Sam Gets Reviews
← Back to home

Data Processing Agreement

Last updated: 21 September 2026

Important status note

This document reflects the system audit completed on 21 September 2026. Items marked “owner confirmation required” are intentionally unresolved; no legal detail, transfer safeguard, retention period, certification or notification process has been assumed.

This DPA is written for Sam’s current service and should be read with the Privacy Policy and Terms of Service.

1. Parties and roles

This Data Processing Agreement (DPA) forms part of the agreement between the client business using Sam Gets Reviews (Controller) and Minotaur Media Limited, trading as Sam Gets Reviews (Processor), where the Processor handles personal data on the Controller’s behalf.

The Controller determines why and how its customer data is used. The Processor will process that data only on the Controller’s documented instructions, including service settings and authorised integrations, unless UK law requires otherwise. If law requires other processing, the Processor will inform the Controller beforehand unless legally prohibited.

For account administration, billing, service security and Sam’s own website enquiries, Sam may act as a controller rather than a processor. Those activities are governed by the Privacy Policy.

2. Subject matter and duration

The subject matter is the provision of Sam’s review-request, reputation-management, Google Business Profile, integration, reporting and automation services. Processing begins when the Controller supplies data, connects an integration or enables a relevant feature, and continues while the service is provided or records are retained on the Controller’s instructions.

Cancellation currently stops or limits access and automation but does not automatically erase all client data. Data is deleted or returned on a verified request or through an authorised administrative deletion process, subject to applicable legal retention and the current limitations in section 12. No fixed post-termination deletion period is claimed.

3. Nature and purpose of processing

  • Importing, validating, normalising, deduplicating and storing customer contact records.
  • Sending and tracking review requests and reminders by email, SMS or WhatsApp according to region, consent, opt-out, spacing and account settings.
  • Personalising review-request text and, where enabled, images or other media.
  • Receiving customer, job or invoice data from authorised Jobber, Xero, Zapier or webhook connections.
  • Reading Google Business Profile details and reviews; drafting, approving and publishing review replies where enabled.
  • Preparing or publishing Google Business Profile and optional social content, including analysing uploaded work photos or videos.
  • Matching review activity to requests and producing dashboards, summaries, insights, reports and operational logs.
  • Operating subscriptions, support, security monitoring, abuse controls and service administration.

4. Categories of data subjects

  • Customers and previous customers of the Controller.
  • Prospective customers or referred leads where the Controller lawfully supplies or enables collection of their details.
  • Google reviewers whose public review data is available through the connected Business Profile.
  • The Controller’s owners, staff, account users and authorised integration users.

5. Types of personal data

The service is not designed to receive special-category or criminal-offence data. The Controller must not upload such data unless strictly necessary, lawful, documented and separately agreed. Free-text reviews may nevertheless contain sensitive information entered by third parties; this is not permission to upload sensitive datasets.

  • Names, first names, phone numbers, email addresses and contact preferences.
  • Job, visit, service, invoice and transaction context, including completion or payment dates, staff member, value and currency where supplied.
  • Source-system identifiers, integration metadata, import filename, file type, row number and deduplication information.
  • Review-request messages, delivery status, provider identifiers, click activity, IP address and user agent where recorded.
  • Consent, attestation, unsubscribe, SMS opt-out and suppression records.
  • Google reviewer display name, rating, review text, date, replies and related analysis.
  • Private feedback, referral details, uploaded photos or videos, notes and AI quality assessments where those features are used.
  • Client account, business profile, connected-platform, support and billing metadata.

6. Processor obligations

  • Process personal data only on documented instructions and tell the Controller if an instruction appears to infringe applicable data-protection law.
  • Ensure authorised personnel are subject to confidentiality obligations and access data only as required.
  • Maintain appropriate technical and organisational measures proportionate to the processing and risks in Annex B.
  • Taking account of the processing, reasonably assist with data-subject requests and with security, breach, DPIA and regulatory consultation duties.
  • At the Controller’s choice, delete or return personal data at the end of services unless law requires retention, subject to the limitations recorded here.
  • Provide information reasonably necessary to demonstrate compliance and permit proportionate audits on reasonable notice, protecting other clients and security.
  • Keep records needed to evidence instructions, security events, consent and opt-out handling, and authorised administrative actions.

7. Sub-processors and connected recipients

The providers below were identified in the current service. “Controller-enabled” means the Controller chooses to connect or use that service; it may act under its own terms and is not necessarily Sam’s sub-processor for every client.

Locations shown as requiring confirmation were not established from current code or supplier contracts. No jurisdiction is inferred from a provider’s brand or headquarters.

ProviderPurpose and dataStatus / location
Base44Managed hosting, database, authentication, functions, workflows, file storage and built-in AI integration; may process all service data stored or routed through Sam.Confirmed platform provider. Documentation says US storage is the default; this app’s selected residency and plan require owner confirmation.
TwilioSMS and WhatsApp delivery, templates, inbound keywords and delivery callbacks; phone numbers, message content, consent, opt-out and provider metadata.Confirmed. Processing locations and transfer terms require owner confirmation.
ResendTransactional and review-request email delivery; recipient name/email, business sender details and message content.Confirmed. Processing locations and transfer terms require owner confirmation.
StripeSubscription checkout, billing and webhooks; client email, business identifier, customer/subscription/payment status. Customer review contacts are not ordinarily sent.Confirmed. Processing locations and transfer terms require owner confirmation.
Google Business Profile APIsOAuth, business details, reviews, replies, posts, profile media and aggregate metrics.Controller-enabled. Processing locations and applicable terms require owner confirmation.
Base44 Core AI and configured modelsDrafting replies, posts, recommendations and insights; prompts can contain business data, reviewer name/text and uploaded image URLs.Confirmed use. The contractual AI provider chain, retention and locations require confirmation from supplier terms.
Meta (Facebook and Instagram)Optional social publishing; page/account identifiers, post captions, review excerpts and media.Controller-enabled. Location and transfer terms require owner confirmation.
JobberSource of authorised client, job and completed-visit information used to prepare review requests.Controller-enabled data source. Controller remains responsible for its Jobber relationship.
XeroSource of paid-invoice and contact data used to identify review-request candidates.Controller-enabled data source. Controller remains responsible for its Xero relationship.
ZapierTransfers completed-job or customer payloads selected by the Controller into Sam.Controller-enabled integration. Zapier terms and location require Controller review.
ipapi.coReceives a website visitor’s IP address to return country for regional pricing and content; timezone is the fallback.Confirmed on the public website. Jurisdiction and retention require owner confirmation.
OutscraperAdmin prospecting and public Google Maps search/review retrieval; search queries and public business/reviewer data.Confirmed configuration. Not routine client-customer messaging; location and terms require owner confirmation.
Local FalconOptional local-search grid scanning using business place ID, keyword and coordinates.Code exists, but an active credential was not confirmed. Include only if enabled; location and terms require owner confirmation.

8. Sub-processor changes

The Controller gives general written authorisation for the confirmed providers in section 7, subject to a right to object on reasonable data-protection grounds.

Current gap: Sam does not have a verified automated or contractual process for advance notice of material sub-processor additions or replacements. Before this DPA is relied upon as signed, the owner must adopt a notification method, notice period and objection process and maintain an authoritative register. This page is not evidence that notifications already occur.

9. International transfers

Base44 documentation states that US storage is the default, while some plans can select EU or UK storage; uploaded media and some account or billing data may remain in the US. The actual setting for this app has not been confirmed. Other providers operate internationally and may process data outside the UK.

The code does not establish whether supplier contracts rely on UK adequacy regulations, the UK IDTA, the UK Addendum to the EU SCCs or another safeguard. The owner must verify and document the mechanism for each restricted transfer. Sam does not claim a safeguard merely because a supplier commonly offers it.

10. Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting data processed under this DPA and provide available information reasonably needed for assessment, notification and remediation. This differs from the Controller’s own duty, where applicable, to notify the ICO within 72 hours of becoming aware of a reportable breach.

Current controls record provider failures, unusual volumes, admin actions and operational health issues. Current gap: no complete documented breach-classification, escalation, client-contact and post-incident process was confirmed. The owner must approve and operationalise that process and identify the incident contact.

11. Data-subject rights

Taking account of the nature of processing, Sam will reasonably assist with access, rectification, erasure, objection, restriction and portability requests where applicable. The Controller remains responsible for validating the request, deciding the lawful response and communicating with the data subject.

If a customer contacts Sam directly about data processed for a client, Sam should identify and refer the request to the relevant Controller unless law requires a direct response. A standard internal request-routing procedure and response contact were not confirmed and require owner implementation.

12. Data retention and deletion

Action required: adopt and technically enforce a retention schedule by category; complete and verify client deletion across every entity and stored file; define backup expiry; reconcile Facebook deletion wording; and specify limited billing, consent, suppression and audit evidence retained for law or claims. No invented general 30-day promise is made.

  • Customer and review-request records: no general automatic retention period was found. Records remain until individually deleted or included in administrative client deletion.
  • Cancellation: changes billing or access and pauses automation; it does not itself erase stored customer, review, message or integration records.
  • CSV/XLS/XLSX imports: the original file is parsed in the user’s browser and is not uploaded by that flow. Normalised contacts and source filename, type, session and row metadata are stored. Browser memory is released when the session or page ends.
  • Jobber webhook events: raw payloads are not stored; hashes and metadata for processed or ignored events are deleted daily after 30 days. Resulting customer, request and activity records are not deleted by that job.
  • Google disconnect: connection records and tokens are deleted and profile connection fields cleared; previously synced reviews and related records remain until separately deleted.
  • Jobber disconnect: encrypted tokens are cleared, while historical integration, customer and request records remain.
  • Facebook deletion callback: currently deletes Facebook connection records only. Existing broader 30-day deletion wording is not fully matched by the callback and requires correction.
  • Full client deletion: a super-admin routine attempts deletion of many business-scoped records and keeps a minimal audit entry. It omits some entity types, treats individual failures as non-fatal and does not confirm deletion of uploaded file objects.
  • Base44 platform deletion and backups: documentation says deleted records may remain recoverable for 30 days; plan-dependent database backup retention may be 7 or 30 days. This app’s plan, backup settings and file-storage deletion behaviour require owner confirmation.
  • Legal retention: no complete schedule for billing, consent, opt-out, audit or dispute records was confirmed.

13. Security measures

Confirmed measures are listed in Annex B. Security is risk-based and no system is completely secure. Sam does not claim ISO certification, SOC 2 certification, PCI certification, routine penetration testing, a dedicated DPO or mandatory MFA because those claims were not established for Sam. Provider certifications are not presented as Sam certifications.

14. Controller responsibilities

  • Establish and document a lawful basis for supplying and instructing Sam to process personal data.
  • Ensure supplied data is accurate, relevant and limited to what is necessary.
  • Comply with UK GDPR, PECR and applicable privacy, direct-marketing and electronic-communications rules.
  • Determine whether each request, reminder, referral or message is lawful for the relationship and territory; legitimate interests must be assessed, not assumed.
  • Record and honour consent, objection, suppression and opt-out requirements and promptly communicate relevant changes.
  • Configure users and integrations appropriately, protect credentials and review automated content/settings where human approval is appropriate.
  • Not upload unnecessary special-category, criminal-offence, confidential or unrelated information.

15. Legal and privacy contacts

  • Processor: Minotaur Media Limited, trading as Sam Gets Reviews.
  • Service and privacy email currently used by the application: support@samgetsreviews.com.
  • Registered company number: OWNER CONFIRMATION REQUIRED.
  • Registered office and service address: OWNER CONFIRMATION REQUIRED.
  • ICO registration number, if applicable: OWNER CONFIRMATION REQUIRED.
  • Data-protection and incident-response contact: OWNER CONFIRMATION REQUIRED. No DPO is claimed.

Annex A — Processing details

ItemProcessing detail
ControllerThe client business identified in the Sam account, order or service agreement.
ProcessorMinotaur Media Limited, trading as Sam Gets Reviews.
Subject matterReview requests, review and reputation management, connected customer-data sources, Google Business Profile content, reporting and automation.
DurationFor the service term and thereafter until deletion or return under documented instructions and the verified retention process. No fixed general deletion period is currently enforced.
Nature and purposeCollection, import, recording, organisation, normalisation, matching, storage, retrieval, analysis, AI-assisted generation, transmission, publication, restriction and deletion for the purposes in section 3.
Data subjectsClient customers and previous customers, lawfully supplied prospects or referred leads, Google reviewers, and client account users or staff.
Personal dataContact details; job, service and invoice context; review and message data; consent and opt-out records; identifiers and integration metadata; account and business data; optional feedback, referrals and media.
Special-category dataNot intentionally required. Clients must not supply it without necessity, lawful basis and prior written agreement.

Annex B — Confirmed security measures

  • Managed HTTPS/TLS for the hosted application; Base44 states platform data is encrypted in transit and at rest.
  • Google, Jobber, Xero and Facebook OAuth tokens are encrypted before database storage using AES-GCM 256 with per-record salt and IV and backend-held keys; secrets are held in platform secret storage, not frontend code.
  • Authentication, per-entity row access rules, owner scoping and server-enforced support, admin and super-admin roles for privileged operations.
  • Signed or hashed OAuth state, signed Stripe, Jobber and Meta callbacks, authenticated webhooks or API keys, payload validation and bounded payload sizes.
  • Operational rate limits, daily and spacing limits, opt-out guards, idempotency keys, queue claims, retry limits and global circuit-breaker controls for messaging and automation.
  • Administrative action logs, provider and delivery logs, health-issue records and abnormal-volume alerts. These are monitoring controls, not a complete incident-response programme.
  • Client-side parsing of customer CSV and Excel files so original customer-list files are not uploaded by that flow.
  • Restricted backend access to integration tokens; token values are not returned to the browser and code paths avoid logging credentials.
  • Test-account suppression intended to prevent real outbound messages during controlled tests.
  • Verified deletion actions require elevated admin access and explicit confirmation, although completeness limitations are recorded in section 12.

Annex C — Claims not made

The audit did not verify the following, so this DPA deliberately does not claim them:

  • Sam-specific ISO 27001, SOC 2, PCI DSS or other certification.
  • Mandatory MFA for all Sam administrative or client accounts.
  • A fixed penetration-testing or vulnerability-scanning schedule for Sam.
  • A confirmed UK data-residency configuration for this app.
  • This app’s backup plan, restore testing, retention and uploaded-file backup behaviour.
  • A documented employee security-training, access-review or device-management programme.
  • A complete tested breach-response and client-notification playbook.
  • Executed UK transfer safeguards and Article 28 terms for every provider.

Agreement and precedence

This DPA applies when incorporated into a signed order, service agreement or other documented acceptance. If it conflicts with the main agreement on personal-data protection, this DPA prevails to that extent. The unresolved owner-confirmation items must be completed before relying on this page as an executed agreement.