Requests

Strong Reviews will assist the Client with data-subject deletion, restriction, objection, and access requests independently of the normal retention window; such requests do not need to wait for the selected period to expire, and a "Never" setting will not prevent compliance. Opt-out records will not be removed in a manner that could cause accidental re-contact. Sub-processors are subject to equivalent deletion and retention obligations for any retained field they process.