Data processing agreement
The Article 28 GDPR terms under which Laudiance processes personal data on your behalf: your testimonial givers' words, faces, voices and consent records. This agreement is part of the Terms of Service, binds from the moment you use the service, and we countersign a copy on request.
In effect from 5 August 2026.
The short version
For the personal data inside your testimonials — your customers' names, words, faces, voices and consent records — you are the controller and SOULSOLUTIONS S.R.L., the company behind Laudiance, is your processor. You decide whom to ask, what consent wording they see, what gets published and what gets deleted; we carry those decisions out and do nothing else with the data.
This agreement takes effect when you accept the Terms of Service or first use the service. There is no signature ceremony and no PDF to chase: acceptance is what makes it bind. If your lawyer or data protection officer needs a countersigned copy on file, email contact@laudiance.com and we will return one. The numbered sections below are the agreement itself, written to be put on file as they stand.
1. Parties, scope and effect
This agreement is between the customer named on the account ("you", the account holder who creates and operates a workspace) and SOULSOLUTIONS S.R.L., a company registered in Romania under trade register number J2026038112009, fiscal code 54876124, with its registered office at Str. Parângului nr. 9, et. 2, ap. 11, Târgu Mureș, jud. Mureș, România, which operates the Laudianceservice ("Laudiance"). It is the data processing agreement that Article 28(3) GDPR requires between a controller and its processor.
It forms part of the Terms of Service and takes effect when you accept them or first use the service, whichever comes first. "GDPR" means Regulation (EU) 2016/679 together with the member-state data protection law that applies to you. This version applies from 5 August 2026. Laudiance countersigns a copy on request; no signature is needed for it to bind.
2. Roles: you are the controller, Laudiance is the processor
"Customer Personal Data" means the personal data Laudiance processes for you in operating the service: everything your testimonial givers submit through your forms and request links, the media they record or upload, the consent records the service captures for you, the people who appear in testimonials you import or add by hand, and the names and email addresses of the people you ask for testimonials.
For Customer Personal Data, you are the controller and Laudiance is the processor. You decide whom to ask, what to ask, what consent wording to show, what to approve, what to publish and what to delete; Laudiance executes those decisions and nothing else. If you use Laudiance on behalf of a client (for example on the Agency plan), you may yourself be a processor for that client; Laudiance is then your sub-processor, this agreement still binds Laudiance to you, and you warrant that your client has authorised the arrangement.
Laudiance is a controller in its own right for your account data: your email address, login credentials, plan, billing records and support correspondence. The privacy policy covers that processing; this agreement does not.
3. Subject matter, duration, nature and purpose of the processing
Article 28(3) requires these details to be fixed in the contract.
| Detail | Description |
|---|---|
| Subject matter | Operation of the Laudiance service for you: hosted testimonial forms, personalised request links, a moderation inbox, a hosted Wall of Love, an embeddable widget, and import, export and deletion tooling. |
| Duration | The term of your agreement with Laudiance, plus the time deletion takes to complete under section 12 once the account closes. |
| Nature | Collection through your forms and request links; storage; hosting and transmission when your pages, walls, widgets and digest emails are served; organisation and moderation at your direction; pseudonymisation of IP addresses; export; erasure. |
| Purpose | Enabling you to collect, moderate and display customer testimonials with verifiable consent. Laudiance processes Customer Personal Data for no purpose of its own: no advertising, no profiling, no sale, no model training. |
4. Categories of data subjects and types of personal data
The table lists every category the service touches.
| Data subjects | Personal data processed |
|---|---|
| Submitters: your customers who complete a testimonial form or record a video | Name; role and company; profile photo; star rating; testimonial text and per-question answers; video including face and voice; submission language; the consent timestamp and the exact consent text version the person agreed to; a pseudonymised digest of the IP address (keyed hash, key rotated daily) held in the consent event record and in rate-limit counters. |
| Request recipients: people you ask for a testimonial through a personalised link | Name; email address if you add one; request timestamps (link created, marked sent, opened, started, completed). |
| Featured individuals: people in testimonials you import by CSV or add manually | Name; role and company; photo; rating; testimonial text; date. Stored flagged as imported, with no consent record, because Laudiance did not witness one. |
| Visitors: anyone who opens your form, wall, request page or embedded widget | Pseudonymised IP digests for rate limiting, which expire on a rolling basis. Raw IP addresses appear transiently in the infrastructure logs of the hosting sub-processors in section 8, and a visitor who is shown a photo or video reaches the storage sub-processor directly, which sees their IP address and user agent (section 7). Public pages set no cookies and write nothing to browser storage. |
The service asks for no special category data (Article 9 GDPR) and no data about criminal convictions, and you must not use it to invite either. Free text and video can still reveal such data incidentally, because a voice and a face carry more than a name; that content arrives at your direction and you remain responsible for it as controller. The service performs no automated decision-making and no profiling.
5. Your instructions
Your complete documented instructions are: this agreement, the Terms of Service, and the actions you take in the product, such as creating a form, editing consent wording, approving, publishing, unpublishing, tagging, importing, exporting, or deleting. Laudiance processes Customer Personal Data only on those instructions, including for transfers to third countries, unless European Union or member-state law requires otherwise; in that case Laudiance informs you of the legal requirement before processing, unless that law forbids the disclosure on important grounds of public interest.
Laudiance tells you without undue delay if, in its view, an instruction infringes the GDPR, and may pause that instruction until you confirm or amend it. Laudiance owes you no legal advice by giving that warning.
6. Confidentiality
Laudiance authorises access to Customer Personal Data only for people who need it to operate, support or secure the service, and only under a written confidentiality obligation or a statutory duty of confidence. The obligation survives the end of their engagement.
7. Security of processing (Article 32)
Article 32 asks for measures appropriate to the risk. The list below describes what the shipped system does today; where a control has a limit, the limit is stated next to it. Laudiance may strengthen or adjust these measures and will not materially weaken them without notice under section 15.
- EU residency.The database, uploaded media (video, photos, logos) and authentication data live in Supabase's Frankfurt region (eu-central-1). Data at rest stays in the European Union.
- Tenant isolation. Every database table carries row-level security; anonymous database access to data tables does not exist; public pages read and write through server code with explicit field allowlists. Automated isolation tests sign in as two different tenants plus an anonymous client against a real database and verify that cross-tenant reads, writes and storage-path guesses fail.
- Private media. All storage buckets are private. Media is reachable only through signed URLs that expire after at most one hour, so unpublishing and deletion revoke access in fact, and no permanent public media URL exists. Uploads are capped in size, checked against a MIME allowlist, verified against their actual bytes, and SVG is never accepted.
- Consent integrity. Consent wording is versioned append-only, and each testimonial references the exact version its author saw. The evidential core of a testimonial (author, text, answers, rating, media, source, consent time and version) is immutable at the database layer; your typo fixes are stored beside the original, never over it. An insert-only consent event log mirrors every consent record for tamper evidence.
- Hard deletion. Deleting a testimonial removes its database rows and stored files in one routine. Deleting an account cancels billing first, removes every workspace, testimonial, file and consent record, and resumes on its own if interrupted. Public caches revalidate on every change, so removed content stops being served at once.
- IP minimisation. The application stores no raw IP address. Rate limiting and consent evidence use keyed HMAC digests of the IP, and the key rotates daily.
- Cookie-free public surfaces. Your forms, wall, widget and request pages set no cookies, write nothing to browser storage, load no external fonts, and load no third-party script, analytics tag or advertising tag. The dashboard uses strictly necessary authentication cookies only; no analytics or tracking cookies exist anywhere.
- One request that leaves our domain, stated rather than glossed. Photos and videos are served to the visitor's browser straight from the storage sub-processor in section 8, on a host of the form
<project-ref>.supabase.co, through signed links that expire within an hour. A visitor shown a photo or a video therefore connects to that host, which sees their IP address and user agent. The link identifies the object and carries nothing about the visitor, and the host sets no cookie. It is a storage bucket in Frankfurt, not an analytics or advertising service, but it is a request to a third party and the DPA says so. - Rendering. Testimonial content renders as text, never as HTML, on every surface that shows it.
- Encryption. TLS protects every connection in transit; storage at rest is encrypted by the infrastructure provider as part of its platform.
- Abuse controls. Public endpoints enforce signed render tokens that bind each submission to the consent version the page displayed and to a minimum fill time, per-form honeypots, sliding per-IP rate limits checked before the request body is read and a per-form daily cap checked once the form is known, length caps on every field, per-workspace and per-form storage quotas, and signature verification with event-id idempotency on billing webhooks.
- Access control. Production credentials exist only as server-side configuration, and the privileged database key is confined to server-only modules that can never reach the client bundle.
Two limits sit alongside these controls, stated so nothing here overclaims: a signed media URL issued moments before a deletion keeps working until its signature lapses, at most one hour; and Vercel and Supabase retain raw client IPs in their own infrastructure logs under their own retention policies, which is why the IP claim above is scoped to the application.
8. Sub-processors
You give general written authorisation for the sub-processors in the table — the same four the privacy policy and the GDPR page of this site list, kept current in all three places.
| Sub-processor | Role | Company and data location |
|---|---|---|
| Supabase | Database, file storage and authentication. Also serves photos and videos directly to visitors' browsers, so it sees their IP addresses. | US company. Our project runs in the EU (eu-central-1, Frankfurt); data at rest stays in the EU. |
| Vercel | Hosting: serves the application | US company. Runs the application code and sees request traffic, including IP addresses, in its infrastructure logs. |
| Stripe | Payments and subscription billing | US company with EU infrastructure and EU entities for European billing. |
| Resend | Transactional email (welcome email, daily digest) | US company with EU sending infrastructure. |
There is no conditional or optional sub-processor. The four above are the whole list, and nothing in the product switches a fifth one on. Note that Supabase is the only one a visitor's browser reaches directly: it serves the photos and videos, as section 7 describes.
Laudiance tells you before a new or replacement sub-processor touches Customer Personal Data, by email to the account address and by updating the published list, and the notice states when the change takes effect. You may object before that date on reasonable, data-protection-related grounds. If Laudiance cannot resolve the objection — by configuration, by carve-out or by not proceeding — you may terminate the affected subscription, export your data first, and receive a pro-rata refund of prepaid fees for the unused period.
Laudianceengages each sub-processor under a written contract imposing data protection obligations at least as protective as this agreement, including for security of processing, and remains fully liable to you for each sub-processor's performance.
9. Helping you answer data subject rights
Requests from testimonial givers and request recipients belong to you as controller. The assistance Article 28(3)(e) requires is built into the product, so most requests need no ticket:
- Access and portability: Settings, Privacy and data, Export downloads machine-readable JSON with your forms, every testimonial in every status, original and edited text, every consent record, your review-request list, tags and media references
- Erasure: deleting a testimonial removes the database row and its files and takes it off your wall and widget at once; deleting the account removes everything
- Rectification: you can correct testimonial text while the original stays preserved beside your edit. The author's name, role, rating and media are immutable by design, because editing them would corrupt the consent record; when an author asks for such a change, delete the testimonial and collect it again
- Objection and withdrawn consent: unpublishing propagates immediately, and deletion is always available
If a data subject contacts Laudiance directly about your workspace, Laudiance forwards the request to you without undue delay and does not answer it on your behalf. Where a request exceeds what the built-in tools can do, Laudiance provides reasonable further assistance, taking into account the nature of the processing and the information available to it.
10. Personal data breaches
Laudiance notifies you of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it, by email to the account address.
The notice describes, as far as then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Laudiance may provide the information in phases as the investigation progresses, and documents every breach and its remediation so you can meet your own duties under Articles 33 and 34. Deciding whether to notify a supervisory authority or the data subjects stays with you — the 72-hour clock in Article 33 is yours, running from your awareness — and Laudiance does not make that notification for you.
11. Assistance with security, impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, Laudiance assists you with your obligations under Articles 32 to 36 GDPR. In practice: section 7 and the GDPR documentation on this site are written so you can lift them into a data protection impact assessment, and Laudiance answers reasonable follow-up questions from you, or arising from a supervisory-authority consultation, without undue delay.
12. Deletion and return at the end of the service
You can take your data out or destroy it yourself at any time during the term: export is self-service, and deletion works per testimonial or for the whole account.
When the agreement ends, or when you delete the account, Laudiance deletes all Customer Personal Data: database rows, media files and consent records together. Any subscription is cancelled first, your public pages stop resolving from the first second, and the deletion job resumes automatically if interrupted, so a partial run cannot leave media behind. On written request Laudiance confirms completion in writing.
Three qualifications, because they are true: a signed media URL issued just before deletion can keep working for up to one hour; deleted data can persist in the hosting sub-processor's routine backups until they rotate out of the provider's retention window, and those backups exist for disaster recovery and are never used to restore deleted records; and where European Union or member-state law requires Laudiance to retain something, Laudiance retains only that, only for as long as the law requires, and tells you which law.
13. Audits and information
Laudiance makes available to you all information necessary to demonstrate compliance with Article 28: this agreement, the GDPR documentation on this site, the current sub-processor list, the compliance documentation each sub-processor publishes, and written answers to a reasonable security questionnaire.
You, or an independent auditor you mandate who is not a competitor of Laudiance, may audit this compliance on reasonable written notice, at reasonable intervals, during business hours, remotely where the subject allows it, and under confidentiality. An audit never includes other customers' data (the tenant isolation in section 7 is also why an auditor cannot reach it) or sub-processor premises; for those, the sub-processors' own audit programmes apply. Each party bears its own costs. An audit a supervisory authority requires, or one following a personal data breach, is reasonable by definition.
14. International transfers
Customer Personal Data at rest stays in the European Union (Frankfurt, eu-central-1). Every current sub-processor is a US-headquartered company operating EU infrastructure, so Chapter V GDPR still applies: their non-EU staff can have administrative access for support and operations, and content served through a global edge network transits points of presence outside the EU.
For each such transfer, Laudiancerelies on the transfer mechanism in its contract with that sub-processor: the European Commission's Standard Contractual Clauses (Decision 2021/914), and the EU-US Data Privacy Framework where the sub-processor holds a valid certification. If a mechanism is invalidated, Laudiance moves the affected transfer to a lawful alternative or stops it.
Laudiance is established in Romania and initiates no transfer of Customer Personal Data outside the EEA other than through the sub-processors in section 8. Said plainly for your vendor review: if your compliance bar requires EU-owned vendors end to end, Laudiance does not meet it today, and section 8 is the honest state of things.
15. Liability, precedence, changes and contact
Liability under this agreement follows the limitations and caps in the Terms of Service. Nothing in this agreement or the Terms limits what a data subject can claim under Article 82 GDPR.
If this agreement conflicts with the Terms of Service on the protection of personal data, this agreement prevails, and no sub-processor term reduces your rights under it. It is governed by the law of Romania and lasts for as long as Laudiance processes Customer Personal Data, ending when deletion under section 12 completes.
Laudiance may update this agreement to track the law, the case law or the service, and announces material changes by email to the account address before they take effect; sub-processor changes follow section 8. Privacy matters and questions: contact@laudiance.com. Laudiance countersigns a copy of this agreement on request.