Data Processing Addendum

Last updated: 19 July 2026

Processor terms applying where ReplyEveryReview acts on a customer's instructions.

This Data Processing Addendum forms part of the ReplyEveryReview Terms and Conditions. It applies where Lewis Clarke trading as ReplyEveryReview processes personal information on behalf of a customer and the customer is the controller and ReplyEveryReview is the processor. It does not apply to processing for which ReplyEveryReview independently determines the purposes and essential means and therefore acts as controller.

5.1 Definitions

Applicable Data Protection Law: the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and other binding UK data-protection law applying to the processing.

Customer Personal Data: personal information processed by ReplyEveryReview as a processor on behalf of the customer.

Subprocessor: another processor appointed by ReplyEveryReview to process Customer Personal Data.

Controller, Processor, Processing, Personal Data, Personal Data Breach and Data Subject: the meanings given under Applicable Data Protection Law.

5.2 Processing details

Subject matter and duration. The processing concerns operation of ReplyEveryReview's customer, agency and public-conversation workflow services. It continues for the duration of the customer agreement and any limited period reasonably required to export, return or securely delete Customer Personal Data.

Nature and purpose:

  • receiving onboarding and campaign instructions
  • storing business-profile and workspace information
  • collecting or receiving public-conversation findings
  • filtering, deduplicating and matching results
  • applying AI-assisted relevance, intent, sentiment and suitability scoring
  • preparing summaries and suggested replies
  • supporting human review and approval
  • generating reports and providing support
  • maintaining security and audit records
  • deleting or returning information at the end of the service

Types of information and people. Customer Personal Data may include names, work contact details, public usernames and profile information, public post or review text, source URLs, dates, public engagement information, general location information, keyword and competitor references, AI-generated scores, reply drafts, workflow notes and account activity. It may relate to customer or agency personnel, client representatives, people posting publicly online, reviewers, commenters, prospective customers and support contacts.

5.3 Documented instructions

ReplyEveryReview will process Customer Personal Data only in accordance with the customer's documented lawful instructions, as necessary to provide the contracted service, or where required by applicable law. The Terms, onboarding profile, account configuration, approved campaigns, support requests and written customer instructions together form the documented instructions. If ReplyEveryReview believes an instruction infringes Applicable Data Protection Law, it will inform the customer unless prohibited by law. ReplyEveryReview is not required to follow an instruction requiring unlawful access to private information, discriminatory targeting, unlawful sensitive-data processing, compromised security, infringement of third-party rights or a material unagreed service change.

5.4 Customer responsibilities

The customer is responsible for determining that its processing is lawful, choosing an appropriate lawful basis, providing required privacy information, issuing lawful and proportionate instructions, responding to its data subjects, ensuring search terms are not discriminatory, authorising account users, reviewing replies and ensuring public engagement complies with law and platform rules.

5.5 Confidentiality

ReplyEveryReview will ensure that people authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, receive access only where reasonably necessary, understand their responsibilities and do not use the information for unauthorised purposes.

5.6 Security

ReplyEveryReview will maintain measures appropriate to the nature and risk of processing. These may include role-based access, individual accounts, secure authentication, encrypted transmission, restricted production access, environment separation, logging, secure backups, security updates, incident-response procedures, supplier assessment, staff confidentiality, data minimisation and defined deletion processes. The customer acknowledges that no online system can guarantee absolute security.

5.7 Subprocessors

The customer gives ReplyEveryReview general written authorisation to appoint subprocessors necessary to provide the service. ReplyEveryReview will perform reasonable due diligence, enter into written terms imposing appropriate data-protection obligations, remain responsible for the subprocessor's processor obligations and maintain information about material subprocessors. Where reasonably practicable, ReplyEveryReview will provide notice before appointing a new material subprocessor. A customer with a reasonable data-protection objection should contact privacy@replyeveryreview.co.uk promptly. The parties will work in good faith to address the objection. Where no reasonable alternative exists, the customer may stop the affected processing or terminate the affected service before the new subprocessor begins processing.

5.8 International transfers

ReplyEveryReview will not make a restricted transfer of Customer Personal Data outside the United Kingdom unless the destination is covered by UK adequacy regulations, an appropriate transfer agreement or addendum is in place, another lawful transfer mechanism applies, or the transfer is otherwise permitted by law.

5.9 Data-subject requests

Taking account of the nature of the processing, ReplyEveryReview will provide reasonable assistance where the customer receives a request for access, correction, deletion, restriction, objection, portability or review of automated processing. Where ReplyEveryReview receives a request relating to Customer Personal Data for which the customer is controller, it will normally forward the request, direct the person to the customer or respond according to the customer's instructions. It will not independently fulfil the request unless authorised or legally required.

5.10 Personal-data breaches

ReplyEveryReview will notify the customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Where available, the notice will describe the nature of the breach, affected systems and information, likely consequences, containment steps, corrective measures, recommended customer action and a contact for further information. ReplyEveryReview will provide reasonable cooperation with the customer's investigation and notification obligations. Notification does not constitute an admission of fault or liability.

5.11 DPIAs and regulatory consultation

ReplyEveryReview will provide reasonable information and assistance required for the customer's data-protection impact assessment, risk assessment, regulatory consultation where legally required and demonstration of the security and operation of the processing. Assistance beyond the normal service may be subject to reasonable additional charges where substantial custom work is required, unless the need results from ReplyEveryReview's breach.

5.12 Deletion and return

At the end of the service, ReplyEveryReview will, subject to available functionality and the customer's choice, provide a reasonable opportunity to export information, return relevant Customer Personal Data or delete or anonymise it. ReplyEveryReview may retain information where required by law or reasonably needed to establish, exercise or defend legal claims. Backup information will remain protected and be removed through the normal backup cycle.

5.13 Compliance information and audits

ReplyEveryReview will make available information reasonably necessary to demonstrate compliance with this Addendum. The customer may request further information no more than once per year unless a confirmed breach has occurred, a regulator requires it or there is a reasonable basis to suspect material non-compliance. An audit must be arranged on reasonable notice, occur during normal business hours, avoid unnecessary disruption, protect other customers' information, use existing independent reports where sufficient and be paid for by the customer unless it identifies a material ReplyEveryReview breach. No audit may expose another customer's information, credentials, source code or security-sensitive material beyond what is reasonably required.

5.14 Records

ReplyEveryReview will maintain appropriate processor records where required. The customer remains responsible for its own controller records.

5.15 Liability and priority

The liability provisions in the Terms apply to this Addendum unless Applicable Data Protection Law requires otherwise. Nothing limits liability where it cannot legally be limited. Where there is a conflict, mandatory data-protection law takes priority, this Addendum takes priority for processor obligations, and the remaining Terms apply after that.

5.16 Contact

Questions about this Addendum should be sent to privacy@replyeveryreview.co.uk.