Sub-Processors & Data Processing

Third-party service providers that process data on our behalf

GDPR Article 28 Compliance

In accordance with GDPR Article 28, we maintain a transparent list of all third-party sub-processors that process personal data on our behalf. Each processor has a signed Data Processing Agreement (DPA) in place. We will notify users of any changes to this list at least 30 days before a new sub-processor begins processing personal data.

Data Controller

Entity: 5S Reviews

Role: Data Controller (GDPR Art. 4(7))

DPO Contact: support@5sreviews.com

Data Transfer Mechanism: Standard Contractual Clauses (SCCs)

8

Sub-Processors

8

Active DPAs

0

Pending Changes

Sub-Processor List

Supabase Inc.

DPA Active
Purpose: Database hosting, user authentication, and real-time data services
Data Processed: User accounts, business data, reviews, AI responses, consent records
Data Location: United States (AWS us-east-1)

Stripe, Inc.

DPA Active
Purpose: Payment processing, subscription management, tax calculation, and invoicing
Data Processed: Billing information, subscription details, payment methods, tax IDs
Data Location: United States

Anthropic PBC (Claude AI)

DPA Active
Purpose: Primary AI language model for generating review responses
Data Processed: Review text, business context, brand voice preferences
Data Location: United States

OpenAI, LLC

DPA Active
Purpose: Fallback AI language model for review response generation
Data Processed: Review text, business context
Data Location: United States

Resend, Inc.

DPA Active
Purpose: Transactional and notification email delivery
Data Processed: Email addresses, email content, delivery metadata
Data Location: United States

Twilio Inc.

DPA Active
Purpose: SMS and WhatsApp notification delivery for review approvals
Data Processed: Phone numbers, message content, delivery status
Data Location: United States

Google LLC

DPA Active
Purpose: OAuth authentication, Google Business Profile API, Google Places API
Data Processed: Google account info, business profile data, review data, place information
Data Location: United States

Functional Software (Sentry)

DPA Active
Purpose: Application error monitoring and performance tracking (optional)
Data Processed: Error logs, stack traces, request metadata (no PII)
Data Location: United States

Sub-Processor Change Notifications

We will notify customers at least 30 days before engaging any new sub-processor or making material changes to existing sub-processor arrangements.

Notifications are sent to the account owner's email address. If you object to a new sub-processor, you may terminate your agreement by contacting support@5sreviews.com.

Request a Data Processing Agreement

Enterprise and business customers can request a signed DPA directly. Contact us at support@5sreviews.com with subject line "DPA Request" and we will provide a signed copy within 5 business days.

Related Policies