Last updated: 27 July 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by Reviewal (the "Processor") on behalf of you or your organization (the "Controller") in connection with your use of Sentinel by Reviewal (the "Service"). This DPA is entered into pursuant to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR.
This DPA forms part of, and is subject to, the Terms of Service between the parties. In the event of any conflict between this DPA and the Terms of Service with respect to the processing of personal data, this DPA prevails.
By accepting the Terms of Service and using Sentinel, you are deemed to have accepted this DPA where GDPR or an equivalent data protection law applies to your use of the Service. A signed counterpart is available on request at sentinel@reviewal.team.
Terms used but not defined in this DPA have the meanings given to them in the GDPR. For clarity:
The subject matter of the processing is the provision of the Sentinel service: a social media compliance monitoring platform.
The processing will continue for the duration of the Controller's subscription to Sentinel, plus any post-termination period required to return or delete the data in accordance with Section 9.
The Processor processes personal data to provide the Service: authenticating users, ingesting public social media content from connected accounts, performing AI-assisted compliance analysis, storing scan results and metrics, generating dashboards and reports, and delivering notifications.
Sentinel is not designed for the processing of special categories of personal data (sensitive data under Article 9 GDPR). The Controller agrees not to knowingly submit such data to Sentinel except in the ordinary course of scanning publicly available social media content that may incidentally contain such data.
The Processor undertakes to:
The Controller warrants that:
The Controller grants the Processor general written authorization to engage sub-processors in connection with the provision of the Service. The current list of sub-processors is set out in Annex A to this DPA.
The Processor will:
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Further detail is available on request. The Processor may update its security measures from time to time, provided the level of protection is not materially reduced.
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data. The notification will include, to the extent known at the time:
The Processor will cooperate with the Controller in the fulfillment of the Controller's obligations under Articles 33 and 34 GDPR.
The Controller acknowledges that certain sub-processors are located in third countries outside the European Economic Area (see Annex A). For such transfers, the Processor relies on appropriate safeguards under Chapter V of the GDPR, including the European Commission's Standard Contractual Clauses (SCCs) as adopted by Commission Decision (EU) 2021/914 of 4 June 2021. Where applicable, the Processor also relies on sub-processor participation in the EU-U.S. Data Privacy Framework.
Where the UK GDPR applies, the parties incorporate the UK International Data Transfer Addendum to the SCCs, as issued by the UK Information Commissioner.
Upon termination of the Service, the Processor will, at the Controller's choice, return or delete all personal data processed on the Controller's behalf, unless retention is required by applicable law. Deletion from production systems will be completed within thirty (30) days of termination; deletion from backups will be completed on the next backup rotation cycle (typically within 7 to 14 days thereafter).
The Processor will make available to the Controller, upon reasonable request, all information necessary to demonstrate compliance with this DPA. On-site audits are not required in the normal course. Where the Controller's supervisory authority requires an audit, the parties will cooperate in good faith, and the Controller will bear the reasonable costs of such an audit.
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA excludes or limits liability that cannot be excluded or limited under applicable law.
This DPA is governed by the law specified in the Terms of Service, subject to mandatory data protection law. Nothing in this DPA overrides mandatory data subject rights under the GDPR or equivalent laws.
For questions or notices under this DPA, please contact sentinel@reviewal.team.
The following sub-processors are engaged by the Processor in connection with the provision of Sentinel. This list is current as of the "Last updated" date at the top of this DPA and may be updated in accordance with Section 5.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Authentication and primary database hosting | European Union | EU-hosted; DPA in place |
| Railway | Application hosting, backend workers, and user-uploaded content storage | European Union | EU-hosted; DPA in place |
| Anthropic | Primary AI engine for compliance analysis of captions, bio text, and uploaded media | United States | SCCs; no training on API inputs |
| Groq | Fallback AI engine and Whisper audio transcription for video scans | United States | SCCs; no training on API inputs |
| Apify | Scraping public Instagram profile and post data | European Union / United States | SCCs |
| Resend | Transactional email delivery (notifications, alerts, receipts) | United States | SCCs |
| Stripe | Payment processing and subscription management | United States / European Union | SCCs; PCI-DSS Level 1 |
"SCCs" refers to the Standard Contractual Clauses issued by the European Commission (Decision (EU) 2021/914). Where a sub-processor is located in the United States, the Processor also relies, where applicable, on that sub-processor's certification under the EU-U.S. Data Privacy Framework.
Reviewal is the trading name of Chafai Solutions LLC, a limited liability company organized under the laws of the State of Delaware, United States, with registered office at 16192 Coastal Highway, Lewes, Delaware 19958, United States. All references to "Reviewal" (as Processor) in this DPA are to Chafai Solutions LLC.