Legal

Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you, the customer (the "Controller"), and Revinsta (the "Processor"). It applies whenever Revinsta processes personal data on your behalf, and it sets out how that processing is carried out. Where you and Revinsta have signed a separate negotiated agreement, that agreement prevails over this DPA to the extent of any conflict.

Roles and scope

For guest and reviewer data that you bring into Revinsta, you act as the Controller and Revinsta acts as the Processor. Revinsta processes this personal data only to provide the service described in the Terms of Service, only on your documented instructions (which the Terms and your configuration in the product constitute), and for no independent purpose of its own.

Categories of data and data subjects

The personal data processed under this DPA typically includes:

Data subjects are your guests, the reviewers of your properties, and the people you invite to your account. You are responsible for ensuring you have a lawful basis to provide this data to us and to have it processed for these purposes.

Our obligations as Processor

Sub-processors

You authorise Revinsta to engage sub-processors to deliver the service - including cloud hosting, our database provider, an email delivery provider, a payment processor, and the AI model providers used to draft replies and reports. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you a reasonable way to learn of changes to our sub-processors and to object on reasonable data-protection grounds.

AI processing

Review text and the context you provide are sent to AI model providers to generate reply drafts, analytics and reports. We work with providers that do not train their foundation models on data submitted through their business interfaces. AI output can contain mistakes; you remain responsible for content published under your name, as set out in the Terms of Service.

International transfers

Where personal data is transferred to a country without an adequacy decision, such transfers are made under an appropriate safeguard - for example the applicable Standard Contractual Clauses - which are incorporated into this DPA by reference.

Security measures

Revinsta maintains measures appropriate to the risk, including encryption of data in transit, access controls and least-privilege administration, encryption of stored integration credentials, network isolation of secret data, regular backups, and logging of administrative actions. We review these measures as the service evolves.

Audits

On reasonable written request, and no more than once per year unless required by a supervisory authority, we will make available the information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality protections.

Contact

For any request relating to this DPA or to the processing of personal data, use the contact form linked in the site footer.