Legal

Data Processing Agreement

Effective · May 1, 2026Jurisdiction · EEA / UKVersion · 4.0

The plain-language version

  • ·For your review and reply data you are the Controller and we are the Processor, acting on your instructions.
  • ·For your own account, billing and product-usage data we are an independent Controller — see the Privacy Policy.
  • ·Sub-processors are listed in section 4. 14-day notice before any new one.
  • ·Security measures and audit rights are in sections 5 and 6.
  • ·This DPA is incorporated by reference into the main Terms of Service.

This summary is for convenience. The legal terms below are what actually govern your use of the service.

1.Parties and scope

This Data Processing Agreement (the “DPA”) supplements the ReviewBox Terms of Service between AT WORK Inc, trading as ReviewBox, a partnership firm constituted under the Indian Partnership Act, 1932 in India (the “Processor”), and the customer (the “Controller”).

It applies whenever the Processor processes personal data on behalf of the Controller in the EEA, UK, or Switzerland.

Categories of data subjects: end users of Controller's mobile applications (review authors). Categories of personal data: review content, author handles, device/locale metadata, ratings.

2.Roles and responsibilities

Controller determines the purposes and means of processing. Processor processes Customer Data only on documented instructions from Controller, except as required by law.

Processor shall promptly inform Controller if, in its opinion, an instruction infringes applicable data protection law.

3.Confidentiality

Processor ensures persons authorised to process Customer Data are bound by confidentiality (employment contract, NDA) and are limited to those who need access to perform the services.

4.Sub-processors

Controller grants general authorisation for the sub-processors listed at /sub-processors. Processor notifies Controller of any intended new sub-processor at least 14 days in advance; Controller may object on reasonable grounds.

The authoritative list is the /sub-processors page. It currently includes Supabase (database), Clerk (authentication), Stripe (billing), Groq (AI inference, no data retention), Google (AI inference), Resend (email), PostHog (analytics), Upstash (rate limiting).

5.Security measures

Processor implements and maintains the following technical and organisational measures:

  • Encryption of Customer Data in transit using TLS, and at rest by the database provider.
  • Tenant isolation enforced by row-level security policies in the database, so a workspace can access only its own records.
  • Access to production systems limited to personnel who require it, protected by multi-factor authentication.
  • Credentials held in environment configuration and not committed to source control.
  • Audit logging of privileged mutations within the application.

Processor does not currently hold SOC 2, ISO 27001 or an equivalent certification and makes no representation that it does. Where a certification is obtained, this Addendum will be updated to identify it and the issuing auditor.

6.Audit rights

Processor makes available to Controller the information reasonably necessary to demonstrate compliance with this Addendum, and responds to reasonable security questionnaires. Processor holds no third-party audit report at present, so none is offered; if one is obtained it will be made available on request under NDA.

Controller may conduct an audit no more than once per calendar year, on 30 days' notice, during business hours and at Controller's expense, subject to confidentiality obligations.

7.International transfers

Processor is established in India, which is not the subject of a European Commission adequacy decision, and engages sub-processors established outside the EEA. Customer Data protected by the GDPR is therefore transferred internationally.

Where Customer Data protected by the GDPR is transferred to Processor, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply, with Module Two (controller to processor) governing the transfer between Controller and Processor, and Module Three (processor to processor) governing onward transfers to Processor's sub-processors. For transfers from the United Kingdom, the ICO's International Data Transfer Addendum to those Clauses applies; for Switzerland, the Clauses apply with the amendments required by Swiss law.

Controller's acceptance of this Addendum constitutes execution of the applicable Clauses. The details required by their annexes — the parties, the categories of data subjects and personal data, the purposes of processing, the retention period, the technical and organisational measures, and the list of sub-processors — are those set out in this Addendum and on our Sub-processors page. A countersigned copy of the Clauses is available on request from privacy@tryreviewbox.com.

8.Personal-data breach notification

Processor notifies Controller without undue delay (and in any event within 72 hours of becoming aware) of a personal data breach, including the nature of the breach, affected data subjects, likely consequences, and mitigation steps.

Processor maintains a register of all personal data breaches, whether or not notification is required, and makes it available to Controller on request.

9.Data return and deletion

Upon termination of the agreement or Controller's written request, Processor will delete or return all Customer Data within 30 days, at Controller's choice, and provide written certification of deletion.

Processor may retain Customer Data where required by applicable law, for the minimum period required, and will inform Controller of any such retention.

10.Liability

Each party's liability under this DPA is subject to the limitations set out in the main Terms of Service, except to the extent that applicable law prohibits such limitations in the context of data protection obligations.

Questions about this DPA? legal@tryreviewbox.com

AT WORK Inc, trading as ReviewBox · Registered in India · legal@tryreviewbox.com