Data Processing Agreement
How AI Review Sensor processes personal data on behalf of its customers, including obligations, sub-processors, and data-subject rights.
Last updated: July 1, 2026
Product: AIReviewSensor (https://www.aireviewsensor.com)
Operated by: VASUNDHARA SOLUTIONS LAB LLP
Effective date: 1 July 2026
Last updated: 1 July 2026
This Data Protection Agreement forms part of, and is subject to, the Terms of Use between the parties. It applies where the Processor processes Personal Data on behalf of the Controller in connection with the Service. Where this DPA conflicts with the Terms of Use on data-protection matters, this DPA prevails.
1. Definitions
Terms such as "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Sub-processor," and "Supervisory Authority" have the meanings given in the GDPR and, where applicable, the DPDP Act, 2023 (India) and the CCPA/CPRA. "Applicable Data Protection Law" means all such laws applicable to the processing.
2. Roles of the parties
The Controller determines the purposes and means of processing the Personal Data contained in reviews, ratings, comments, and messages processed through the Service.
The Processor processes that Personal Data only on the Controller's documented instructions, which include the Terms of Use, this DPA, and the configuration you set in the app.
For account-registration data of the Customer's own users, the Processor may act as an independent Controller as described in the Privacy Policy.
3. Subject matter, duration, nature, and purpose (Annex 1)
Subject matter: processing of Personal Data contained in app-store reviews, business-profile reviews, social-media comments, and direct messages, to display them and to generate and post reply/response content.
Duration: for the term of the Customer's subscription and any wind-down period.
Nature and purpose: retrieval, storage, AI-assisted generation of replies, and publication of replies to connected platforms.
4. Categories of Data Subjects and Personal Data (Annex 1)
Data Subjects: end customers and members of the public who leave reviews/ratings, post comments, or send messages on the Controller's connected accounts; the Controller's own team members.
Categories of Personal Data: names, usernames/handles, profile identifiers, the content of reviews/comments/messages (which may contain opinions and any personal details the individual chose to include), and reply content.
No special-category data is intended to be processed. The Controller must not use the Service to process special-category or sensitive data except with a valid lawful basis and appropriate safeguards.
5. Processor obligations
The Processor shall:
Process Personal Data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case it will inform the Controller unless prohibited).
Ensure persons authorized to process Personal Data are bound by confidentiality.
Implement appropriate technical and organizational security measures (Annex 2).
Respect the conditions for engaging Sub-processors (Section 6).
Assist the Controller, insofar as possible, in responding to Data Subject requests (Section 7).
Assist the Controller with security, breach notification, data-protection impact assessments, and prior consultations (Sections 8–9).
At the Controller's choice, delete or return Personal Data at the end of the services and delete existing copies, unless retention is required by law (Section 10).
Make available information necessary to demonstrate compliance and allow for audits (Section 11).
6. Sub-processors (Annex 3)
The Controller provides general authorization for the Processor to engage Sub-processors listed in the Sub-processor List. We use a limited number of trusted providers to run the Service -> for hosting, AI reply generation, payment processing (Paddle), email, and analytics.
The Processor imposes data-protection obligations on each Sub-processor that are substantially the same as those in this DPA.
The Processor will give the Controller prior notice of any intended addition or replacement of a Sub-processor, and the Controller may object on reasonable data-protection grounds.
The Processor remains liable to the Controller for its Sub-processors' performance.
7. Data Subject rights
The Processor will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures — insofar as possible — to fulfil the Controller's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If the Processor receives a request directly from a Data Subject, it will forward it to the Controller and not respond directly except on the Controller's instruction or as required by law.
8. Personal Data breaches
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its own notification obligations to authorities and Data Subjects.
9. Impact assessments and consultation
The Processor will provide reasonable assistance to the Controller with data-protection impact assessments and any required prior consultation with Supervisory Authorities, taking into account the nature of processing and information available to the Processor.
10. Return and deletion
On termination of the services, the Processor will, at the Controller's election, delete or return all Personal Data and delete existing copies, except to the extent retention is required by Applicable Data Protection Law. Platform-mandated deletion requirements (e.g., Meta, Google) are honored regardless of the Controller's instruction.
11. Audits
The Processor will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, security, frequency, and notice conditions. The Processor may satisfy audit obligations by providing third-party certifications or reports where available.
12. International transfers
Where the Processor transfers Personal Data outside the EEA, UK, or other regulated regions, it will ensure an appropriate transfer mechanism is in place, such as the EU Standard Contractual Clauses and the UK IDTA/Addendum, which are incorporated by reference where required. The parties will complete the SCC modules and annexes as applicable.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use, to the extent permitted by Applicable Data Protection Law.
14. Governing law
This DPA is governed by the same law as the Terms of Use (India, courts at Surat, Gujarat), except where Applicable Data Protection Law requires the law of another jurisdiction for specific matters (for example, the law governing the SCCs).
Annex 1 — Details of processing
(as described in Sections 3–4 above)
Annex 2 — Technical and organizational security measures
Encryption in transit (TLS) and at rest
Encrypted storage of OAuth tokens
Hashed passwords
Role-based access control and least-privilege access
Network security and segregation
Logging and monitoring
Regular backups
Vendor/sub-processor due diligence
Incident-response procedures
Staff confidentiality obligations
Annex 3 — Sub-processor List
(as described in Sections 6 above)
How to execute this DPA
This DPA is incorporated into and accepted as part of the Terms of Use. No separate signature is required for it to apply. If your organisation requires a signed copy, contact [email protected].

