Praise Patch
Data Processing Addendum

Data Processing Addendum

How we handle your customers’ personal data on your behalf, with extra terms for customers covered by the EU or UK GDPR.

Effective September 30, 2026. Last updated September 30, 2026.

AI Profit Garden, LLC, a Nevada limited liability company
9107 W. Russell Rd, Las Vegas, NV 89148
hello@praisepatch.com

1. What this addendum is

This Data Processing Addendum (the “Addendum”) forms part of the Praise Patch Terms of Service (the “Terms”) between you, the customer who holds a Praise Patch account (“you” or the “Customer”), and AI Profit Garden, LLC, a Nevada limited liability company, the company that makes Praise Patch (“we,” “us,” or “Praise Patch”). Our address is 9107 W. Russell Rd, Las Vegas, NV 89148, and you can reach us at hello@praisepatch.com.

Most of this Addendum applies whenever the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) or the UK General Data Protection Regulation together with the UK Data Protection Act 2018 (“UK GDPR”) applies to personal data you process using Praise Patch. Together these are the “Data Protection Laws.”

Section 8 is different. It applies to every Praise Patch customer, wherever you and your customers are. If the Data Protection Laws do not apply to you, section 8 is the part of this Addendum that applies to you, and nothing else here changes your Terms.

If anything in this Addendum conflicts with the Terms on a question of personal data, this Addendum wins. On everything else, the Terms win.

2. The words we use

3. Who is who

For Reviewer Data, you are the controller and we are the processor. You decide whom to ask for a review, what questions to ask, what to approve, and where to publish. We hold and process Reviewer Data only so the service can do those things for you.

For Account Data, we are an independent controller. How we handle it is described in the Praise Patch Privacy Policy, not in this Addendum.

The details of the processing we carry out for you are set out in Annex 1.

4. What we commit to as your processor

4.1 We follow your instructions

We process Reviewer Data only on your documented instructions. Your instructions are: the Terms, this Addendum, the way you use the features of Praise Patch (adding a customer, sending a request, approving or declining a review, publishing a review or taking it off your page, exporting, deleting), and removing a review where the reviewer has asked for its removal and you have not acted on that request within 10 business days of our forwarding it to you. We will not process Reviewer Data for any other purpose. If we believe an instruction would break the Data Protection Laws, we will tell you before acting on it.

4.2 We keep it confidential

Every person we allow to access Reviewer Data is bound by a duty of confidentiality, whether by contract or by law. At the date of this Addendum that is our founder and any contractor working under a written confidentiality agreement.

4.3 We keep it secure

We maintain the technical and organizational measures described in Annex 2, and we keep them appropriate to the risk. We may improve them over time. We will not reduce the overall level of protection during the term of this Addendum.

4.4 We use a short list of sub-processors, and we tell you before it changes

You give us general authorization to use the sub-processors listed in Annex 3. Each one is bound by written terms that protect Reviewer Data at least as well as this Addendum does, and we remain responsible to you for their work.

Before we add or replace a sub-processor, we will email the address on your account at least 30 days in advance. We send this notice to every Praise Patch customer (section 8).

If you object on reasonable data protection grounds and we cannot resolve it, you may end your use of Praise Patch and ask us to delete your data. If you are within 30 days of your purchase and have not yet published an approved review, we will refund your one-time purchase in full, as the Terms provide. If you pay for a monthly subscription upgrade, we will also refund any unused subscription period.

4.5 We help you answer the people in your data

Praise Patch gives you the tools to handle most requests yourself: you can see, approve, decline, take off your page, export, and delete any review, and you can remove a customer from your list. If a data subject contacts us directly about Reviewer Data, we will forward the request to you, because it is your page and your relationship. If a reviewer asks us to remove their review and you have not acted within 10 business days of our forwarding the request, we will remove it, as section 4.1 provides. Where you need more from us, we will give reasonable help so you can respond within the time the Data Protection Laws allow. If a request creates real cost for us, we may charge a reasonable fee, and we will tell you before we do.

4.6 We help with assessments and regulators

On reasonable request, we will give you the information you need for a data protection impact assessment, or for a consultation with a supervisory authority, to the extent it concerns processing we do for you.

4.7 We tell you about incidents, fast

If we become aware of a Security Incident, we will notify you without undue delay and in any case within 72 hours of confirming it. The notice will say what we know at that point: what happened, what data and roughly how many people are affected, what we have done, and what we recommend you do. We will keep you updated as we learn more. Notice is not an admission of fault.

4.8 We give it back, or delete it, when you leave

While your account is open you can export your reviews and customer list at any time. We delete Reviewer Data, including stored video and audio files, within 30 days of a verified request or the closure of your account, except records of reviewer consent, which you instruct us to retain for three years to document the permission under which a review was published. Backups are retained for seven days and are not restored after deletion. Apart from those consent records, we keep Reviewer Data after deletion only where the law requires it, and only for as long as it requires.

4.9 We show our work

We will give you the information reasonably needed to show that we meet this Addendum. Once in any 12-month period, on 30 days’ written notice, you or an independent auditor you appoint (bound by confidentiality) may verify our compliance. We will start with written answers and documents. An on-site audit happens only if a supervisory authority requires it, or written evidence is genuinely insufficient, and it takes place during business hours without disrupting the service. You bear the costs of any audit you request.

4.10 We keep records

We keep the records of processing that Article 30 of the GDPR requires of a processor, and we will make them available to a supervisory authority on request.

5. What you commit to as controller

6. Where the data goes

Praise Patch is operated from the United States. Reviewer Data is stored in the United States. It may be processed in other locations where our sub-processors operate, as listed in Annex 3, including in transit through Cloudflare’s global network. By using Praise Patch you instruct us to transfer Reviewer Data to those locations.

For transfers of personal data subject to the GDPR, the parties enter into the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated by reference into this Addendum with the selections set out in Annex 4. For transfers subject to UK GDPR, the parties also enter into the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (the “UK Addendum”), completed as set out in Annex 4. If a supervisory authority or court decides that a different or additional mechanism is required, the parties will work together in good faith to put it in place.

7. Liability, term, and the rest

Each party’s liability under this Addendum, including the Standard Contractual Clauses, is subject to the limits and exclusions in the Terms, and counts toward the same overall cap. Nothing here limits liability that the Data Protection Laws do not allow to be limited, and nothing in this Addendum limits any data subject’s rights under the Standard Contractual Clauses.

This Addendum lasts as long as we process Reviewer Data for you, and the deletion obligation in section 4.8 survives after that.

This Addendum is governed by the law that governs the Terms, the laws of Nevada, except where the Standard Contractual Clauses or the UK Addendum require otherwise, in which case the law and courts set out in Annex 4 apply to those clauses.

Questions about this Addendum go to hello@praisepatch.com.

8. Commitments to every customer

The rest of this Addendum applies where the Data Protection Laws apply. The commitments in this section apply to every Praise Patch customer, including customers in the United States, whether or not the Data Protection Laws apply to you. Where this section points to another section, that section applies to you for this purpose.

Annex 1. Details of the processing

Annex 2. Technical and organizational measures

These are the measures in place at the date of this Addendum. They are described in more detail in the Praise Patch Information Security Policy.

Annex 3. Sub-processors

Current at the date of this Addendum. We email every customer at least 30 days before this list changes (sections 4.4 and 8).

Annex 4. Transfer mechanism selections

The Standard Contractual Clauses (Module Two, controller to processor) are incorporated with these selections. Where the Clauses call for an annex, the corresponding Annex of this Addendum supplies it.

Agreement

This Addendum is incorporated into the Terms and applies automatically to every Customer to whom the Data Protection Laws apply, from the date the Customer first uses Praise Patch or the date this Addendum is posted, whichever is later. A Customer that requires a signed copy may request one at hello@praisepatch.com.

A signed copy uses the signature block below.