Data Processing Agreement (DPA)
Annex A to the Terms of Service — how we process your customers' data.
Last updated: 29/07/2026
Provider details
Trade name: Mapraise Reputation Marketing
Legal provider: FILIOS CHRISTOS (sole proprietorship)
VAT (ΑΦΜ): 178132130 · Activity code (ΚΑΔ): 73.11.11
Registered address: 11 Polykratous St., Peristeri 12134, Greece
Email: info@mapraise.com
This Agreement is entered into between the Customer (as defined in the Terms of Service), as data controller, and Mapraise (Christos Filios, VAT 178132130, registered in Peristeri), as data processor. It forms an integral Annex A to the Terms of Service and is accepted electronically together with them (Art. 28(9) GDPR — the written form includes the electronic form).
1. Subject matter & duration
Processing of the Customer's End Customer data for the provision of the Service, for as long as the contract lasts and until the actions of Article 11 have been completed.
2. Nature & purpose of processing
Entry/import of contacts; sending review invitations by SMS on behalf of the Customer; handling objection (opt-out) declarations; keeping records of consent/objection; producing reports for the Customer.
3. Type of data
Full name, mobile phone number, date of visit, consent/objection metadata (dates, channel, source, sending records), as well as the content/text of reviews analysed through the Service. There is no processing of special categories of data (Art. 9), nor of data of minors to the knowledge of the parties.
4. Categories of data subjects
The Customer's own customers (End Customers — consumers).
5. Processing on documented instructions only (Art. 28(3)(a))
Mapraise processes the data solely on the documented instructions of the Customer — as set out in the Terms, in this Agreement and in the settings of the Service — including transfers to third countries, unless required by EU or Member State law (in which case it informs the Customer beforehand, unless that is prohibited). If Mapraise considers that an instruction infringes the GDPR or another provision, it informs the Customer without delay.
5.1 No model training (AI): Mapraise ensures that End Customers' personal data is not used to train the foundation models of Mapraise or of its sub-processors (e.g. Anthropic), but only to produce the output (inference) requested by the Customer.
6. Confidentiality (point (b))
The persons processing the data on behalf of Mapraise are bound by an obligation of confidentiality.
7. Security (point (c), Art. 32)
Mapraise implements the appropriate technical and organisational measures set out in Annex B.
8. Sub-processors (point (d), Art. 28(2) & (4))
8.1. The Customer gives general written authorisation for the sub-processors listed in table 8.4. Mapraise informs the Customer of intended additions/replacements 14 days in advance, by email to the Customer's administrator email address or by notice in the application (dashboard), with a right to object; if the Customer objects and no workable alternative exists, either party may terminate without penalty.
8.2. Mapraise imposes on its sub-processors the same data protection obligations as those in this Agreement and remains fully liable to the Customer for their performance.
8.3. Transfers outside the EEA take place only with appropriate safeguards (EU Standard Contractual Clauses or an equivalent mechanism).
8.4. Approved sub-processors as at the effective date:
| Sub-processor | Role | Location / Transfer |
|---|---|---|
| HighLevel Inc. (GoHighLevel / LeadConnector) | CRM & automations | USA — SCCs |
| Yuboto Ltd | SMS delivery | Greece |
| Cloudflare Inc. | Network/infrastructure (redirects, workers) | USA/EU — SCCs |
| Google LLC | Email/tooling infrastructure | USA/EU — SCCs |
| Stripe | Payments (Customer data, not End Customer data) | USA/EU — SCCs |
| Anthropic PBC | AI text processing (e.g. replies to reviews) | USA — SCCs |
9. Assistance with data subject rights (point (e))
Mapraise assists the Customer, by appropriate technical and organisational measures, in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection). Requests received directly by Mapraise are forwarded to the Customer without undue delay and at the latest within seven (7) business days. Objections to SMS are executed automatically and immediately by the systems of the Service, as a standing instruction of the Customer.
10. Assistance with security & breaches (point (f), Art. 32–36)
Mapraise assists the Customer in complying with Art. 32–36, taking into account the information available. In the event of a personal data breach concerning the List, Mapraise informs the Customer without undue delay, within 48 hours from the moment Mapraise establishes with certainty that the breach has occurred, providing the information required by Art. 33(3).
11. Deletion or return on termination (point (g))
On termination of the Service, and at the Customer's choice: (a) return of a full copy of the List (together with the consent/objection records) in a common machine-readable format — the default, consistent with the ownership section of the Terms of Service — and (b) deletion of the data and its copies from Mapraise's systems within 30 days, unless EU or Member State law requires retention. Exception: the objection (opt-out) register is retained to the extent required so that the objection continues to be respected.
12. Demonstrating compliance & audits (point (h))
Mapraise makes available to the Customer all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits/inspections by the Customer or an auditor mandated by the Customer, on reasonable notice of 15 business days, once every 12 months except following an incident, without access to the data of other Mapraise customers. Such audits will be carried out primarily by way of security questionnaires and/or certificates provided by Mapraise. An on-site audit is permitted only where the above are insufficient to demonstrate compliance, will be conducted at the Customer's expense, and without disrupting the proper operation of Mapraise.
13. Liability & Indemnity
13.1. Allocation under the GDPR: Pursuant to Article 82 GDPR, Mapraise (as processor) is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful documented instructions of the Customer.
13.2. Mutual indemnity for fines & claims: Each party (the "Responsible Party") agrees to indemnify and hold the other party harmless from any third-party claim, proven damage or administrative fine imposed by the Data Protection Authority, to the extent that it was caused by a culpable breach of the Responsible Party's obligations under this Agreement or the GDPR.
13.3. Specific liability of the Customer: The Customer bears sole responsibility and undertakes to indemnify Mapraise in full where a fine is imposed on, or a claim is raised against, Mapraise as a result of the Customer's failure to secure a lawful basis (e.g. lack of consent of End Customers before entering them into the Service) or as a result of the Customer's unlawful instructions.
13.4. Limitation of liability: Subject to any mandatory law (e.g. for wilful misconduct or gross negligence), Mapraise's total contractual liability under this Annex is expressly subject to the limitations and liability caps set out in the Terms of Service.
14. Duration, governing law, version
This Agreement applies for as long as the Terms of Service apply. Greek law, courts of Athens. Version v2.0 — 29 July 2026, accepted electronically together with the Terms (recorded in accordance with Article 5 of the Terms).
ANNEX B — Technical & organisational measures
- Access control: Named accounts, least necessary access, 2FA on the administrative systems (GHL, Cloudflare, Google, Yuboto).
- Encryption: Data in transit exclusively over TLS; encryption at rest by the infrastructure providers.
- Secrets management: No credential/API key in documents or conversations; storage only in the corresponding systems (Worker secrets etc.).
- Customer separation: A separate environment (sub-account) per customer; no cross-referencing of data between customers.
- Enforcement of objections: A DND/blacklist mechanism applied automatically on every send, with a field recording the date of objection.
- Logging: Retention of send logs and of consent change records.
- Minimisation: Only name, mobile number and date of visit are collected — no End Customer email in Phase A.
- Backup policy: Regular, encrypted backups of the data through the approved infrastructure providers, in order to ensure the availability of the data and immediate restoration in the event of a physical or technical incident.
- Incident response: A procedure exists for the immediate identification, assessment and containment of security incidents. Where a data breach is established, Mapraise notifies the Customer without undue delay and provides assistance in accordance with Article 10 of this Agreement.
- Staff training & confidentiality: Every employee, agent or external contractor of Mapraise (if and when there is one) who gains access to the data is bound by written confidentiality and non-disclosure clauses (NDA) and receives appropriate briefing/training on data protection principles (GDPR).
Version 2.0 — July 29, 2026