Data Processing Agreement
Last updated: 7 September 2026When Rekly handles personal data about your guests — for example an email a diner leaves to unlock your WiFi — you are the controller and Rekly is your processor. This agreement sets out how we process that data on your instructions, as Article 28 of the GDPR (and equivalent Albanian law) requires. It supplements our Terms of Service.
01Purpose
This DPA applies to personal data that Rekly processes on your behalf in providing the service. For your own account data, Rekly is the controller and the Privacy Policy applies instead.
02Roles of the parties
- You (the venue) are the Controller — you decide to collect guest data and for what purpose.
- Rekly is the Processor — we process that data only to run the service and only on your documented instructions (these terms and your settings are those instructions).
03Scope of processing (Annex 1)
| Subject matter | Providing Rekly's reputation, review-collection, menu and WiFi-capture features |
| Duration | For the term of your subscription, plus any short wind-down period |
| Nature & purpose | Collecting, storing, organising and transmitting guest contacts; sending review invitations where you enable it |
| Types of data | Guest email addresses and/or phone numbers; associated timestamps and venue |
| Data subjects | Your guests and customers who interact with your Rekly-powered pages |
04Rekly's obligations
- Process personal data only on your instructions, unless the law requires otherwise (in which case we'll tell you where allowed).
- Keep the data confidential and ensure our staff are bound by confidentiality.
- Apply appropriate technical and organisational security (see §8).
- Not use one venue's guest data for another venue, or for our own marketing.
- Assist you — taking account of the nature of processing — with data-subject requests, security, breach notification, and any required assessments.
- Make available the information needed to show compliance and allow reasonable audits.
05Your obligations
You confirm you have a lawful basis and, where required, valid consent to collect and process the guest data you gather through Rekly; that your own privacy notice tells guests about it; and that your instructions to us comply with the law. You control retention and deletion of your guest contacts.
06Sub-processors (Annex 2)
You authorise Rekly to engage sub-processors to deliver the service. Each is bound by data-protection terms equivalent to these, and we remain responsible for their performance. Current sub-processors:
| Sub-processor | Function | Location |
|---|---|---|
| Places & Business Profile APIs | EU / US (SCCs) | |
| AI provider (Google Gemini / Anthropic) | Drafting review replies | EU / US (SCCs) |
| Stripe | Payment processing | EU / US (SCCs) |
| Email provider | Sending transactional email | EU / US (SCCs) |
| Hosting provider | Application hosting & storage | EU |
We'll give you notice of any new or replacement sub-processor and a chance to object on reasonable data-protection grounds.
07International transfers
Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or the European Commission's Standard Contractual Clauses (or the equivalent for Albania-based controllers), together with any needed supplementary measures.
08Security measures (Annex 3)
- Encryption of data in transit (TLS) and encryption of sensitive stored tokens.
- Hashed passwords and optional two-factor authentication.
- Role-based access controls and the principle of least privilege.
- Per-venue data isolation, logging and monitoring.
- Regular backups and a documented recovery process.
09Personal-data breaches
If we become aware of a personal-data breach affecting your data, we'll notify you without undue delay and give you the information you reasonably need to meet your own notification duties to the authority and affected individuals.
10Data-subject rights
Rekly provides self-service tools (for example exporting or deleting a venue's guest contacts) and will otherwise assist you in responding to access, deletion, correction and objection requests from your guests. If a guest contacts us directly about your data, we'll refer them to you as the controller.
11Deletion & return at the end
On termination, at your choice, we'll delete or return the guest personal data we hold for you and delete existing copies within a reasonable period, unless the law requires us to keep it. You can also delete guest contacts yourself at any time while the service is active.
Email us at hello@rekly.co and we'll get back to you.