1. Introduction
This Privacy Policy explains how Praisera collects, uses, retains and protects personal data in connection with the service available at praisera.com and with the Praisera review widget.
Praisera enables businesses and professionals to collect, organize, moderate, analyze and display reviews on their websites or digital resources.
This Policy applies to:
- Clients and Account Users;
- Review Authors;
- Widget Visitors;
- visitors to praisera.com;
- persons who contact Praisera or submit reports about reviews.
When a Client integrates the Praisera widget into its own website, the Client’s privacy notice may also apply.
2. Who Praisera is
When Praisera acts as controller, the controller is:
- Name: Dmitry Museychuk
- Trade name: Praisera
- Status: self-employed professional established in Spain
- Privacy: [email protected]
- Legal: [email protected]
- Support: [email protected]
Additional legal information is available in our Legal Notice.
Praisera has not appointed a Data Protection Officer. Based on our current assessment, we are not required to appoint one under Article 37 of the GDPR.
3. Our role: Controller and Processor
Praisera may act as:
- Controller, when it determines the purposes and means of the processing; or
- Processor, when it processes personal data on behalf of a Client in accordance with the Client’s documented instructions.
We act as Controller mainly for account administration, security, payments, support, communications, abuse prevention, reports, content takedown, evidence, legal compliance and operation of the Service.
We act as Processor when we process personal data on behalf of the Client to collect, moderate, display, analyze or notify reviews, manage resources, categories, widget configuration, Client responses, widget events and reports configured by the Client.
When Praisera acts as Processor, the Data Processing Agreement applies. The Client is responsible for having a valid legal basis, providing appropriate notices and configuring the Service lawfully.
4. Professional use, minimum age and restricted sectors
Praisera is offered to Clients acting in a professional or commercial capacity. It is not offered to consumers as Clients.
Clients, Account Users and Review Authors must be at least 18 years old.
The Service is not directed to minors and we do not knowingly collect personal data from persons under 18 years of age. If you believe that a minor has created an account or that a review contains personal data of a person under 18 years of age, you may contact us at [email protected].
Praisera is not designed for sectors or uses where reviews are foreseeably likely to include sensitive data, data relating to minors, criminal data or other high-risk data. The full restrictions are described in the Terms of Service.
5. Personal data we process
The data we process depends on how you interact with Praisera.
Account Users
We may process name, email address, role, workspace, authentication data, session data, language, legal acceptance records, basic account activity and security records.
Review Authors
We may process first name, last name, email address, alias, visible name preference, authentication data, OAuth provider if used, submitted reviews, ratings, categories, language, moderation status and associated metadata.
When the Review Author chooses to display only their alias, we use that alias as the visible name in the public review.
Widget Visitors
When the widget loads or is used, we may process technical request metadata, such as IP address, user agent, technical headers, domain from which the widget is loaded and widget interaction events.
We may also use an identifier for each page load, kept in browser memory and not reused between visits. We do not use this data for advertising, cross-site tracking or profiling.
Visitors to praisera.com
We may process technical request metadata to deliver the website, protect it, prevent abuse and maintain its availability.
Reporters
If you submit a report about a review, we may process your email address, the reported review, the category and description of the report, verification status, decision taken, related communications and limited technical metadata for abuse prevention.
Clients and business contacts
We may process workspace name, country, sector, identity and email address of Account Users, Service configuration, notification recipients, subscription or customer identifiers in Stripe, and support, legal, privacy or sales communications.
We do not store full card numbers, security codes or payment credentials.
Partners and Partner Program applicants
If you apply to participate in the Partner Program, participate as a partner, use a referral code or link, promote Praisera as a partner or receive commissions, we may process name, email address, company, agency or trade name, country, website, professional profiles or promotional channels, information about your services, target customers, approval status, referral code or link, attribution data, Referred Customers, commission amounts, payment details, tax information, invoices, forms, communications, compliance records, anti-fraud records, Program activity and other information reasonably necessary to evaluate, administer, protect and enforce the Partner Program.
You must not send us sensitive data, data of persons under 18 years of age, criminal data, credentials, tokens, identity documents, unnecessary data or high-risk data as part of the Partner Program, unless Praisera expressly requests it and there is a valid basis for doing so.
6. Purposes and legal bases
We process personal data to:
- create and administer accounts;
- authenticate users and protect sessions;
- operate, protect and maintain the Service;
- collect, moderate and display reviews on behalf of the Client;
- send notifications configured by the Client;
- respond to support, privacy, legal or commercial inquiries;
- manage payments, subscriptions, taxes and accounting;
- maintain operational metrics, reliability and improvement of the Service;
- handle reports, takedowns, evidence and Statements of Reasons where applicable;
- evaluate partner applications, approve or reject participants, administer the Partner Program, attribute referrals, calculate commissions, manage discounts, make payments, prevent fraud or abuse, resolve attribution disputes, verify compliance with the Partner Program Terms and comply with tax, accounting and legal obligations related to the Program;
- comply with legal obligations and respond to competent authorities.
The legal bases may include:
- performance of a contract;
- compliance with legal obligations;
- legitimate interest;
- consent, where applicable;
- Client instructions when Praisera acts as Processor.
Where we rely on legitimate interest, we assess that such interest does not unduly override the rights and freedoms of the affected individuals.
Praisera will not send direct electronic marketing communications unless legally permitted under applicable ePrivacy and LSSI rules, including prior consent or an applicable soft opt-in. Any marketing communication will include a simple and free opt-out mechanism.
7. Special categories of data
Praisera does not request and is not designed to process special categories of personal data, data relating to criminal convictions or offenses, data of persons under 18 years of age or other high-risk personal data.
Because reviews may include free text, a person could incidentally submit such data in breach of the applicable Terms. If we become aware of content that should not be displayed, we may restrict it, remove it, redact it, delete it or retain limited evidence in accordance with this Policy, the applicable Terms and the law.
8. Recipients and providers
We may share personal data with:
- the relevant Client and authorized members of its team within the workspace, in relation to reviews, responses, configuration, reports and other data processed on behalf of that Client;
- technical providers that help provide, protect, maintain or support the Service;
- Stripe for payments and subscriptions;
- available OAuth providers, such as Google, if the Review Author chooses to sign in with them;
- legal, tax or accounting advisers;
- competent authorities, courts or law enforcement bodies where legally required;
- reporters, affected Review Authors and relevant Clients, to the extent necessary to handle reports or communicate decisions.
The current list of providers that may process personal data, including their function, location and safeguards, is available in our Subprocessors List.
Authorized Praisera personnel may access personal data only where necessary to operate, protect, maintain or support the Service, manage a request, investigate an incident, comply with legal obligations or protect the integrity of the Service.
9. International transfers
Praisera’s main infrastructure is hosted in the European Economic Area.
Some providers may process personal data or provide support from countries outside the EEA. Where this occurs, Praisera will use valid transfer mechanisms under the GDPR, such as adequacy decisions, Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where applicable, or other appropriate safeguards.
More information is available in the Subprocessors List.
10. Data retention
We retain personal data only for as long as necessary for the purposes described, unless we must retain it for a longer period due to a legal obligation, dispute, claim, security, abuse prevention or documented legal hold.
The main retention periods are:
- Account data: for the duration of the account. After account closure or a verified deletion request, personal data is anonymized or deleted from primary systems within the time necessary to complete the process, subject to identity verification, legal obligations, security, abuse prevention, disputes, backups and other applicable exceptions.
- Client return: after termination or workspace closure, the Client may request return or export in accordance with the DPA, normally before closure or within 30 days after termination.
- Reviews after workspace closure: they are removed from public display and retained for up to 12 months in primary systems for disputes, administration of Review Author accounts, reports, legal compliance or integrity of the Service. After that period, they are anonymized, unless earlier deletion or longer retention is justified by a legal obligation, active report, dispute, security, abuse prevention, legal hold or independent controller basis.
- Confirmed reports, decisions and Statements of Reasons: up to 24 months by default.
- Widget events, application logs and notifications: up to 90 days.
- Error events in Sentry: according to the retention period of the plan used, currently 30 days. If the plan or configuration changes in the future, retention may be up to 90 days.
- Tax, accounting and billing records: for the periods required by applicable law.
- Backups: retained in a staggered cycle of approximately 3–4 months and deleted according to the ordinary backup rotation.
Where Praisera retains evidence copies of a removed or reported review, it retains them only for documentation, legal compliance, disputes, abuse prevention or defense against claims. They are not used to republish the review.
11. Cookies and similar technologies
Praisera does not use cookies or persistent browser storage for advertising, cross-site tracking, profiling or marketing purposes.
The storage we use is limited to strictly necessary purposes or preferences requested by the user, such as maintaining a session, remembering language or preserving temporary widget state during a visit.
The widget may use per-page-load identifiers kept in browser memory and non-persistent technical tokens for security or functionality. They are not used for advertising or tracking.
Network security providers, such as Cloudflare, may set cookies, tokens or technical identifiers that are strictly necessary for security, abuse mitigation, load balancing, bot protection, verification flows or Service delivery.
We do not deploy a Praisera cookie consent banner as of the Effective Date because, according to our current inventory, we do not use non-essential cookies or non-essential persistent storage. If this changes, we will update this Policy and request consent where necessary.
12. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, secure credential storage, authentication and access controls, separation between workspaces, request limiting, security logs, monitoring, internal controls, backups and recovery.
Praisera does not guarantee absolute security.
We do not hold ISO 27001 or SOC 2 certifications as of the Effective Date.
13. Automated decision-making
Praisera does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR.
Some mechanisms operate automatically, such as moderation rules configured by the Client, default automatic publication, request limiting, protection against malicious traffic or security controls. These mechanisms are not used to profile individuals or to make decisions with legal or similarly significant effects.
The automatic publication of a review in accordance with the Client’s configuration or the ordinary behavior of the Service does not, by itself, constitute automated decision-making within the scope of Article 22 of the GDPR.
14. Your rights
Under the GDPR, you may have the right to:
- access your personal data;
- request rectification;
- request deletion;
- request restriction of processing;
- request portability where applicable;
- object to processing based on legitimate interest;
- withdraw consent where processing is based on consent;
- not be subject to automated decisions within the scope of Article 22;
- lodge a complaint with a supervisory authority.
These rights are not absolute. They apply under the conditions, limits and exceptions provided in the GDPR and applicable law. In some cases, Praisera may fully or partially deny a request, retain certain data, restrict processing instead of deleting it, or request additional information to verify your identity or understand the request.
Where a request affects data necessary to maintain an account, provide a functionality, comply with legal obligations, manage security, prevent abuse, handle reports, retain evidence or defend claims, Praisera may limit, suspend, close or anonymize the affected account or functionality where necessary and legally permitted.
To exercise your rights, contact us at [email protected].
We will respond without undue delay and, in any event, within one month. Where the request is complex or we receive many requests, we may extend the period by up to two additional months, informing you within the first month.
We may take reasonable measures to verify your identity. If your request concerns data that we process as Processor on behalf of a Client, we may refer it to the relevant Client or coordinate with them in accordance with the DPA.
Praisera’s lead supervisory authority is:
Spanish Data Protection Agency (AEPD) C/ Jorge Juan, 6 28001 Madrid Spain https://www.aepd.es
You may also lodge a complaint with the supervisory authority of your country of habitual residence, place of work or place of the alleged infringement.
15. Reports, unlawful content and privacy
If you believe that a review displayed through Praisera is unlawful, infringes your rights, contains personal data that should not be displayed or violates applicable rules, you may report it by:
- using the reporting tool integrated into the widget; or
- writing to [email protected] or [email protected].
To process a report, we may ask you to identify the review, explain the reason, provide a contact detail and, where appropriate, confirm that you are acting in good faith.
When we receive a sufficiently substantiated report, we act without undue delay. Depending on the case, we may temporarily restrict or hide the review, remove it, redact it, delete content, escalate the report to the relevant Client, retain limited evidence or refuse to act if the report is not sufficiently substantiated, is duplicate, abusive or does not allow the affected content to be identified.
Reports submitted through the widget may require email verification. Praisera may process an unverified report where required by law, where submitted by a competent authority, or where there is sufficient information and a legal, security, privacy, abuse prevention or Service integrity reason justifies it.
Where applicable under the Digital Services Act, Praisera may acknowledge receipt, communicate a decision, issue a Statement of Reasons and offer reconsideration channels.
Praisera’s single point of contact for communications relating to the Digital Services Act is [email protected]. We accept communications in Spanish and English.
If you disagree with a decision on a report or with a restriction applied to a review, you may request reconsideration by writing to [email protected]. This does not limit your right to go to court or, where applicable, to contact the competent Digital Services Coordinator.
DSA status
As of the Effective Date, Praisera is operated by a self-employed professional carrying out an economic activity. Based on its size, resources and current activity, Praisera considers that it qualifies as a microenterprise or small enterprise for the purposes of the applicable provisions of the Digital Services Act.
This reference does not imply that Praisera is a registered commercial company. We will review this position if our circumstances, size, activity or the applicable law change.
16. Changes to this Policy
We may update this Policy to reflect legal, technical, operational or Service changes.
Where reasonably possible or legally required, we will notify substantial changes by email, within the Service or through other appropriate means.
Non-substantial changes, such as clarifications or editorial corrections, may take effect upon publication.
The current version is identified by the date and version number at the beginning of this Policy.
17. Languages
This Policy is available in Spanish, English and French. All three versions are legally binding.
In case of inconsistency, the English version will prevail, unless applicable law requires otherwise. If a version is unavailable or not up to date, the most recent published version identified by its version number and effective date will prevail.
18. Contact
For any questions about this Policy or about the processing of your personal data:
- Privacy: [email protected]
- Legal: [email protected]
- Support: [email protected]