Data Processing Addendum
Effective September 3, 2026. Raveful is operated by a sole proprietor registered in Israel. The registered name and postal address are provided on request to the email below, on every invoice, and to any supervisory authority. Contact: support@raveful.app
This Addendum forms part of the Terms of Service between the customer ("Controller") and the operator of Raveful ("Processor") whenever the customer uses Raveful to process personal data of its own customers. It is designed to satisfy Article 28 of the GDPR and UK GDPR. No signature is needed; it applies automatically. A countersigned copy is available on request.
1. Subject matter and duration
Processing of testimonial data (names, titles, companies, ratings, written answers, video, audio, captions, consent records) for the purpose of collecting, moderating, and publishing testimonials, for as long as the customer has an account.
2. Processor obligations
- Process personal data only on the Controller's documented instructions, which are the Terms, this Addendum, and the settings the Controller chooses in the product.
- Ensure staff with access are bound by confidentiality.
- Apply the technical and organisational measures in section 5.
- Engage sub-processors only under section 4.
- Assist the Controller with data-subject requests, security, breach notification, and impact assessments, taking into account the nature of the processing.
- Notify the Controller of a personal data breach without undue delay, and in any case within 48 hours of becoming aware.
- On termination, delete or return all personal data within 30 days (backups within 90 days) unless the law requires storage.
- Make available the information needed to demonstrate compliance and allow audits, at most once a year on 30 days' notice, at the Controller's cost, or by providing recent third-party audit reports of our sub-processors.
3. Controller obligations
The Controller warrants it has a lawful basis for the data it collects through Raveful, provides its own privacy notice to submitters, and gives only lawful instructions.
4. Sub-processors
The Controller gives general authorisation for the sub-processors listed below. We will email account holders at least 14 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and, if we cannot resolve it, terminate with a pro-rata refund of prepaid fees.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Frankfurt, Germany) |
| Vercel Inc. | Hosting, CDN, privacy-friendly analytics (no cookies) | USA and EU edge |
| Polar Software Inc. | Merchant of record: checkout, subscriptions, invoices, taxes | USA |
| Groq Inc. | Speech-to-text for video captions | USA |
| Resend Inc. | Transactional email | USA |
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Per-workspace row-level security enforced in the database; least-privilege service keys.
- Hashed passwords, rate limiting on authentication, secrets held only in the hosting provider's encrypted configuration.
- Daily encrypted backups in the EU; point-in-time recovery.
- Logged administrative access; annual review of access rights.
6. International transfers
Personal data is stored in the EU. Where a sub-processor processes data outside the EU/UK, the transfer is covered by an adequacy decision, the EU-US Data Privacy Framework, or the Standard Contractual Clauses (Module 3, processor to processor) with the UK Addendum. The Standard Contractual Clauses (Module 2, controller to processor) are incorporated between the Controller and the Processor to the extent the Controller is in the EU/UK and the Processor is outside it.
7. Liability
Liability under this Addendum is subject to the limits in the Terms of Service, except where the GDPR does not allow limitation.