01Who We Are
INFUSION AI, trading as Strong Reviews ("Strong Reviews", "we", "us", "our"), operates the "StrongReviews" Google Review Automation system that helps businesses collect, manage, and respond to customer reviews.
For the purposes of UK data protection law, INFUSION AI (trading as Strong Reviews) is the data controller for the personal data of visitors to our website and users of our platform.
Email: hello@infusion-ai.net
Address: 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at the email address above.
02What This Policy Covers
This Privacy Policy explains how we collect, use, store, and share personal data when you:
- Visit our website (strongreviews.co.uk)
- Sign up for and use our "StrongReviews" Google Review Automation system
- Contact us for support or sales enquiries
- Receive or respond to review requests sent via our platform (end customers of our business clients)
03The Personal Data We Collect
3.1 Platform Users (Business Customers & Their Teams)
When you register for and use the Strong Reviews platform, we collect:
- Account information: Full name, business email address, job title, company name
- Billing information: Billing address, VAT number (payment card details are handled directly by Stripe — we do not store card numbers)
- Usage data: Login timestamps, feature usage, settings, and preferences
- Communications: Support tickets and emails you send to us
- Technical data: IP address, browser type, device identifiers, and session data
3.2 End Customers (Recipients of Review Requests)
When our business customers use Strong Reviews to request reviews from their own customers, we process on their behalf:
- Contact details: Name, mobile number, and/or WhatsApp-registered number
- Review content: Any review text or ratings submitted or pulled in from Google
- Interaction data: Whether a review request was delivered, opened, clicked, or actioned
- AI-generated content: Where a business customer enables automated replies, AI-generated reply text published to Google on their behalf; where manual replies are used, no reply content is AI-generated (see Section 4.1)
- Reply settings: Business tone-of-voice preferences, reply instructions, and example replies supplied by the business customer to personalise generated replies
- Metadata: Timestamps and the business that sent the request
3.3 Website Visitors
When you visit our website, we automatically collect:
- IP address and approximate location
- Browser and device information
- Pages visited, time spent, and referral source
- Cookie data (see Section 9)
04How We Use Your Personal Data
We process personal data for the following purposes and rely on the legal bases set out below:
| Purpose | Legal Basis |
|---|---|
| Providing and managing your platform account | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| Processing payments and managing subscriptions via Stripe | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| Sending platform-related communications (e.g. receipts, system alerts) | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| Sending review requests via SMS and WhatsApp on behalf of business customers | Processed on the documented instructions of our business customer, who is responsible for identifying and documenting the applicable UK GDPR lawful basis and for separately complying with PECR (including consent or soft opt-in requirements where applicable) |
| Importing reviews from Google on behalf of business customers | Legitimate interests of the business customer (Art. 6(1)(f) UK GDPR) |
| Using AI to generate, personalise, and (where authorised) publish review replies on behalf of business customers | Legitimate interests of the business customer (Art. 6(1)(f) UK GDPR) |
| Improving our platform and fixing bugs | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| Sending marketing communications to existing customers | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| Sending marketing to new prospects | Consent (Art. 6(1)(a) UK GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) UK GDPR) |
| Preventing fraud and maintaining platform security | Legitimate interests (Art. 6(1)(f) UK GDPR) |
4.1 AI-Assisted Reply Generation
Business customers can choose how their Google review replies are handled:
- Manual replies: The business customer writes and publishes every reply itself. Strong Reviews does not generate or publish replies unless this feature is enabled.
- Automated personalised replies: The business customer authorises Strong Reviews to generate and publish personalised replies to new Google reviews on its behalf.
Where automated replies are enabled, our platform uses artificial intelligence to analyse the reviewer's name (where available), star rating, review text, the business customer's business information, and its chosen tone of voice and reply instructions, in order to generate a personalised reply. This processing:
- May result in a reply being published automatically to the connected Google Business Profile without individual human approval before each reply, where the business customer has enabled this option
- Is only carried out where the business customer has expressly selected or authorised automated replies — it is not enabled by default
- May, for certain sensitive or high-risk reviews (see Section 4.2), be held for manual handling rather than published automatically
- Does not make any automated decisions that produce legal or similarly significant effects on end customers
The business customer remains responsible for reviewing the suitability of its reply settings, instructions, tone, and any information it provides to Strong Reviews, and may disable automated replies or edit/delete a published reply via Google Business Profile at any time.
4.2 Sensitive or High-Risk Reviews
Where automated replies are enabled, Strong Reviews may still avoid publishing an automatic reply, hold a reply for manual review, apply a more cautious response template, or notify the business customer instead of publishing a reply, where a review appears to involve a complaint, legal allegations, threats, discrimination, safeguarding concerns, medical or health information, a financial dispute, sensitive personal information, allegations of misconduct, a one-star or otherwise high-risk review, or any other situation where an automated public response may be inappropriate. The exact escalation rules applied may depend on the business customer's selected settings and service plan.
05Data Processor Responsibilities
Where our business customers use Strong Reviews to manage review requests sent to their own customers, our business customers are the data controllers for those end-customer records. Strong Reviews acts as a data processor on their behalf.
In that capacity, we process end-customer data only on the documented instructions of our business customers, as set out in our Data Processing Agreement (available on request and incorporated into our Terms of Service).
06Who We Share Your Data With
We do not sell personal data. We share data only with the following categories of sub-processor, each bound by a data processing agreement:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Stripe | Subscription billing and payment processing | USA (IDTA safeguards in place) |
| Vercel | Frontend application hosting and delivery — receives only technical logs, IP addresses, and request metadata, not customer names, mobile numbers, or review information | USA (IDTA safeguards in place) |
| Supabase | Database and data storage | West Europe (London) |
| Twilio | SMS message delivery | USA (IDTA safeguards in place) |
| Meta / WhatsApp | WhatsApp messaging infrastructure (routed via Twilio) | USA (IDTA safeguards in place) |
| Review data import via Google Business Profile API | USA (IDTA safeguards in place) | |
| OpenAI | AI-assisted review reply generation | USA (IDTA safeguards in place) |
We may also share data with legal or regulatory authorities where required by law or to protect our rights.
07International Data Transfers
Our primary database is hosted in London (West Europe) via Supabase. However, several of our sub-processors are based outside the UK (see Section 6).
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- The UK's International Data Transfer Agreement (IDTA)
- Adequacy decisions issued by the UK Secretary of State
- Standard contractual clauses approved for use under UK law
You can request details of the specific safeguards in place for any transfer by contacting us at hello@infusion-ai.net.
08How Long We Keep Your Data
We retain personal data for as long as necessary for the purpose it was collected, using the following general position: data used to provide the Services is retained for the duration of the active contract or campaign, and may be retained for up to 30 days afterwards; limited suppression records are retained for up to 12 months to prevent accidental re-contact; and certain records are retained for longer where required by law, accounting obligations, security requirements, or to establish or defend legal claims.
| Data Type | Retention Period |
|---|---|
| Platform account data | Duration of the commercial relationship, plus any additional period required for accounting, taxation, legal, or contractual purposes |
| Customer contact and campaign data (processed on behalf of business customers) | Duration of the active campaign or contract, plus up to 30 days afterwards, unless a longer period is required by law or agreed with the business customer |
| Google review data and generated replies | Duration of the service, plus up to 30 days after termination, unless a shorter or longer period is agreed. Published reviews and replies may remain visible on Google after we delete our own copy, as Google controls the public platform. |
| Suppression and opt-out records | Up to 12 months after the related campaign data is deleted, limited to the minimum information needed to prevent accidental re-contact and evidence compliance |
| Billing records | The period required by applicable UK accounting, taxation, and legal obligations (currently 7 years) |
| Support communications | 3 years |
| Marketing enquiries | 2 years from last interaction |
| Technical logs and security records | Only for as long as reasonably necessary for security, fraud prevention, system monitoring, troubleshooting, incident investigation, and legal compliance, in accordance with our internal retention schedule |
| Cookies | See Section 9 |
After the applicable retention period, data is securely deleted, anonymised, or rendered inaccessible. We may anonymise data instead of deleting it where it can no longer identify an individual. Deleted data may remain temporarily within encrypted infrastructure backups until the relevant provider's normal backup cycle expires; backup data is protected by appropriate technical and organisational measures, is not accessed for normal business purposes, and is not intentionally reintroduced into the live service.
Where our business customers ask us to delete, correct, or suppress specific customer records, or to delete a campaign list, we will act on that instruction without undue delay, subject to technical feasibility and our own legal obligations.
8.1 Contact Retention and Redaction Settings
For customer contacts uploaded by our business customers, each business customer chooses a retention setting that controls when specified personal information is automatically redacted: Never, 7, 14, 30, 60, or 90 days. This is a documented processing instruction from the business customer as data controller.
The selected period does not begin when a contact is imported. It begins when our cleanup process first identifies that the contact has become eligible for redaction, which happens when any of the following occurs:
- A Google review is successfully matched to the contact
- The contact opts out of further communication
- The contact is marked "Do not contact"
- The contact's complete review-request and follow-up sequence has finished, with no message remaining scheduled, queued, or currently sending
- The business customer or an authorised Strong Reviews user manually archives the contact
For example, where a 30-day setting is selected, the relevant personal information is normally redacted 30 days after the contact is first marked eligible. Background cleanup does not run instantaneously — redaction takes place during the next scheduled cleanup cycle after the period expires.
8.2 What Redaction Removes and What Is Retained
Redaction is not full deletion of the contact record. When a contact reaches the end of its selected retention period, we remove the following from the live contact and request records: phone number, job notes, AI personalisation text, the stored wording of outgoing messages, and equivalent message-personalisation content. The request history is kept for operational reporting, but the contact name shown there becomes "Anonymised Contact" and stored outgoing message content becomes "[Message removed by retention policy]".
We currently continue to retain, after redaction: the contact's display name within the underlying contact record; invoice date; import date and source; contact/campaign status; message delivery statuses, dates, and channel; request and follow-up status; whether a review was matched; aggregate campaign/performance information; and a salted hash derived from the former phone number, where it existed.
Important: because the underlying contact record retains a display name, and a salted hash of the former phone number may still allow recognition or matching, the resulting record is not fully anonymous — it is redacted and, in part, pseudonymised. It remains protected as personal data and subject to the retention and deletion controls described in this policy.
8.3 Salted Hashes
Where a phone number existed, we retain a salted hash of the former value after the original is removed. The hash is used only to maintain suppression records, prevent accidental re-contact, identify duplicate imports, and prevent repeat campaign inclusion. Access is limited to authorised personnel and systems that require it for those purposes. Salted hashes are treated as personal data or pseudonymous personal data, not anonymous information, and are deleted in line with the retention and post-termination rules in this policy.
8.4 The "Never" Setting
Selecting "Never" means our automatic redaction process will not redact the contact solely because it has become eligible under the normal retention-window process described above. It does not override a valid data-subject deletion request, a business customer's instruction to delete or redact the record, our post-termination deletion obligations, applicable storage-limitation law, or any other legal or contractual deletion requirement. "Never" is not permission to retain personal data indefinitely without review or justification, and the business customer remains responsible for choosing an appropriate setting and periodically reviewing whether continued retention is still necessary.
8.5 Reporting Information
We retain limited campaign and request-history information after redaction so business customers can view meaningful performance reports: message delivery status, request/follow-up dates, communication channel, whether a review was generated or matched, aggregate request/review numbers, conversion information, source, invoice and import dates, and campaign/contact status. Detailed message wording and personalisation content are removed under the retention policy. We do not describe this reporting information as anonymous where it remains connected to a display name, salted hash, or other identifier; where it is genuinely no longer linked or linkable to an individual, we describe it as aggregated or anonymous reporting information.
8.6 Changing Your Retention Setting
A business customer can request a change to its retention setting at any time. We will confirm how the requested change applies to existing eligible contacts before it is implemented. Selecting a longer period does not restore information that has already been redacted, and permanently removed message content, contact details, and personalisation information cannot normally be recovered. We may apply a shorter retention period than selected where required by law, or refuse an instruction that would be unlawful, excessive, or technically unsupported.
8.7 Data-Subject Rights and Redaction
Automatic contact redaction is separate from a formal data-subject rights request. Where you exercise an applicable right to erasure, restriction, objection, or access, we will assist the relevant business customer (as controller); your request does not need to wait for the normal retention window to expire; a "Never" setting will not prevent us from complying; and retained salted hashes and metadata are taken into account when assessing what personal data remains about you.
| Data / Field | Action at Redaction | Retained? | Purpose |
|---|---|---|---|
| Phone number | Removed | No (salted hash only) | — |
| Job notes / AI personalisation text | Removed | No | — |
| Stored outgoing message wording | Replaced with "[Message removed by retention policy]" | No | — |
| Contact name in request history | Replaced with "Anonymised Contact" | Display label only | Operational reporting |
| Display name in underlying contact record | Not removed at redaction | Yes | Record management; remains personal data subject to retention and deletion controls |
| Salted hash of former phone number | Retained | Yes (pseudonymous) | Suppression, dedupe, re-contact prevention (see 8.3) |
| Message delivery status, dates, channel | Retained | Yes | Performance reporting |
| Review-match status, aggregate stats | Retained | Yes | Performance reporting |
| Invoice date, import date/source, status | Retained | Yes | Operational/billing reference |
09Cookies
Our website and platform currently use only strictly necessary cookies required to provide secure access and core functionality. We do not currently use analytics, marketing, or advertising cookies.
- Strictly necessary cookies: Required for the website and platform to function (no consent required)
Because no optional cookies are currently used, the website does not display an optional-cookie consent banner. You can control strictly necessary cookies through your browser settings, although blocking them may affect platform functionality. For more information, see our Cookie Policy.
10Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Ask us to correct inaccurate or incomplete data
- Right to erasure: Ask us to delete your data in certain circumstances
- Right to restriction: Ask us to limit how we process your data
- Right to data portability: Request your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: Our AI-assisted reply generation and publication (where enabled by a business customer) does not constitute solely automated decision-making with legal or similarly significant effects on you
To exercise any of these rights, contact us at hello@infusion-ai.net. We will respond within one calendar month.
End customers: If you received a review request from one of our business customers and wish to exercise your data rights, please contact that business directly — they are the data controller for your personal data. We can assist them in fulfilling your request.
11Data Protection Complaints
If you wish to raise a complaint about how we have handled your personal data, please contact us at hello@infusion-ai.net with the subject line "Data Protection Complaint".
In accordance with the Data (Use and Access) Act 2025, we will:
- Acknowledge your complaint within 30 days of receipt
- Investigate your complaint without undue delay and keep you informed of progress
- Notify you of the outcome once our investigation is complete
We take all data protection complaints seriously and will work to resolve them fairly and promptly.
12The Right to Complain to the ICO
If you are unhappy with how we have handled your personal data or your complaint, you have the right to lodge a complaint with the UK's supervisory authority:
We would appreciate the opportunity to address your concerns before you contact the ICO — please raise a complaint with us first using the process in Section 11.
13Security
We take data security seriously and implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:
- Encryption in transit (TLS) and at rest
- Role-based access controls
- Secure hosting within Supabase (London data centre)
- Regular security assessments
No method of transmission over the internet is completely secure. If you believe your data has been compromised, please contact us immediately at hello@infusion-ai.net.
14Children's Data
Our platform is intended for business use only. It is not directed at individuals under the age of 16, and we do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us so we can delete it promptly.
15Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, where changes are material, notify you by email or in-platform notification.
Your continued use of our platform following any update constitutes acceptance of the revised policy.
16Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or your personal data:
Email: hello@infusion-ai.net
Address: 43 Garrard Avenue, Margate, Kent, CT9 5PY, United Kingdom
As Oscar Wilde might have observed: "The truth is rarely pure and never simple" — which is exactly why you need a Privacy Policy that says what it means.