Processor terms for B2B customers.
Who we are in your data flow
You (the venue or operator) are the data controller for the personal data of your guests, reviewers, and your own team members in your Verdscore account. Verdscore is the processor — we process that data on your documented instructions to deliver the service you signed up for (review monitoring, AI reply drafts, alerts, analytics).
Categories of data we process
- Your account data — email, name, hashed password, login activity, billing state via Stripe.
- Venue identifiers — Google place IDs + TripAdvisor listing URLs you claim or track.
- Public review data — reviewer display name, rating, review text, photos, and timestamps as published on Google Maps + TripAdvisor. We never write to those platforms; we read what they expose publicly.
- Derived analytics — sentiment scores, theme tags, AI reply drafts. Generated by Verdscore based on the public review data above.
Security measures
- Encryption in transit (TLS 1.2+) and at rest (full-disk).
- Bcrypt password hashing — we never see or store plaintext.
- HTTP-only Secure SameSite=Lax session cookies + signed CSRF tokens.
- Per-route rate limits + Cloudflare Turnstile on public forms.
- Audit log of every admin impersonation, manual override, and sensitive change — reviewable on request.
- 72-hour breach notification commitment (GDPR Article 33).
Subprocessors
Verdscore relies on a small set of vetted subprocessors to deliver the service — see the full, dated list at Subprocessors. We commit to giving signed customers 30 days' notice before adding or removing a subprocessor, and to objection rights in line with the SCCs.
International transfers
Verdscore is operated from the EU (Hetzner Cloud, Nuremberg). Some sub-processors (Stripe, Cloudflare, Resend, Google Maps Platform, TripAdvisor Content API, Anthropic) may store or process data in the United States or other countries.
For transfers to the US, we rely on the EU-US Data Privacy Framework where the sub-processor is certified (Stripe, Cloudflare, Google, Resend) and on the EU Standard Contractual Clauses (2021/914, Module 2) for those that are not, including Anthropic. A Transfer Impact Assessment is maintained for each US recipient and available on request.
Sub-processing + your rights
- Audit: on reasonable notice and under NDA we provide responses to a security questionnaire or a recent penetration-test summary.
- Data subject requests: if one of your end users contacts us directly, we forward it to you within 5 business days so the controller can respond.
- Return + deletion: on termination we return your account data on request and delete it within 30 days, retaining only what we're legally required to keep (invoices for 7 years per tax law).
Getting a signed DPA
For procurement workflows that need a counter-signed DPA on file, email [email protected] with subject “DPA request”. We'll send the standard Verdscore DPA (incorporating SCCs 2021/914 modules 2+3) ready to sign. Typical turnaround is 2–3 business days.