ReplyTune legal
Data Processing Addendum
- Version
- 1.0
- Effective
- October 4, 2026
This Data Processing Addendum ("DPA") is part of the agreement between Primanza LLC ("ReplyTune," "we") and the business that uses the ReplyTune service ("Customer," "you"), as defined in the Terms of Service. It governs our processing of Customer Personal Data and controls over the Terms of Service if the two conflict on that subject.
01Definitions
- Customer Personal Data means personal information that we process on Customer's behalf in providing the Service, mainly the personal information in Google reviews of Customer's locations and in the replies to them.
- Privacy Laws means the U.S. federal and state laws on privacy and data protection that apply to the processing of Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and comparable state laws.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Business," "controller," "service provider," "contractor," "processor," "consumer," "sell," "share" and "deidentified" have the meanings given in the applicable Privacy Laws. Other capitalized terms have the meanings given in the Terms of Service.
02Roles of the parties
For Customer Personal Data, Customer is the business or controller, and we are its service provider or processor. We process Customer Personal Data only on Customer's behalf and only for the business purpose of providing the Service. Our handling of the personal information of Customer's own account users, as a business in our own right, is described in our Privacy Policy.
03Details of the processing
| Topic | Description |
|---|---|
| Business purpose | Providing the Service: retrieving reviews, drafting replies with artificial intelligence, showing reviews and replies in the dashboard, publishing the replies Customer authorizes, and the support, security and billing that go with them. |
| Nature of processing | Collection from Google, storage, analysis (including sentiment classification), generation of reply drafts, display, transmission to Google, deletion. |
| Data subjects | People who review Customer's locations on Google, and Customer's staff or other people named in reviews or replies. |
| Categories of data | Reviewer's public Google display name and profile photo link, review text, star rating and date, the reply and its status, and any other information a reviewer chooses to include in a review. |
| Sensitive data | None is requested. A reviewer may volunteer sensitive information in a review; it is processed only as part of the review and is not used for any other purpose. |
| Duration | For as long as the Service is provided, then deleted as described in Section 15. |
04Customer's instructions
The Agreement and Customer's configuration and use of the Service are Customer's complete instructions for processing Customer Personal Data. We will tell Customer if we believe an instruction violates Privacy Laws, and we may decline to follow it.
05Service provider commitments
We will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the business purpose stated in Section 3, or as Privacy Laws otherwise permit a service provider;
- retain, use or disclose Customer Personal Data outside the direct business relationship between Customer and us;
- combine Customer Personal Data with personal information we receive from or on behalf of anyone else, or collect from our own interactions with a consumer, except as Privacy Laws permit;
- use Customer Personal Data to train artificial-intelligence models.
We will comply with the obligations Privacy Laws place on service providers and processors and provide the level of privacy protection they require. We will notify Customer if we determine that we can no longer meet those obligations. Customer may take reasonable and appropriate steps to ensure that we use Customer Personal Data consistently with Customer's obligations under Privacy Laws and, on notice, to stop and remediate any unauthorized use. We certify that we understand and will comply with the restrictions in this section.
06Confidentiality of personnel
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality, and access is limited to those who need it to provide, secure or support the Service.
07Security
We maintain technical and organizational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and storage with hosting providers that encrypt data at rest;
- passwords stored only as one-way bcrypt hashes; activation and password-reset links that are single-use and expire;
- isolation of each customer's data from every other customer's, and role-based access for our team;
- two-factor authentication on administrator accounts, and an append-only audit log of administrator actions;
- rate limiting on sign-in and other sensitive endpoints;
- encrypted database backups that expire within 30 days.
We may update these measures as long as the overall level of protection is not reduced.
08Sub-processors
Customer authorizes us to engage the sub-processors listed on our sub-processor page. We bind each sub-processor by written contract to data-protection obligations at least as protective as this DPA, and we remain responsible for its performance.
We will notify Customer by email at least 15 days before a new sub-processor begins processing Customer Personal Data. Customer may object on reasonable data-protection grounds within that period. If we cannot address the objection, Customer may terminate the affected part of the Service, and we will refund the prepaid fees for the unused part of the Subscription Term.
09Consumer requests
If we receive a request from a consumer to exercise a right under Privacy Laws regarding Customer Personal Data, we will promptly forward it to Customer and will not respond to it ourselves except to direct the consumer to Customer, unless the law requires otherwise. Taking into account the nature of the processing, we will help Customer respond to such requests, including by deleting or correcting Customer Personal Data where the Service does not let Customer do so itself.
10Assessments and cooperation
We will give Customer the information reasonably necessary for it to carry out data protection assessments and to meet its other obligations under Privacy Laws, taking into account the nature of the processing and the information available to us.
11Security Incidents
We will notify Customer without undue delay, and in any event within 72 hours, after we confirm a Security Incident affecting Customer Personal Data. The notice will describe, as far as is then known, the nature of the incident, the data and people affected, and the steps we are taking. We will take reasonable steps to contain and remedy the incident and will cooperate with Customer in meeting any notification obligation it has under state breach-notification laws. Our notice is not an admission of fault.
12Demonstrating compliance
On Customer's written request to support@replytune.com, we will make available the information reasonably necessary to demonstrate our compliance with this DPA. Customer may, no more than once in any 12-month period and with at least 30 days' notice, have a reasonable assessment of our compliance carried out by itself or by an independent assessor bound by confidentiality, at Customer's expense and in a way that does not disrupt the Service or compromise other customers' data. We may instead provide a report from a qualified independent assessor.
13Deidentified data
If we deidentify information derived from Customer Personal Data, we will take reasonable measures to ensure it cannot be associated with an individual, publicly commit to maintain and use it only in deidentified form, not attempt to reidentify it, and require anyone we share it with to do the same.
14Where data is processed
Customer Personal Data is processed in the United States and, where a sub-processor's listed location says so, in the European Union. We will not process it elsewhere without updating the sub-processor list under Section 8.
15Deletion and return
When the Agreement ends, we delete Customer Personal Data within 30 days, unless the law requires us to keep it. Data in backups is deleted as the backups expire, within 30 days, and is not used for any other purpose in the meantime. Before the Agreement ends, Customer may ask us to export Customer Personal Data. Deleting the account from the dashboard deletes Customer Personal Data immediately, subject to the same backup expiry.
16No protected health information
The Service is not designed to process protected health information under HIPAA, and we are not Customer's business associate. Customer will not use the Service in a way that requires a business associate agreement.
17Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.