Legal

Data Processing Agreement

📅 Effective: March 2026 🏢 Seven9IT Solutions 📍 Toronto, Ontario, Canada
Table of Contents
  1. Definitions
  2. Roles & Responsibilities
  3. Nature of Processing
  4. Data Subject Rights
  5. Sub-processors
  6. Security Measures
  7. Data Breach Notification
  8. Data Retention & Deletion
  9. Governing Law
  10. Contact
Section 01

Definitions

Section 02

Roles & Responsibilities

When you use OptiReply to process customer review data from your Google Business Profile, you act as the Controller and Seven9IT Solutions acts as the Processor.

We process your customer data only on your documented instructions — specifically, to provide the OptiReply platform services you have subscribed to.

We will not process personal data for any purpose beyond delivering the agreed services without your explicit written consent.

Section 03

Nature of Processing

CategoryDetails
Subject matterCustomer review management and AI response generation
DurationFor the term of your OptiReply subscription
NatureCollection, storage, analysis, and display of review data
PurposeEnabling businesses to manage and respond to Google reviews
Data typesCustomer names, review text, star ratings, timestamps
Data subjectsCustomers who have left reviews on your Google Business Profile

Processing is conducted solely to deliver OptiReply services under your subscription.

Google API Data — No AI Training: We do not use data obtained through Google Business Profile APIs to train, retune, or improve our AI models or any machine learning models. Google API data is used exclusively to deliver the services visible in your OptiReply dashboard — responding to reviews and providing business insights. All AI-generated responses are intended for human review and approval before being published to Google.
Section 04

Data Subject Rights

We will assist you in fulfilling data subject requests under applicable law (PIPEDA, GDPR where applicable). If a data subject contacts us directly, we will promptly redirect them to you as the Controller.

Section 05

Sub-processors

We engage the following sub-processors to deliver OptiReply services. All sub-processors are bound by data protection obligations no less restrictive than this DPA.

Sub-processorPurposeLocation
SupabaseDatabase & authenticationAWS us-east-1
StripePayment processingUnited States
VercelFrontend hostingGlobal CDN
Google CloudAPI servicesUnited States
AI providersResponse generationUnited States

We will notify you of any material changes to our sub-processor list with reasonable advance notice.

Section 06

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Section 07

Data Breach Notification

In the event of a personal data breach, we will notify you without undue delay and within 72 hours of becoming aware of the breach, providing:

Section 08

Data Retention & Deletion

Upon termination of your subscription or upon your written request, we will delete or return all personal data processed on your behalf within 30 days, unless retention is required by applicable law.

See our Data Deletion Policy for the full process.

Section 09

Governing Law

This DPA is governed by the laws of the Province of Ontario, Canada, and the federal laws of Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA).

Section 10

Contact

For DPA-related inquiries:

OptiReply — Seven9IT Solutions

📍 Toronto, Ontario, Canada

📧 privacy@seven9it.com

🌐 www.optireply.com