Legal document

Data Processing Agreement

How Seven9IT Solutions processes personal data on your behalf as your OptiReply Processor.

Version 1.0 Effective August 6, 2026 Seven9IT Solutions, Whitby
Privacy Terms DPA Data Deletion AI Policy Security
On this page
1

Definitions

  • Controller — The business or individual using OptiReply who determines the purpose and means of processing personal data
  • Processor — Seven9IT Solutions / OptiReply, acting on behalf of the Controller
  • Personal Data — Any information relating to an identified or identifiable natural person
  • Processing — Any operation performed on personal data, including collection, storage, retrieval, and deletion
  • Data Subject — The individual whose personal data is being processed (e.g., your customers who leave reviews)
2

Roles & Responsibilities

Where you use OptiReply to process personal data — including customer review data from a connected Google Business Profile and feedback submitted directly through OptiReply's QR code and feedback tools — you act as the Controller and Seven9IT Solutions acts as the Processor.

We process your data only on your documented instructions. Your use of the OptiReply platform — including your account configuration, feature selections, connected integrations (such as a Google Business Profile), and requests made to our support team — constitutes your documented processing instructions under this DPA, unless otherwise agreed in writing.

We will not process personal data for any purpose beyond delivering the agreed services without your explicit written consent.

3

Nature of Processing

CategoryDetails
Subject matterCustomer review management, AI response generation, and feedback collected through OptiReply's QR and feedback tools
DurationFor the term of your OptiReply subscription
NatureCollection, storage, analysis, and display of review and feedback data
PurposeEnabling businesses to manage and respond to reviews and customer feedback
Data typesCustomer names, review or feedback text, star ratings, contact information (where submitted), and timestamps
Data subjectsCustomers who have left reviews on a connected Google Business Profile or submitted feedback directly through OptiReply

Processing is conducted solely to deliver OptiReply services under your subscription.

No AI Training: We do not use data processed on your behalf — including data obtained through a connected Google Business Profile — to train, retune, or improve our AI models or any machine learning models. This data is used exclusively to deliver the services visible in your OptiReply dashboard: responding to reviews and providing business insights. All AI-generated responses are intended for human review and approval before being published.
4

Data Subject Rights

We will assist you in fulfilling data subject requests under applicable law (PIPEDA, GDPR where applicable). If a data subject contacts us directly, we will promptly redirect them to you as the Controller.

  • Right of access to personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability

We do not currently offer a self-service tool for deleting a single data subject's information independently of a full account deletion. If you need to fulfill a specific data subject's erasure request without deleting your OptiReply account, contact us at privacy@seven9it.com and we will assist you directly.

5

Sub-processors & International Transfers

We engage the following sub-processors to deliver OptiReply services. All sub-processors are bound by data protection obligations no less restrictive than this DPA.

Sub-processorPurposeLocation
Google Cloud Platform (incl. Cloud SQL)Application and database hostingUnited States
StripePayment processingUnited States
AnthropicAI response generationUnited States
Google (Gemini API)AI response generationUnited States
ResendTransactional email deliveryUnited States
Google AnalyticsPlatform usage analyticsUnited States

We will notify you of any material changes to our sub-processor list with reasonable advance notice.

Some of our sub-processors operate outside Canada, primarily in the United States. As a result, personal data processed on your behalf may be transferred to and processed in a jurisdiction other than your own. Where this occurs, we use appropriate contractual and organizational safeguards, consistent with applicable privacy laws, to help ensure that data continues to receive an appropriate level of protection.

6

Security Measures

We implement technical and organizational measures designed to protect the personal data we process on your behalf, including:

  • Encryption of personal data in transit (TLS/HTTPS)
  • Role-based access controls limiting data access within the platform
  • Secure, hashed storage of account credentials
  • Access to our production infrastructure limited to authorized personnel

We are continuing to expand our operational monitoring and infrastructure access controls as the platform scales.

7

Data Breach Notification

In the event of a personal data breach, we will notify you without undue delay and within 72 hours of becoming aware of the breach, providing:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
8

Data Retention & Deletion

Upon termination of your subscription or upon your written request, we will delete or deactivate the personal data processed on your behalf as follows:

  • Most personal data — including reviews, feedback, business and location records, and account access data — is deleted immediately upon a verified deletion request.
  • Certain account, subscription, and billing records are retained in a restricted, access-limited state for as long as required for financial, audit, security, legal, or operational purposes, and are not used for any other purpose.
  • If your account is connected to a Google Business Profile, deletion removes our stored copy of the associated data. This does not automatically revoke the associated Google OAuth access on Google's side. We recommend also revoking OptiReply's access directly through your Google Account settings to fully disconnect the integration.

See our Data Deletion Policy for the full process.

9

Audit & Compliance

Upon reasonable written request, we will provide you with information reasonably necessary to demonstrate our compliance with this DPA, such as a summary of our security practices and sub-processor arrangements. Such requests may be made no more than once per calendar year, unless required by applicable law or following a verified security incident.

10

Confidentiality

We ensure that personnel authorized to process personal data on your behalf are subject to a duty of confidentiality with respect to that data.

11

Liability

Liability arising under this DPA is subject to the limitation of liability set out in our Terms of Service.

12

Governing Law

This DPA is governed by the laws of the Province of Ontario, Canada, and the federal laws of Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

13

Contact

For DPA-related inquiries:

OptiReply — Seven9IT Solutions Whitby, Ontario, Canada privacy@seven9it.com www.optireply.com