Data Processing Addendum (DPA)
Between: Maven Advertising SRL (operating the ReviewMix service, "Processor"), Iași, România; Trade Register (ONRC) no. J2021003339221 · EUID ROONRC.J2021003339221 · CUI (unique registration code) 21027661 · VAT RO46019966
and
[Customer legal name] ("Controller"), acting through the account holder identified on ReviewMix's systems.
Effective date: The date Controller accepts the ReviewMix Terms of Service, or enters into a separate agreement referencing this DPA.
1. Purpose and scope
This Data Processing Addendum ("DPA") supplements the agreement between the Controller and the Processor ("Principal Agreement", being the ReviewMix Terms of Service unless otherwise specified) with respect to processing of personal data by the Processor on behalf of the Controller.
This DPA applies when the Processor processes personal data on the Controller's behalf under Article 28 GDPR. It does not apply to personal data for which ReviewMix is itself the controller (such as the Controller's own account data).
Where there is a conflict between this DPA and the Principal Agreement, this DPA prevails on matters of data protection.
2. Definitions
Terms used in this DPA have the meanings given in GDPR (Regulation (EU) 2016/679), including: personal data, processing, controller, processor, data subject, sub-processor, supervisory authority, personal data breach.
3. Subject matter, duration, and nature of processing
Subject matter. Personal data of individuals who submit testimonials to the Controller via a ReviewMix collection link, and related consent and audit records. Where the Controller has connected a Google Business Profile, also the review data of persons who have posted reviews of the Controller's business on Google (publicly available, accessed via the Controller's OAuth authorization).
Duration. For the duration of the Principal Agreement, plus any retention period required by applicable law or set out in this DPA.
Nature of processing. Collection, storage, display, modification (on data subject request), retrieval, transmission, and deletion of testimonial content and associated metadata. For Google Business Profile data: retrieval via OAuth API, caching in EU Postgres, scheduled refresh, and immediate purge on Controller disconnection.
Purpose. To provide the ReviewMix service to the Controller as described in the Principal Agreement.
Categories of data subjects.
- Natural persons who submit testimonials to the Controller via ReviewMix collection links.
- Natural persons who have posted Google reviews of the Controller's business on Google Maps/Search (only when Controller has connected their Google Business Profile).
Categories of personal data.
Collected testimonials:
- Name
- Role or job title (optional)
- Company name (optional)
- Email address
- Testimonial content
- Photograph (optional)
- Consent records (timestamps, IP hashes, consent text version)
- Metadata (submission timestamp, widget source, status)
- An optional reference supplied by the Controller's own system (for example an order reference), carried on the collection link
Google Business Profile reviews (only when Controller has enabled GBP connection):
- Reviewer display name (as posted on Google)
- Review text (optional — Google permits star-only reviews)
- Star rating (1–5)
- Profile photo URL (link only; image hosted by Google)
- Review publication timestamp
- External reply URL (constructed at import; used for Reply-on-Google feature)
Legal basis and reviewer notice (Google Business Profile data). Following qualified legal review (June 2026):
- (i) Legal basis. The Controller's lawful basis for processing publicly-available Google review data is Art. 6(1)(f) GDPR (legitimate interest) — surfacing and displaying genuine reviews of the Controller's own business. Google's Terms of Service grant the technical right of API access; they do not supply the lawful basis, which rests on the Controller's legitimate interest.
- (ii) Transfer module. The ReviewMix→Google LLC API transfer is governed by SCC Module 3 (Processor-to-Processor), because Google LLC acts as a sub-processor to ReviewMix (itself the Processor). See Section 14.
- (iii) Reviewer (Art. 14) notice. The Art. 14(5)(b) "disproportionate effort" exemption applies: there is no direct relationship between ReviewMix and the Google reviewer, and individually notifying reviewers whose public reviews are imported would involve disproportionate effort. The Controller (as Controller) discloses this processing in its own privacy notice. ReviewMix, as Processor, bears no direct Art. 14 notice obligation toward Google reviewers.
Special categories of data. The Controller agrees not to submit special categories of data under Art. 9 GDPR through the service without a specific legal basis that the Controller has documented. The service is not designed for processing of such data.
4. Roles and responsibilities
The Controller is the controller of the personal data processed under this DPA. The Processor is the processor. Each party shall comply with the obligations applicable to its role under GDPR.
The Controller determines the purposes and means of processing by:
- Configuring widgets and collection settings
- Inviting or permitting data subjects to submit testimonials
- Deciding which testimonials to approve, reject, edit, or delete
- Providing any data subject notifications beyond those the Processor provides natively
Independent Controllership for Compliance Proof. Following qualified legal review (June 2026): on termination of the Principal Agreement the Processor's Art. 28 role ceases, and ReviewMix transitions to an Independent Controller (an "Independent Controller Transition" per EDPB Guidelines 07/2020 — not joint controllership) strictly for retaining the consent ledger. The retained records are limited to consent-proof metadata: submission timestamps, pseudonymised IP hashes, and consent text versions. ReviewMix retains these in its own legitimate interest as proof of consent under Art. 7(1) GDPR and for the establishment, exercise, or defence of legal claims. The retention period is 3 years following account closure (Romanian Civil Code Art. 2517 general limitation), after which the records are deleted. See Section 12.
5. Controller's instructions
The Processor shall process personal data only on documented instructions from the Controller, including as specified in the Principal Agreement, this DPA, and any configuration choices the Controller makes in the service. The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes GDPR or other applicable data protection law.
6. Confidentiality
The Processor ensures that persons authorized to process personal data are bound by confidentiality obligations, whether by contract or statutory duty.
7. Security of processing
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:
- Pseudonymization and encryption where appropriate
- Measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
- Measures to restore availability and access to personal data in a timely manner in the event of a physical or technical incident
- Regular testing and evaluation of the effectiveness of technical and organizational measures
Current security measures are described in Annex II (Technical and Organizational Measures).
8. Sub-processors
8.1 Authorization
The Controller grants general authorization for the Processor to use sub-processors. The current list is published at app.reviewmix.eu/legal/subprocessors and in legal/subprocessors.md.
8.2 Notification of changes
The Processor will notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance, giving the Controller the opportunity to object to such changes.
8.3 Objection
If the Controller has a reasonable objection to a new sub-processor on data-protection grounds, the Controller may notify the Processor in writing within 30 days of notification. The parties will negotiate in good faith to resolve the objection. If no resolution is reached, the Controller may terminate the Principal Agreement for that reason without penalty, with a pro-rated refund of any pre-paid fees.
8.4 Sub-processor contracts
The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA. The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
9. Data subject rights
The Processor provides native features enabling data subjects to exercise their rights directly:
- Access and portability: self-service export at the submitter's personal link (
app.reviewmix.eu/t/<token>) - Rectification: self-service edit at the same link
- Erasure: self-service consent withdrawal and deletion request at the same link
- Restriction: effective immediately upon withdrawal of relevant consent
For any data subject request that the Processor receives directly but that properly belongs to the Controller, the Processor will promptly forward the request and provide reasonable assistance, taking into account the nature of processing and the information available.
10. Data breach notification
The Processor notifies the Controller without undue delay and in any case within 72 hours after becoming aware of a personal data breach affecting the Controller's data. The notification includes, to the extent known:
- The nature of the breach, including categories and approximate numbers of data subjects and records concerned
- The name and contact details of the Processor's contact point (privacy@reviewmix.eu)
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its adverse effects
The Processor assists the Controller with the Controller's own notification obligations to supervisory authorities and data subjects.
11. Data Protection Impact Assessments and prior consultation
The Processor provides reasonable assistance to the Controller in carrying out Data Protection Impact Assessments and conducting prior consultations with supervisory authorities, taking into account the nature of processing and the information available.
12. Deletion or return of data
At the Controller's choice, on termination of the Principal Agreement, the Processor shall delete or return all personal data processed on behalf of the Controller, and delete existing copies, unless Union or Member State law requires storage.
On termination, the underlying personal data (names, emails, testimonial content, photographs) is permanently deleted. The immutable consent records (submission timestamps, pseudonymised IP hashes, consent text versions) are retained for 3 years following account closure as proof of consent, then deleted. Following qualified legal review (June 2026), the 3-year period reflects the Romanian Civil Code Art. 2517 general limitation, and during this period ReviewMix holds the consent ledger as an Independent Controller in its own legitimate interest (Art. 7(1) GDPR + defence of legal claims) — see Section 4 ("Independent Controllership for Compliance Proof").
13. Audits
13.1 Information
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in this DPA and Article 28 GDPR. The Processor maintains documentation of its security program, sub-processor arrangements, and data-subject-request handling. Upon reasonable written request, the Processor provides a summary of this documentation to the Controller.
13.2 Audits
The Controller has the right to audit the Processor's compliance with this DPA. Unless a supervisory authority requires otherwise:
- The Controller provides at least 30 days' prior written notice
- Audits occur no more frequently than once per calendar year, except following a confirmed personal data breach
- Audits are conducted during business hours, minimize disruption, and respect confidentiality
- The Controller bears the costs of audits conducted by third-party auditors of its choice
- The Processor may satisfy audit requests by providing reasonable alternative evidence (such as summaries, policies, or third-party attestations) where available
14. International data transfers
The Processor processes personal data primarily within the European Union (Hetzner, Germany). Some sub-processors (Cloudflare, Resend, Google LLC) may involve transfers outside the EEA. For Google LLC specifically (GBP API): ReviewMix's EU servers fetch review data from Google's US API endpoints on the Controller's behalf; data is immediately stored in EU Postgres after retrieval; no review data is retained outside the EU. For such transfers, the Processor relies on:
- EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) between the relevant parties
- Supplementary technical and organizational measures as documented in Annex II
- Transfer Impact Assessments available on reasonable request
SCC module. Following qualified legal review (June 2026): where ReviewMix is the data exporter and a sub-processor in a third country (e.g. Google LLC) is the importer, SCC Module 3 (Processor-to-Processor) applies, because ReviewMix acts as Processor and the sub-processor as onward processor. ReviewMix additionally signs SCC Module 2 (Controller-to-Processor) with the Controller only where the Controller is established outside the EEA; for EEA-established Controllers no Module 2 SCCs are required.
15. Liability
Liability under this DPA is subject to the limitations in the Principal Agreement, except that nothing in the Principal Agreement or this DPA limits either party's liability under Article 82 GDPR to the extent such limitation would be inconsistent with that Article.
16. Term
This DPA takes effect on the Effective Date and remains in force for as long as the Processor processes personal data on behalf of the Controller, plus any required post-termination retention.
17. Miscellaneous
- Changes. The Processor may update this DPA to reflect changes in applicable law or its processing operations. Material changes will be notified at least 30 days in advance; the Controller may terminate the Principal Agreement without penalty if it objects to a material change.
- Severability. If any provision is unenforceable, the rest remains in effect.
- Governing law. This DPA is governed by the laws of Romania, except that nothing herein displaces the application of GDPR as Union law.
Annex I — Details of processing
Categories of data subjects: Natural persons who submit testimonials via Controller's collection link(s).
Categories of personal data: See Section 3.
Nature and purpose of processing: See Section 3.
Duration of processing: For the duration of the Principal Agreement plus retention period in Section 12.
Sub-processors: See app.reviewmix.eu/legal/subprocessors.
Annex II — Technical and Organizational Measures
Current measures include:
Infrastructure. EU-resident hosting on Hetzner Online GmbH (Germany). Physical and environmental security managed by Hetzner under ISO 27001 certification.
Encryption. TLS 1.2+ for data in transit. Third-party OAuth credentials (Google Business Profile) are encrypted at the application level with AES-256-GCM, so they are never stored in plaintext. GPG encryption for backups before transfer to object storage; backups are encrypted before they leave the host and are never written to object storage in plaintext.
Access control. Magic-link-only authentication for Controller users (no passwords). Opaque, high-entropy session tokens (not JWTs) held server-side as keyed digests and delivered in HttpOnly, Secure, SameSite=Lax cookies. Role-based access in administrative systems. Principle of least privilege. Audit logging of all administrative actions.
Authentication secrets. Magic-link and session tokens are persisted only as keyed HMAC-SHA-256 digests; ReviewMix stores no plaintext credential at any point. Magic-link tokens are single-use, short-lived, and delivered by email.
Rate limiting. Per-endpoint and per-IP rate limits to prevent abuse and enumeration.
Input validation. All API boundaries use schema validation (Zod). File uploads restricted by type, size, and MIME sniffing; re-encoded server-side to remove metadata.
Monitoring. Structured logging. Centralized error capture (GlitchTip, self-hosted). Uptime monitoring. Weekly review of anomalies.
Resilience. Nightly backups retained 30 days. Weekly backups retained 1 year. Backup restore drills at least quarterly.
Incident response. Documented runbooks. 72-hour breach notification procedure. Designated contact: security@reviewmix.eu.
Personnel. Limited to founder at initial stage; all persons with access are contractually bound to confidentiality.
Vendor management. Sub-processors selected for EU residence where possible and bound by DPA. Regular review of sub-processor list.
Minimization. Raw IP addresses retained 30 days then hashed. Logs scrubbed for PII. Data minimization at the product layer (separate consent per use, no collection of fields we don't need).
Annex III — List of sub-processors
Current list maintained at app.reviewmix.eu/legal/subprocessors and in legal/subprocessors.md.
Changelog
- 19 August 2026 — Annex II accuracy corrections. Four published technical measures did not match the implemented system and were corrected to it, and one true measure that had gone unlisted was added (application-level AES-256-GCM encryption of stored Google OAuth credentials): session tokens are opaque and HMAC-digested rather than "encrypted JWT"; magic-link tokens are keyed HMAC-SHA-256 rather than bcrypt; the correlation-ID clause was removed (structured logging ships, correlation IDs do not); and the disk-level encryption claim was removed, no full-disk encryption being in place at this version. Non-material — mechanism descriptions only; no operative determination, obligation or liability changed.
- 2 July 2026 — Editorial: legal-review attributions reworded impersonally; internal review-status note refreshed. Non-material — no operative determination changed.
- 28 June 2026 — Initial publication.