BBuild my reviews

Data Processing Agreement

Last updated: 26 August 2026 · Forms part of the Terms of Service. No signature is required; we will sign a copy on request to support@buildmyreviews.app.

1. Parties and roles

Controller: the Merchant subscribing to Build my reviews.

Processor: L&AS VENTURES SINGLE MEMBER PRIVATE COMPANY, Zeppou 33, 16675 Glyfada, Greece, AFM 802718607.

This Agreement applies where we process personal data about the Merchant's own customers ("Players") on the Merchant's behalf, under Article 28 GDPR. It does not apply to the Merchant's own account data, for which we are the controller.

2. Subject matter, duration, nature and purpose

We process Player data in order to provide the Service described in the Terms: creating player accounts, running the prize wheel, issuing and validating prizes, sending prize and follow-up e-mails, recording consents, producing the Merchant's reports and preventing abuse. Processing lasts as long as the Merchant's subscription, plus the retention periods in the Privacy Policy.

3. Categories of data subject and data

Data subjects: the Merchant's customers who use a Player Page.

Personal data: name, e-mail address, profile picture where the Player signs in with Google, consent records, spins, prizes and prize codes, redemption status, event records including review-link clicks and time away from the page, a one-way device hash, and any optional private feedback the Player writes.

No special categories of data are processed. The Merchant must not configure the Service to collect health, biometric, political, religious or similar data.

4. Our obligations

We will: process Player data only on the Merchant's documented instructions, which are given through the settings in the dashboard and these Terms; ensure that everyone authorised to process the data is bound by confidentiality; implement the technical and organisational measures in Annex A; respect the conditions in section 5 for engaging sub-processors; assist the Merchant with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing; delete or return Player data at the end of the Service, except where EU or Member State law requires retention; and make available the information needed to demonstrate compliance and allow audits as described in section 8.

If an instruction from the Merchant appears to infringe the GDPR, we will inform the Merchant and may suspend that instruction.

5. Sub-processors

The Merchant gives general authorisation for the sub-processors listed in the Privacy Policy and at buildmyreviews.app/legal/subprocessors. We will give 30 days' notice by e-mail before adding or replacing a sub-processor. The Merchant may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Merchant may terminate the affected part of the Service and receive a pro-rata refund. Each sub-processor is bound by data protection terms no less protective than these.

6. International transfers

Where a sub-processor processes data outside the EEA, transfers rely on an adequacy decision or on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module three, processor to sub-processor), which are incorporated by reference with Greece as the supervisory jurisdiction.

7. Security and breaches

We maintain the measures in Annex A. We will notify the Merchant without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting Player data, with the information available to us, and will assist the Merchant in meeting their own notification duties.

8. Audits

On reasonable written notice, and not more than once a year unless a breach or an authority requires otherwise, we will answer a data protection questionnaire and provide the documentation reasonably needed to demonstrate compliance with this Agreement. An on-site audit may be carried out at the Merchant's cost if the documentation does not answer the question.

9. Data subject requests

Players can exercise their rights directly in the Service: the account page linked from every e-mail lets them see their prizes, withdraw consent and delete their data. Where a request reaches us instead of the Merchant, we act on it and inform the Merchant. The dashboard also lets the Merchant export and delete any Player.

10. Deletion and return

On termination the Merchant can export Player data as CSV from the dashboard for 30 days. After that we delete Player data, including from backups within a further 30 days, except where law requires retention.

Annex A — Technical and organisational measures

Access control — least-privilege access, individual named accounts, two-factor authentication on the administrative platforms, no shared credentials, secrets held in a managed password vault.

Encryption — TLS 1.2+ in transit for every connection; data at rest encrypted by the storage provider; session tokens signed and time-limited; device identifiers stored as one-way hashes.

Segregation — every workspace's data is scoped to its own identifiers and every query is filtered by workspace at the API layer; odds, costs and other commercial data never leave the server.

Resilience — serverless infrastructure across multiple locations, nightly database backups retained 30 days, restore procedure rehearsed and documented.

Monitoring — application error reporting, uptime monitoring with alerting, rate limiting on authentication and gameplay endpoints, audit trail of prize redemptions.

Development — code review before deployment, staging environment separate from production with separate credentials, dependency scanning, no production data in development.

Personnel — a small number of named individuals with access, bound by confidentiality, access removed on departure.

Sub-processor management — written terms with each sub-processor, list published, 30 days' notice of change.