On this page
Definitions
- Controller — The business or individual using OptiReply who determines the purpose and means of processing personal data
- Processor — Seven9IT Solutions / OptiReply, acting on behalf of the Controller
- Personal Data — Any information relating to an identified or identifiable natural person
- Processing — Any operation performed on personal data, including collection, storage, retrieval, and deletion
- Data Subject — The individual whose personal data is being processed (e.g., your customers who leave reviews)
Roles & Responsibilities
Where you use OptiReply to process personal data — including customer review data from a connected Google Business Profile and feedback submitted directly through OptiReply's QR code and feedback tools — you act as the Controller and Seven9IT Solutions acts as the Processor.
We will not process personal data for any purpose beyond delivering the agreed services without your explicit written consent.
Nature of Processing
| Category | Details |
|---|---|
| Subject matter | Customer review management, AI response generation, and feedback collected through OptiReply's QR and feedback tools |
| Duration | For the term of your OptiReply subscription |
| Nature | Collection, storage, analysis, and display of review and feedback data |
| Purpose | Enabling businesses to manage and respond to reviews and customer feedback |
| Data types | Customer names, review or feedback text, star ratings, contact information (where submitted), and timestamps |
| Data subjects | Customers who have left reviews on a connected Google Business Profile or submitted feedback directly through OptiReply |
Processing is conducted solely to deliver OptiReply services under your subscription.
Data Subject Rights
We will assist you in fulfilling data subject requests under applicable law (PIPEDA, GDPR where applicable). If a data subject contacts us directly, we will promptly redirect them to you as the Controller.
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
We do not currently offer a self-service tool for deleting a single data subject's information independently of a full account deletion. If you need to fulfill a specific data subject's erasure request without deleting your OptiReply account, contact us at privacy@seven9it.com and we will assist you directly.
Sub-processors & International Transfers
We engage the following sub-processors to deliver OptiReply services. All sub-processors are bound by data protection obligations no less restrictive than this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (incl. Cloud SQL) | Application and database hosting | United States |
| Stripe | Payment processing | United States |
| Anthropic | AI response generation | United States |
| Google (Gemini API) | AI response generation | United States |
| Resend | Transactional email delivery | United States |
| Google Analytics | Platform usage analytics | United States |
We will notify you of any material changes to our sub-processor list with reasonable advance notice.
Some of our sub-processors operate outside Canada, primarily in the United States. As a result, personal data processed on your behalf may be transferred to and processed in a jurisdiction other than your own. Where this occurs, we use appropriate contractual and organizational safeguards, consistent with applicable privacy laws, to help ensure that data continues to receive an appropriate level of protection.
Security Measures
We implement technical and organizational measures designed to protect the personal data we process on your behalf, including:
- Encryption of personal data in transit (TLS/HTTPS)
- Role-based access controls limiting data access within the platform
- Secure, hashed storage of account credentials
- Access to our production infrastructure limited to authorized personnel
We are continuing to expand our operational monitoring and infrastructure access controls as the platform scales.
Data Breach Notification
In the event of a personal data breach, we will notify you without undue delay and within 72 hours of becoming aware of the breach, providing:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
Data Retention & Deletion
Upon termination of your subscription or upon your written request, we will delete or deactivate the personal data processed on your behalf as follows:
- Most personal data — including reviews, feedback, business and location records, and account access data — is deleted immediately upon a verified deletion request.
- Certain account, subscription, and billing records are retained in a restricted, access-limited state for as long as required for financial, audit, security, legal, or operational purposes, and are not used for any other purpose.
- If your account is connected to a Google Business Profile, deletion removes our stored copy of the associated data. This does not automatically revoke the associated Google OAuth access on Google's side. We recommend also revoking OptiReply's access directly through your Google Account settings to fully disconnect the integration.
See our Data Deletion Policy for the full process.
Audit & Compliance
Upon reasonable written request, we will provide you with information reasonably necessary to demonstrate our compliance with this DPA, such as a summary of our security practices and sub-processor arrangements. Such requests may be made no more than once per calendar year, unless required by applicable law or following a verified security incident.
Confidentiality
We ensure that personnel authorized to process personal data on your behalf are subject to a duty of confidentiality with respect to that data.
Liability
Liability arising under this DPA is subject to the limitation of liability set out in our Terms of Service.
Governing Law
This DPA is governed by the laws of the Province of Ontario, Canada, and the federal laws of Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
Contact
For DPA-related inquiries: