Last updated 2026-08-11. Explains how the Repuso API handles personal data under the EU/UK GDPR. Read alongside the API Privacy Policy and API Terms. For the consumer product see the main Repuso GDPR notice.
The Repuso API is operated by OnClick Solutions Ltd ("Repuso", "we"). For any data-protection request, email hello@repuso.com or use our support page. If you require a signed Data Processing Addendum (DPA), request one at the same address.
Which role we play depends on the data:
| Data | Your role | Our role |
|---|---|---|
| Review profiles you choose to monitor, and the reviews/ratings returned for them | Controller - you decide which public profiles to collect | Processor - we collect and normalize on your documented instructions (your API calls) |
| Your account: sign-in email, API keys, plan, billing, usage metering | Data subject / customer | Controller |
| Security, abuse-prevention and service telemetry | - | Controller (legitimate interest) |
For your account data (where we are controller) you can access, export, correct, restrict or delete it - email us and we respond within one month.
For review data (where you are controller), a reviewer's request usually reaches you. As your processor we assist: you can delete any monitored profile through the API, which removes its collected reviews; or ask us to remove specific records. Deleting a profile via DELETE /v1/channels/{id} purges its stored reviews on our side.
We may process data on infrastructure outside your country. Where personal data is transferred out of the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the relevant sub-processors. Our DPA incorporates the SCCs by reference.
We use a limited set of third parties strictly to run the service. Review data is retrieved from the public source platforms you select.
| Sub-processor | Purpose |
|---|---|
| Cloud hosting & crawling infrastructure | Run the API, database and crawlers |
| Stripe | Payments and billing |
| Transactional email provider | Login codes, quota and billing notices |
We will give notice of material changes to this list so you can object before a new sub-processor begins processing.
API traffic is TLS-encrypted. API keys are stored hashed and encrypted at rest and are never shown again after creation - keep them confidential, never embed them in client-side code or public repositories, and rotate immediately if exposed. Access to production data is restricted and logged. We may suspend or rotate keys showing signs of compromise. To report a security or data-protection concern, email hello@repuso.com.
If you process personal data of individuals in the EU/UK through the API, you can request our Data Processing Addendum, which sets out our processor obligations under Art. 28 GDPR and includes the SCCs for international transfers. Email hello@repuso.com to receive and countersign it.
We will update this page and the "last updated" date when this notice changes materially.