Data Processing Agreement

Last updated: 2 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Wiser Visibility, a trading name of Artificial Integrity Limited ("we", "us", "Processor"), and the client identified in the applicable order or account ("you", "Controller"), and applies wherever we process personal data on your behalf as part of the Automated Google Review Request Service (or the Bundle including it).

1. Definitions

1.1. "UK GDPR", "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in the UK GDPR and the Data Protection Act 2018.

1.2. "Services Agreement" means our Terms of Service, as agreed between us and you.

1.3. "Sub-processor" means any third party engaged by us to process personal data on your behalf in connection with the Services.

2. Subject Matter, Duration, and Scope

2.1. This DPA applies to our processing of personal data on your behalf as part of delivering the Automated Google Review Request Service, for the duration of the Services Agreement.

2.2. Nature and purpose of processing: sending review requests (by email, SMS, and/or automated call) to your customers on your instructions, and managing and reporting on responses to those requests.

2.3. Types of personal data processed: names, email addresses, phone numbers, and any other contact or identifying details you provide to us for this purpose.

2.4. Categories of data subjects: your customers, as identified in the contact lists or data you provide or make available to us.

3. Our Obligations as Processor

We agree that we will:

3.1. Process personal data only on your documented instructions, including in relation to transfers of personal data to a third country, unless required to do otherwise by UK law, in which case we will inform you before processing (unless the law prohibits this).

3.2. Ensure that any personnel authorised to process personal data under this DPA are subject to a duty of confidentiality.

3.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Clause 6.

3.4. Not engage another processor (sub-processor) without your prior general or specific written authorisation, as set out in Clause 4.

3.5. Taking into account the nature of the processing, provide reasonable assistance to you, by appropriate technical and organisational measures, to help you respond to requests from data subjects exercising their rights under UK GDPR.

3.6. Provide reasonable assistance to you in ensuring compliance with your obligations relating to the security of processing, breach notification, and data protection impact assessments, taking into account the information available to us.

3.7. At your choice, delete or return all personal data to you at the end of the provision of the relevant Service, and delete existing copies, unless UK law requires us to retain the data.

3.8. Make available to you information reasonably necessary to demonstrate compliance with the obligations in this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, on reasonable notice and subject to reasonable confidentiality safeguards.

4. Sub-processors

4.1. You provide general authorisation for us to engage sub-processors to help deliver the Services, provided we impose data protection terms on them that are no less protective than this DPA.

4.2. Our current sub-processor for this purpose is HighLevel LLC, a subsidiary of GoHighLevel Inc. (the platform used to send and manage review requests), together with the further sub-processors it engages to deliver its own platform (for example, for data storage and message delivery), as published and kept up to date at [https://www.gohighlevel.com/sub-processors]. We will notify you (for example, via our website or by email) if we intend to add or replace our own sub-processor, and you may object on reasonable data protection grounds within 14 days of that notice; if we cannot resolve your objection, either party may terminate the affected Service.

5. International Transfers

5.1. Where personal data is transferred outside the UK in connection with the Services (for example, to our sub-processor referred to in Clause 4.2), we will ensure appropriate safeguards are in place in accordance with UK data protection law, such as reliance on the UK's data protection adequacy regulations (including the UK-US Data Bridge, where applicable), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

6. Security

6.1. We maintain reasonable technical and organisational measures appropriate to the nature of the personal data processed, including restricting access to personal data to those who need it to deliver the Services, relying on our sub-processor's security measures for data hosted on its platform, and using industry-standard encryption for data in transit where supported by that platform.

7. Personal Data Breaches

7.1. We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide you with information reasonably available to us to help you meet any of your own breach notification obligations.

8. Liability

8.1. Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement.

9. Term and Termination

9.1. This DPA takes effect on the date you first subscribe to the Automated Google Review Request Service (or the Bundle including it) and continues for as long as we process personal data on your behalf under that Service, notwithstanding termination of the Services Agreement, until such processing ends in accordance with Clause 3.7.

10. General

10.1. Save as set out in Clause 8 (Liability), in the event of any conflict between this DPA and the Services Agreement in relation to the processing of personal data, this DPA prevails.

10.2. This DPA is governed by the laws of England and Wales, consistent with the governing law provisions of the Services Agreement.