thereviews

Legal

Data Processing Addendum

Effective from 25 September 2026. Version 1.0.

This addendum is between TheReviews, a TJG venture operated by Ikaroa (“we”, the processor) and the business that uses the invitation features of TheReviews (“you”, the controller). Registered address available on request. It forms part of the Terms for Businesses and is written to meet Article 28 of the UK GDPR and the EU GDPR.

1. How this addendum applies

This addendum takes effect the first time you send, queue or upload a review invitation, whether from the dashboard, a CSV file, a store integration or the API. It does not need a signature. If your own policies require a signed copy, email email@thereviews.net and we will return a countersigned PDF of this text with the date. We will not negotiate different terms for standard plans; Enterprise agreements may add to this addendum but not weaken it.

2. Roles

You are the controller of the customer data you give us to invite. You decide who is on the list and you are responsible for having a lawful basis to give it to us for this purpose. We are your processor for that data: we hold it, send the invitation, record whether it was delivered, opened and used, and delete it on the schedule below.

The moment an invited customer clicks through and creates an account with us, we become an independent controller of the account and the review they write, under the Privacy Policy. The review is theirs, licensed to us to display, and this addendum does not give you any rights over it.

We are also an independent controller of the unsubscribe suppression list, because honouring an unsubscribe is our own legal obligation as the sender. That list survives the end of this addendum.

3. Subject matter, duration, nature and purpose

Subject matterCustomer contact records you supply so that we can invite those customers to review your business on TheReviews.
DurationFor as long as you use the invitation features, plus the retention period in section 10.
Nature of the processingStorage; queuing; sending a single invitation email per record through our email provider; recording delivery, open and completion status; expiry after 30 days; deletion.
PurposeTo ask each customer, once, to review the order they placed with you, on your behalf, and to give you counts of how many were sent, opened and completed.

4. Categories of data and data subjects

Data subjects: your customers, being the people who placed an order or otherwise dealt with you and whom you choose to invite.

Categories of personal data: email address; name, if you supply it; an order or booking reference; the order date; the date and status of the invitation (queued, sent, opened, reviewed, expired); and the message-delivery events our email provider reports (delivered, bounced, complained).

Special category data: none. Do not send us any. If a customer record contains health, religious, political, sexual-orientation or similar data, we will delete the record and tell you.

5. Our obligations as processor

We will:

  • process the data only to send invitations and report on them, and only on your documented instructions, which are the invitation features as they work on the day you use them. If we believe an instruction breaks data protection law, we tell you and pause the instruction;
  • make sure the people who can access the data are bound by confidentiality;
  • apply the security measures in section 7;
  • use only the sub-processors in section 6, and tell you before adding one;
  • help you respond to data subject requests, as section 9 describes;
  • help you with data protection impact assessments and consultations with a supervisory authority, where the processing under this addendum is the subject, at no charge for reasonable requests;
  • delete the data at the end of the service, as section 10 describes;
  • give you the information you need to show that we are meeting these obligations, as section 11 describes.

We will not use the customer data to contact your customers for any purpose other than the invitation you asked for and the moderation notices that follow if they write a review. We will not sell it, share it with another business, or use it to build profiles.

6. Sub-processors

You give us general authorisation to use the sub-processors below. Each is bound by a written contract that imposes the same obligations as this addendum.

Sub-processorPurposeLocation
Vercel Inc.Hosting for the application, the dashboard and the API. Short-lived request logs.United States
Neon Inc.Postgres database holding invitation records and their status.United States (region us-east-1 at the time of writing)
Open Doors, operated by Ikaroa on the LeadConnector platformContact storage and sending of invitation and notification emails.United States
Mailgun Technologies, Inc.Mail carrier behind Open Doors: delivery, bounce and complaint handling.United States
Stripe, Inc.Billing for your plan. Stripe does not receive customer data; it is listed because it processes your own billing contact details.United States, with EU entities for EU customers

If we intend to add or replace a sub-processor, we email the organisation owner at least 30 days before the change and update this page. If you object on reasonable data protection grounds and we cannot resolve the objection, you can stop using the invitation features and we delete the data under section 10; that is your only remedy for an objection, and no fees are refunded for it beyond unused whole months of a yearly plan.

7. Security measures

The measures below are in place now. They are described in more detail in the Privacy Policy and are kept current there.

  • All traffic between browsers, our servers, the database and our email provider is encrypted in transit with TLS. The database is encrypted at rest by the provider.
  • Access to the production database and to the email provider is limited to the people who operate the service, each with their own credentials.
  • Invitation tokens are stored only as SHA-256 hashes, are single use, and expire after 30 days. The raw token is held encrypted with AES-256-GCM only until the email is sent.
  • IP addresses and device fingerprints on reviews are stored only as keyed HMAC-SHA256 hashes; the raw values are never written to the database.
  • Dashboard access requires a signed-in user with a role on your organisation. A dashboard page never trusts a business id from the URL without checking that role.
  • API keys are stored hashed and can be revoked at any moment. Outbound webhooks are signed so you can verify their origin.
  • Inbound events from Stripe and store integrations are verified against their signing secrets before anything is written.
  • Every write to a review or invitation status is logged with the actor type and time.
  • Backups are taken by the database provider and roll off within 30 days.

8. Personal data breaches

If we become aware of a personal data breach affecting the data we process for you, we tell the organisation owner by email without undue delay and in any case within 72 hours of becoming aware. The notice says what happened, which categories of data and roughly how many records are affected, what we have done about it, what we recommend you do, and who to contact at our end. If we do not have all of that within 72 hours we send what we have and follow up. We do not tell your customers or a supervisory authority on your behalf unless you ask us to in writing or the law requires it of us as sender.

9. Helping you with data subject requests

If one of your customers asks you for access to, correction of, or deletion of the data we hold under this addendum, email email@thereviews.net with the customer's email address and we act within ten business days. If a customer contacts us directly about an invitation we sent for you, we point them to you, and we act on an unsubscribe immediately without referring it, because that is our obligation as the sender.

Deleting a customer's invitation record does not delete a review they have written, because by then they are our data subject, not yours. They can delete their own review from their account settings at any time.

10. Deletion at the end of the service

Invitation records are deleted 24 months after the send date in the ordinary course. When you close your organisation account, disconnect all invitation channels, or ask us in writing to stop, we delete every invitation record for your businesses within 30 days, including the contact records in Open Doors, and confirm by email. Aggregate counts (how many invitations were sent each month) are kept for the business's statistics and contain no personal data.

Two things are not deleted, and we say so here rather than in a footnote: the unsubscribe suppression list, which we hold as controller so the unsubscribe holds; and any review a customer wrote, which belongs to them. Enterprise agreements may set a shorter retention period than 24 months.

11. Audit

Once in any 12-month period, and additionally after a breach that affected your data, you may audit our compliance with this addendum by sending a written questionnaire to email@thereviews.net. We answer in writing within 30 days and provide supporting evidence where it exists (provider certifications, configuration extracts, the log). An on-site or remote inspection is available only where a supervisory authority requires it or an Enterprise agreement provides for it, on 30 days' notice, during business hours, under confidentiality, and at your cost.

12. International transfers

The sub-processors in section 6 are in the United States. For data about people in the United Kingdom we rely on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; for people in the European Economic Area we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914), module three (processor to processor) between us and each sub-processor, and module two (controller to processor) between you and us, which you and we are taken to have entered into by this addendum with you as data exporter and us as data importer, with the optional docking clause included, the general authorisation option for sub-processors, English law as the governing law and the courts of England and Wales as the forum, and this addendum as the description of the processing. Where a sub-processor is certified under the EU-US Data Privacy Framework or its UK extension, we rely on that in addition. Copies of the clauses we hold with each sub-processor are available on request, with commercial terms redacted.

13. Liability and precedence

The liability cap in section 11 of the Terms for Businesses applies to this addendum. Where this addendum and the Terms for Businesses disagree about the processing of personal data, this addendum wins; where either disagrees with a mandatory provision of the UK GDPR or the EU GDPR, the law wins. This addendum ends when you stop using the invitation features and the deletion in section 10 is complete.

Questions to email@thereviews.net. Every document is listed on the Legal hub.