Data Processing Agreement (DPA)
Version 1.0 · Last updated: 5 October 2026
1. Parties and roles
Controller: the customer who subscribes to the service (the business owner), who decides the purposes for which the data of its own customers are used.
Processor: Valensa Consulting LLC, 407 Lincoln Road, Suite 12N, Miami Beach, FL 33139, United States, which provides the BravoRank service from the European Union (Portugal). Contact: info@valensaconsulting.com.
The customer's own data (account, billing and contact details) is not governed by this agreement: we are the controller of that data and process it under our Privacy Policy.
2. Subject matter and duration
The Processor processes personal data on behalf of the Controller solely to provide the contracted service: managing its Google Business Profile (updating the profile, publishing posts, replying to reviews where the Controller has authorised it), requesting and collecting feedback from its customers, measuring its local ranking and showing the results in its dashboard and reports.
This agreement lasts as long as the subscription; its confidentiality obligations survive termination.
3. Data and data subjects
- Data subjects: customers and prospective customers of the Controller who interact with its Google profile or its feedback page (QR code), and members of its team who use the dashboard.
- Data: public name or alias and profile photo of a review author, review text, rating and date; data a customer voluntarily leaves on the feedback page (e.g. name, contact details and comment); and name and email of dashboard users.
- We do not process special categories of data (health, beliefs, etc.) unless a third party writes them on their own initiative in a public review; in that case they are only read in order to reply.
4. Processor obligations
The Processor undertakes to:
- Process the data only on the Controller's documented instructions, namely this agreement, the Terms of Sale and the settings the Controller configures in its dashboard. It will inform the Controller if an instruction appears to infringe the GDPR.
- Not use the data for its own purposes, nor sell or disclose it to third parties.
- Ensure that persons authorised to process the data are bound by confidentiality.
- Implement the security measures in section 6.
- Engage only the sub-processors listed in section 5, under the conditions described there.
- Assist the Controller in responding to data subject requests (access, rectification, erasure, objection, etc.) and forward without delay any request received directly.
- Assist the Controller with its obligations regarding security, breach notification and, where applicable, impact assessments.
- Notify the Controller of any personal data breach affecting its data without undue delay and in any event within 48 hours of becoming aware of it, with the information available so that the Controller can meet its own obligations.
- Upon termination, and at the Controller's choice, return or delete the data within 90 days of the request, unless the law requires retention. Encrypted backups are deleted in their ordinary cycle, at the latest after 30 days.
- Make available to the Controller the information necessary to demonstrate compliance with this agreement and allow reasonable audits, preferably documentary, with 30 days' notice and at the Controller's expense.
5. Sub-processors
The Controller grants general authorisation for the Processor to use the following sub-processors:
- Clouding.io — servers running the service (Barcelona, Spain; within the EEA).
- Google LLC — Google Business Profile API, to read and update the profile (USA).
- OpenAI, L.L.C. — drafting posts and suggested review replies (USA). Data sent via the API is not used to train models.
- Resend, Inc. — sending service emails such as review alerts (USA).
- Cloudflare, Inc. — storage of backups, encrypted before leaving our servers (USA).
The Processor imposes on each sub-processor data protection obligations equivalent to those in this agreement and remains liable for their performance. It will notify the Controller at least 15 days in advance of any new or replacement sub-processor, by publishing it on this page or by email; the Controller may object on reasonable grounds and, if no solution is found, cancel without penalty.
6. Security
Technical and organisational measures applied in accordance with Article 32 GDPR:
- Encryption of all communications (TLS) and of backups (encrypted with our own key before leaving the server).
- Access to data restricted to those who need it, with individual credentials.
- Access to the Google profile through the permission the Controller grants from its own account, which it can revoke at any time without losing the profile.
- Daily backups allowing the service to be restored after an incident.
- Logging of relevant actions performed on the profile and periodic review of the measures.
7. International transfers
Where data leaves the European Economic Area (sub-processors in the USA), the transfer relies on the Standard Contractual Clauses approved by the European Commission or, where applicable, the EU-US Data Privacy Framework.
8. Controller obligations
The Controller warrants that it has a legal basis for us to process its customers' data and informs them where required. Review replies on its behalf are only published if it has expressly authorised this in its dashboard.
9. Governing law and precedence
This agreement is governed by the GDPR and applicable data protection law. On data protection matters it prevails over any other document of the service. The lead supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD), Portugal, without prejudice to the right to lodge a complaint with the local authority (in Spain, the AEPD).