Skip to content
GrowthBull.
How it works Why reviews Pricing Compare tools About FAQ
Sign in Start free
How it works Why reviews Pricing Compare tools About FAQ Sign in Start free

Data processing agreement

Version 1.0 - effective 7 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of service between TMR Digital Ltd (company number 15550089, registered office 60 Tottenham Court Road, Suite 4387a, Fitzrovia, London, W1T 2EW, United Kingdom), trading as Growth Bull ("we", "us", the "Processor"), and the business or agency holding the account (the "Controller", "you"). It applies whenever we process personal data about your customers on your behalf, and it is the written contract required by Article 28(3) of the UK GDPR (and, where it applies, the EU GDPR). Words like "personal data", "processing", "controller", "processor" and "personal data breach" have their GDPR meanings.

Where an agency holds the account and adds its own clients, each client business is the Controller of its customers' data, the agency is our customer and a processor for that business, and we act as the agency's sub-processor on these same terms. The agency is responsible for passing these terms on to its clients.

1. Instructions

We process your customers' personal data only on your documented instructions. Your instructions are: this DPA, the settings you choose in the app (which jobs create requests, the message wording, timing and reminders), the customer lists you connect or upload, and any written instruction you send to hello@growthbull.io. We will tell you at once if we believe an instruction breaks data protection law. We never use your customers' details for our own purposes, never sell or share them, and never contact them except with the review invitations you have set up.

2. Confidentiality

Everyone we authorise to process personal data is bound by a duty of confidence. Staff access to raw customer contact details is masked in our administration screens and logs; only what is needed to diagnose a delivery problem is shown.

3. Security

We take the technical and organisational measures in Annex C, appropriate to the risk: encryption in transit and at rest, encrypted backups, keyed hashing of contact details once they are no longer needed in the clear, least-privilege access, signed webhooks and a published retention schedule.

4. Sub-processors

You give us general written authorisation to use the sub-processors listed in Annex B. We will email the address on your account at least 30 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may end your subscription without penalty before the change takes effect. Every sub-processor is bound by a written contract imposing data protection obligations equivalent to this DPA, and we remain fully liable to you for their performance.

5. Data subject rights

We help you respond to your customers' requests to access, correct, erase, restrict, port or object to the processing of their data. In the app you can erase one customer (every copy we hold, leaving only a hashed do-not-contact record so they are never asked again) and export everything we hold about them as JSON. If a customer contacts us directly we will pass the request to you within five working days and act on your instruction, or, for an opt-out, honour it immediately.

6. Assisting you: breaches and impact assessments

If we become aware of a personal data breach affecting your customers' data we will notify the email address on your account without undue delay and in any case within 24 hours, with what we know, the likely consequences and the measures taken, and we will keep you updated so you can meet your own 72-hour obligation to the ICO. We will give you reasonable assistance with data protection impact assessments and prior consultation about the processing we carry out for you.

7. Deletion and return at the end

While your account is open you can export your data at any time. When you close your account (from Settings, or by asking us) we delete the account and every customer record within 30 days, except: records we must keep by law (VAT and accounting records, six years); the hashed do-not-contact list, kept so an opted-out customer is never messaged again even if the business returns; and copies inside backups, which expire on the windows in the retention schedule and against which every erasure is replayed if a backup is ever restored.

8. Audits and information

We will make available the information you reasonably need to show that we meet Article 28, including this DPA, our record of processing and our sub-processor contracts, and we will allow and contribute to audits or inspections by you or an auditor you mandate, on 30 days' written notice, no more than once a year unless a supervisory authority requires otherwise or a breach has occurred.

9. Your obligations as Controller

You confirm that you have a lawful basis to give us your customers' details and to have review invitations sent to them. For text and email invitations in the UK that means the Privacy and Electronic Communications Regulations "soft opt-in": you collected the details yourself, in the course of a sale or negotiation of your own services, you gave the person a way to refuse marketing when you collected them, and every message we send carries an opt-out (it does). When you upload a list you attest to this for each list, and we record that attestation. You will keep the details accurate, tell us promptly of any customer who objects, and not upload details of anyone who has told you they do not want to hear from you. You are responsible for your own compliance with the UK GDPR and PECR as Controller and will indemnify us against claims arising from instructions or data that breach them.

10. Liability and term

Each party is liable under Article 82 for damage caused by its own processing in breach of the GDPR. Nothing in this DPA limits the liability of either party for anything that cannot be limited by law; otherwise the liability caps in the Terms of service apply. This DPA lasts as long as we process personal data for you and survives termination until every copy is deleted under section 7. If it conflicts with the Terms, this DPA wins for data protection matters. It is governed by the law of England and Wales.

Annex A - description of the processing

Subject matterInviting a business's customers to leave a Google review after a completed job, and recording the outcome.
DurationFor as long as the business holds a Growth Bull account, then deletion under section 7.
Nature and purposeReceiving completed-job records from the business's accounting or CRM software, an uploaded list or manual entry; sending one text or email invitation and one reminder; hosting the review page; recording opens, clicks to Google, private feedback and opt-outs; reporting the results to the business.
Categories of data subjectThe business's customers (typically homeowners and small-business clients of UK trades).
Categories of personal dataName; mobile number; email address; invoice reference and amount; the messages sent and their delivery status; page opens, Google clicks, star ratings and private feedback text; opt-out records. No special-category data is sought or knowingly processed.
Controller's dataSeparately, as controller, we hold the account holder's name, email, mobile, business details and billing records under the privacy policy.

Annex B - authorised sub-processors

Sub-processorPurposeLocation of processingTransfer safeguard
Railway CorporationApplication hosting and the database volume (all customer data at rest, nightly snapshots)hosting region "ams"Railway Data Processing Agreement incorporating the EU Standard Contractual Clauses and the UK Addendum; SOC 2 Type 2
Twilio (Twilio Ireland Limited / Twilio Inc.)Sending review-request text messages and receiving STOP repliesIreland (EU) and the United States; delivered by UK mobile networksTwilio Data Protection Addendum (Standard Contractual Clauses, UK Addendum, Binding Corporate Rules)
Plus Five Five, Inc. (Resend)Sending review-request and account emailsUnited StatesResend Data Processing Agreement with Standard Contractual Clauses and the UK Addendum
Google LLCSign-in for business accounts and Business Profile lookups (Places API)United States / globalReceives no customer contact data - only the business account holder's sign-in and the business's public listing reference
DataForSEOLocal search-ranking data for the Rank MapUnited States / globalReceives no personal data - a search phrase and map coordinates only
Revolut LtdCard payments, subscriptions and invoices for business accountsUnited KingdomReceives no customer data - the business account holder's billing details only; card numbers never touch our systems

Where personal data leaves the UK it is protected by an approved transfer mechanism (the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses). Changes to this list are notified under section 4.

Annex C - technical and organisational measures

  • Encryption in transit: HTTPS everywhere with HSTS; provider APIs over TLS; signed webhooks (Twilio, Resend, Revolut, Xero, QuickBooks, Square) that fail closed.
  • Encryption at rest: host volume encryption; accounting and CRM tokens encrypted with AES-256-GCM; every offsite backup encrypted with AES-256-GCM under a separate key before it leaves the server.
  • Data minimisation: a customer's name, number and email are held in the clear only while a request is live and inside the 90-day never-ask-twice window, then replaced by a keyed HMAC-SHA256 hash; the do-not-contact list is stored hashed; private feedback text expires after 90 days; uploaded lists are parsed in memory and never stored.
  • Access control: passwordless sign-in (Google or single-use emailed links), CSRF protection, per-tenant scoping checked on every request, agency isolation, masked customer details in staff screens and logs, rate limits on public forms.
  • Erasure tooling: per-customer erasure and export in the app; whole-account deletion in one click; an erasure ledger replayed onto any restored backup.
  • Backups and recovery: consistent nightly snapshots, 7 days on-volume, 30 days encrypted offsite, pruned automatically; documented restore and breach procedures.
  • Monitoring: scheduler and delivery health checks with alerts to the operator; server errors recorded without personal data.

Retention schedule

What we keep and for how long. These periods are enforced automatically by the service; the same numbers appear in our record of processing.

DataKept for
Customer name, mobile number and email on a review requestUntil the request is finished and 90 days have passed (the never-ask-twice window); then replaced by a keyed hash
The keyed hash of a customer contactTwelve months for the repeat-customer filter; permanently on the do-not-contact list (opt-outs, bounces, erasures)
Private feedback text90 days from when it was left; the star count is kept
Message log (what was sent, to whom, delivery status)180 days (failed sends 365 days as deliverability evidence); the address is masked as soon as the request is retired
Audit trail (who approved what)365 days; entries naming a customer are cleared when the request is retired
Raw invoice and CRM webhook payloads30 days
Setup-call bookings (prospects)12 months
Waiting-list emails6 months after the launch email
Business account, billing records, connection tokensWhile the account is open; deleted within 30 days of closure except VAT and accounting records (six years, HMRC)
BackupsOn-volume snapshots 7 days; encrypted offsite snapshots 30 days; host volume backups 6 days. Erasures are replayed onto any restored backup

Contact

Data protection questions, sub-processor objections and breach notices: hello@growthbull.io. Postal address: TMR Digital Ltd, 60 Tottenham Court Road, Suite 4387a, Fitzrovia, London, W1T 2EW, United Kingdom. See also our privacy policy and terms of service.

GrowthBull.

Get the Google reviews you deserve. Built for UK local businesses.

How it works Pricing About Help Partner programme For agencies Book a free setup call Sign in Privacy Terms Refunds Sitemap

Every review is the customer's own words, left by them on your public Google profile. Reply STOP or one tap unsubscribes, always.

© 2026 Growth Bull · hello@growthbull.io · 10-day free trial · 30-day money-back guarantee · Cancel any time

Growth Bull is a trading name of TMR Digital Ltd, a company registered in England & Wales (company no. 15550089). Registered office: 60 Tottenham Court Road, Suite 4387a, Fitzrovia, London, W1T 2EW, United Kingdom. Payments are taken securely by card. TMR Digital Ltd is the seller of record and is registered for UK VAT.