Legal

Data Processing Addendum

Redrock Reputation Limited — last updated September 2025

Incorporated into and forming part of the Redrock Rep Terms and Conditions.

1

Incorporation and Scope

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms and Conditions between Redrock Reputation Limited (“Redrock Rep”, “Processor”) and the Customer (“Controller”). Defined terms used but not defined here have the meaning given to them in the Terms and Conditions.

This DPA applies where Redrock Rep processes personal data on behalf of the Customer in the course of providing the Services. It does not apply to personal data that Redrock Rep processes as an independent controller for its own purposes (for example, billing and account administration), which is addressed in Redrock Rep's Privacy Policy.

In the event of any conflict between this DPA and the main Terms and Conditions in relation to the processing of personal data, this DPA shall prevail.

2

Details of Processing

Subject matter

The processing of personal data by Redrock Rep on behalf of the Customer in connection with the delivery of the Services specified in the Order Form.

Duration

For the duration of the subscription, and thereafter only to the extent required by applicable law or for the period necessary to complete any agreed return or deletion of personal data.

Nature and purpose of processing

Processing activities may include collection, storage, retrieval, use, disclosure and deletion of personal data, carried out for the purpose of delivering the Services to the Customer, which may include Google Business Profile management, review management, customer feedback collection, social media posting, website operation, and digital loyalty programme management.

Types of personal data

Depending on the Services, this may include: names, email addresses, phone numbers, and business information of end-customers; review content, ratings and feedback submitted by end-customers; loyalty membership information including first name, date of birth, loyalty activity and notification preferences; and other information provided by the Customer or its end-customers in connection with the Services.

Categories of data subjects

The Customer's end-customers and, where applicable, the Customer's own employees or representatives interacting with the Services.

3

Processor Obligations

Redrock Rep shall, in relation to personal data processed on behalf of the Customer:

  • Process personal data only on documented instructions from the Customer, unless required by applicable law to process otherwise. Where applicable law requires processing, Redrock Rep will inform the Customer of that requirement before processing, unless the law prohibits doing so.
  • Ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR.
  • Not engage sub-processors without prior general written authorisation of the Customer. The Customer provides general written authorisation for Redrock Rep to engage the categories of sub-processors described in Section 4. Redrock Rep will inform the Customer of intended changes to sub-processors and give the Customer a reasonable opportunity to object before the change takes effect.
  • Assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligations to respond to requests from data subjects exercising their rights under UK GDPR.
  • Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Redrock Rep.
  • At the Customer's choice, delete or return all personal data to the Customer after the end of the provision of the Services, and delete existing copies unless applicable law requires their storage.
  • Make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable prior notice and confidentiality obligations.
4

Sub-Processors

The Customer provides general written authorisation for Redrock Rep to engage sub-processors to assist in delivering the Services. Redrock Rep currently engages sub-processors in the following categories:

  • Payment processing providers
  • Online form and data collection providers
  • Hosting and infrastructure providers
  • Reputation management and review technology providers
  • Digital loyalty programme technology providers
  • Scheduling and calendar service providers
  • Email and communication service providers

A current list of principal sub-processors is available to Customers on written request to customerservice@redrockrep.co.uk. Redrock Rep will impose data protection obligations on sub-processors equivalent to those set out in this DPA.

Where Redrock Rep intends to add or replace a sub-processor, it will give the Customer at least 14 days prior notice. If the Customer reasonably objects to the change on data protection grounds, the parties shall seek to resolve the objection in good faith. If the objection cannot be resolved, either party may terminate the Services on reasonable notice without penalty.

5

Security

Redrock Rep shall implement and maintain appropriate technical and organisational measures to protect personal data processed on behalf of the Customer against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures shall take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to individuals.

Redrock Rep shall ensure that access to personal data is limited to those who need access for the purpose of delivering the Services, and that such persons are subject to appropriate confidentiality obligations.

6

Personal Data Breaches

In the event that Redrock Rep becomes aware of a personal data breach affecting personal data processed on behalf of the Customer, Redrock Rep shall:

  • Notify the Customer without undue delay, and where feasible within 72 hours of becoming aware of the breach.
  • Provide the Customer with sufficient information to enable the Customer to meet any applicable reporting obligations.
  • Take reasonable steps to mitigate the effects of and to minimise any damage resulting from the breach.

The Customer is responsible for determining whether the breach needs to be reported to the ICO and for making any such report, taking into account the information provided by Redrock Rep.

7

International Data Transfers

Where Redrock Rep transfers personal data outside the UK in the course of providing the Services, it shall ensure that such transfers are made in accordance with applicable UK data protection law, including by relying on UK adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. Redrock Rep shall provide the Customer with details of any such transfer arrangements on request.

8

Return and Deletion of Data

On termination of the Services, and at the Customer's written request, Redrock Rep shall either return to the Customer, or securely delete, all personal data processed on the Customer's behalf, together with all copies, within a reasonable period. Redrock Rep shall certify in writing that deletion has been completed, unless applicable law requires retention of the personal data, in which case Redrock Rep shall inform the Customer and continue to apply the obligations of this DPA to the retained data.

9

Controller Obligations

The Customer, as data controller, warrants and represents that:

  • It has a lawful basis for processing the personal data it instructs Redrock Rep to process.
  • It has provided all necessary privacy information to data subjects whose data is shared with Redrock Rep or processed through the Services.
  • Its instructions to Redrock Rep comply with applicable data protection law.
  • It will promptly notify Redrock Rep if it becomes aware of any inaccuracy in personal data or any exercise of data subject rights that requires action by Redrock Rep.
10

Governing Law

This DPA is governed by and construed in accordance with the laws of England and Wales. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

11

Contact

For queries relating to this DPA or data processing matters, please contact:

Redrock Reputation Limited

Email: customerservice@redrockrep.co.uk