This Data Processing Agreement ("DPA") forms part of Praisera’s Terms of Service or any other written agreement between Praisera and the Client (the "Agreement"). This DPA applies when Praisera processes personal data on behalf of the Client in connection with the Service.
1. Parties and definitions
"Praisera" means Dmitry Museychuk, a self-employed professional established in Spain, operating commercially under the name "Praisera".
"Client" means the company, self-employed professional, organization or other entity that uses the Service in a professional or commercial capacity.
"Service" means the Praisera platform for collecting, managing, moderating, analyzing and displaying reviews.
"Client Personal Data" means personal data processed by Praisera on behalf of the Client through the Service.
"Account Users" means natural persons authorized by the Client to access or manage a workspace.
"Review Authors" means natural persons who create an account to submit, edit, delete or manage reviews.
"Review Content" means the content, ratings, categories, attachments if available, metadata and related information submitted by Review Authors or managed by the Client through the Service.
"Data Protection Laws" means the GDPR, Spanish data protection law and any other applicable data protection or privacy laws that apply to the processing of Client Personal Data.
"GDPR" means Regulation (EU) 2016/679.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data processed by Praisera as Processor.
Terms such as "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given to them in the GDPR.
2. Roles of the parties
The Client acts as Controller of the Client Personal Data. Praisera acts as Processor of the Client Personal Data.
Praisera acts as an independent Controller for processing activities for which Praisera determines the purposes and means, including account administration, subscription administration, billing reconciliation, security of the Service, independent management of reports, verification of reporters, issuance or retention of Statements of Reasons where applicable, legal compliance, support communications, operational metrics for Praisera’s own administration of the Service, and other Controller activities described in the Privacy Policy.
For clarity, this DPA applies only to processing carried out by Praisera as Processor on behalf of the Client.
3. Processing details
The subject matter, duration, nature, purpose, categories of data subjects and types of personal data are described in Annex 1.
Praisera may make reasonable technical or operational changes to the Service provided that they do not materially reduce the level of protection of Client Personal Data or substantially alter the purposes covered by this DPA.
4. Client instructions
Praisera will process Client Personal Data only in accordance with documented instructions from the Client, unless processing is required by European Union or Member State law. In such case, Praisera will inform the Client before the processing, unless prohibited by law.
Documented instructions include the Agreement, this DPA, the configuration of the Service, actions by authorized Account Users, documented support requests and any other written instruction accepted by Praisera.
Praisera is not required to follow instructions that are unlawful, technically infeasible, contrary to the Agreement, outside the scope of the Service, or that create an unacceptable security, privacy, legal, abuse, integrity or operational risk, unless Data Protection Laws require otherwise.
If Praisera considers that an instruction infringes Data Protection Laws, it will inform the Client without undue delay, unless prevented by law or security reasons.
5. Client obligations
The Client is responsible for:
- determining the purposes and means of the processing;
- having a valid legal basis to collect, moderate, display, export and process reviews;
- providing appropriate privacy notices;
- configuring the Service lawfully;
- ensuring that notification recipients are authorized to receive the relevant information;
- not entering or instructing the processing of sensitive data, data relating to persons under 18 years of age, criminal data or other high-risk data prohibited by the Agreement;
- responding to data subject requests when acting as Controller;
- removing or disabling the widget when it stops using the Service or closes its account.
The Client will not use the Service in sectors, jurisdictions or contexts prohibited by the Terms of Service.
6. Confidentiality and access
Praisera will ensure that persons authorized to process Client Personal Data are subject to appropriate confidentiality obligations.
Praisera will limit access to Client Personal Data to those who need such access to provide, protect, maintain or support the Service, or to comply with applicable legal obligations.
Support access is governed by Section 15.
7. Security
Praisera will implement appropriate technical and organizational measures to protect Client Personal Data against unauthorized access, accidental loss, alteration, disclosure or destruction.
The main measures are described in Annex 2. Praisera may update them to reflect technical improvements, operational changes, changes in risk, infrastructure changes or provider changes, provided that such updates do not materially reduce the overall level of protection.
8. Subprocessors
The Client gives Praisera general authorization to engage subprocessors to provide the Service.
The current list of subprocessors, including their function, location and data protection safeguards, is available in the Subprocessors List published at Subprocessors List.
Praisera will enter into, accept or maintain a written agreement, electronic agreement, data processing addendum or other binding contractual instrument with each subprocessor that processes Client Personal Data. Such instrument will impose, in substance, data protection obligations equivalent to those imposed on Praisera under this DPA, to the extent applicable to the nature of the subprocessor’s service.
Praisera will remain responsible to the Client for the performance of the data protection obligations of its subprocessors to the extent required by Data Protection Laws.
9. Changes to subprocessors
Praisera may add or replace subprocessors. Where the change is material to the processing of Client Personal Data, Praisera will update the Subprocessors List and, where reasonably possible, notify the Client by email, within the Service or through another reasonable channel.
The Client may object to a new subprocessor on reasonable and documented data protection grounds within the period indicated in the notice or, if no period is indicated, within thirty (30) days.
If the Client validly objects, Praisera may offer mitigation measures, limit the affected processing, allow the affected functionality to be disabled, replace the subprocessor or allow the Client to terminate the affected part of the Service. If the subprocessor is necessary to provide the Service and Praisera cannot reasonably accommodate the objection, the Client’s sole remedy will be to terminate the affected part of the Service, unless the law requires otherwise.
10. International transfers
Praisera’s main application infrastructure, database and backups will be hosted within the European Economic Area, unless otherwise indicated in the Subprocessors List or in a written agreement with the Client.
Where a subprocessor or provider processes Client Personal Data outside the EEA, Praisera will use a valid transfer mechanism under Chapter V of the GDPR, such as an adequacy decision, Standard Contractual Clauses, active certification under the EU-U.S. Data Privacy Framework where applicable, or another valid safeguard.
Praisera may update transfer mechanisms where necessary to maintain a valid mechanism, provided that the level of protection is not materially reduced.
11. Assistance to the Client
Taking into account the nature of the processing and the information available, Praisera will reasonably assist the Client in:
- responding to data subject requests relating to Client Personal Data;
- complying with security of processing obligations;
- assessing and managing personal data breaches;
- conducting data protection impact assessments where applicable;
- responding to prior consultations with supervisory authorities where applicable.
Assistance will be provided mainly through documentation, this DPA, the Privacy Policy, the Subprocessors List, reasonably available security documentation and reasonable responses to specific requests.
Praisera may charge reasonable costs for assistance that exceeds standard support, unless the assistance is necessary due to Praisera’s breach of this DPA.
12. Data subject requests
If Praisera receives a request relating to Client Personal Data processed as Processor, Praisera may forward the request to the Client, instruct the data subject to contact the Client or coordinate the response with the Client.
Praisera is not required to act directly on Client Personal Data without instructions from the Client, unless required by Data Protection Laws or where Praisera acts as an independent Controller in relation to the affected activity.
13. Personal data breaches
Praisera will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data processed by Praisera as Processor.
The notice will include, to the extent reasonably available:
- the general nature of the breach;
- the categories of data and persons affected, where known;
- the measures taken or proposed to contain or mitigate the breach;
- information reasonably necessary for the Client to assess its notification obligations.
Praisera may provide information in stages. Notice of a breach does not constitute an admission of fault or liability.
14. Deletion and return
Termination of the Agreement, subscription cancellation, account closure and management of inactive accounts are governed by the Terms of Service or the applicable agreement.
The Client’s lack of use of the Service does not, by itself, imply automatic termination of the Agreement or this DPA.
Upon termination of the affected Service or closure of the Client account, the Client may request return or export of Client Personal Data processed solely as Processor before account closure or within thirty (30) days after termination, unless Praisera agrees otherwise in writing or the law requires a different period.
During that period, Praisera may deactivate the workspace, remove public display, limit operational access and temporarily retain the reasonably necessary available data to handle a return or export request.
After the thirty (30) day period has expired, Praisera may delete or anonymize Client Personal Data processed solely as Processor in accordance with its standard process.
The Client may request immediate deletion of Client Personal Data processed solely as Processor. In such case, unless an applicable legal obligation applies, Praisera may begin deletion or anonymization without retaining an additional export window, and the Client will be deemed to waive return or export.
The export will be provided in a reasonable, commonly used format available within the Service or through reasonably assisted support. The right to export reviews or related data does not transfer to the Client any intellectual property rights of Review Authors and does not affect the Reviewer Terms.
Deletion or return does not apply to data that Praisera retains as an independent Controller, including report records, Statements of Reasons, abuse prevention records, security records, legal compliance records, billing records, tax records, Service integrity records, evidence copies or data excluded from Client Personal Data under Section 2.
Backups are deleted in accordance with Praisera’s backup retention cycle. Praisera does not surgically purge data from backups, unless it decides to do so at its discretion or the law requires it.
15. Support access
Where support requires access to data controlled by the Client, Praisera will process such data as Processor, unless the access is carried out for independent purposes of security, legal compliance, abuse prevention, Service integrity, report management, disputes or defense against claims.
For ordinary support, where available and appropriate, Praisera may use ephemeral, time-limited and read-only support sessions limited to the affected workspace. Such access may be logged and, where granted through the support flow, notified to the Client owner or primary administrator, unless a legal, security, privacy, abuse, Service integrity or third-party protection reason justifies delaying or limiting the notice.
Security incidents, legal compliance, abuse, reports, takedown, infrastructure recovery or Service integrity may require controlled operator access outside the ordinary support flow, subject to proportionate internal controls.
16. Audits
Praisera will make available to the Client information reasonably necessary to demonstrate compliance with this DPA, mainly through this DPA, the Privacy Policy, the Subprocessors List, reasonably available security documentation and written responses to reasonable requests.
The Client may request a reasonable audit no more than once every twelve (12) months, unless there is a documented material breach or legal requirement. Before requesting an intrusive audit, the Client must attempt to resolve its questions through documentation and written responses.
Any auditor must be independent, qualified, subject to confidentiality and not be a competitor of Praisera or act on behalf of a competitor.
Audits must be notified with reasonable advance notice, conducted during business hours, limited to the necessary scope and must not compromise security, confidentiality, availability, trade secrets, legal privilege, data of other clients or the integrity of the Service. They will not include penetration testing, scanning, access to source code, databases, data of other clients or production infrastructure unless previously agreed in writing.
Praisera may reject, suspend or limit an audit that compromises the interests described above, while seeking to offer reasonable alternative information where possible.
Praisera may charge reasonable costs for audits or assistance that exceed standard documentation, unless the audit reveals a material breach by Praisera.
17. Prohibited sensitive processing
The Client will not use the Service to process special categories of personal data, data relating to criminal convictions or offenses, data relating to persons under 18 years of age or other high-risk data, unless expressly authorized in writing by Praisera and additional safeguards are agreed.
If Praisera becomes aware of such use, it may suspend, restrict or terminate the affected Service, remove or restrict content, require corrective measures or take other reasonable measures.
18. Liability and indemnification
Each party’s liability under this DPA will be subject to the limitations and exclusions in the Agreement, except to the extent Data Protection Laws do not allow such limitation or exclusion.
The Client will indemnify and hold Praisera harmless from third-party claims, regulatory claims, damages, penalties, costs and expenses, to the extent legally recoverable or indemnifiable, arising from unlawful instructions, lack of legal basis, insufficient notices, unlawful configuration, unauthorized recipients, prohibited use of the Service, submission of sensitive or high-risk data, Review Content or responses under the Client’s control, or the Client’s breach of this DPA, the Agreement or Data Protection Laws.
This indemnity will not apply to the extent the claim arises directly from Praisera’s breach of this DPA or Data Protection Laws applicable to Praisera.
19. Order of precedence
In the event of a conflict between this DPA and the Agreement regarding the processing of Client Personal Data by Praisera as Processor, this DPA will prevail.
In the event of a conflict between this DPA and the Privacy Policy, this DPA will prevail only with respect to the processing of Client Personal Data by Praisera as Processor. The Privacy Policy will continue to apply to activities in which Praisera acts as Controller.
In the event of a conflict between this DPA and Standard Contractual Clauses or another mandatory transfer mechanism, such mechanism will prevail to the extent of the conflict.
20. Changes
Praisera may update this DPA to reflect legal, technical, operational, security, provider, Service or Praisera structure changes.
Praisera will not make material changes that materially reduce the level of protection of Client Personal Data without notifying affected Clients.
If a material adverse change affects the processing of Client Personal Data and the Client reasonably objects on data protection grounds, the Client may terminate the affected part of the Service before the change takes effect, unless the change is necessary due to law, security, provider continuity, Service integrity or urgent operational need.
If ownership or operation of the Service is transferred to a company or other successor entity, that entity will assume Praisera’s obligations under this DPA and the transfer will not materially reduce the level of protection of Client Personal Data.
21. Contact
For questions related to this DPA:
- Privacy: [email protected]
- Legal: [email protected]
- Support: [email protected]
Annex 1 — Processing details
Subject matter: provision of the Praisera Service to the Client, including collection, management, moderation, analysis and display of reviews.
Duration: during the term of the Agreement and, after termination, for the time necessary for return/export, deletion or anonymization, expiration of backups, legal obligations, legal holds, disputes, active reports, security, abuse prevention or defense against claims.
Nature and purpose: collection of reviews, structuring by resources/categories/ratings, moderation configured by the Client, display through the widget, Client responses, reports, analytics, configured notifications, moderation/audit records, support and technical operation of the Service.
Categories of data subjects: Account Users, Review Authors, Widget Visitors, recipients of notifications configured by the Client and persons incidentally mentioned in reviews, responses, configurations, notifications or communications.
Types of personal data: names, aliases, email addresses, roles, account/workspace identifiers, review content, ratings, categories, responses, review metadata, widget configuration, resources, moderation rules, notification data, widget events, timestamps, origin domain, user agent, technical headers, moderation/audit records, support communications and data contained in backups.
Special categories: the Service is not designed to process special categories of data, criminal data, data relating to persons under 18 years of age or other high-risk data. The Client must not enter or instruct the processing of such data.
Annex 2 — Technical and organizational measures
Praisera maintains technical and organizational measures appropriate to the size, nature, scope and risk of the Service, including, as applicable:
- access limited to authorized personnel and based on need;
- confidentiality of authorized personnel;
- logical separation between Client workspaces;
- authentication, session and permission controls;
- passwords stored as salted hashes;
- multi-factor authentication for Account Users where available, enabled or required;
- encryption in transit through HTTPS/TLS;
- traffic protection through network and security providers;
- proportionate application, security and audit logs;
- error and availability monitoring;
- request limiting and anti-abuse controls;
- content reporting and review mechanisms;
- limited, logged and controlled support access;
- periodic backups with staggered retention cycle;
- review of relevant providers and data processing agreements where applicable;
- documented transfer mechanisms where applicable;
- internal incident response process, including classification, containment, risk assessment, notification analysis and remediation.
Praisera will review these measures when substantial changes occur in the architecture, providers, authentication, widget delivery, threat model or nature of the Service.