PRIVACY POLICY – REVIEWGUIDE
This is an English translation provided for convenience. In the event of any discrepancy, the Polish-language version prevails.
This Privacy Policy describes how personal data of users of https://reviewguide.eu (the "Service", "ReviewGuide") is processed, and the use of cookies. It fulfils the information obligation under Articles 13 and 14 GDPR.
1. Data controller
The controller of personal data is:
PEPE COMPANY sp. z o.o. ul. Świętokrzyska 18 / 405, 00‑052 Warsaw, Poland Tax ID (NIP): 5732861000, Court Register No. (KRS): 0000599316 E‑mail: contact@reviewguide.eu
(the "Controller").
The Controller has not appointed a Data Protection Officer. All data protection matters can be directed to the e‑mail above. (If a DPO is appointed in the future, their contact details will be provided here.)
2. Scope
- This Policy concerns the data of persons who: visit the Service, create an Account and use the Service (Customers — restaurants and their representatives), contact the Controller, or subscribe to marketing communications.
- Data of Google review authors. In providing the Service, the Controller also processes personal data contained in reviews published on Google (e.g. author name/nickname, review content). With respect to that data, the Controller acts as a rule as a processor on behalf of the Customer (restaurant), who is the controller of that data. The terms of such processing are set out in the Data Processing Agreement (DPA). This Policy primarily describes processing in which PEPE COMPANY sp. z o.o. is the controller.
3. Categories of data, purposes and legal bases
| Purpose | Categories of data | Legal basis (GDPR) |
|---|---|---|
| Registration and Account operation, providing the Service, login and Google integration | name, e‑mail, company/premises data, Google account identifiers, technical authentication data | Art. 6(1)(b) (performance of contract) |
| Processing payments and billing, issuing invoices | billing data, company data, transaction data (no full card data) | Art. 6(1)(b) and (c) (legal obligation — accounting, tax) |
| Handling complaints and enquiries | contact data, correspondence content | Art. 6(1)(b) and (f) (legitimate interest) |
| Compliance with legal obligations (tax, accounting) | data on invoices and records | Art. 6(1)(c) |
| Direct marketing of own services, newsletter | e‑mail, name | Art. 6(1)(f) (legitimate interest) or Art. 6(1)(a) (consent), depending on channel |
| Establishing, pursuing and defending claims | data necessary to pursue/defend claims | Art. 6(1)(f) |
| Analytics, security and improvement of the Service | technical data, logs, cookies | Art. 6(1)(f) and — for consent-based cookies — Art. 6(1)(a) |
4. Voluntary nature of providing data
Providing data is voluntary but necessary to conclude and perform the Agreement and use the Service. Failure to provide data required for registration, payment or Google integration makes it impossible to provide the Service.
5. Recipients of data
Personal data may be shared with the following categories of recipients, only to the extent necessary:
- hosting and cloud infrastructure providers (data storage and processing, databases), e.g. Amazon Web Services (AWS), Google Cloud, Vercel;
- Stripe — the Payment Operator handling recurring payments (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA);
- providers of artificial intelligence models and services used to generate responses to reviews, e.g. OpenAI, Anthropic, Google;
- Google — in connection with the Google Business Profile integration (Google Ireland Limited / Google LLC);
- providers of transactional and marketing e‑mail services (notifications, newsletter), e.g. Amazon SES, SendGrid (Twilio), Postmark, Brevo, Mailchimp;
- providers of analytics tools (statistics and improvement of the Service), e.g. Google Analytics;
- providers of customer support tools (chat, help desk, CRM), e.g. Intercom, Crisp, HubSpot;
- providers of accounting, legal and advisory services (accounting office, law firm, advisors);
- authorised public authorities — on the basis of law;
- review-data providers (Dane opinii / review data provider) — third parties that collect and make available to the Controller publicly available Google review data (e.g. author name/nickname, review content, rating, date) for the purpose of providing the Service, in particular Outscraper (possible transfer of data outside the EEA, based on Standard Contractual Clauses — SCC).
The list above covers categories of recipients and typical providers used within the Service; the Controller uses a selection of them according to the tools actually implemented. A current list of key processors (sub-processors) forms an annex to the Data Processing Agreement (DPA) and is available on request.
Entities processing data on the Controller's behalf do so under data processing agreements and only per the Controller's instructions.
6. Transfers outside the EEA
Some of the providers used by the Controller — in particular providers of artificial intelligence services (e.g. OpenAI), Google services, Stripe, the review-data provider (Outscraper) and cloud infrastructure providers — may process personal data outside the European Economic Area (EEA), including in the United States. In such cases, transfers take place on the basis of appropriate safeguards under Chapter V GDPR, in particular:
- a European Commission adequacy decision, including under the EU–U.S. Data Privacy Framework — for providers certified under that programme, or
- Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where necessary by additional safeguards.
A copy of the safeguards applied, or information on where they are available, can be obtained by contacting the Controller at contact@reviewguide.eu.
7. Retention periods
- Account and Service data — for the term of the Agreement and, thereafter, for the limitation period for claims.
- Billing data and accounting records — for the period required by law (as a rule 5 years from the end of the relevant tax year).
- Data processed on the basis of consent — until consent is withdrawn.
- Data processed on the basis of legitimate interest (including marketing) — until an effective objection is raised or the purpose ceases.
8. Rights of data subjects
Data subjects have the right to:
- access their data and obtain a copy;
- rectification;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability;
- object to processing based on legitimate interest, including direct marketing;
- withdraw consent at any time (without affecting the lawfulness of processing before withdrawal);
- lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00‑193 Warsaw, Poland.
To exercise these rights, please contact the e‑mail in section 1.
9. Automated decision-making and profiling
- The Controller uses AI models to automatically generate proposed responses to reviews. This does not constitute automated decision-making producing legal or similarly significant effects on natural persons within the meaning of Article 22 GDPR — the generated content is a proposal, and the decision to publish is made by the Customer (a human).
- The Controller does not carry out profiling producing the effects referred to in Article 22 GDPR.
10. Data security
The Controller applies appropriate technical and organisational measures to ensure data security, adequate to the risks and categories of data, including encryption of transmission (SSL/TLS), access control and infrastructure safeguards.
11. Cookies
The use of cookies and similar technologies is described in a separate Cookie Policy available in the Service.
12. Changes to this Policy
The Controller may update this Policy. Material changes will be communicated in the Service or electronically. The current version applies from the date indicated above.