Privacy · RecensioAI B.V.

    Privacy Policy

    Last updated: August 24, 2026Official documentKvK 42028360 · BTW NL869375556B01
    At RecensioAI we take the protection of personal data seriously. This document explains which data we process, why, and what rights you have under the GDPR.

    1. Who are we?

    This privacy policy applies to the processing of personal data by:

    RecensioAI B.V.
    Trade name: RecensioAI
    Registered office: De Nieuwe Erven 3, unit 14563, 5431 NV Cuijk, Netherlands
    Email: support@recensioai.com
    Chamber of Commerce number: 42028360
    VAT identification number: NL869375556B01

    In this privacy policy, we use the terms "RecensioAI", "we", "us" or "our".

    2. When is RecensioAI a data controller and when a processor?

    Depending on the situation, RecensioAI may act as:

    a. Data Controller

    We are the data controller for personal data that we process for our own purposes, such as:

    • creating and managing accounts,
    • billing and administration,
    • customer service and support,
    • security, monitoring and fraud prevention,
    • communication with customers and prospects,
    • improving our platform,
    • marketing communications, where permitted,
    • website usage, cookies and analytics.

    b. Data Processor

    In some cases, we process personal data on behalf of our customers. This applies, for example, when our customers use RecensioAI to:

    • send review requests,
    • upload customer data,
    • collect feedback,
    • centralize reviews,
    • have review responses drafted,
    • collect data from visitors of their guest WiFi via WiFi Social (captive portal) and use it for their own marketing,
    • send newsletters, broadcasts and win-back campaigns to their own audiences via Email Marketing,
    • use reports or flows for their own customers or visitors.

    In those situations, our customer determines the purpose of the processing and RecensioAI acts as a processor, unless expressly stated otherwise.

    3. To whom does this privacy policy apply?

    This privacy policy applies to:

    • visitors to our website,
    • persons who contact us,
    • customers and users of our platform,
    • representatives and contact persons of customers,
    • persons whose data is processed through our customers on the platform,
    • persons whose public review data is visible within the platform through linked review platforms.

    4. What personal data do we process?

    Depending on the situation, we may process the following personal data:

    a. Data from website visitors

    • IP address
    • browser and device data
    • cookie data
    • language settings
    • usage and click behavior on the website
    • form submissions

    b. Data from customers and account users

    • name
    • company name
    • email address
    • phone number
    • billing details
    • payment status and subscription details
    • login and account details
    • communication with support
    • settings and preferences on the platform

    c. Data of end customers or data subjects of our customers

    Depending on what our customer processes or links, this may include:

    • name
    • email address
    • phone number
    • review content
    • Feedback
    • responses to review requests
    • rating scores
    • metadata related to sent requests
    • data that our customer imports or has processed through integrations

    d. Data from review platforms and external integrations

    When a customer links review platforms, we may receive or retrieve data from, for example:

    • Google
    • Facebook
    • Trustpilot
    • TripAdvisor
    • Booking.com
    • Yelp
    • Airbnb
    • Expedia
    • other linked review or communication platforms

    This may include:

    • public review texts
    • review score
    • date and time of the review
    • username or profile name as visible on the external platform
    • responses to reviews
    • metadata of linked locations or business profiles

    e. AI and automation data

    If AI functionalities are enabled, review texts, feedback, contextual data and draft responses may be processed to generate automatic replies, analyses or recommendations.

    5. How do we obtain personal data?

    We obtain personal data in various ways:

    • directly from you, for example through the website, contact forms, demo requests, support requests or account registration;
    • through our customers, when they upload, import or have data processed through the platform;
    • through linked review platforms and external integrations;
    • automatically through cookies, log files, analytics and use of the website or platform;
    • through payment providers, communication providers or other service providers necessary for providing our services.

    When personal data is not obtained directly from the data subject, this usually happens through our customer or through a link activated by our customer. In that case, our customer is generally responsible for informing data subjects, unless the law or the actual role distribution dictates otherwise.

    6. For what purposes do we process personal data and on what basis?

    We only process personal data for specific purposes and on the basis of a valid legal ground.

    a. Account management and service delivery

    We process personal data to:

    • create accounts,
    • provide access to the platform,
    • manage subscriptions,
    • make features available,
    • provide support,
    • perform onboarding.

    Legal basis: performance of the contract and/or legitimate interest.

    b. Billing, administration and payment processing

    We process personal data for:

    • invoicing,
    • subscription costs,
    • payment processing,
    • bookkeeping,
    • tax and administrative obligations.

    Legal basis: performance of the contract and legal obligation.

    c. Review requests, feedback flows and review management

    We process personal data so that our customers can:

    • send review requests,
    • collect feedback,
    • centralize reviews,
    • view statistics and reports,
    • use AI responses.

    Legal basis: in most cases, processing on behalf of our customer. The customer is then responsible for a valid legal ground. RecensioAI processes this data on behalf of the customer.

    d. Customer service, support and communication

    We process personal data for:

    • answering questions,
    • support via email, or phone,
    • following up on tickets,
    • feedback on accounts or issues.

    Legal basis: performance of the contract and legitimate interest.

    e. Security, fraud prevention and monitoring

    We process personal data for:

    • security of our systems,
    • monitoring of performance and disruptions,
    • detection of abuse, fraud or unauthorized access,
    • audit and logging purposes.

    Legal basis: legitimate interest and, where necessary, legal obligation.

    f. Platform improvement

    We use personal data and usage data to:

    • improve performance,
    • fix bugs,
    • develop functionalities,
    • optimize user experience.

    Legal basis: legitimate interest.

    g. Marketing and newsletters

    We may use personal data for:

    • sending updates,
    • tips, newsletters or product information,
    • following up on demo or contact requests.

    Legal basis: consent or legitimate interest, depending on the situation and applicable rules.

    h. Compliance with laws and regulations

    We may process personal data to comply with:

    • tax obligations,
    • administrative obligations,
    • requests from competent authorities,
    • other legal obligations.

    Legal basis: legal obligation.

    7. AI functionalities

    RecensioAI may use AI for, among other things:

    • generating draft responses to reviews,
    • analyzing feedback,
    • structuring review or reputation data,
    • making suggestions or recommendations.

    In this regard:

    • AI output may be incorrect, incomplete or inappropriate;
    • customers remain responsible for reviewing, adjusting and publishing AI-generated output, unless expressly agreed otherwise;
    • we do not use AI to make fully automated decisions with legal effects or similarly significant consequences for data subjects, unless this is expressly and lawfully arranged and communicated otherwise.

    If necessary, review texts, feedback or contextual data may be shared with AI service providers acting as our processor or sub-processor.

    8. With whom do we share personal data?

    We do not sell personal data.

    We may share personal data with:

    a. Service providers and processors

    Such as:

    • hosting and cloud providers
    • email providers
    • SMS and communication providers
    • or messaging providers
    • payment providers
    • support and helpdesk tools
    • analytics providers
    • AI service providers
    • security and monitoring providers

    b. Customer-activated integrations

    When a customer activates a link with a review platform or other external service, personal data may be exchanged with that external party.

    c. Government bodies or competent authorities

    If we are legally required to do so or if it is necessary for the protection of our rights or the security of our platform.

    d. Legal successors or parties involved in an acquisition

    In case of merger, acquisition, restructuring or sale of (part of) our company, insofar as permitted by law.

    9. Is personal data processed outside the EEA?

    Our primary servers and hosting are located in Europa.

    However, in certain cases personal data may be processed or accessible outside the European Economic Area (EEA), for example when we use certain external software providers, AI service providers, communication providers, support tools or other sub-processors, or when a customer-activated integration processes personal data outside the EEA.

    When personal data is transferred outside the EEA, we ensure appropriate safeguards where necessary, such as:

    • an adequacy decision of the European Commission, or
    • Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented where necessary with appropriate additional measures.

    10. How long do we retain personal data?

    We do not retain personal data longer than necessary for the purpose for which they were collected, unless we are required to retain them longer by law or a legitimate interest.

    In general, we apply the following retention periods:

    • account and customer data: as long as the account is active and thereafter for a maximum of 24 months, unless longer is needed for administration, evidence or disputes;
    • invoice and administrative data: as long as legally required, typically 7 years;
    • support communications: in principle, a maximum of 24 months after completion, unless longer is needed for file building or disputes;
    • website and analytics data: according to relevant cookie and analytics settings, or shorter if technically necessary;
    • data we process on behalf of customers: according to customer instructions and/or contractual agreements, and in principle deleted or anonymized after termination of the agreement, unless a legal retention obligation applies;
    • Backups: may temporarily still contain personal data until the relevant backup cycle is overwritten.

    We periodically review retention periods and delete or anonymize data as soon as reasonably possible.

    10b. Meta Platforms (Facebook, Instagram, Threads, Messenger)

    When a customer activates a Meta integration, we obtain access to a limited set of data necessary to display and manage reviews, posts and messages within RecensioAI on the customer's behalf. We support integrations with Facebook Pages, Instagram Business, Threads and Messenger.

    What data do we process per source?

    • Page and user access tokens (stored encrypted)
    • Reviews, comments, post content and related metadata
    • Inbound and outbound messages (Messenger, Instagram DM)
    • Profile name, avatar, page ID and public page statistics

    Purpose limitation

    We use Meta data exclusively to (a) display reviews, posts and messages in the RecensioAI dashboard, and (b) allow customers to publish or respond from within RecensioAI. We never use Meta data for advertising, AI model training, sale or transfer to third parties outside the sub-processors listed in this policy.

    Retention and revocation

    Tokens are stored encrypted and automatically deleted when the customer disconnects the integration or terminates the account. Cached Meta content is wiped at the latest 90 days after disconnection. The customer can revoke the integration at any time via Settings → Integrations or via Meta Business Settings on their own page. For instructions, see Data Deletion Instructions.

    Sub-processors

    For the processing of Meta data and the general operation of the platform we use the following sub-processors (all under GDPR-compliant data processing agreements):

    • Supabase (EU) — database, authentication and file storage
    • Google Gemini & OpenAI — AI models for review replies and analyses
    • Resend — transactional email delivery
    • Stripe — payment processing
    • Cloudflare — CDN, bot mitigation and Turnstile
    • Third-party SMS provider (premium SaaS, EU/US)SMS delivery under GDPR Standard Contractual Clauses

    10c. SMS communications and opt-out

    Recipients of SMS messages sent via the Platform can send STOP to the sending number at any time to stop receiving SMS messages. Messages containing STOP or HELP are processed automatically. Numbers that have sent STOP are placed on a permanent suppression list and will not receive any further SMS messages via the Platform, unless the data subject explicitly re-consents.

    11. Cookies and similar technologies

    We use cookies and similar techniques on our website and possibly also in parts of our platform.

    These may be used for:

    • proper functioning of the website,
    • security,
    • preferences and language settings,
    • analytics and usage statistics,
    • marketing or tracking, if applicable and permitted.

    For more information, please refer to our cookie policy. Where legally required, we ask for consent in advance for non-essential cookies.

    12. Security

    We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, unwanted disclosure and unlawful processing.

    Measures used may include:

    • role-based access restriction,
    • encryption where appropriate,
    • logging and monitoring,
    • backup and recovery procedures,
    • secure connections,
    • vendor management,
    • internal procedures for incidents and data breaches.

    However, no system is completely secure. Therefore, we cannot guarantee absolute security.

    13. Your rights

    As a data subject, you have, insofar as legally applicable, the right to:

    • access your personal data,
    • rectification of inaccurate data,
    • erasure of data,
    • restriction of processing,
    • objection to processing,
    • data portability,
    • withdrawal of previously given consent,
    • filing a complaint with a supervisory authority.

    You can submit a request via support@recensioai.com.

    We may request additional information to verify your identity before responding to a request.

    We will respond to your request in principle within one month. If your request is complex or if we receive many requests, we may extend this period as the GDPR allows, provided we inform you in a timely manner.

    14. Complaints

    If you have complaints about how we handle personal data, we first ask you to contact us at support@recensioai.com.

    You also have the right to file a complaint with a competent supervisory authority, such as:

    • the Dutch Data Protection Authority in the Netherlands, or
    • the competent privacy supervisory authority in the country where you live, work or where the alleged infringement took place.

    15. Public reviews and external platforms

    RecensioAI may display or process public reviews, scores, profile information or metadata when a customer links a review platform.

    Important:

    • the rules and privacy terms of the relevant review platform continue to apply;
    • RecensioAI has no control over how external review platforms process personal data themselves;
    • the fact that data is publicly visible on an external platform does not automatically mean that all further processing is unrestricted;
    • customers remain responsible for the lawful use of linked integrations and data within their own business operations.

    16. Minors

    Our services are not aimed at children under 16. We do not knowingly collect personal data from children without valid consent or other legal basis. If we discover that such data has been unlawfully collected, we will take appropriate measures.

    17. Changes to this privacy policy

    We may update this privacy policy from time to time, for example in case of:

    • changes in laws and regulations,
    • changes in our services or integrations,
    • changes in the way we process personal data.

    The most current version will always be published on our website. In case of significant changes, we will communicate this additionally where appropriate.

    18. Google API Services — Limited Use Disclosure

    RecensioAI uses the Google Business Profile API to help customers manage their Google Business Profile (reading and replying to reviews, publishing posts, updating location information) and — optionally, only after the customer explicitly connects it — the Google Analytics API to display read-only website statistics in the dashboard. RecensioAI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    Concretely this means:

    • We use Google user data solely to provide or improve user-facing features that the user has requested.
    • We do not transfer Google user data to third parties except as necessary to provide those features, for security reasons, or to comply with applicable law.
    • We do not use or transfer Google user data for serving advertisements.
    • No humans read Google user data unless we have the user's affirmative agreement, it is necessary for security (e.g. investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations.

    Which OAuth scopes do we request?

    • https://www.googleapis.com/auth/business.manage required to manage the user's linked Google Business Profiles on their behalf: read and update location information, read and reply to reviews, and publish posts/photos.
    • https://www.googleapis.com/auth/analytics.readonly optional, only when the user connects their own Google Analytics 4 property. Strictly read-only: we read aggregated website statistics (visitors, traffic sources, most-viewed pages and conversion events) to display them in the user's own dashboard. We cannot change anything in the Analytics account.

    A full per-scope explanation — which fields we read, how long we keep them and how to revoke access — is available on our Google Data Use page.

    What data do we store and for how long?

    • OAuth access and refresh tokens — stored encrypted, deleted within 30 days after disconnection or account termination.
    • Google account ID and location IDs of the linked business profiles.
    • Review text, ratings, replies and related metadata, only as needed to provide the service.
    • Posts, media references and publication status.

    How do you revoke access?

    After disconnection Google tokens are permanently deleted within 30 days. Previously fetched review data remains available as historical reporting unless the customer requests deletion.

    19. Sub-processors

    To deliver our services we use the following sub-processors. With each of these parties we have a data processing agreement in place and, where applicable, EU Standard Contractual Clauses.

    PartyRoleLocation
    SupabaseDatabase, authentication, file storageEU (Frankfurt)
    ResendTransactional, newsletter and campaign emailEU / US (SCCs)
    StripePayment processing and billingEU / US (SCCs)
    CloudflareCDN and Turnstile bot protectionGlobal (SCCs)
    Google LLCBusiness Profile API (reviews, posts, locations) and Analytics API (read-only website statistics, optional)US (SCCs)
    Google Gemini & OpenAIAI models (Gemini, OpenAI) for review replies and analysesEU / US (SCCs)
    QRServerQR code renderingEU

    An up-to-date list is available on request via support@recensioai.com.

    20. Retention periods

    • Review requests and end-customer contact data: 24 months after last contact.
    • Visitor data from review pages, Wi-Fi portals and kiosk (email address, name, consent status): 24 months after last contact, or sooner upon a deletion request or unsubscribe.
    • Demo workspaces: automatically deleted after 24 hours.
    • Shared scan reports: 10 days, then automatically deleted.
    • Prospects table (lead capture): 10 days.
    • AI prompts and outputs: maximum 30 days for debugging and quality improvement.
    • Authentication and audit logs: 12 months.
    • Google OAuth tokens: deleted within 30 days after disconnection.
    • Billing and administrative records: 7 years (Dutch statutory tax retention obligation).

    21. Automated decision-making and AI

    Our AI features (for example suggested review replies, sentiment analysis and recommendations) generate drafts or suggestions. A human (the customer or their employee) always reviews and confirms before publication. There is no solely-automated decision-making producing legal effects for data subjects within the meaning of Article 22 GDPR.

    22. Visitor data on review pages (email field, Google One Tap, Wi-Fi and kiosk)

    RecensioAI customers use a public review page (/r/…), a Wi-Fi sign-in page or a kiosk mode to ask their guests for a review. On these pages visitors can voluntarily leave their email address. For that processing the customer (the business using the page) is the data controller; RecensioAI acts as processor.

    Email field above the review button

    • What data: the email address the visitor enters, the consent status ("Get updates" on/off), the timestamp, a hashed version of the IP address and the browser user agent — solely for abuse and fraud prevention.
    • Why: to add the visitor as a contact in the business's contact list, so the business can later send a review request or news.
    • Legal basis: consent (Article 6(1)(a) GDPR) for marketing messages. The checkbox is optional: if the visitor leaves it unchecked, the email address is stored without marketing consent and is not used for commercial messages.
    • Entering an email address is never a condition for leaving a review on Google; the visitor can always leave the page without further use.
    • Businesses can switch this feature off entirely in their dashboard. When it is off, no email address is processed.

    Google One Tap (Google Identity Services)

    • On the review page, Google One Tap may be shown. If the visitor chooses to continue with their Google account, we receive a signed token from Google containing: email address, name (first and last), profile picture URL and a Google account identifier (sub).
    • We verify the token signature with Google before anything is stored. No Google password is processed and no access to the visitor's Google account is requested.
    • Legal basis: the visitor's explicit action to continue with Google (consent). This data is used solely to create the contact record for that specific business.
    • In this case Google is an independent controller for the sign-in process; Google's own privacy policy applies to it.
    • One Tap is not shown in kiosk mode or in embedded (embed) views.

    What do we not do with this visitor data?

    • We do not sell or rent this data and do not share it with other RecensioAI customers. Contacts are strictly isolated per account.
    • We do not use this data for advertising profiles or to train AI models.
    • We do not link this data to the content of a specific Google review: which review a visitor leaves remains unknown to us.

    Frequency protection, unsubscribing and deletion

    • Every email or SMS message to a contact contains an unsubscribe (opt-out) link. For SMS, replying STOP also works.
    • Unsubscribing works per business: if you click the unsubscribe link in an email from business A, only business A stops emailing you. Emails from another business that uses RecensioAI remain possible, because each business is a separate controller with its own contact relationship.
    • On the same unsubscribe page you can choose 'unsubscribe from all businesses' with one click. We then block your email address platform-wide for marketing and review requests. Hard bounces and spam complaints also lead to a platform-wide block.
    • A marketing unsubscribe does not block strictly necessary messages from RecensioAI itself, such as password resets or invoices to our own customers.
    • We apply built-in contact frequency protection so a visitor is not approached multiple times within a short period, even if the same address arrives through multiple channels.
    • Visitors can request access, correction or deletion via support@recensioai.com or directly with the business concerned. We handle such a request within 30 days.
    • Retention period: see section 20.

    23. Mobile apps (Android and iOS)

    Alongside the web version we offer the RecensioAI app for Android (Google Play) and iOS (Apple App Store). The app is a secure view of the same dashboard: same features, same account, same security. This section describes specifically how the mobile app handles data and also serves as our disclosure for the Google Play User Data policy, the Google Play Data safety section and Apple's App Store privacy (App Privacy) requirements.

    a. What data does the app collect?

    • Account and profile data: name, email address, language preference, business and location details and your role within the account. Required to sign you in and show the right location.
    • App activity: which screens you use and which actions you perform (for example replying to a review or sending a request), including audit logs for security.
    • Business content you manage yourself: reviews, feedback, contacts, campaigns, messages and AI drafts within your account.
    • Technical and diagnostic data: device type, operating system version, app version, language, time zone, IP address and crash or error reports. Required for stability, abuse prevention and support.
    • Push token: a device-specific identifier from Apple (APNs) or Google (FCM) when you allow notifications. Used solely to send you notifications; we never use it as an advertising identifier.

    The app does not collect an advertising ID, your phone's contact list, SMS or call logs, calendar data, health data, biometrics, or precise background location.

    b. Device permissions and what we use them for

    • Notifications (optional): to alert you about a new review, negative feedback or a task that needs attention.
    • Camera (optional): only when you scan a QR code yourself or take a photo for your business profile or website. Nothing is captured in the background.
    • Photos and files (optional): only to pick an image or logo you want to upload. We do not scan your photo library.
    • Network access: required to securely sync your data with our platform.

    Every optional permission is requested only at the moment you use the relevant feature, with a clear explanation. You can withdraw them at any time in your phone's settings; the app keeps working without that feature.

    c. Sharing, selling and tracking

    • We do not sell or rent app data and do not share it with data brokers or advertising networks.
    • The app contains no advertising SDKs and does not track you across other apps or websites. On iOS we therefore do not request App Tracking Transparency permission.
    • Data is only shared with the sub-processors required to deliver the service (hosting, email, SMS, payments, AI processing and push delivery). See section 19 for the list and section 9 for transfers outside the EEA.
    • Data from the app is not used to train third-party AI models.
    • Use of Google APIs in the app (for example Google Business Profile and Analytics) is covered by the Limited Use disclosure in section 18.

    d. Security in the app

    • All communication between the app and our servers is encrypted via HTTPS/TLS.
    • Session tokens are stored in the device's secure storage and expire automatically; signing out erases them immediately.
    • Access to data is isolated per account and per location at server level, including in the app.
    • We do not permanently store business content offline on your device; only a temporary cache is used to keep the app fast.

    e. Deleting your account and data

    As required by Google Play, you can delete both your account and your data, inside the app and via the web — without needing to install the app:

    • In the app: Settings → Account → 'Delete account'.
    • Via the web: see our deletion instructions page at recensioai.com/data-deletion, or send a request to support@recensioai.com.
    • You can also choose partial deletion: only your contacts, only a linked integration or only one location, without closing your account.
    • We confirm within 7 days, delete within 30 days and purge backups within a maximum of 90 days. Legally required records (such as invoices) are retained for the statutory retention period.

    f. Audience and minors

    The app is a business tool for entrepreneurs and their staff and is not intended or designed for children. We do not target users under 18 and do not knowingly collect data from children (see also section 16).

    g. App stores and payments

    Subscriptions are taken out via our website and processed by our payment provider; we never receive or store full card details. Google and Apple independently process data about the download, installation and any in-app purchases of the app; their own privacy policies apply to that.

    24. Contact

    For questions about this privacy policy or about the processing of personal data, you can contact:

    RecensioAI B.V.
    De Nieuwe Erven 3, unit 14563
    5431 NV Cuijk
    Netherlands
    Email: support@recensioai.com
    Chamber of Commerce number: 42028360
    VAT identification number: NL869375556B01

    Questions about this document?

    Our privacy & compliance team replies within 2 business days.

    support@recensioai.com