Legal
GDPR & Data Processing
Last updated: May 23, 2026
1. Roles
For customer review data and team member data, the customer is the controller and BridgeReview.AI acts as a processor under Art. 28 GDPR. BridgeReview.AI processes data only to provide and secure the service in accordance with documented customer instructions.
2. Processing activities
Processing includes storage, retrieval, synchronization with connected review platforms, AI draft generation, customer support, security monitoring, encrypted backups, and deletion on customer instruction. See the full list of categories in our Privacy Policy section 3.
3. Named subprocessors
We engage the subprocessors listed in the Privacy Policy section 7. Material additions or replacements are announced 30 days in advance via email to the workspace owner. Customers may object in writing within that window.
4. Security measures
Access controls (Supabase RLS scoped per organization), encryption in transit (TLS 1.3) and at rest, least-privilege service keys, database-side audit logging, PII-free application logs, per-request CSP nonce, and HSTS enforced. Full TOM available on request.
5. International transfers
Where subprocessors process data outside the EEA, transfers are protected by Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 and supplementary technical measures.
6. Data Processing Addendum (DPA)
A signed DPA covering the above is available on request. Email privacy@bridgereview.ai with your company name and signing contact; we'll counter-sign within 5 business days.
7. Assistance with data-subject requests
BridgeReview.AI will assist customers (without undue delay) with access, export, deletion, breach notification, and DPIA documentation obligations arising under GDPR.
8. Breach notification
We will notify affected customers without undue delay (and at the latest within 72 hours of becoming aware) of a personal-data breach affecting their workspace.