Privacy Policy
Effective Date: January 1, 2026 Β· UK Data Protection Act & GDPR Compliant Β· Localized for Canada
Verybooked LTD ("Verybooked", "Company", "we", "us", or "our"), a company registered in England and Wales, operating the website reviewautomators.com and trading as Review Automators (and reviewautomators.com by verybookedai.com), is committed to safeguarding the privacy and data rights of our commercial clients, website visitors, and their prospective review recipients.
This Privacy Policy articulates with forensic precision how we collect, process, protect, transfer, and store personal data across our reputation management software, Google Business Profile services, website design solutions, and press release networks. We adhere strictly to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), and relevant international privacy statutes such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
1. Data Controller Identity & Regulatory Registration
Verybooked LTD is the designated Data Controller for all personal data gathered directly from visitors to reviewautomators.com, prospective subscribers, and account holders. We are registered with the United Kingdom Information Commissioner's Office (ICO), the statutory data protection supervisory authority in the UK.
Corporate Contact: Verybooked LTD, London, England, United Kingdom. Privacy Inquiries: [email protected].
2. Categories of Personal Data Collected
We process personal information only to the extent necessary to deliver high-performance reputation management and corporate authority solutions. The categories of data we process include:
- Subscriber Account & Commercial Billing Data: Business trade name, registered corporate address, authorized administrator name, business email address, phone number, and tax identification numbers. Card payments are handled directly by Stripe; we never store raw credit card credentials.
- Client End-Customer Contact Lists: First and last names, mobile telephone numbers, and email addresses uploaded by subscribers for automated review invitation dispatch. We collect transaction timestamps or internal invoice reference IDs when provided by the client.
- Platform Authentication & OAuth Credentials: OAuth tokens granting authorized programmatic access to client Google Business Profiles, Meta Business pages, or connected CRM systems, used strictly to fetch reviews and publish approved responses.
- Technical Telemetry & Essential Cookies: Anonymized IP addresses, browser user agent strings, device classifications, and strictly necessary cookies (such as 'ra_market' to record country and language selections).
3. Legal Bases for Processing under UK/EU GDPR
Under Article 6 of the UK GDPR and EU GDPR, Verybooked LTD processes personal data only where a recognized lawful basis applies:
- Article 6(1)(b) - Performance of a Contract: Processing is essential to execute our software agreement, maintain subscriber accounts, deliver automated SMS and email review invitations, and fulfill purchased services.
- Article 6(1)(f) - Legitimate Interests: Processing is conducted to preserve platform security, prevent fraudulent abuse, detect carrier delivery bottlenecks, and improve service stability, without overriding individual fundamental rights.
- Article 6(1)(c) - Compliance with Legal Obligations: Processing and record retention required by UK HMRC, Companies House, tax legislation, and consumer protection authorities.
- Article 6(1)(a) - Consent: Where an individual has granted specific, informed consent (e.g., subscribing to educational newsletters or testing beta functionality).
4. Data Controller vs. Data Processor Roles (Data Processing Agreement)
To ensure strict compliance with Article 28 of the UK/EU GDPR, Verybooked LTD delineates data responsibilities into two distinct capacities:
1. As Data Controller: For information concerning our subscribers, account administrators, website visitors, and billing records, Verybooked LTD is the Data Controller, determining the purposes and means of processing.
2. As Data Processor: For contact lists uploaded by subscribers containing customer phone numbers and emails for automated review generation, the Subscriber acts as the Data Controller, and Verybooked LTD acts solely as a Data Processor. Verybooked LTD processes such data exclusively pursuant to the client's documented instructions under our standard Data Processing Agreement (DPA). Verybooked LTD does not independently verify end-customer consent and relies strictly on Client's representations that all uploaded contacts were acquired lawfully.
5. Sub-Processors, Data Sharing & Zero-Monetization Policy
Zero Selling or Sharing for Marketing: Verybooked LTD maintains a zero-monetization policy regarding personal data. We do not sell, rent, monetize, license, or trade client data, end-customer contact lists, or mobile phone numbers to third-party data brokers, marketers, or advertisers.
We engage verified, tier-one sub-processors bound by stringent data processing agreements:
- Stripe: PCI-DSS Level 1 certified payment gateway handling billing, subscription processing, and fraud screening.
- Cloudflare & AWS: Enterprise cloud hosting, global edge delivery, DDoS mitigation, and encrypted database infrastructure.
- Twilio: Telecommunications carrier platform executing automated SMS review requests and carrier routing.
- SendGrid & Resend: High-deliverability transactional email delivery infrastructure for review invitations and account alerts.
- OpenAI: Natural language processing models used for review reply drafting and sentiment analysis. API data is not used to train foundation models.
- BrandStoryPresswire: Wire network syndication infrastructure used for client-approved press release distribution to media outlets.
6. International Data Transfers & Safeguards
As an international platform serving clients across the UK, EU, US, Canada, Australia, and Switzerland, data may be processed in facilities located outside your country of residence, including cloud servers located in the UK, the European Union, and the United States.
Whenever personal data subject to the UK GDPR or EU GDPR is transferred outside the UK or EEA, Verybooked LTD implements recognized cross-border safeguards in compliance with Chapter V of the GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses (SCCs), and European Commission Standard Contractual Clauses with supplemental technical encryption safeguards.
7. Data Retention Schedules & Automated Purging
We retain personal data strictly for as long as necessary to achieve the operational purposes outlined in this Policy:
- Subscriber Account Records: Retained for the lifespan of the active commercial subscription plus twelve (12) months following termination to accommodate account restoration requests.
- Uploaded Customer Review Lists: End-customer contact lists uploaded for automated outreach campaigns are automatically purged from active message dispatch databases within ninety (90) days following campaign completion.
- Statutory Financial & Tax Documentation: Invoiced billing records, VAT logs, and accounting transactions are retained for seven (7) years in accordance with UK HMRC statutory corporate record requirements.
8. Enterprise Security Safeguards & Zero-Leakage Architecture
Verybooked LTD enforces industry-leading technical and organizational security controls designed to prevent unauthorized access, disclosure, alteration, or destruction of personal data:
- Cryptographic Safeguards: All web and API communications are encrypted in transit using Transport Layer Security (TLS 1.3). All database records and backup snapshots are encrypted at rest using AES-256.
- Self-Hosted Asset Architecture: ReviewAutomators.com utilizes a zero-leakage asset topology. All typography, fonts, icons, and static scripts are hosted locally on our verified cluster. No visitor IP addresses are leaked to third-party ad networks or tracking CDNs.
- Access Governance & Audit Logging: Strict Role-Based Access Control (RBAC), mandatory Multi-Factor Authentication (MFA) on internal administrative portals, and immutable audit logs.
9. Statutory Rights under UK/EU GDPR
Individuals residing within the United Kingdom and the European Union enjoy substantial statutory data rights under the UK GDPR, Data Protection Act 2018, and EU GDPR:
- Right of Access (SAR): The right to obtain confirmation as to whether your personal data is processed and request a copy of all personal records.
- Right to Rectification: The right to demand immediate correction of inaccurate or incomplete personal information.
- Right to Erasure ('Right to be Forgotten'): The right to request permanent deletion of your personal data where retention is no longer legally justified.
- Right to Restriction & Objection: The right to restrict processing or object to processing conducted under legitimate interests.
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format (CSV/JSON).
- Right to Lodge an ICO Complaint: You have the right to lodge a complaint with the UK supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF (ico.org.uk), or your local EU National Data Protection Authority.
10. California Privacy Rights (CCPA / CPRA Disclosures)
For California residents, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA) requires specific disclosures:
Verybooked LTD does not sell consumer personal information, nor do we share consumer personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than providing our core reputation management services. California residents have the right to request disclosure of categories of personal information collected, request deletion, correct inaccurate information, and be free from discrimination for exercising privacy rights. Submit requests to [email protected].
11. Data Protection Officer & Privacy Inquiries
To exercise any statutory data right, submit a subject access request, or discuss our Data Processing Agreement, contact our Data Protection Officer:
- Data Protection Office: Verybooked LTD, Data Protection & Legal Compliance Division
- Corporate Office: London, England, United Kingdom
- Dedicated Privacy Email: [email protected]