Legal
Data Processing Agreement
Last updated: July 4, 2026
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Reviewcast (“Processor”) and the customer (“Controller”) and applies wherever Reviewcast processes personal data on the Controller’s behalf in the course of providing the service.
Where the EU or UK General Data Protection Regulation applies, the Controller determines the purposes and means of processing and Reviewcast acts solely as a processor. This DPA takes precedence over any conflicting terms in the main agreement with respect to the processing of personal data.
2. Subject matter, nature and duration
Subject matter and nature: Reviewcast monitors public reviews on the Apple App Store and Google Play and delivers them, together with translation, analytics, alerting, and reply tooling, to the destinations the Controller configures (Slack, Discord, Zendesk, email, and webhooks).
Duration: processing continues for as long as the Controller maintains an active account, and thereafter only as needed to complete deletion or return of data as described below.
3. Categories of data and data subjects
Data subjects: the Controller’s workspace members and administrators, and the authors of public app reviews the Controller chooses to monitor.
Categories of personal data: account and workspace-member data (names, email addresses, authentication identifiers); configuration data; and personal data incidentally contained in public reviews (such as a reviewer’s public username and the free-text content they chose to publish). Reviewcast does not intentionally process special categories of personal data.
4. Processing instructions
Reviewcast processes personal data only on the Controller’s documented instructions — including those given through the product’s configuration — and to provide, secure, and support the service, unless required otherwise by applicable law (in which case Reviewcast will notify the Controller unless legally prohibited).
Reviewcast will inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
5. Confidentiality
Reviewcast ensures that personnel authorized to process personal data are bound by appropriate obligations of confidentiality and are granted access only on a need-to-know, least-privilege basis.
6. Security measures
Reviewcast maintains technical and organizational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; encryption of customer-provided store credentials with AES-256; least-privilege access controls and per-tenant isolation enforced at the database layer; audit logging of sensitive actions; and secret management that keeps credentials out of logs.
A summary of current practices is maintained on the Security page and forms Annex B to this DPA.
7. Subprocessors
The Controller provides general authorization for Reviewcast to engage the subprocessors listed in Annex A below. Reviewcast imposes data protection obligations on each subprocessor that are no less protective than those in this DPA and remains responsible for their performance.
Reviewcast will give the Controller at least 30 days’ notice before adding or replacing a subprocessor, during which the Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected service.
8. International transfers
Where processing involves a transfer of personal data outside the EEA or UK, Reviewcast relies on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference into this DPA.
9. Assistance to the Controller
Taking into account the nature of the processing, Reviewcast will provide reasonable assistance to the Controller in responding to data-subject requests (access, rectification, erasure, portability, restriction, and objection) and in meeting its obligations regarding security, breach notification, and data protection impact assessments.
10. Personal data breach
Reviewcast will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide the information reasonably needed for the Controller to meet its own notification obligations.
11. Deletion and return
On termination or expiry of the account, Reviewcast will delete personal data processed on the Controller’s behalf within 30 days, except to the extent retention is required by law. The Controller may request an export of its data before deletion.
12. Audits
Reviewcast will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality.
13. Annex A — Subprocessors
Supabase — managed PostgreSQL database and authentication hosting.
Render — application and background-worker hosting.
Lemon Squeezy — payment processing and Merchant of Record for paid plans.
DeepL — machine translation of review text.
Anthropic — AI processing for sentiment, topic detection, and reply drafting.
Resend — transactional and digest email delivery.
14. Contact
Questions about this DPA, or requests for a countersigned copy, Annex B, or the applicable Standard Contractual Clauses: privacy@reviewcast.co.