BravoRank

Data Processing Agreement (DPA)

This agreement governs how we process the personal data of your customers when we manage your Google Business Profile, in accordance with Article 28 of the General Data Protection Regulation (GDPR). It is accepted when you subscribe to the service and forms part of the Terms of Sale. This English version is the reference version and prevails in case of discrepancy.

Version 1.0 · Last updated: 5 October 2026

1. Parties and roles

Controller: the customer who subscribes to the service (the business owner), who decides the purposes for which the data of its own customers are used.

Processor: Valensa Consulting LLC, 407 Lincoln Road, Suite 12N, Miami Beach, FL 33139, United States, which provides the BravoRank service from the European Union (Portugal). Contact: info@valensaconsulting.com.

The customer's own data (account, billing and contact details) is not governed by this agreement: we are the controller of that data and process it under our Privacy Policy.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller solely to provide the contracted service: managing its Google Business Profile (updating the profile, publishing posts, replying to reviews where the Controller has authorised it), requesting and collecting feedback from its customers, measuring its local ranking and showing the results in its dashboard and reports.

This agreement lasts as long as the subscription; its confidentiality obligations survive termination.

3. Data and data subjects

4. Processor obligations

The Processor undertakes to:

  1. Process the data only on the Controller's documented instructions, namely this agreement, the Terms of Sale and the settings the Controller configures in its dashboard. It will inform the Controller if an instruction appears to infringe the GDPR.
  2. Not use the data for its own purposes, nor sell or disclose it to third parties.
  3. Ensure that persons authorised to process the data are bound by confidentiality.
  4. Implement the security measures in section 6.
  5. Engage only the sub-processors listed in section 5, under the conditions described there.
  6. Assist the Controller in responding to data subject requests (access, rectification, erasure, objection, etc.) and forward without delay any request received directly.
  7. Assist the Controller with its obligations regarding security, breach notification and, where applicable, impact assessments.
  8. Notify the Controller of any personal data breach affecting its data without undue delay and in any event within 48 hours of becoming aware of it, with the information available so that the Controller can meet its own obligations.
  9. Upon termination, and at the Controller's choice, return or delete the data within 90 days of the request, unless the law requires retention. Encrypted backups are deleted in their ordinary cycle, at the latest after 30 days.
  10. Make available to the Controller the information necessary to demonstrate compliance with this agreement and allow reasonable audits, preferably documentary, with 30 days' notice and at the Controller's expense.

5. Sub-processors

The Controller grants general authorisation for the Processor to use the following sub-processors:

The Processor imposes on each sub-processor data protection obligations equivalent to those in this agreement and remains liable for their performance. It will notify the Controller at least 15 days in advance of any new or replacement sub-processor, by publishing it on this page or by email; the Controller may object on reasonable grounds and, if no solution is found, cancel without penalty.

6. Security

Technical and organisational measures applied in accordance with Article 32 GDPR:

7. International transfers

Where data leaves the European Economic Area (sub-processors in the USA), the transfer relies on the Standard Contractual Clauses approved by the European Commission or, where applicable, the EU-US Data Privacy Framework.

8. Controller obligations

The Controller warrants that it has a legal basis for us to process its customers' data and informs them where required. Review replies on its behalf are only published if it has expressly authorised this in its dashboard.

9. Governing law and precedence

This agreement is governed by the GDPR and applicable data protection law. On data protection matters it prevails over any other document of the service. The lead supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD), Portugal, without prejudice to the right to lodge a complaint with the local authority (in Spain, the AEPD).