Legal
Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you, the customer (the "Controller"), and Revinsta (the "Processor"). It applies whenever Revinsta processes personal data on your behalf, and it sets out how that processing is carried out. Where you and Revinsta have signed a separate negotiated agreement, that agreement prevails over this DPA to the extent of any conflict.
Roles and scope
For guest and reviewer data that you bring into Revinsta, you act as the Controller and Revinsta acts as the Processor. Revinsta processes this personal data only to provide the service described in the Terms of Service, only on your documented instructions (which the Terms and your configuration in the product constitute), and for no independent purpose of its own.
Categories of data and data subjects
The personal data processed under this DPA typically includes:
- Guest and reviewer names, and the content of reviews and survey responses;
- Guest contact details (email address or phone number) that you upload or sync to send post-stay feedback requests;
- Account users you invite - their names, email addresses and role within your account.
Data subjects are your guests, the reviewers of your properties, and the people you invite to your account. You are responsible for ensuring you have a lawful basis to provide this data to us and to have it processed for these purposes.
Our obligations as Processor
- Process personal data only on your instructions and for the purposes above;
- Ensure people authorised to process the data are bound by an appropriate duty of confidentiality;
- Implement appropriate technical and organisational security measures (see below);
- Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your security, breach-notification and impact-assessment obligations;
- Notify you without undue delay after becoming aware of a personal data breach affecting your data;
- On termination, delete or return your personal data as described in the Privacy Policy, save where storage is required by law.
Sub-processors
You authorise Revinsta to engage sub-processors to deliver the service - including cloud hosting, our database provider, an email delivery provider, a payment processor, and the AI model providers used to draft replies and reports. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give you a reasonable way to learn of changes to our sub-processors and to object on reasonable data-protection grounds.
AI processing
Review text and the context you provide are sent to AI model providers to generate reply drafts, analytics and reports. We work with providers that do not train their foundation models on data submitted through their business interfaces. AI output can contain mistakes; you remain responsible for content published under your name, as set out in the Terms of Service.
International transfers
Where personal data is transferred to a country without an adequacy decision, such transfers are made under an appropriate safeguard - for example the applicable Standard Contractual Clauses - which are incorporated into this DPA by reference.
Security measures
Revinsta maintains measures appropriate to the risk, including encryption of data in transit, access controls and least-privilege administration, encryption of stored integration credentials, network isolation of secret data, regular backups, and logging of administrative actions. We review these measures as the service evolves.
Audits
On reasonable written request, and no more than once per year unless required by a supervisory authority, we will make available the information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality protections.
Contact
For any request relating to this DPA or to the processing of personal data, use the contact form linked in the site footer.