Article 28 GDPR processor terms
Data Processing Agreement
- Effective:
- July 10, 2026
- Last updated:
- July 10, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Primanza LLC, doing business as ReplyTune ("Processor", "we"), and the customer that accepts the Terms ("Controller", "you"). It governs our processing of personal data on your behalf and applies to the extent such processing is subject to the GDPR, the UK GDPR, the Swiss FADP, the CCPA/CPRA or another applicable data-protection law ("Data Protection Laws").
Where you are established in, or your processing is subject to the laws of, the EEA, UK or Switzerland, this DPA is binding without separate signature upon your acceptance of the Terms. If you require a countersigned copy, contact privacy@primanza.com. In case of conflict on data-protection matters, this DPA prevails over the Terms.
Contents
- 01Definitions
- 02Roles and Scope of Processing
- 03Processing on Documented Instructions
- 04Confidentiality of Personnel
- 05Security Measures
- 06Sub-processing
- 07Assistance with Data Subject Rights
- 08Personal Data Breach Notification
- 09Data Protection Impact Assessments
- 10International Transfers
- 11Return and Deletion
- 12Audits and Information
- 13CCPA/CPRA Service Provider Terms
- 14Liability and Order of Precedence
- 15Annex I — Description of Processing
- 16Annex II — Technical and Organizational Measures
- 17Annex III — List of Sub-processors
01Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Standard Contractual Clauses" or "SCCs" means the clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner. "Customer Personal Data" means personal data contained in Customer Data that we process on your behalf.
02Roles and Scope of Processing
As between the parties, you are the controller (or a processor acting on behalf of another controller) and we are the processor of Customer Personal Data. Each party will comply with its obligations under Data Protection Laws. The subject matter, nature, purpose and duration of the processing, and the categories of data subjects and personal data, are described in Annex I.
You warrant that you have a valid legal basis and all necessary rights, notices and consents to provide Customer Personal Data to us and to instruct the processing described here, including in relation to the authors of reviews, and that your instructions comply with Data Protection Laws.
03Processing on Documented Instructions
We will process Customer Personal Data only on your documented instructions, including as set out in the Terms, this DPA and your configuration and use of the Service, unless required to do otherwise by law to which we are subject (in which case we will inform you unless the law prohibits it on important grounds of public interest). We will immediately inform you if, in our opinion, an instruction infringes Data Protection Laws. We will not sell Customer Personal Data or process it for our own purposes.
04Confidentiality of Personnel
We ensure that persons authorized to process Customer Personal Data are subject to an appropriate duty of confidentiality and process the data only as instructed. We limit access to those who need it to provide the Service.
05Security Measures
We implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects. We may update these measures provided the level of protection is not materially reduced.
06Sub-processing
You provide general authorization for us to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed at /subprocessors. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
We will give you at least 30 days' notice (by updating the Sub-processors page and, where you subscribe to notifications, by email) before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period by writing to privacy@primanza.com. If we cannot reasonably accommodate your objection, you may, as your sole remedy, terminate the affected part of the Service and receive a pro-rata refund of prepaid, unused fees.
07Assistance with Data Subject Rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If we receive such a request directly, we will, unless legally prohibited, promptly inform you and direct the data subject to you, and we will not respond except on your instruction.
08Personal Data Breach Notification
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. We will reasonably assist you in meeting your own breach-notification and communication obligations.
09Data Protection Impact Assessments
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to help you carry out data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 of the GDPR.
10International Transfers
Where our processing of Customer Personal Data involves a transfer from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you act as a processor for another controller.
- In Clause 7, the optional docking clause applies. In Clause 9, Option 2 (general written authorization) applies with the 30-day notice period in Section 6 of this DPA.
- In Clause 11, the optional independent-dispute-resolution language does not apply.
- In Clause 17, the SCCs are governed by the law of Ireland; in Clause 18, disputes are resolved before the courts of Ireland (or, where you are in the EEA, the courts of your member state where permitted).
- Annexes I, II and III of this DPA populate the corresponding annexes of the SCCs.
For transfers subject to the UK GDPR, the UK Addendum is incorporated and completed using the information in the Annexes, with Primanza LLC as the data importer. For transfers subject to the Swiss FADP, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority. Where a sub-processor is certified under the EU-U.S. Data Privacy Framework, we may rely on that mechanism for the relevant transfer.
11Return and Deletion
On termination of the Service, and at your choice, we will delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. Deletion of Customer Personal Data following account deletion occurs within 30 days, subject to expiry of routine backups on a rolling basis during which the data remains protected and inaccessible for other processing.
12Audits and Information
We will make available information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To protect the security and confidentiality of our environment and other customers, audits will: be limited to no more than once per year (unless required by a supervisory authority or following a breach); be subject to reasonable prior notice and confidentiality; be conducted during business hours without unreasonable disruption; and be satisfied first by our provision of relevant documentation, certifications and reports where these reasonably address your request.
13CCPA/CPRA Service Provider Terms
Where we process personal information subject to the CCPA/CPRA on your behalf, we act as a service provider. We will: process such personal information only to perform the Service under the Terms and this DPA and for no other purpose; not sell or share it; not retain, use or disclose it outside the direct business relationship or for any purpose other than the specified business purposes; not combine it with personal information from other sources except as permitted by the CCPA/CPRA; and comply with applicable obligations. We certify that we understand and will comply with these restrictions. You may take reasonable steps to ensure we use personal information consistently with your obligations.
14Liability and Order of Precedence
Each party's liability under this DPA and the SCCs, taken together, is subject to the limitations and exclusions of liability in the Terms of Service, to the extent permitted by applicable law. Nothing in this Section limits any party's liability to data subjects under the SCCs or Data Protection Laws. If there is a conflict, the SCCs prevail over the rest of this DPA for the transfers they govern, and this DPA prevails over the Terms on data-protection matters.
15Annex I — Description of Processing
A. Parties
Data exporter / controller: the Customer identified in the Account. Data importer / processor: Primanza LLC, doing business as ReplyTune. Contact: privacy@primanza.com.
B. Categories of data subjects
- The Customer's authorized users and personnel.
- Authors of reviews of the Customer's business locations (reviewers).
- Individuals mentioned in review text or brand configuration.
C. Categories of personal data
- Account and identity data of authorized users (name, email, hashed credentials, profile image).
- Reviewer data synchronized from Google Business Profile: display name, profile photo, star rating, review text and language, and reply history.
- Business and brand configuration data that may contain personal data if the Customer enters it.
D. Special categories of data
Not intended to be processed. The Service is not designed for special-category data. If a reviewer includes such data in free text, it is processed only incidentally as part of the review, at the Customer's instruction and responsibility.
E. Nature and purpose of processing
Hosting and storage; synchronization of reviews from Connected Platforms; AI-based sentiment analysis and drafting of replies; publication of replies at the Customer's election; generation of insight reports; provision of support and security. The purpose is to provide the Service described in the Terms.
F. Frequency and duration
Continuous for the duration of the Customer's subscription; deletion occurs within 30 days of account deletion, subject to legal retention and routine backup cycles.
G. Sub-processors
As listed at /subprocessors, for the purposes and durations stated there.
16Annex II — Technical and Organizational Measures
- Encryption: personal data encrypted in transit using TLS; credentials stored as salted hashes; connection secrets protected against unauthorized access.
- Access control: role-based access on a least-privilege, need-to-know basis; unique credentials; administrative access restricted and monitored.
- Pseudonymization / minimization: collection limited to what is necessary; AI processing uses only the context needed to generate replies; no use of review or reply content to train generative models.
- Resilience and availability: hosting on reputable cloud infrastructure with redundancy and routine backups; measures to restore availability after an incident.
- Network and application security: logical separation of tenants; input validation; protection of API keys and webhooks; secure software-development practices.
- Logging and monitoring: security logging, monitoring for anomalous activity, and retention of logs appropriate to the risk.
- Incident response: documented procedures for detecting, reporting and responding to personal data breaches, including notification to controllers.
- Vendor management: due diligence and contractual data-protection terms with sub-processors.
- Personnel: confidentiality obligations and security-awareness expectations for staff and contractors.
- Deletion: processes to delete or de-identify personal data on termination within the stated window.
These measures reflect the current design of the Service and may be updated as the Service evolves, provided the overall level of protection is not materially reduced.
17Annex III — List of Sub-processors
The authorized sub-processors, their processing purpose, data categories, locations and transfer safeguards are maintained on the Sub-processors page, which forms part of this Annex and is updated in accordance with Section 6.
This DPA is provided by Primanza LLC as part of the ReplyTune Terms of Service. For a signed counterpart or enterprise addendum, contact privacy@primanza.com.