Rekly ← Back to Rekly
Legal

Data Processing Agreement

Last updated: 7 September 2026
Draft for review. This DPA reflects Rekly's actual data flows, but a data-protection lawyer should finalise it (including the Annexes and Standard Contractual Clauses) before it's offered to venues.

When Rekly handles personal data about your guests — for example an email a diner leaves to unlock your WiFi — you are the controller and Rekly is your processor. This agreement sets out how we process that data on your instructions, as Article 28 of the GDPR (and equivalent Albanian law) requires. It supplements our Terms of Service.

01Purpose

This DPA applies to personal data that Rekly processes on your behalf in providing the service. For your own account data, Rekly is the controller and the Privacy Policy applies instead.

02Roles of the parties

03Scope of processing (Annex 1)

Subject matterProviding Rekly's reputation, review-collection, menu and WiFi-capture features
DurationFor the term of your subscription, plus any short wind-down period
Nature & purposeCollecting, storing, organising and transmitting guest contacts; sending review invitations where you enable it
Types of dataGuest email addresses and/or phone numbers; associated timestamps and venue
Data subjectsYour guests and customers who interact with your Rekly-powered pages

04Rekly's obligations

05Your obligations

You confirm you have a lawful basis and, where required, valid consent to collect and process the guest data you gather through Rekly; that your own privacy notice tells guests about it; and that your instructions to us comply with the law. You control retention and deletion of your guest contacts.

06Sub-processors (Annex 2)

You authorise Rekly to engage sub-processors to deliver the service. Each is bound by data-protection terms equivalent to these, and we remain responsible for their performance. Current sub-processors:

Sub-processorFunctionLocation
GooglePlaces & Business Profile APIsEU / US (SCCs)
AI provider (Google Gemini / Anthropic)Drafting review repliesEU / US (SCCs)
StripePayment processingEU / US (SCCs)
Email providerSending transactional emailEU / US (SCCs)
Hosting providerApplication hosting & storageEU

We'll give you notice of any new or replacement sub-processor and a chance to object on reasonable data-protection grounds.

07International transfers

Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses (or the equivalent for Albania-based controllers), together with any needed supplementary measures.

08Security measures (Annex 3)

09Personal-data breaches

If we become aware of a personal-data breach affecting your data, we'll notify you without undue delay and give you the information you reasonably need to meet your own notification duties to the authority and affected individuals.

10Data-subject rights

Rekly provides self-service tools (for example exporting or deleting a venue's guest contacts) and will otherwise assist you in responding to access, deletion, correction and objection requests from your guests. If a guest contacts us directly about your data, we'll refer them to you as the controller.

11Deletion & return at the end

On termination, at your choice, we'll delete or return the guest personal data we hold for you and delete existing copies within a reasonable period, unless the law requires us to keep it. You can also delete guest contacts yourself at any time while the service is active.

Questions?

Email us at hello@rekly.co and we'll get back to you.

© 2026 Rekly Privacy Terms Cookies DPA Help Home