1. What this addendum is
This Data Processing Addendum (the “Addendum”) forms part of the Praise Patch Terms of Service (the “Terms”) between you, the customer who holds a Praise Patch account (“you” or the “Customer”), and AI Profit Garden, LLC, a Nevada limited liability company, the company that makes Praise Patch (“we,” “us,” or “Praise Patch”). Our address is 9107 W. Russell Rd, Las Vegas, NV 89148, and you can reach us at hello@praisepatch.com.
Most of this Addendum applies whenever the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) or the UK General Data Protection Regulation together with the UK Data Protection Act 2018 (“UK GDPR”) applies to personal data you process using Praise Patch. Together these are the “Data Protection Laws.”
Section 8 is different. It applies to every Praise Patch customer, wherever you and your customers are. If the Data Protection Laws do not apply to you, section 8 is the part of this Addendum that applies to you, and nothing else here changes your Terms.
If anything in this Addendum conflicts with the Terms on a question of personal data, this Addendum wins. On everything else, the Terms win.
2. The words we use
- Personal data, controller, processor, sub-processor, data subject, processing, personal data breach, supervisory authority. These carry the meanings given in the Data Protection Laws.
- Reviewer Data. Personal data about the people you ask for reviews and the people who leave them: their first names, email addresses, optional phone numbers, optional business names and descriptions of their own business, star ratings, review content in video, audio, or text (including a person’s image and voice), and the consent record.
- Account Data. Personal data about you and the people who operate your account: your name, email address, business details, purchase record, and activity inside the service.
- Security Incident. A personal data breach affecting Reviewer Data in our care, or in the care of one of our sub-processors.
3. Who is who
For Reviewer Data, you are the controller and we are the processor. You decide whom to ask for a review, what questions to ask, what to approve, and where to publish. We hold and process Reviewer Data only so the service can do those things for you.
For Account Data, we are an independent controller. How we handle it is described in the Praise Patch Privacy Policy, not in this Addendum.
The details of the processing we carry out for you are set out in Annex 1.
4. What we commit to as your processor
4.1 We follow your instructions
We process Reviewer Data only on your documented instructions. Your instructions are: the Terms, this Addendum, the way you use the features of Praise Patch (adding a customer, sending a request, approving or declining a review, publishing a review or taking it off your page, exporting, deleting), and removing a review where the reviewer has asked for its removal and you have not acted on that request within 10 business days of our forwarding it to you. We will not process Reviewer Data for any other purpose. If we believe an instruction would break the Data Protection Laws, we will tell you before acting on it.
4.2 We keep it confidential
Every person we allow to access Reviewer Data is bound by a duty of confidentiality, whether by contract or by law. At the date of this Addendum that is our founder and any contractor working under a written confidentiality agreement.
4.3 We keep it secure
We maintain the technical and organizational measures described in Annex 2, and we keep them appropriate to the risk. We may improve them over time. We will not reduce the overall level of protection during the term of this Addendum.
4.4 We use a short list of sub-processors, and we tell you before it changes
You give us general authorization to use the sub-processors listed in Annex 3. Each one is bound by written terms that protect Reviewer Data at least as well as this Addendum does, and we remain responsible to you for their work.
Before we add or replace a sub-processor, we will email the address on your account at least 30 days in advance. We send this notice to every Praise Patch customer (section 8).
If you object on reasonable data protection grounds and we cannot resolve it, you may end your use of Praise Patch and ask us to delete your data. If you are within 30 days of your purchase and have not yet published an approved review, we will refund your one-time purchase in full, as the Terms provide. If you pay for a monthly subscription upgrade, we will also refund any unused subscription period.
4.5 We help you answer the people in your data
Praise Patch gives you the tools to handle most requests yourself: you can see, approve, decline, take off your page, export, and delete any review, and you can remove a customer from your list. If a data subject contacts us directly about Reviewer Data, we will forward the request to you, because it is your page and your relationship. If a reviewer asks us to remove their review and you have not acted within 10 business days of our forwarding the request, we will remove it, as section 4.1 provides. Where you need more from us, we will give reasonable help so you can respond within the time the Data Protection Laws allow. If a request creates real cost for us, we may charge a reasonable fee, and we will tell you before we do.
4.6 We help with assessments and regulators
On reasonable request, we will give you the information you need for a data protection impact assessment, or for a consultation with a supervisory authority, to the extent it concerns processing we do for you.
4.7 We tell you about incidents, fast
If we become aware of a Security Incident, we will notify you without undue delay and in any case within 72 hours of confirming it. The notice will say what we know at that point: what happened, what data and roughly how many people are affected, what we have done, and what we recommend you do. We will keep you updated as we learn more. Notice is not an admission of fault.
4.8 We give it back, or delete it, when you leave
While your account is open you can export your reviews and customer list at any time. We delete Reviewer Data, including stored video and audio files, within 30 days of a verified request or the closure of your account, except records of reviewer consent, which you instruct us to retain for three years to document the permission under which a review was published. Backups are retained for seven days and are not restored after deletion. Apart from those consent records, we keep Reviewer Data after deletion only where the law requires it, and only for as long as it requires.
4.9 We show our work
We will give you the information reasonably needed to show that we meet this Addendum. Once in any 12-month period, on 30 days’ written notice, you or an independent auditor you appoint (bound by confidentiality) may verify our compliance. We will start with written answers and documents. An on-site audit happens only if a supervisory authority requires it, or written evidence is genuinely insufficient, and it takes place during business hours without disrupting the service. You bear the costs of any audit you request.
4.10 We keep records
We keep the records of processing that Article 30 of the GDPR requires of a processor, and we will make them available to a supervisory authority on request.
5. What you commit to as controller
- You have a lawful basis to give us Reviewer Data, and you tell the people in it what you are doing, in a way that meets the Data Protection Laws. In practice this means the people you add are customers you have actually done business with.
- Your instructions to us are lawful, and you will not ask us to process Reviewer Data in a way that would break the Data Protection Laws.
- You will not ask people for special category data (health, religion, and the like) through Praise Patch, and you will decline and delete any review that contains it unless you have a lawful basis to keep it.
- You respond to data subjects who exercise their rights, using the tools in the service first and asking us for help where you need it.
- You keep your account credentials safe and do not share your login, as the Terms require.
6. Where the data goes
Praise Patch is operated from the United States. Reviewer Data is stored in the United States. It may be processed in other locations where our sub-processors operate, as listed in Annex 3, including in transit through Cloudflare’s global network. By using Praise Patch you instruct us to transfer Reviewer Data to those locations.
For transfers of personal data subject to the GDPR, the parties enter into the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated by reference into this Addendum with the selections set out in Annex 4. For transfers subject to UK GDPR, the parties also enter into the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (the “UK Addendum”), completed as set out in Annex 4. If a supervisory authority or court decides that a different or additional mechanism is required, the parties will work together in good faith to put it in place.
7. Liability, term, and the rest
Each party’s liability under this Addendum, including the Standard Contractual Clauses, is subject to the limits and exclusions in the Terms, and counts toward the same overall cap. Nothing here limits liability that the Data Protection Laws do not allow to be limited, and nothing in this Addendum limits any data subject’s rights under the Standard Contractual Clauses.
This Addendum lasts as long as we process Reviewer Data for you, and the deletion obligation in section 4.8 survives after that.
This Addendum is governed by the law that governs the Terms, the laws of Nevada, except where the Standard Contractual Clauses or the UK Addendum require otherwise, in which case the law and courts set out in Annex 4 apply to those clauses.
Questions about this Addendum go to hello@praisepatch.com.
8. Commitments to every customer
The rest of this Addendum applies where the Data Protection Laws apply. The commitments in this section apply to every Praise Patch customer, including customers in the United States, whether or not the Data Protection Laws apply to you. Where this section points to another section, that section applies to you for this purpose.
- Confidentiality. We keep Reviewer Data confidential, and every person we allow to access it is bound by a duty of confidentiality (section 4.2).
- Your instructions. We process Reviewer Data only to provide Praise Patch to you and on your instructions, including the standing instruction to remove a review when a reviewer has asked for its removal and you have not acted within 10 business days of our forwarding it (section 4.1).
- Breach notice. If we become aware of a Security Incident affecting your data, we will notify you without undue delay and in any case within 72 hours of confirming it (section 4.7).
- Deletion. We delete Reviewer Data within 30 days of a verified request or the closure of your account, except records of reviewer consent, which are kept for three years. Backups are retained for seven days and are not restored after deletion (section 4.8).
- Sub-processor changes. We email you at least 30 days before we add or replace a sub-processor listed in Annex 3 (section 4.4).
Annex 1. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Collection, storage, display, and publication of customer reviews on behalf of the Customer, and the emails that ask for them. |
| Duration | For as long as the Customer holds a Praise Patch account, plus the deletion period in section 4.8. |
| Nature and purpose | Storing the Customer’s list of people to ask; sending review requests and up to two follow-up reminders from the Customer’s name; receiving and storing reviews in video, audio, or text; recording consent; holding each review privately until the Customer approves it; publishing approved reviews on the Customer’s public review page and, if the Customer chooses, on its own website through the Praise Patch embed; creating Share Studio images from approved reviews, which the Customer may use, with excerpts from its reviews, on its website, social media, and marketing within the reviewer’s consent; exporting on request; deleting on request. |
| Categories of data subjects | The Customer’s own customers and clients who are asked for, or leave, a review. Reviewers confirm that they are 18 or older. |
| Categories of personal data | Identity and contact: first name, email address, optional phone number (which the Customer may store for its own records; Praise Patch does not send text messages), optional business name, and an optional description of the reviewer’s own business. Review content: video and audio recordings (which include the reviewer’s image and voice), typed text, star rating, answers to the Customer’s prompts. Consent record: the exact wording agreed to and the time of agreement. Operational: email delivery and unsubscribe status, and the time a review was submitted, approved, declined, or published. |
| What is published | Only for reviews the Customer approves: the reviewer’s first name, their business name or description of their own business (if given), star rating, and the review itself in text, video, or audio. Email addresses and phone numbers are never published. |
| Special categories | None are requested by the service. The Customer agrees not to solicit them (section 5). No biometric data is processed, and video is not used to identify anyone. |
| Frequency | Continuous, for the duration of the account. |
| Retention | For the life of the account. Deleted within 30 days of a verified request or account closure, except records of reviewer consent, which are kept for three years. Backups are retained for seven days and are not restored after deletion (section 4.8). |
Annex 2. Technical and organizational measures
These are the measures in place at the date of this Addendum. They are described in more detail in the Praise Patch Information Security Policy.
- Encryption. All traffic uses HTTPS (TLS). Data and stored files are encrypted at rest by our hosting and database provider.
- Authentication. Customer passwords are stored only as one-way bcrypt hashes and are never visible to us. Leaked-password protection blocks passwords found in public breach lists. Signed-in sessions time out after a period of inactivity. Reviewers never create an account or a password.
- Media. Review video and audio are held in private storage. There are no permanent public file links. On public review pages, approved media is delivered through signed links that expire after 5 minutes. Pending and declined reviews are never linked.
- Access control. Row-level security is enabled on every table in the database. Public review pages read data only through functions that return approved reviews. Administrative access to our providers is limited to the founder and protected by a password manager. Multi-factor authentication is required on all administrative accounts.
- Private by default. Every review is held privately until the Customer approves it. Nothing publishes automatically.
- Minimization and tracking. The service collects only what a review needs. There is no profiling and no sale of data. There are no advertising pixels or third-party trackers. Basic analytics are provided by our hosting provider. The app itself sets only one functional cookie, which remembers a display preference.
- Artificial intelligence. Praise Patch does not use artificial intelligence to analyze or make decisions about Reviewer Data. The application is built with AI-assisted development tools (Lovable). These tools are not restricted from the production database and may access stored data when used to build and troubleshoot the service. Preview and production share one database.
- Change control. Every code change is versioned, backed up to a separate source repository, and passed through an automated security scan before publishing. The source repository holds code only, with no customer data and no secret keys. Secret keys are kept in the platform’s encrypted secret store.
- Backups and resilience. The database is backed up daily, and backups are retained for seven days. The application source is held in two independent locations.
- Incident response. A written procedure for containing, assessing, and notifying incidents, with the notification timing in section 4.7.
- Providers. Each sub-processor is chosen for its security practices, is bound by its own data processing terms, and is listed in Annex 3.
- People. Everyone with access is bound by confidentiality. Access is removed when a role ends.
- Deletion. Data is deleted within 30 days of a verified request or account closure, including stored video and audio files, except records of reviewer consent as set out in section 4.8.
Annex 3. Sub-processors
Current at the date of this Addendum. We email every customer at least 30 days before this list changes (sections 4.4 and 8).
| Sub-processor | What it does | Location |
|---|---|---|
| Supabase Pte. Ltd. (Singapore) | Database, account authentication, and private storage for uploaded video and audio files. | Data hosted in the United States (AWS us-west-1, Northern California). |
| Plus Five Five, Inc. (Resend) | Sends review request emails, follow-up reminders, and account emails on our behalf. | United States (sending domain hosted in AWS us-east-1, Northern Virginia). |
| Lovable Labs Incorporated, 1 Lincoln St, Boston, MA 02111, USA | Hosts the application, provides website analytics, and provides AI-assisted development tools that may access stored data when used to build and troubleshoot the service. | United States. Lovable and its providers may also process data in other countries. |
| Cloudflare, Inc. (United States) | Content delivery and security for the website. | Edge locations worldwide. |
Annex 4. Transfer mechanism selections
The Standard Contractual Clauses (Module Two, controller to processor) are incorporated with these selections. Where the Clauses call for an annex, the corresponding Annex of this Addendum supplies it.
| Clause or table | Selection |
|---|---|
| Clause 7 (docking clause) | Included. |
| Clause 9 (sub-processors) | Option 2, general written authorization. Notice period: 30 days. |
| Clause 11 (redress) | The optional independent dispute resolution language is not included. |
| Clause 13 (supervision) | The supervisory authority is determined by Annex I.C of the Clauses: the authority of the EU member state where the Customer is established, or where the Customer’s EU representative is established, or where the data subjects are located, as applicable. |
| Clause 17 (governing law) | The laws of Ireland. |
| Clause 18 (forum) | The courts of Ireland. |
| Annex I.A (parties) | Data exporter: the Customer, as identified in its Praise Patch account. Data importer: AI Profit Garden, LLC, a Nevada limited liability company, the company that makes Praise Patch, 9107 W. Russell Rd, Las Vegas, NV 89148, hello@praisepatch.com. |
| Annex I.B (processing) | As set out in Annex 1 of this Addendum. |
| Annex II (measures) | As set out in Annex 2 of this Addendum. |
| Annex III (sub-processors) | As set out in Annex 3 of this Addendum. |
| UK Addendum, Table 1 | Parties and contact details as in Annex I.A above. Key contact for the importer: Shelly Phillips, Managing Member, hello@praisepatch.com. |
| UK Addendum, Table 2 | The Approved EU SCCs, Module Two, with the selections above, as incorporated into this Addendum. |
| UK Addendum, Table 3 | Annexes 1A, 1B, II, and III as set out above. |
| UK Addendum, Table 4 | Either party may end the UK Addendum as set out in its Section 19. |
Agreement
This Addendum is incorporated into the Terms and applies automatically to every Customer to whom the Data Protection Laws apply, from the date the Customer first uses Praise Patch or the date this Addendum is posted, whichever is later. A Customer that requires a signed copy may request one at hello@praisepatch.com.
A signed copy uses the signature block below.
| Customer | AI Profit Garden, LLC | |
|---|---|---|
| Business name | ______________________ | AI Profit Garden, LLC, a Nevada limited liability company, the company that makes Praise Patch |
| Signed by | ______________________ | Shelly Phillips |
| Title | ______________________ | Managing Member |
| Signature | ______________________ | ______________________ |
| Date | ______________________ | ______________________ |