RATECARDS PROSign in

RATECARDS PRO

Data Processing Agreement

Version
0.1-draft
Status
Draft — not yet in force
Last updated
2026-09-08

This Data Processing Agreement forms part of the agreement between the Customer and RATECARDS L.L.C-FZ for RATECARDS PRO. It applies whenever the Service processes personal data on the Customer's behalf — above all the personal data of the Customer's reviewers — and sets out each party's obligations, the sub-processors used, where data is processed and the security measures maintained.

1. Parties, scope and precedence

This DPA is between the business that has accepted the Terms of Service or signed an Order Form (the Customer, the controller) and RATECARDS L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates (RATECARDS, the processor). It is incorporated into the Agreement by reference and takes effect on the date the Customer first uses the Service. Either party may request a countersigned copy at support@ratecards.co.

This DPA applies to Customer Personal Data: personal data contained in Customer Data that RATECARDS processes on the Customer's behalf in providing the Service — in particular reviewer identifiers, display names, review text and replies mirrored from the platforms the Customer connects, and the personal data of the Customer's own staff that the Customer enters into its workspace. It does not apply to Users' sign-in and session data (credentials, sessions, verification tokens, invitations), which RATECARDS processes as a controller under the Privacy Policy. A User's name, email address, role and location scope are held in both capacities: as account data under the Privacy Policy, and as Customer Personal Data under this DPA where they appear in the Customer's workspace.

If this DPA conflicts with the Terms or an Order Form, this DPA prevails for the processing of personal data. If the Standard Contractual Clauses referred to in the International transfers section conflict with this DPA, the Clauses prevail.

2. Definitions

  • Data Protection Law — every law that applies to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, together with any executive regulations issued under it (PDPL).
  • Personal data, controller, processor, data subject, processing and personal data breach have the meanings given in Data Protection Law.
  • Sub-processor — a third party engaged by RATECARDS to process Customer Personal Data.
  • Agreement, Service, Order Form, Customer Data, User, Workspace, Location and Touchpoint have the meanings given in the Terms of Service.
  • Platform — a third-party review platform the Customer connects to the Service (an independent controller, not a sub-processor).
  • Standard Contractual Clauses — the clauses adopted by the European Commission in Decision (EU) 2021/914 for the transfer of personal data to third countries, Module Two (controller to processor), and, where UK law applies, the UK International Data Transfer Addendum.

3. Roles of the parties

The Customer is the controller of Customer Personal Data and determines the purposes and means of its processing. RATECARDS is the Customer's processor. Each party will comply with the obligations Data Protection Law places on it in that role. The Customer confirms that it has a lawful basis for the processing it instructs, including for mirroring reviews from each Platform it connects, and that its instructions comply with the Platform's terms.

4. Processing on documented instructions

  • RATECARDS will process Customer Personal Data only on the Customer's documented instructions, including for transfers to a third country, unless required to do so by Union or Member State law to which RATECARDS is subject; in that case RATECARDS will inform the Customer of the legal requirement before processing, unless the law prohibits this. Where a law of the United Arab Emirates or another third country requires processing contrary to the Customer's instructions, RATECARDS will inform the Customer before complying, unless that law prohibits this, and will comply only to the extent legally required.
  • The Customer's instructions are: the Agreement, this DPA (including Annex 1), the configuration the Customer's Users apply in the Service (which Platforms are connected, which features are enabled, which replies are published), and any further written instructions the Customer gives.
  • RATECARDS will inform the Customer immediately if, in its opinion, an instruction infringes Data Protection Law. RATECARDS may then suspend the instruction until the Customer confirms or changes it.

5. Confidentiality of personnel

RATECARDS ensures that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality (by contract or statute) and processes the data only on instructions. Access is granted on a need-to-know basis; changes to critical records are captured in the audit log described in Annex 2.

6. Security of processing

RATECARDS implements and maintains the technical and organisational measures described in Annex 2, and will not reduce the overall level of protection they provide during the term. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, these measures are designed to ensure a level of security appropriate to the risk.

7. Sub-processors

  • The Customer gives RATECARDS general written authorisation to engage the sub-processors listed in Annex 3, and any replacement or additional sub-processor engaged under this section.
  • RATECARDS will give the Customer's workspace owners at least 30 days' notice by email before a new sub-processor starts processing Customer Personal Data. The Customer may object in writing on reasonable, documented data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected part of the Service, or the Agreement, without penalty and with a pro-rata refund of prepaid fees.
  • RATECARDS engages each sub-processor under written data-processing terms — the vendor's data-processing addendum named in Annex 3 — that impose data-protection obligations providing at least the same level of protection as this DPA, and remains fully liable to the Customer for the sub-processor's performance.
  • A sub-processor that Annex 3 marks as planned is disclosed in advance, not yet processing; RATECARDS will still give the Customer's workspace owners the notice above before it starts processing Customer Personal Data, and the objection right runs from that notice.
  • The Platforms the Customer connects are not sub-processors: they are independent controllers with which the Customer has its own relationship, and review data flows between the Customer's Platform account and its workspace under the Platform's terms.

8. Assistance with data-subject requests

Taking into account the nature of the processing, RATECARDS will assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If a data subject contacts RATECARDS directly about Customer Personal Data, RATECARDS will not respond on the merits but will forward the request to the Customer without undue delay and tell the data subject it has done so. Erasure is carried out by overwriting the subject's personal fields in place and recording the subject on a platform-wide erasure list that every backup restore is checked against, so erased data cannot be resurrected (today by an operator following a written procedure; an automated flow is planned).

9. Assistance with security, breach notification and impact assessments

  • RATECARDS will notify the Customer's workspace owners of a personal data breach affecting Customer Personal Data immediately upon becoming aware of it — and in every case without undue delay and no later than 72 hours after becoming aware, so that a Customer subject to the UAE PDPL can make its own immediate notification and a Customer subject to the GDPR can meet its 72-hour deadline. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point; information may be provided in phases as it becomes available.
  • RATECARDS will assist the Customer in meeting its own obligations regarding security of processing, breach notification to authorities and data subjects, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to RATECARDS.
  • RATECARDS may charge reasonable costs for assistance that goes beyond what the Service and this DPA already provide, and will tell the Customer before incurring them.

10. Deletion and return at the end of the Service

At the Customer's choice, RATECARDS will return (as an export in a common machine-readable format) and/or delete all Customer Personal Data after the end of the provision of the Service. RATECARDS will delete the Customer's workspace data 30 days after termination — or earlier if the Customer asks in writing after receiving its export — and destroy the key material that protected the workspace's Platform credentials; every Platform authorisation is revoked within seven business days of termination so the Customer can disassociate its Platform accounts. Copies held in backups are overwritten in the ordinary backup cycle described in Annex 2 and are protected until then by the same measures. RATECARDS may retain data where, and for as long as, Union or Member State law — or, for a Customer subject to the PDPL, UAE law — requires it, and will continue to protect it under this DPA.

11. Information and audit

RATECARDS will make available to the Customer all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are limited to once in any 12-month period unless required by a supervisory authority or following a personal data breach, are conducted on at least 30 days' written notice during business hours, must not unreasonably disrupt the Service or expose other customers' data, and are at the Customer's cost. RATECARDS will first answer written questions and provide its security documentation and test evidence; an on-site inspection is reserved for cases those answers cannot resolve.

12. International transfers

The Service is hosted in Frankfurt, Germany (European Union). RATECARDS is established in the United Arab Emirates and administers the Service from there, and the sub-processors in Annex 3 process Customer Personal Data in the locations stated there, some of which are outside the EU/EEA, the UK and the UAE.

  • Customers subject to the GDPR or UK GDPR. The Customer's engagement of RATECARDS is a transfer to a third country. The parties agree the Standard Contractual Clauses (Module Two), which are incorporated into this DPA by reference with the following selections: Clause 7 (docking) included; Clause 9 option 2 (general authorisation, 30 days' notice as in this DPA); Clause 11 optional language not included; Clause 13 and Annex I.C: the supervisory authority of the EU member state in which the Customer is established; Clause 17 option 1: the law of Ireland; Clause 18: the courts of Ireland. Annex I.A of the Clauses is completed as follows: data exporter — the Customer, at the name, address and contact details in its Order Form or workspace account, role controller; data importer — RATECARDS L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates, support@ratecards.co, role processor; each party's acceptance of this DPA stands as its signature and date. Annex I.B is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by Annex 3. For Customers subject to the UK GDPR the UK International Data Transfer Addendum (ICO, version B1.0) is incorporated: Table 1 — the parties as identified in this DPA; Table 2 — the Clauses with the selections above; Table 3 — Annexes 1, 2 and 3 of this DPA; Table 4 — either party may end the Addendum as set out in its section 19. RATECARDS makes an onward transfer of Customer Personal Data to a sub-processor outside the EU/EEA only where Clause 8.8 of the Clauses is met — Module Three Clauses concluded with that sub-processor (the data-processing terms in Annex 3 incorporate them where they say so) or another transfer tool under Chapter V of the GDPR.
  • Customers subject to the UAE PDPL. Customer Personal Data leaves the UAE for the EU hosting location and for the sub-processors in Annex 3. Until the UAE Data Office approves the destination countries or agreements under Article 22 of the PDPL, these transfers are made under Article 23: RATECARDS binds each recipient by contract to protection equivalent to the PDPL's provisions, measures, controls and requirements (this DPA and the sub-processor terms in Annex 3), and the Customer, by accepting this DPA, instructs and authorises the transfers for the performance of the Agreement.
  • Where a supervisory authority or a change in Data Protection Law requires a different or additional transfer mechanism, the parties will cooperate in good faith to put it in place promptly.

13. Liability, term and general

  • Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except that nothing limits liability to data subjects under the Standard Contractual Clauses or under Data Protection Law where it cannot be limited.
  • This DPA lasts as long as RATECARDS processes Customer Personal Data on the Customer's behalf, including the deletion period above, and is governed by the law and courts stated in the Terms, except where the Standard Contractual Clauses require otherwise.
  • RATECARDS may update Annex 3 under the sub-processor section, and Annex 2 to strengthen (never weaken) the measures. Other changes to this DPA follow the change procedure in the Terms.

14. Annex 1 — Details of the processing

ItemDescription
Subject matterThe provision of the RATECARDS PRO review-management service to the Customer under the Agreement.
DurationThe term of the Agreement plus the 30-day deletion period, and any longer period required by law.
Nature and purposeMirroring the Customer's reviews from connected Platforms into its workspace; storing and displaying them; computing review metrics; storing and publishing the Customer's replies; classifying reviews and drafting replies with an AI model for a User's review or, where a workspace owner has opted the Workspace into the risk-based mode under the Terms, publishing lower-risk drafts automatically; issuing Touchpoints that redirect the Customer's customers to a Platform's review page; providing connection-health and sync status; supporting, securing, backing up and restoring the Service.
Categories of data subjectsIndividuals who have reviewed the Customer's locations on a connected Platform (reviewers); the Customer's Users, as members of the Customer's workspace (their role, location scope, the invitations the Customer issues and the replies they author).
Categories of personal dataFor reviewers: the Platform's reviewer identifier and display name, the review text, rating, language, timestamps, edit history as reported by the Platform, any reply, and the classification and AI drafts derived from the review. For Users, as processed on the Customer's behalf: role, location scope, the invitee email addresses on invitations the Customer issues, the replies they author and identifiers of their actions in the audit log (a User's account data as such is controller data under the Privacy Policy).
Special categories of dataNone are requested or intended. Review text is free text written by reviewers and may incidentally contain any information a reviewer chooses to write; the Customer must not instruct processing that targets special categories.
Frequency of transferContinuous, for the duration of the Service.
RetentionAs stated in the Privacy Policy's retention table and the deletion section above.

15. Annex 2 — Technical and organisational measures

The measures below are those in force on the date of this version, stated as built. Where a measure depends on a sub-processor that Annex 3 marks as planned, or on a step that is still carried out manually, the row says so.

AreaMeasure
Tenant isolationEvery table holding Customer Data carries the workspace identifier; PostgreSQL row-level security is enabled and forced on each such table with a permissive-grant plus restrictive-fence policy pair; the tenant context is set per database transaction and an absent context yields zero rows (fail-closed). The application's database role is a non-owner role without superuser or bypass-RLS rights. Guard, database and isolation test suites run in continuous integration on every change; a scheduled daily check against the live database verifies the row-level-security catalogue, the database roles and the fail-closed behaviour.
Credential protectionPlatform OAuth tokens and webhook secrets are stored under envelope encryption: a unique AES-256-GCM data key per record, itself wrapped by a key-encryption key held outside the database (a software key today; Google Cloud KMS once that sub-processor in Annex 3 is active); the ciphertext binds the workspace and connection identity; keys are rotated and re-wrapped by a dedicated job; credentials are never written to logs.
Transport and accessTLS on every external connection and on the connection between the application and the database. Passwords are stored as scrypt hashes. Email addresses are verified before first sign-in. Sign-in, sign-up, password-reset and magic-link endpoints are rate-limited. Sessions are database-backed and expire after 7 days of inactivity.
AuthorisationRole- and location-scoped permissions inside each workspace (owner, admin, location manager, staff, viewer); membership changes take effect on the next request; workspace owners control invitations and revocations.
AuditAn append-only audit log captures changes to critical records by database trigger, storing record identifiers, the action, the actor and the changed column names — never values. The application role can only insert and read audit rows.
Ingress hardeningPublic endpoints are rate-limited per client IP; sync-ingress endpoints enforce a request-body size cap and a request deadline; webhook and notification endpoints verify authenticity, answer uniformly on failure and de-duplicate replays.
Backup and recoveryContinuous point-in-time recovery of the managed PostgreSQL cluster (base backups plus continuous write-ahead-log archiving) with a rolling restore window of 3 days on the current hosting plan (7 days on a larger plan), plus logical backups kept for 7 days; the database, its replicas and every backup are encrypted at rest with AES-256 by the hosting provider. Recovery targets — recovery point objective 15 minutes, recovery time objective 4 hours — were met in the first restore drill on 2026-09-09 (12 minutes and 11 minutes 52 seconds respectively). Restores follow a written checklist that includes role and policy verification, an isolation check, and a mandatory sweep of the erasure list so that erased personal data is not resurrected.
ErasureErasure requests are executed by overwriting the data subject's personal fields in place and recording the subject on a platform-wide erasure list (today a documented procedure run by an operator; an automated flow is planned); audit rows are retained because they contain identifiers only.
Change control and testingAll changes are made through version control with automated type-checking, linting, unit, database, guard and isolation test suites required to pass before deployment; deployments are sequenced by continuous integration after the checks pass.
Sub-processor and personnel controlsSub-processors are engaged under the written data-processing terms named in Annex 3. The production database accepts connections only from the application's least-privilege roles and from an allow-listed operator address; operator access is limited to named RATECARDS staff on a need-to-know basis.
MonitoringStructured application logs and metrics; alert rules for job failures, dead-letter queues and lost tenant context are defined in code, with delivery to the monitoring service in Annex 3 planned; log lines are scrubbed of database detail fragments that could echo field values; application logs are retained by the hosting provider for 7 days.

16. Annex 3 — Sub-processors

The sub-processors engaged, or planned and disclosed in advance, on the date of this version. RATECARDS keeps this list current under the sub-processor section above; the version and date at the top of this page change when it does.

Sub-processorEntityServiceData processedLocation of processingTransfer safeguardData-processing terms
RenderRender Services, Inc., 525 Brannan Street Ste 300, San Francisco, CA 94107, United StatesCloud hosting of the application, background workers, scheduled jobs and the PostgreSQL database, including backups (point-in-time recovery, 3-day window) and application logs (7-day retention)All Customer Data, including Customer Personal DataFrankfurt, Germany (EU) — the region every service and the database are deployed in; the database, its replicas and all backups are encrypted at rest (AES-256)Data is hosted in the EU. Render's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Decision 2021/914) and the UK Addendum for any transfer outside the EEA, and Render states it participates in the EU-US Data Privacy FrameworkRender Data Processing Addendum
Zoho Corporation (ZeptoMail)Zoho Software Trading L.L.C, Dubai, United Arab Emirates (Zoho's contracting entity for customers in the UAE), part of the Zoho Corporation groupDelivery of transactional email (email verification, sign-in links, password resets, workspace invitations)Recipient email address and the content of the transactional message; delivery logs are kept by Zoho for 60 daysUnited States — the data-centre group that serves ZeptoMail accounts registered on zoho.com; service data is encrypted at restZoho's Data Processing Addendum, which Zoho states is based on the EU model contractual clauses — issued by Zoho on request; RATECARDS will obtain and execute it before these terms come into forceZoho GDPR compliance and Data Processing Addendum
AnthropicAnthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, United StatesLarge-language-model inference for reply drafts and review classification (planned — not yet enabled on the Service)Per request: the review text, the reviewer's display name as shown on the Platform, the location name, the Customer's brand-voice settings and our instructions; the model's outputInference may run in any geography Anthropic operates in, including the United States; copies Anthropic retains are stored in the United States and are deleted within 30 days of receipt (longer only where Anthropic's trust-and-safety systems flag the content or the law requires)Anthropic's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Modules Two and Three) with the UK and Swiss addenda; under its Commercial Terms Anthropic may not train models on customer contentAnthropic Data Processing Addendum
Google Cloud (Cloud KMS)Google Cloud EMEA Limited, Ireland (Google's contracting entity for customers in the Middle East; address as published in Google Cloud's terms)Key management: wrapping and unwrapping the data-encryption keys that protect Platform credentials (planned — the Service currently runs on a software key)No personal data — key material onlyAn EU key location (the Frankfurt region or the EU multi-region); Cloud KMS key material stays in its chosen location for the life of the key, at rest and in useGoogle's Cloud Data Processing Addendum, which applies the EU Standard Contractual Clauses to restricted transfers; no personal data is sentGoogle Cloud Data Processing Addendum
Grafana Labs (Grafana Cloud)Raintank Inc. dba Grafana Labs, 165 Broadway 23rd Floor, New York, NY 10006, United StatesOperational monitoring and alerting: metrics, traces and error logs, 14-day retention on the free tier (planned — not yet connected)Operational telemetry: identifiers, timings, error classes and alert notifications — no review contentGrafana Cloud runs on United States infrastructure by default; an EU region (Frankfurt, Germany) is selectable when the stack is created and will be chosen if the plan in use permits it — otherwise telemetry is processed in the United States under the transfer safeguard in the next columnGrafana Labs' Data Processing Agreement incorporates the EU Standard Contractual Clauses (Modules Two and Three) and the UK International Data Transfer Addendum, and Grafana Labs states it participates in the EU-US Data Privacy FrameworkGrafana Labs Data Processing Agreement

Not sub-processors. Google Business Profile and Trustpilot are Platforms the Customer connects and are independent controllers; Tripadvisor is linked to and not mirrored; Google Sign-In is an identity provider a User may choose. Their processing is governed by their own terms with the Customer or the User.