This Data Processing Addendum ("DPA") forms part of the Master Service Agreement, Infrastructure Agreement, or other written agreement (the "Agreement") between Shout About Us, Inc. ("SAU") and the customer identified in the Agreement ("Customer"). It applies to the extent SAU processes Personal Data on Customer’s behalf in providing the Services. Capitalized terms not defined here have the meaning in the Agreement. In case of conflict, this DPA controls as to the processing of Personal Data.
Standard terms.This DPA is SAU’s standard and is the same for every customer. SAU does not negotiate customer-specific retention, deletion, or security terms. Clauses 12 and 13 apply automatically where the Personal Data is subject to the laws they reference and are inert otherwise. Hosting region is set in the Order Form.
Customer is the Controller (or Business) of Personal Data it provides to SAU. SAU is the Processor (or Service Provider). Where Customer is itself a Processor for its own clients, Customer warrants that it has authority to engage SAU as a Sub-processor and SAU processes Personal Data on the instructions of Customer. SAU is an independent Controller only of its own business records (for example, Customer’s billing contacts and SAU’s security logs) and processes those under its own privacy policy.
SAU processes Personal Data only on Customer’s documented instructions, which consist of the Agreement, this DPA, Customer’s configuration of the Services, and Customer’s use of the API and application. SAU does not sell Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the direct business relationship, or combine it with Personal Data received from other sources except as permitted for a Service Provider under CCPA. SAU will inform Customer if, in SAU’s opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is amended or confirmed.
SAU limits access to Personal Data to personnel and contractors who need it to perform the Services, who are bound by written confidentiality obligations, who have completed security awareness training, and who use company-managed devices. Access is role-based, uses named identities with multi-factor authentication, and is reviewed quarterly.
SAU maintains the technical and organizational measures in Annex 2, including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256 via AWS Key Management Service); infrastructure hosted in dedicated AWS accounts with private networking, web application firewall, and intrusion detection; logging of security-relevant events retained 12 months; change management with peer review and protected branches; vulnerability management including annual third-party penetration testing; and documented incident response. SAU may update these measures provided the overall level of protection is not materially reduced.
Customer authorizes SAU to engage the Sub-processors listed in Annex 3. SAU will give Customer at least 30 days notice before a new Sub-processor processes Personal Data, by email to Customer’s designated contact and by updating the list published at shoutaboutus.com/dpa. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected Services without penalty. SAU imposes on each Sub-processor data protection obligations no less protective than this DPA and remains responsible for each Sub-processor’s performance.
SAU will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests from Data Subjects to exercise their rights (access, correction, deletion, portability, restriction, objection). If SAU receives such a request directly relating to Customer’s Personal Data, SAU will forward it to Customer within 5 business days and will not respond except to acknowledge receipt and refer the requester to Customer, unless required by law. SAU logs all requests for 24 months.
SAU retains Personal Data only as long as needed to provide the Services and as set out in the Retention Policy. Without limitation: end-customer contact details submitted for review solicitation are deleted 90 days after the last message to that contact; records of solicitation sends and consent, which contain no contact details, are retained for 4 years; reviewer information is limited to the publicly displayed name; log data is retained for 12 months (security) and 90 days (application).
Deletion does not apply to: (a) aggregated or de-identified data that cannot reasonably identify Customer, any business, or any individual; (b) financial and transaction records, including Customer’s name, invoice amounts, dates, and location counts, retained for 7 years as required by law and used for no other purpose; (c) records SAU is required to retain by law or by the Agreement (for example, customer-count records); (d) data subject to a legal hold, which is deleted when the hold is lifted. SAU will notify Customer of any legal hold affecting Customer’s data where legally permitted.
SAU stores only the data classes and fields defined in the Retention Policy and does not retain raw third-party responses, reviewer profile information beyond the displayed name, per-user activity streams beyond application log retention, or prompts and outputs of AI-assisted drafting beyond the final response record and 14-day diagnostic logs. Customer agrees to submit only Personal Data necessary for the Services.
SAU notifies Customer’s designated security contact of a Security Incident affecting Customer’s Personal Data within 48 hours of SAU confirming the incident. Notification includes a description of the incident, the categories and approximate volume of Personal Data and Data Subjects affected, the measures taken or proposed, and a contact. Where full details are not yet available, SAU notifies with what is known and updates as the investigation proceeds. SAU cooperates with Customer’s reasonable requests to investigate, and assists Customer with any notification Customer must make to regulators or Data Subjects. Notification is not an admission of fault.
If SAU receives a subpoena, court order, regulatory demand, or other legal process seeking Personal Data or other Customer data in SAU’s possession, SAU will: (a) notify Customer promptly and before responding, unless legally prohibited; (b) provide Customer a reasonable opportunity to object, intervene, or seek a protective order; (c) disclose only the portion legally required; and (d) cooperate with Customer’s reasonable efforts to limit or resist disclosure. Customer will reimburse SAU’s reasonable costs, including reasonable attorneys’ fees and engineering time, of responding to legal process directed at Customer’s data, except where the process arises from SAU’s own breach of this DPA or the Agreement. This Clause applies with particular force to records held in connection with first-party review infrastructure, including review submissions, reviewer details, and moderation records.
On at least 30 days written notice and no more than once in any 12-month period, Customer may audit SAU’s compliance with this DPA. SAU may satisfy an audit request by providing its most recent SOC 2 report (or, before the first report is issued, a written description of controls and confirmation of the audit engagement and target date), a completed security questionnaire, and reasonable written responses to follow-up questions. Any on-site or direct audit is at Customer’s expense, conducted by a mutually agreed independent third party under confidentiality, during business hours, and without access to other customers’ data or to production systems.
SAU hosts the Services in the region specified in the Order Form (United States unless otherwise stated). Where Customer transfers Personal Data to SAU from a jurisdiction that restricts international transfers, the following apply automatically:
SAU will conduct and document a transfer impact assessment for EEA and UK transfers on request and will notify Customer if it becomes unable to comply with the SCCs.
Where Customer discloses to SAU Personal Data that is subject to the Privacy Act 1988 (Cth), SAU undertakes to handle that Personal Data in accordance with the APPs as if SAU were an APP entity. Customer’s disclosure is made in reliance on this undertaking as the contractual protection required under APP 8.1. SAU acknowledges that Customer remains accountable under APP 8.1 for SAU’s acts and practices in relation to that Personal Data, and SAU will indemnify Customer against liability Customer incurs under APP 8.1 arising from SAU’s breach of this undertaking, subject to an aggregate cap of two times the fees paid or payable by Customer in the 12 months preceding the claim. This clause does not apply to Personal Data not subject to the Privacy Act 1988.
Customer is responsible for: the lawfulness of its instructions and of the Personal Data it provides; obtaining and retaining any consents required for Personal Data it submits, including for review solicitation by email or SMS; the security of its own systems, credentials, and API tokens; designating and maintaining a security contact and a Sub-processor notice contact; and notifying its own users of termination and the export window.
Where Customer uses first-party review infrastructure, Customer will defend, indemnify, and hold harmless SAU and its officers, directors, employees, and contractors against any third-party claim, demand, proceeding, loss, or expense (including reasonable attorneys’ fees) arising from or relating to: (a) Customer’s review guidelines, content policies, or terms of service; (b) any moderation decision made by or on behalf of Customer, including any decision to publish, decline to publish, edit, remove, or retain a review; (c) content published on or removed from Customer’s review platform; (d) any claim by a consumer, business, or regulator concerning the accuracy, fairness, or lawfulness of Customer’s review platform or its operation; and (e) the instructions Customer gives SAU in connection with the foregoing. SAU operates the infrastructure and records Customer’s decisions; Customer determines the rules and makes the decisions. This indemnity does not apply to the extent a claim arises from SAU’s own breach of this DPA or the Agreement.
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except as stated in Clauses 13 and 14A. This DPA takes effect on the effective date of the Agreement and remains in force until SAU has deleted all Customer Personal Data in accordance with Clause 8.
| Item | Description |
|---|---|
| Subject matter | Provision of review management services: aggregation of business reviews, response drafting and posting, review solicitation, reporting. |
| Duration | The term of the Agreement plus the deletion period in Clause 8. |
| Nature and purpose | Collection, storage, organization, analysis, transmission, and deletion of Personal Data as necessary to provide the Services to Customer. Where Customer uses first-party review infrastructure, SAU stores and displays review submissions and operates the moderation workflow on Customer’s instructions; Customer defines the applicable guidelines and makes all moderation decisions. |
| Categories of Data Subjects | Customer’s personnel (account users, billing and technical contacts); Customer’s business clients’ personnel (location users); end customers of those businesses whose contact details are submitted for review solicitation; individuals who have published reviews on third-party platforms (display name only); and, where Customer uses first-party review infrastructure, consumers who submit reviews directly to Customer’s own review platform. |
| Categories of Personal Data | Names, business email addresses, phone numbers, user account identifiers, roles; end-customer names, email addresses, and phone numbers for solicitation (deleted 90 days after last message); publicly displayed reviewer names and review text; response text; usage and security logs. Where first-party review infrastructure is used: consumer name and email address, and where Customer supplies them, phone number and order or transaction identifier, together with the review content submitted and moderation records. |
| Special categories | None intended. Customer must not submit special category or sensitive Personal Data. |
| Frequency | Continuous for the term. |
| Retention | Per Clause 8 and the Retention Policy. |
| Area | Measure |
|---|---|
| Hosting | AWS, dedicated accounts per component under an AWS Organization; region per Order Form. |
| Encryption | TLS 1.2+ in transit; AES-256 at rest via AWS KMS; cryptographic erasure on deletion. |
| Access control | Named identities, MFA, role-based least privilege, quarterly access reviews, same-day removal at offboarding; API access by per-customer tokens with rotation. |
| Network | Private VPCs, security groups, AWS WAF, no public database endpoints, TLS termination at load balancer. |
| Logging and monitoring | CloudTrail organization trail, GuardDuty, CloudWatch, Datadog; security logs 12 months; alerting to on-call. |
| Change management | Ticketed changes, peer review, protected branches, CI/CD deployment, rollback plan. |
| Vulnerability management | Dependency and container scanning; patch cadence; annual third-party penetration test. |
| Backup and recovery | 35-day automated backups; documented and tested restore; restored copies deleted after use. |
| Data lifecycle | Classification of every data store; automated daily aging; event-driven offboarding with verification and certificate; immutable deletion log. |
| Incident response | Documented plan; 48-hour customer notification from confirmation; annual exercise. |
| Personnel | Background screening proportionate to role; confidentiality terms; annual security training; company-managed devices with encryption and endpoint protection. |
| Vendors | Sub-processor assessment at onboarding and annually; contractual flow-down; 30-day change notice. |
| Assurance | SOC 2 Type I (Security, Confidentiality) in progress; report available to customers under confidentiality on issuance. |
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and infrastructure | All | United States (region per Order Form) |
| OpenAI, L.L.C. | AI-assisted response drafting | Review text and context in transit; zero data retention configured | United States |
| Intuit Mailchimp / Mandrill | Email delivery for review solicitation | End-customer name and email; message content | United States |
| Bandwidth Inc. | SMS delivery for review solicitation | Phone numbers; message content; delivery metadata | United States |
| Front App, Inc. | Customer support inbox and conversation management | Customer and end-customer correspondence and contact details | United States |
| Data Outsourcing India | Operational services | Limited authorized access to customer and location data | India |
| Datadog, Inc. | Monitoring and logging | Application and security logs | United States |
| Salesforce, Inc. | CRM; partner reporting integrations where contracted | Customer personnel contact details; summary statistics | United States |
| Google LLC (Google Workspace) | Business email, documents, and support correspondence | Customer personnel contact details; support correspondence | United States |
| Dotsquares Ltd | Technical services | Limited authorized access to customer data as necessary to provide the Services | India; United States |
| Contracted support personnel | Support services | Limited authorized access to customer correspondence and platform data | Philippines |
| Stripe, Inc. | Payment processing for customers paying by card | Billing contact details; payment card data is held by Stripe, not SAU | United States |
The current Sub-processor list is published at shoutaboutus.com/dpa. Changes are notified per Clause 6.
| Purpose | SAU contact | Customer contact |
|---|---|---|
| Security Incidents (Clause 10) | security@shoutaboutus.com | [per Order Form] |
| Sub-processor notices (Clause 6) | privacy@shoutaboutus.com | [per Order Form] |
| Data subject requests (Clause 7) | privacy@shoutaboutus.com | [per Order Form] |
| Export and deletion (Clause 8) | support@shoutaboutus.com | [per Order Form] |