Data Processing Agreement
Last updated: September 4, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written or electronic agreement between ReputationGauge, Inc. ("ReputationGauge","we", "us", or "our") and the customer entity identified in the applicable order ("Customer" or "you") for the use of the ReputationGauge platform and related services (collectively, the "Services").
By accessing or using the Services, you agree to be bound by this DPA. This DPA is incorporated into and subject to the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA will govern with respect to data processing matters.
1. Definitions
For the purposes of this DPA, the following terms have the meanings set out below:
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by ReputationGauge on behalf of the Customer as part of providing the Services.
- "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
- "Data Controller" means the Customer, who determines the purposes and means of processing Personal Data.
- "Data Processor" means ReputationGauge, which processes Personal Data on behalf of the Customer pursuant to this DPA.
- "Sub-processor" means any third-party processor engaged by ReputationGauge to process Personal Data on behalf of the Customer.
- "Data Subject" means the individual to whom Personal Data relates.
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including but not limited to the GDPR, CCPA, and any national implementing legislation.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
2. Scope and Roles
This DPA applies where and to the extent that ReputationGauge processes Personal Data on behalf of the Customer in connection with the provision of the Services. The Customer acts as the Data Controller and ReputationGauge acts as the Data Processor with respect to such Personal Data.
The subject matter, nature, purpose, and duration of processing, as well as the types of Personal Data and categories of Data Subjects, are described in Schedule A (Processing Details) appended to this DPA. Processing is carried out solely for the purpose of providing, maintaining, and improving the Services as described in the Terms of Service.
3. Processor Obligations
ReputationGauge shall, with respect to Personal Data processed under this DPA:
- Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by applicable law.
- Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Section 6.
- Respect the conditions for engaging Sub-processors as set out in Section 4.
- Assist the Customer, insofar as possible, with fulfilling the Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
- Assist the Customer in ensuring compliance with obligations relating to security of processing, data breach notification, data protection impact assessments, and prior consultation.
- At the Customer's choice, delete or return all Personal Data to the Customer after the end of the provision of Services, and delete existing copies unless applicable law requires storage.
- Make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits as set out in Section 10.
4. Sub-processors
The Customer provides general authorisation for ReputationGauge to engage Sub-processors to assist in providing the Services. ReputationGauge shall maintain an up-to-date list of its Sub-processors, which is available upon written request. Before engaging any new Sub-processor or replacing an existing one, ReputationGauge will provide the Customer with prior written notice (at least 30 days in advance) so that the Customer may object.
Where ReputationGauge engages a Sub-processor, ReputationGauge shall impose data protection obligations on that Sub-processor that are no less protective than those set out in this DPA. ReputationGauge remains fully liable to the Customer for the performance of the Sub-processor's obligations.
5. Data Subject Rights
ReputationGauge shall promptly notify the Customer if it receives a request from a Data Subject in relation to Personal Data processed under this DPA. ReputationGauge shall not respond to such a request directly without the Customer's prior written authorisation, unless required to do so by applicable law. ReputationGauge will provide reasonable assistance to the Customer to enable the Customer to fulfil its obligations under Applicable Data Protection Law with respect to:
- Rights of access, rectification, erasure, and portability.
- Rights to restriction of and objection to processing.
- Rights related to automated decision-making and profiling.
6. Security Measures
ReputationGauge shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data. These measures include, at a minimum:
- Encryption of Personal Data in transit and at rest using industry-standard protocols.
- Regular testing, assessment, and evaluation of the effectiveness of security measures.
- Access controls and authentication mechanisms to ensure only authorised personnel can access Personal Data.
- Pseudonymisation and anonymisation techniques where feasible and appropriate.
- Physical and environmental security controls for infrastructure hosting Personal Data.
- Employee training on data protection and security practices, including confidentiality obligations.
- Business continuity and disaster recovery plans tested on a regular basis.
7. Data Breach Notification
In the event of a confirmed Personal Data breach, ReputationGauge shall notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Such notification shall, to the extent then known, include:
- A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned.
- The name and contact details of ReputationGauge's data protection contact.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
ReputationGauge shall co-operate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of each such Personal Data breach. Notification of a breach does not constitute an acknowledgement of fault or liability.
8. International Data Transfers
ReputationGauge may transfer Personal Data to countries outside the European Economic Area ("EEA") or the United Kingdom only where an appropriate safeguard is in place, including:
- An adequacy decision by the European Commission or the UK Secretary of State confirming that the recipient country ensures an adequate level of protection.
- Standard Contractual Clauses ("SCCs") as approved by the European Commission (or equivalent UK mechanisms), which are hereby incorporated into this DPA by reference where required.
- Other valid transfer mechanisms permitted under Applicable Data Protection Law.
Where SCCs apply, they shall be deemed entered into by the parties and supplemented by any applicable transfer impact assessment or supplementary measures required to ensure the SCCs provide essentially equivalent protection.
9. Deletion and Return of Personal Data
Upon termination or expiry of the Services, or upon written request from the Customer, ReputationGauge shall, at the Customer's election:
- Return to the Customer a complete copy of all Personal Data in a machine-readable format within 30 days; and/or
- Securely delete and destroy all Personal Data (including copies) within 30 days, and provide written confirmation of deletion upon the Customer's request.
ReputationGauge may retain Personal Data to the extent required by applicable law, provided that ReputationGauge ensures the confidentiality of such Personal Data and does not process it for any other purpose.
10. Audits and Inspections
ReputationGauge shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. ReputationGauge shall permit the Customer (or its designated third-party auditor) to conduct audits or inspections of ReputationGauge's processing activities, subject to the following conditions:
- The Customer provides at least 30 days' prior written notice of the intended audit, except where required by a supervisory authority or following a confirmed data breach.
- Audits are conducted during normal business hours and do not unreasonably disrupt operations.
- Third-party auditors must execute a confidentiality agreement reasonably acceptable to ReputationGauge before conducting an audit.
- Audit costs (including any ReputationGauge staff time) shall be borne by the Customer unless the audit reveals a material breach by ReputationGauge of this DPA.
ReputationGauge may satisfy audit obligations by providing current third-party audit reports (e.g. SOC 2 Type II, ISO 27001) in lieu of permitting an on-site audit, subject to the Customer's reasonable acceptance.
11. Liability
Each party's liability under this DPA shall be subject to the exclusions and limitations of liability set out in the Terms of Service. Where both parties are responsible for damage caused by a breach of this DPA or Applicable Data Protection Law, each party shall be liable for the part of the damage for which it is responsible.
To the fullest extent permitted by law, ReputationGauge's aggregate liability to the Customer under or in connection with this DPA shall not exceed the amounts paid or payable by the Customer to ReputationGauge in the twelve (12) months immediately preceding the event giving rise to the claim.
12. Term and Termination
This DPA shall remain in force for the duration of the Services provided under the Terms of Service. Termination or expiry of the Terms of Service shall automatically terminate this DPA, subject to the survival of any obligations that by their nature should survive, including obligations relating to confidentiality, security, and deletion of Personal Data.
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. Any amendment or modification to this DPA must be made in writing and signed by authorised representatives of both parties.
Schedule A — Processing Details
Subject Matter
ReputationGauge processes Personal Data to provide its review management, monitoring, and customer feedback platform to the Customer.
Duration
For the duration of the Services as specified in the applicable order, plus any retention period required by applicable law.
Nature and Purpose of Processing
- Collecting and aggregating online reviews and ratings on behalf of the Customer.
- Sending review request communications to the Customer's end-customers.
- Providing analytics and reporting dashboards to the Customer.
- Storing and displaying review content for reputation management purposes.
Types of Personal Data
- Contact information (name, email address, phone number).
- Review content submitted by or about Data Subjects.
- Business interaction data (purchase history, service records as provided by Customer).
- Device and usage data (IP addresses, browser type, interaction logs).
Categories of Data Subjects
- The Customer's end-customers and business contacts.
- Reviewers and respondents who interact with review request communications.
- The Customer's employees or authorised users of the platform.
Questions about this Data Processing Agreement? Contact us at support@reputationgauge.com
Back to Home