Privacy Policy
Effective date: 28 June 2026 Last updated: 1 October 2026 Controller: Maven Advertising SRL (operating the ReviewMix service), Iași, România; Trade Register (ONRC) no. J2021003339221 · EUID ROONRC.J2021003339221 · CUI (unique registration code) 21027661 · VAT RO46019966
1. Who we are
ReviewMix is a review aggregation and testimonial collection platform operated by Maven Advertising SRL, a limited liability company registered in Romania. We help website owners import Google Business Profile reviews and collect customer testimonials, display them together in a single embeddable widget, while respecting the rights of the people whose data we process.
We are the data controller for personal data relating to:
- Our own customers (people with a ReviewMix account)
- Visitors to our marketing website at reviewmix.eu and our app at app.reviewmix.eu
- People who contact us at support@reviewmix.eu, privacy@reviewmix.eu, or any other ReviewMix email
We act as a data processor on behalf of our customers for personal data relating to:
- People who submit testimonials via a collection link hosted by one of our customers
- People who have posted Google reviews of a customer's business, when that customer has connected their Google Business Profile to ReviewMix
Role split (per qualified legal review, June 2026). For live testimonial data, the customer is the data controller and ReviewMix is strictly a processor under Art. 28 — the customer determines purposes and means; ReviewMix acts on documented instruction. This is not joint controllership. For the consent metadata (the consent ledger: grants, withdrawals, and their technical metadata) that ReviewMix retains after the customer relationship ends, ReviewMix becomes an independent controller strictly for that ledger, processing it to evidence that valid consent existed at the time of collection (defense of legal claims, Art. 6(1)(f)). This is an "Independent Controller Transition" in the sense of EDPB Guidelines 07/2020 — an independent-controller posture, not joint controllership.
2. Contact
- Email: privacy@reviewmix.eu
- Postal: Maven Advertising SRL, Iași, România — the full registered address is on the Romanian trade register under J2021003339221, and we will supply it on request to anyone who needs to write to us on paper
- Data Protection Contact: the founder, reachable at privacy@reviewmix.eu. Following qualified legal review (June 2026), no mandatory Data Protection Officer is triggered under GDPR Art. 37 — ReviewMix's processing does not consist of large-scale regular-and-systematic monitoring or large-scale special-category processing — so the founder acting as the primary data-protection contact is sufficient for v1.
3. What personal data we collect
3.1 When you create a ReviewMix account (we are controller)
- Email address
- Name (optional, provided by you)
- If you choose the optional "Sign in with Google": your Google account email address, display name and Google account identifier, received from Google LLC (US) when you authorize the sign-in — see § 7 on transfers. Signing in by magic link sends nothing to Google.
- Billing information processed via Stripe: name, billing address, VAT number, payment method details (payment method data is held by Stripe, not by us)
- Account activity: widgets created, testimonials approved, logins, plan changes
3.2 When you visit reviewmix.eu or app.reviewmix.eu (we are controller)
- IP address. We process it briefly for security and routing and keep it in raw form for 30 days, then hash it. With analytics consent your IP also reaches PostHog Inc., which derives an approximate country and device type from it and does not store it, and Google LLC on the marketing site. On the marketing site the Google tag's pre-consent measurement pings also carry your IP to Google; see our Cookie Policy.
- User agent string (browser, operating system, device type)
- With analytics consent: pages viewed, referrer, device/browser information, anonymous distinct IDs and session IDs (the dashboard can pick up the PostHog identifier from an earlier reviewmix.eu visit, so both sites can count one browser once), interaction events, and masked session replay through PostHog Inc. on the marketing site and inside the app dashboard; GA4 visitor/session identifiers and usage events through Google LLC on the marketing site. Text you type is masked before replay leaves your browser. On reviewmix.eu, which shows only our own content, other page text is recorded as it appears, except a help-centre search the page repeats back, which stays masked. In the dashboard, page text is masked except our own interface text, which we mark readable one element at a time, so our customers' data and the figures and dates shown from their accounts stay masked; element attributes are also masked, and page addresses and links sent without their query strings. Images are blocked on both sites. We never send PostHog your account identity, name or email address.
- With analytics consent, a small number of events are sent to PostHog Inc. by our servers rather than by your browser, recording that something you did reached a defined point: an account was created, a sign-in completed, a checkout was started, an account closure was requested. (A checkout being started is not a checkout being paid — we record that you reached Stripe, not what happened there.) They carry the same anonymous identifier your browser already uses for analytics, the name of the event and the time it happened. They also carry the analytics library's own technical fields — which library sent the event, its version, and that it came from a server rather than a browser — which describe our software, not you. They never carry your email address, your name, your account identifier, or anything you typed, and because they are sent by our server rather than your browser we switch off the location lookup that would otherwise run, so they carry no country either. Without analytics consent none of them is sent, and none is sent if your browser has no analytics identifier yet: we do not create one to send an event. This is the one kind of analytics that happens on pages where the analytics library itself never runs, such as sign-in and sign-up: we count that the step finished, and record nothing about the page you were on.
- On the marketing site, the Google tag also sends cookieless measurement pings to Google LLC while you have not yet answered the consent banner; analytics cookies require opt-in. Section 4.5 gives our basis for those pings and how to stop them.
3.3 When you submit a testimonial via our customer's collection link (we are processor)
- Name
- Role or job title (optional)
- Company name (optional)
- Email address
- The testimonial text you write
- Photograph (optional, only if you upload one)
- Granular consent records: which uses of your data you have permitted, with timestamp, IP address hash, and the version of the consent text you saw
- The website that invited you (inferred from the widget)
- An optional reference supplied by the business that invited you (for example an order number), carried on the link you followed, showing them which of their requests your testimonial answered — deleted if you ask for your data to be erased
3.4 When you contact us
- Email address and any content you include in your message
3.5 When a site owner has connected a Google Business Profile (we are processor for the site owner)
If you have posted a review of a business on Google, and that business is a ReviewMix customer who has connected their Google Business Profile, ReviewMix may access and cache the following data about your review via Google's API:
- Your display name as it appears on Google
- Your review text (if you included text, not just a star rating)
- Your star rating (1–5)
- A URL to your Google profile photo. The URL is stored. The image itself is hosted by Google and is not stored by us — when your photo is shown in a business's widget, we fetch it from Google on request and serve it from our own servers, so your image is never requested directly from Google by the visitor's browser and Google does not receive that visitor's IP address from the business's website. Where the business uses a consent manager, the photo is shown only to visitors who have consented; other visitors see initials instead and no request is made.
- The date you posted your review on Google
- A URL linking back to your review on Google
This data is publicly available on Google Maps and Google Search. We access it using the business owner's authorized OAuth credentials, store it in EU infrastructure (Hetzner, Germany), and display it in the business owner's widget.
The business owner may also reply to your review from within ReviewMix (added 2026-08-29). Such a reply is composed by the business owner, sent to Google using the owner's authorized credentials, and published by Google on your review under the business's name — exactly as if the owner had replied in Google's own tools. ReviewMix stores a copy of the owner's reply (the owner's content, not yours) alongside the cached review; Google remains the system of record, and a reply edited or deleted on Google replaces our copy at the next refresh.
Following qualified legal review (June 2026): (a) Lawful basis: the business owner's (Controller's) legitimate interest under Art. 6(1)(f) — displaying reviews about their business that reviewers voluntarily posted publicly on Google. Google's Terms of Service grant the Controller the right of access to their own GBP data; they do not themselves supply the GDPR lawful basis. (b) Art. 14 notice: the Art. 14(5)(b) "disproportionate effort" exemption applies to direct reviewer notice for publicly-posted review data; the Controller (the business owner) discloses this processing in their own privacy notice. ReviewMix, as processor, bears no direct Art. 14 obligation toward the reviewer. (c) No direct relationship: there is no direct ReviewMix↔reviewer relationship — the reviewer never interacts with ReviewMix, and ReviewMix does not become a controller toward the reviewer by caching the review on the Controller's instruction.
4. Why we process your data and under what legal basis
4.1 To provide the ReviewMix service to our customers
- Legal basis (account data): performance of our contract with you (GDPR Art. 6(1)(b))
- Legal basis (testimonial submitter data): the customer's contract with the submitter, for which we act as processor under Art. 28
4.2 To process payments
- Legal basis: performance of contract (Art. 6(1)(b)) and compliance with tax law (Art. 6(1)(c))
4.3 To send transactional emails (magic links, confirmations, service notifications)
- Legal basis: performance of contract (Art. 6(1)(b))
4.4 To secure our service (rate limiting, abuse prevention, error monitoring)
- Legal basis: legitimate interest (Art. 6(1)(f)) — our interest in preventing fraud and abuse of the service, balanced against your interest in not being surveilled. We minimize this by hashing IPs after 30 days and scrubbing PII from error logs.
4.5 To understand how our service is used
- Legal basis: consent (Art. 6(1)(a)) for PostHog product analytics and masked session replay, and for GA4 analytics cookies; device storage and access also require consent under Art. 5(3) ePrivacy Directive. The same consent governs the events our servers send: they read the choice stored on your device and send nothing when it is absent or refused. They add no storage of their own, so Art. 5(3) is met by the identifier that is already there rather than by anything new.
- Separate basis for one narrow case: the Google tag's measurement pings while you have not yet answered the banner, described under “When you visit reviewmix.eu or app.reviewmix.eu”. Those store nothing on your device but do carry your IP address and browser information to Google LLC, and our basis for that is legitimate interest (Art. 6(1)(f)) — knowing how many people reach the site and by what route. You can object (Art. 21) by refusing analytics on the banner, which stops them from the next page you load provided your browser lets us store the refusal, and on the page where you refuse as well where we can, or at privacy@reviewmix.eu. We have documented the balancing test behind this and will share its substance on request.
4.6 To comply with legal obligations
- Legal basis: legal obligation (Art. 6(1)(c)) — retention of invoice data under Romanian tax law, preservation of consent records as proof under Art. 7(1), response to lawful requests from supervisory authorities.
4.7 Photographs
Following qualified legal review (June 2026), ordinary photographs (headshots) used for display are not Art. 9 biometric data. Per Recital 51, a photograph becomes biometric special-category data only when processed through specific technical means permitting unique identification (e.g. facial-recognition or algorithmic facial analysis). ReviewMix performs no facial recognition, identification, or algorithmic analysis — a submitter's photo is processed solely for display. Art. 9 sensitive-category rules are therefore not triggered; the photo is processed on the submitter's Art. 6(1)(a) consent for public display.
4.8 To import and cache Google Business Profile reviews on behalf of site owners (as processor)
When a site owner connects their Google Business Profile, we import and cache their Google reviews and include them in their widget.
- Our role: Processor under Art. 28, acting on the site owner's (Controller's) documented instruction.
- Legal basis (for the Controller): the Controller's legitimate interest under Art. 6(1)(f) in displaying reviews about their business that reviewers voluntarily posted publicly on Google (per qualified legal review, June 2026). Google's Terms of Service grant the Controller the right to access their own GBP data; the ToS are the access right, not the GDPR lawful basis. Reviewer notice is met by the Controller's own privacy notice under the Art. 14(5)(b) disproportionate-effort exemption (see Section 3.5); ReviewMix as processor owes no direct Art. 14 obligation to reviewers.
- Data: Review content and associated metadata as described in Section 3.5. We do not process special categories of data from Google reviews.
4.9 To email you reviews, tips and what's new, only if you ask for them
If you tick the box asking for these emails, we send you about one email a month: practical tips on collecting and answering reviews, and news about ReviewMix. These are marketing emails. They are not the same as the service emails described in Section 4.3 — sign-in links, billing notices and similar — which we send because they are necessary to provide the service, and which do not stop if you unsubscribe from this.
- Where you can tick it: on the sign-in and sign-up form, and in your account settings. It is never pre-ticked anywhere, and refusing has no effect on the service or its price
- Legal basis: your consent (Art. 6(1)(a)), recorded with a timestamp and with a version identifying the exact wording you agreed to
- When the consent is recorded: if you tick it on the sign-in or sign-up form, not when you tick the box but when you then open the link we email you — so a tick you never confirm by using that address creates no record at all. If you turn it on in your account settings, where you are already signed in and the address is already confirmed, it is recorded when you save
- Withdrawal: untick the box in your account settings at any time, or use the unsubscribe link in any such email — either takes effect immediately and we keep no record of you on any mailing list afterwards
- Who sends them: Resend, our email provider, listed in our sub-processors
5. How we obtain your consent
For testimonial submitters, we capture separate consent for each use of your data:
- Displaying your name publicly
- Displaying your photograph publicly (only if you uploaded one)
- Displaying your company name publicly
- Using your testimonial in paid marketing or advertising
Each consent is a separate action. You can grant some and refuse others. Every consent is recorded with the exact text you saw, a timestamp, and technical metadata for audit purposes.
You can withdraw any consent at any time via the self-service link emailed to you at submission, at the URL format app.reviewmix.eu/t/<your-token>. Withdrawal takes effect within 60 seconds across every website displaying your testimonial.
6. Who we share your data with
We share personal data only with the sub-processors listed at app.reviewmix.eu/legal/subprocessors:
- Hetzner Online GmbH (Germany) — hosting
- Cloudflare, Inc. (EU edge, US HQ) — DNS, TLS, CDN, security
- Stripe Payments Europe Ltd. (Ireland) — payment processing
- Resend, Inc. (EU routing, US HQ) — transactional email
- Google LLC (Mountain View, California, USA) — Google Business Profile API for connected businesses, optional “Sign in with Google” identity claims, and GA4 marketing-site analytics for visitors, including visitors without an account. GA4 analytics cookies require consent; the tag also sends cookieless measurement pings while a visitor has not yet answered the banner. SCC Module 3 applies to the GBP integration; marketing analytics is a separate controller processing purpose.
- PostHog Inc. (US; EU Cloud, Frankfurt) — not a sub-processor for your data: this is our own analytics about visitors to our sites, listed because we publish every recipient. Consent-required product analytics and masked session replay on our marketing site and inside the app dashboard, identified only by an anonymous, randomly generated identifier that we never link to your account; Standard Contractual Clauses Module 2 (Controller-to-Processor) cover the transfer. Most of this is sent by your browser; a small number of events about steps you completed are sent by our servers, on the same consent and under the same anonymous identifier.
Each sub-processor is bound by a Data Processing Agreement with us. We do not sell your data. We do not share your data with advertisers or data brokers.
7. International data transfers
ReviewMix's infrastructure is in Germany (Hetzner Frankfurt). Your core data — account information, testimonials, consent records, photographs — is stored in the EU and processed in the EU.
The recipients that involve a transfer outside the EEA are these, and the list is the same one published in our sub-processor register: Cloudflare (US parent), Resend (US parent), Stripe (its EU entity may share data with Stripe, Inc. in the US), Google LLC (for the Google Business Profile API, the optional Google sign-in, and marketing-site Google Analytics), and PostHog Inc. (a US company; the data itself is stored in Frankfurt). For the Google GBP API specifically, ReviewMix's EU servers fetch review data from Google's US API endpoints and immediately store it in EU Postgres — no review data is retained outside the EU. Where data is transferred outside the EU:
- We rely on EU Standard Contractual Clauses (SCCs) as the transfer mechanism
- We rely on supplementary measures (encryption in transit and at rest, minimization of data transferred) to address Schrems II concerns
- Our Transfer Impact Assessments are available on request to customers via privacy@reviewmix.eu
Following qualified legal review (June 2026), the combination of Module 3 Standard Contractual Clauses (Processor-to-Processor) for the ReviewMix→Google LLC GBP transfer, plus data minimization (only the business owner's own publicly-posted GBP review content is fetched) and encryption (in transit and at rest), constitutes a defensible Transfer Impact Assessment posture under current EDPB guidance. Module 3 applies because ReviewMix (the customer's processor) transfers to Google LLC (a further processor); Module 2 (Controller-to-Processor) would apply only where the Customer itself is established outside the EEA.
That assessment was made for the GBP integration and covers it alone. For website analytics ReviewMix is the controller, not a processor, and the transfers to Google LLC and PostHog Inc. for that purpose rest on their own agreements and on your consent; they do not inherit the GBP assessment above.
8. How long we keep your data
| Data | Retention |
|---|---|
| Active ReviewMix account | While your account is open |
| Closed ReviewMix account | 30 days (recovery window), then deleted |
| Testimonial content (PII) | Removed from public display within 60 seconds of consent withdrawal or testimonial withdrawal; the content is then retained unpublished — you can re-engage later or erase it irreversibly at any time via your self-service link. Deleted on account closure. |
| Consent ledger (metadata: grants, withdrawals, technical metadata) | 3 years after the account/customer relationship ends, then deleted (Art. 6(1)(f) — defense of legal claims; Romanian Civil Code Art. 2517 general 3-year limitation period) |
| Invoice and tax data | 10 years under Romanian tax law |
| Audit log of account and admin actions | 7 years |
| Session tokens | Session lifetime + 90 days |
| Magic-link tokens | 24 hours after expiry |
| Raw IP addresses | 30 days, then hashed |
| Application logs | 30 days |
| Error reports (GlitchTip) | 90 days |
| PostHog analytics events and session replay, including the events our servers send; Google Analytics user and event data | Retained by each provider under the retention period configured on our account; the durations of the identifiers stored in your own browser are listed in our Cookie Policy. |
| Backups | Daily: 30 days. Weekly: 1 year. Quarterly cold: 7 years. |
When you withdraw consent for displaying a testimonial, it is hidden from public display within 60 seconds. The testimonial content itself is not deleted by withdrawal — it is retained unpublished so you can re-engage later (editing re-submits it for approval), and you can erase it irreversibly at any time using the erasure option at your self-service link. The consent grant and withdrawal metadata (not the testimonial content itself) is retained for 3 years as described in the table above, so we can evidence that valid consent existed at the time of collection. The 3-year period reflects the general limitation period for legal claims under Romanian Civil Code Art. 2517, balanced as a legitimate interest under Art. 6(1)(f). After the customer relationship ends, ReviewMix holds this consent ledger as an independent controller strictly for that compliance-proof purpose (see Section 1).
9. Your rights
Under GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten") — request deletion, subject to our legal retention obligations
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — at any time, without affecting the lawfulness of prior processing
To exercise any right, email privacy@reviewmix.eu. We respond within 30 calendar days.
Testimonial submitters have immediate self-service for most of these rights at the app.reviewmix.eu/t/<your-token> link emailed to them at submission.
You also have the right to lodge a complaint with a supervisory authority. In Romania, this is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, București Telefon: +40.318.059.211 / +40.318.059.212 Email: anspdcp@dataprotection.ro Web: www.dataprotection.ro
If you are located in another EU member state, you may also contact your local supervisory authority.
10. Cookies and tracking
We use cookies and similar technologies described in detail in our Cookie Policy.
In summary:
- Strictly necessary cookies — always active: session cookie, CSRF token, consent preference cookie
- Functional cookies — only with consent. We set no optional preference cookies; two cookies that remember a choice you made in the dashboard are listed as strictly necessary in the Cookie Policy, together with the dashboard's browser local-storage entries for dismissed notices and for work you have not finished (an unsent reply, unsaved widget settings, onboarding choices, printables options), which stay on your device. The functional choice controls the functionality and personalisation signals passed to Google Analytics
- Analytics cookies — with consent: PostHog Inc. (EU Cloud, Frankfurt) for product analytics and masked session replay on reviewmix.eu and inside the app dashboard at app.reviewmix.eu, and Google LLC for GA4 on reviewmix.eu. The Google tag's cookieless measurement pings, sent only while you have not yet answered the banner, are described under “When you visit reviewmix.eu or app.reviewmix.eu”.
- Not a cookie, but part of the same choice — with analytics consent our servers send PostHog a small number of events recording that a step you took finished. They store nothing on your device and read only the analytics choice and the anonymous identifier that are already there; refusing analytics stops them.
- Advertising cookies — we do not use any. The banner offers the category and records your answer; the advertising permissions we pass to Google are refused for everyone regardless
You can change or withdraw your choices at any time from the floating cookie button on reviewmix.eu, which reopens the banner. The app at app.reviewmix.eu reads the same choice, shows the same banner only when no choice is stored on your device, and Cookie settings in the dashboard's account menu changes or withdraws it there.
11. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning you.
12. Children's data
ReviewMix is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, contact privacy@reviewmix.eu and we will delete it.
The minimum age for valid digital consent in Romania is 16, set by Law 190/2018 (Romania's GDPR implementing law, which adopts the Art. 8(1) default of 16), as confirmed by qualified legal review (June 2026). Below 16, a holder of parental responsibility must consent.
13. Data security
We protect your data with, among other measures:
- TLS encryption for all traffic
- Your Google connection credentials stored encrypted, never in plain text
- Strict access controls (only the founder and future authorized personnel access production data, and only with audit logging)
- Rate limiting and automated abuse detection
- Magic-link-only authentication (no passwords to be stolen)
- Regular backups, encrypted and stored separately
- Annual review of security practices
No system is perfectly secure. We describe our incident response procedure in Section 14.
14. Data breach notification
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority (ANSPDCP) within 72 hours of becoming aware
- Notify you directly without undue delay if the breach is likely to result in high risk to you
- Publish a public statement when appropriate
15. Changes to this policy
We may update this policy. Material changes will be notified to active customers by email at least 30 days before taking effect. The current version is always at app.reviewmix.eu/legal/privacy-policy. A changelog of updates is maintained at the bottom of this page.
16. Governing law
This policy is governed by the laws of Romania and the European Union. Disputes are subject to the jurisdiction of the courts of Iași (the registered seat of Maven Advertising SRL). This forum clause does not override the mandatory right of a consumer to bring proceedings in, or be sued only in, the courts of their own place of domicile under applicable EU consumer-protection rules (Brussels I bis Regulation, Art. 17–19) — the consumer home-forum right is preserved.
Changelog
- 1 October 2026 — Section 10 now also points to the dashboard's browser local-storage entries listed in the Cookie Policy: dismissed notices, and drafts of work you have not finished, kept on your device and deleted when you finish, discard or sign out, or after 7 days (onboarding 24 hours). Nothing is sent to us or to anyone else. Non-material: no new purpose, no new recipient. The draft entries take effect when deployed.
- 27 September 2026 — Section 4.9 pointed to the wrong section for the service emails: it said Section 4.2, which is about payments; they are described in Section 4.3. The reference is corrected. Nothing about what we send, or why, changes.
- 19 September 2026 — Section 4.9 corrected on one point of timing. Since 18 September it has said, of both places you can tick the box, that the consent is recorded only when you open the link we email you. That is true of the sign-in and sign-up form. It was never true of account settings, where you are already signed in and your address is already confirmed, and the change takes effect when you save it. The text now says so for each place separately. Nothing about what we send, to whom, or how you withdraw has changed; this corrects a description of our own system that was wider than the system. It takes effect when deployed.
- 18 September 2026 — Section 4.9 rewritten for the marketing emails. The ask now appears on the sign-in and sign-up form as well as in account settings, and what it asks for is stated more broadly and more plainly: about one email a month with tips on collecting and answering reviews, and ReviewMix news. Three things are newly stated rather than newly done — that these are marketing emails and are separate from the service emails in Section 4.2, which keep coming either way; that the consent is recorded with a version identifying the exact wording agreed to; and that Resend sends them, as our sub-processor list already said. One thing is genuinely new and in your favour: the consent is recorded only when you open the link we email you, so a box ticked and never confirmed from that address creates no record. The previous text described a narrower "product updates" mailing collected only in account settings. No new recipient. It takes effect when deployed.
- 12 September 2026 — With analytics consent, a small number of events are now sent to PostHog by our servers as well as by your browser, recording that a step finished: an account created, a sign-in completed, a checkout started, an account closure requested. They carry the anonymous identifier your browser already uses, the event name, the time, and the analytics library's own technical fields describing the sending software — no email address, no name, no account identifier, nothing you typed, and no country, because the location lookup is switched off for them. Nothing is sent without analytics consent, or if your browser has no analytics identifier yet. This is the first analytics that happens on pages where the analytics library itself never runs, such as sign-in and sign-up; what is recorded there is that the step finished, not anything about the page. No new recipient and no new storage on your device. It takes effect when deployed.
- 11 September 2026 — Session replay records the text of our own pages: on reviewmix.eu as it appears, with typed text and a repeated help-centre search masked; in the dashboard only the interface text we mark readable, with our customers' data, the figures and dates shown from their accounts, and element attributes masked; images blocked on both sites. Also corrected: a star rating chosen when adding a testimonial by hand in the dashboard was recorded, contrary to this policy; that control is now excluded from replay. Non-material: no new purpose, no new recipient, and the newly readable text is our own content. It takes effect when deployed to each site.
- 10 September 2026 (second entry) — The app dashboard now shows the consent banner when no choice is stored on your device, instead of relying on a choice made on reviewmix.eu that customers who sign up directly, or use a new device or a private window, never made. A stored choice is still never asked for again. Also stated: the dashboard can reuse the anonymous PostHog identifier from an earlier reviewmix.eu visit, as it could since PostHog reached the dashboard. No new purpose, no new recipient. The banner takes effect when deployed to the app.
- 10 September 2026 — PostHog analytics and masked replay extended to the app dashboard, on the analytics choice already made on reviewmix.eu, with Cookie settings in the dashboard's account menu to change or withdraw it. Dashboard replay also blocks images and masks element attributes, and page addresses and links are sent without query strings, because those pages show our customers' own data. Non-material: no new recipient, and nobody is measured who has not already opted in. It takes effect when deployed to the app.
- 9 September 2026 — Analytics reversal: legitimate interest (Art. 6(1)(f)) named for the Google tag's pre-consent measurement pings, with the Art. 21 objection route beside it; consent-based PostHog Cloud EU analytics and masked replay, retained marketing-site GA4, recipient and transfer disclosures, and analytics withdrawal controls. GA4 cookieless pings are distinguished from consent-required storage. Also removes a Do Not Track / Global Privacy Control commitment and a functional-cookie description that the service never implemented. A cookie-settings control inside the app is added when analytics reaches the app.
- 19 August 2026 — §13 accuracy corrections: removed the "encrypted storage at the disk level" measure, which did not match the implemented system (no full-disk encryption is in place at this version), and added the application-level encryption of stored Google connection credentials, which does exist and had gone unlisted. Companion to the same-day Annex II corrections in the DPA. Non-material — mechanism descriptions only; no operative term changed.
- 13 August 2026 — Added §4.9 (product-update emails, consent-based, one-click unsubscribe), published together with the feature it describes. Additive disclosure of a new opt-in processing purpose; no existing term changed.
- 2 July 2026 — Editorial: legal-review attributions reworded impersonally throughout; internal review-status note refreshed. Non-material — no operative determination changed.
- 28 June 2026 — Initial publication.