Data Processing Agreement
Version 1.0, last updated 22 August 2026
Draft, not yet in force. RatingPilot is not open to customers yet. This is published early so anyone can read it before they sign up. It will be confirmed and dated before the service opens.
What this is: the agreement that lets us handle your customers' personal information on your behalf. UK data protection law requires it in writing, so it forms part of our Terms of Service and you agree to it when you sign up. There is nothing to sign separately.
Template dated 22 August 2026. This is the agreement that lets RatingPilot lawfully handle your customers' personal information on your behalf. UK data protection law requires it in writing before any of that information is handled, so it forms part of our Terms of Service and is agreed when you sign up.
The short version
You own your customers' information. We only ever touch it to do the jobs you have asked us to do: watch your reviews, draft replies, and send review requests to people you have added. We do not sell it, we do not use it for our own purposes, and we do not let anyone else have it except the companies listed below that help us run the service. When you leave, we delete it within 30 days. Everything below is the detail behind those sentences.
1. Who is who
In data protection law there are two roles. The controller decides what happens to personal information. The processor handles it on the controller's behalf and does only what it is told.
- You, the business using RatingPilot, are the CONTROLLER of your customers' information. You decide who is added, why they are contacted, and what your replies say.
- RatingPilot is the PROCESSOR. We act on your instructions and nothing else.
Your instructions to us are: these terms, the settings you choose inside your account, and the actions you take in it. If you ask us to do something we believe breaks data protection law, we will tell you and we will not do it.
One thing worth being clear about because it is the most common misunderstanding: you are responsible for having the right to contact the customers you add. We enforce consent and opt-outs in the software, but we cannot know whether a given customer really agreed. That is your job as the controller.
2. What we handle, and why
Set out here in the way the law requires, so there is no argument later about scope.
- Subject matter: providing the RatingPilot review management service to you.
- Duration: for as long as you are a customer, plus the deletion period in section 8.
- Nature and purpose: collecting your reviews, classifying them, drafting replies, posting the replies you approve, sending review requests by text and email, recording who opted out, and showing you your own reporting.
- Types of personal information: names, mobile telephone numbers and email addresses of customers you add; the names and review text of people who review you publicly; records of consent and of opt-outs; and the contact details of your own staff who log in.
- Categories of people: your customers, people who leave you public reviews, and your own team members with accounts.
We do not ask for and do not want special category information such as health, religion or anything similar. If a review happens to contain it, we handle it under the same protections and our healthcare rules apply.
3. Keeping it secure
The measures below are what is actually built, not aspirations.
- Connection keys to your Google account are encrypted before they are stored, using AES-256-GCM. They are never stored in plain text and never shown back to anyone.
- Access is by emailed sign-in link rather than passwords, so there is no password to be reused or leaked. Sessions expire and can be revoked instantly.
- What each person can do is enforced in code by their role, not by the interface hiding buttons. One customer can never see another customer's information.
- Incoming messages from our text provider are cryptographically verified, so nobody can forge a message that looks like it came from you.
- Every meaningful action is written to an audit record: who did what, when, and to which record.
- Information is held in the United Kingdom or the European Economic Area wherever the provider allows it, with backups.
We keep these measures under review and may improve them, but we will not weaken the protection you are getting.
4. Our people
Everyone with access to your information is bound by a duty of confidentiality that survives them leaving. Access is limited to those who need it to run the service or to help you when you ask. RatingPilot is a very small operation, so in practice that is a short list, and it is kept short deliberately.
5. The companies that help us run the service
We cannot run RatingPilot without a few specialist providers. You agree to us using the ones listed here. We remain responsible to you for what they do with your information.
- Anthropic (United States) - the AI that drafts the replies. Review text and your voice settings are sent for processing. Anthropic acts as our processor and does not use this information to train its models.
- Google (United States and worldwide) - your Business Profile connection, where reviews are read from and replies are posted to.
- Vercel (United States) - hosting for the website.
- Twilio (United States) - sending review request texts and receiving opt-out replies.
- Resend (United States) - sending emails, including review requests and sign-in links.
- Voyage AI (United States) - turning your past replies into the memory that keeps future replies sounding like you.
- Our database provider, in the United Kingdom or European Economic Area.
Not all of these are handling information yet; the list covers the full service so that it does not need renegotiating as parts of the product switch on. We will tell you at least 30 days before adding or replacing any provider on this list. If you object on reasonable data protection grounds, tell us and we will either find another way or you may cancel without penalty.
Stripe handles your own payment details, not your customers' information, and is a controller in its own right for that.
6. Information leaving the UK
Several of the providers above are in the United States, so some information is transferred outside the United Kingdom. Where that happens we rely on the safeguards UK law recognises: an adequacy decision where one exists, and otherwise the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with a check that the protection actually holds up in practice. Copies are available on request.
7. Helping you meet your duties
You may get requests from people about their information. We will help you answer them.
- If someone asks us directly for a copy of their information, or asks for it to be corrected or deleted, we will not answer for you. We will pass it to you promptly and help you respond.
- You can see, correct, export and delete any contact yourself from inside your account. For anything you cannot do yourself, ask us and we will do it, at no charge, within the time the law allows.
- We will give you the information you reasonably need for a data protection impact assessment or to consult the Information Commissioner, if you ever have to.
8. If something goes wrong
If we become aware of a personal data breach affecting your information, we will tell you without undue delay and in any event within 48 hours of becoming aware of it. We will tell you what happened, who and what is affected as far as we know it, what we are doing about it, and what we suggest you do. We will not wait until we have the full picture before telling you, because you have your own 72 hour duty to the Information Commissioner and you cannot meet it if we are still investigating quietly.
9. Getting your information back, and deletion
You can export your contacts and your reply history at any time while your account is open.
When you stop being a customer, your customers' personal information, your contacts and your voice profile are deleted within 30 days. You can ask for it sooner and we will do it. Replies already published on a review site stay published, because they are part of your business's public record and only that site can remove them.
We keep a minimal record of the account itself, such as invoices and the audit trail, for as long as the law requires us to. That record does not include your customers' contact details.
10. Showing you we are doing this properly
We will give you the information you need to show that we are meeting our obligations, and will co-operate with an audit or inspection you or an auditor you appoint carry out, on reasonable notice and no more than once a year unless a regulator asks for more or there has been a breach. In practice we would far rather answer your questions directly and quickly than turn this into a formality.
11. The legal bits
- This agreement forms part of our Terms of Service. Where the two disagree about the handling of personal information, this agreement wins.
- If any part of it is found unenforceable, the rest still stands.
- It is governed by the law of England and Wales, and the courts of England and Wales have jurisdiction.
- It lasts as long as we hold any of your customers' personal information, even if the main agreement has ended.
Agreeing to this
Ticking the box to accept our Terms of Service when you sign up counts as agreeing to this document, and we record the date and the version you agreed to. UK law allows this agreement to be made electronically and there is no need to sign anything on paper. If your own compliance process needs a signed copy, email hello@ratingpilot.co.uk and we will send you one.