Privacy Policy & Data Processing Agreement (DPA)

Last updated: December 24, 2025

Protecting your data is a priority for GetGoodReputation.com (published by GoodReputation). This document aims to inform you transparently about how we collect, use, and protect your personal data, and about our commitments as a processor of your own customer data.

PART 1: PRIVACY POLICY

(Platform users)

1. Data controller

The data controller is GoodReputation, registered with the RCS of Marseille under number 104 651 955, with headquarters at 25 Boulevard des Dames, 13002 Marseille.

2. Data collected

We collect the information necessary to provide the service:

  • Identity and contact: first name, last name, email address, phone number.
  • Business data: company name, address, Google Business Profile link.
  • Billing data: payment details (processed via Stripe).
  • Statistical data: IP address, cookies.

3. Purposes of processing

  • Managing your account and access to the platform.
  • Performing the contract (billing, technical support).
  • Sending service-related communications (alerts, updates).

4. Data retention

Data is retained for the duration of your subscription. In case of termination, billing data is retained for 10 years (legal obligation), and other data is deleted or anonymized within 12 months.

PART 2: DATA PROCESSING AGREEMENT

(DPA - Art. 28)

1. Purpose and scope

When using GetGoodReputation.com, you may import your own customer data (gender, last name, first name, emails, and phone numbers) to send review requests by email or SMS.

2. Obligations of GetGoodReputation.com (Processor)

  • Instruction: Process your customers' data only on your documented instructions and solely for the purpose of requesting reviews.
  • Confidentiality: Ensure that authorized personnel are bound by a confidentiality obligation.
  • Security: Implement appropriate technical measures (SSL encryption, secure backups) to protect this data.
  • Compliance assistance: Help you, where possible, respond to requests for the exercise of rights of your own customers (access, deletion).

3. Obligations of the User (Controller)

  • You have collected your customers' data lawfully (consent or legitimate interest).
  • You have informed your customers that a third party (GetGoodReputation.com) may process their data for sending review requests.

4. Sub-processors

  • Hostinger: Data hosting (servers in the European Union).
  • Stripe: Payment processing.
  • SMS/Email providers: For the technical delivery of requests.

PART 3: SECURITY AND DATA SUBJECT RIGHTS

1. Security

We implement rigorous security protocols to prevent unauthorized access to imported data. Data is hosted on secure servers located within the European Union.

2. Your Rights

In accordance with GDPR, you have the following rights over your own data:

  • Right of access, rectification, and erasure.
  • Right to data portability.
  • Right to object or restrict processing.
  • To exercise these rights, you can contact us at: contact@getgoodreputation.com.

3. Cookies

GoodReputation uses cookies essential to the platform's operation (authentication). For audience measurement or marketing cookies, your consent is collected via our cookie banner on your first visit.

Why is this structure effective? 1. Clarity: You clearly separate your own data (Part 1) and the data of your customers' customers (Part 2). 2. Article 28 compliance: The DPA section is often missing from SaaS but is mandatory for your customers (businesses) to be compliant. 3. Location: You reassure about EU hosting (via Hostinger), which is a major sales argument.

legal.privacy.subscription_note