Privacy & Compliance

Record of Processing Activities

This is WiserReview's simplified public Record of Processing Activities (RoPA), maintained pursuant to GDPR Article 30. It describes the personal data processing activities carried out by Tatvam Cloud Solutions, Inc.

Version 1.0·Last Updated: March 2026·Tatvam Cloud Solutions, Inc
Note on Controller / Processor roles: WiserReview acts as both a Data Controller (for merchant account data, error monitoring, and billing) and as a Data Processor (for consumer review data, processed on behalf of merchants who are the Controllers). Both roles are reflected in this register. Our Data Processing Agreement governs the Processor relationship.

Processing Activities Register

PA-01

Merchant Account Management

Controller / ProcessorTatvam Cloud Solutions, Inc (as Controller)
PurposeAccount creation, authentication, billing, and platform access management
Legal BasisContract (GDPR Art. 6(1)(b)); Legitimate Interest (Art. 6(1)(f))
Data CategoriesName, email address, company name, hashed password, platform type
Data SubjectsMerchants / business users
RetentionActive subscription lifetime + 60 days post-cancellation
Sub-ProcessorsMicrosoft Azure, MongoDB Atlas, Chargebee
Cross-Border TransfersUnited States (Azure, MongoDB Atlas)
PA-02

Review Request Emails

Controller / ProcessorTatvam Cloud Solutions, Inc (as Processor for Merchant)
PurposeSending automated review request emails to merchant's customers after purchase
Legal BasisLegitimate Interest of Merchant (GDPR Art. 6(1)(f)); merchant is Controller
Data CategoriesCustomer email address, first name, order ID, product name, order date
Data SubjectsEnd consumers (shoppers) of merchant stores
RetentionWhile merchant account is active; auto-deleted on account closure or GDPR request
Sub-ProcessorsAzure Service Bus, AWS SES, SendGrid, Microsoft Azure, MongoDB Atlas
Cross-Border TransfersUnited States
PA-03

Review Collection & Storage

Controller / ProcessorTatvam Cloud Solutions, Inc (as Processor for Merchant)
PurposeCollecting, storing, and managing customer reviews on behalf of merchants
Legal BasisConsent of reviewer; Legitimate Interest of Merchant (merchant is Controller)
Data CategoriesReviewer name, email address, review text, star rating, photos/videos, IP address, submission timestamp
Data SubjectsEnd consumers who submit reviews
RetentionWhile merchant account is active; deleted on review deletion, GDPR request, or account closure
Sub-ProcessorsMicrosoft Azure, MongoDB Atlas, Azure Blob Storage, AWS S3
Cross-Border TransfersUnited States
PA-04

Review Display (Widget)

Controller / ProcessorTatvam Cloud Solutions, Inc (as Processor for Merchant)
PurposeDisplaying approved reviews on merchant storefronts via the WiserReview pixel widget
Legal BasisLegitimate Interest of Merchant
Data CategoriesReviewer name (or anonymized), star rating, review text, review date, photos/videos
Data SubjectsEnd consumers whose reviews are displayed publicly
RetentionSame as review storage (PA-03)
Sub-ProcessorsCloudflare CDN, Microsoft Azure
Cross-Border TransfersCloudflare global edge (caches public widget assets only, no PII in CDN cache)
PA-05

Platform Integration Sync (Shopify, WooCommerce, etc.)

Controller / ProcessorTatvam Cloud Solutions, Inc (as Processor for Merchant)
PurposeSyncing order data from connected e-commerce platforms to trigger review requests and verify purchases
Legal BasisContract / Legitimate Interest of Merchant
Data CategoriesOrder ID, customer email, customer name, product name/ID, order date, platform store ID
Data SubjectsEnd consumers of the merchant's store
RetentionWhile merchant account is active
Sub-ProcessorsMicrosoft Azure, MongoDB Atlas
Cross-Border TransfersUnited States
PA-06

Error Monitoring & Application Diagnostics

Controller / ProcessorTatvam Cloud Solutions, Inc (as Controller)
PurposeDetecting, diagnosing, and resolving application errors and performance issues
Legal BasisLegitimate Interest: ensuring platform reliability and security (Art. 6(1)(f))
Data CategoriesAnonymized request context (URL, browser, error stack trace), IP address fragments, timestamps
Data SubjectsMerchants and, to a limited extent, end consumers interacting with the platform
Retention90 days (automatic log rotation in Sentry)
Sub-ProcessorsSentry
Cross-Border TransfersUnited States (Sentry)
PA-07

Billing & Subscription Management

Controller / ProcessorTatvam Cloud Solutions, Inc (as Controller for billing; Chargebee as Processor)
PurposeProcessing subscription payments, invoicing, and managing subscription lifecycle
Legal BasisContract (GDPR Art. 6(1)(b))
Data CategoriesMerchant name, billing email, subscription plan, payment references (no card data; handled by Chargebee PCI DSS L1)
Data SubjectsMerchants
RetentionDuration of subscription + legally required financial record retention periods
Sub-ProcessorsChargebee (PCI DSS Level 1)
Cross-Border TransfersUnited States (Chargebee)
PA-08

AI-Assisted Text Generation

Controller / ProcessorTatvam Cloud Solutions, Inc (as Controller; Merchant as initiating user)
PurposeGenerating AI-suggested review response text and grammar corrections for merchants
Legal BasisContract / Legitimate Interest
Data CategoriesReview text content only. No PII (names, emails) is sent to OpenAI.
Data SubjectsMerchants (initiating the AI feature); no end-consumer PII involved
RetentionNot retained by OpenAI per API usage terms; not stored in WiserReview beyond the session
Sub-ProcessorsOpenAI (review text only, anonymized, no PII)
Cross-Border TransfersUnited States (OpenAI)
PA-09

GDPR Data Subject Rights Fulfilment

Controller / ProcessorTatvam Cloud Solutions, Inc (as Controller for merchant data; Processor for consumer data)
PurposeProcessing and responding to data subject access, deletion, and portability requests
Legal BasisLegal Obligation (GDPR Arts. 15–22)
Data CategoriesData identified in the original processing activity subject to the request
Data SubjectsMerchants and/or their end consumers
RetentionRecords of requests retained for accountability; 3 years
Sub-ProcessorsNone (internal process)
Cross-Border TransfersNone

General Security Measures

All processing activities are protected by the following technical and organisational measures (full detail at /security):

AES-256 encryption at rest (MongoDB Atlas, Azure Blob Storage, AWS S3)
TLS 1.2+ in transit on all endpoints
Cloudflare WAF + DDoS protection
Workspace-level multi-tenant data isolation
JWT authentication + RBAC (Admin/Editor/Viewer)
MongoDB Atlas IP whitelisting (not publicly accessible)
Continuous automated backups (MongoDB Atlas point-in-time recovery)
Incident response plan with 72-hour breach notification

Full technical security documentation: Incident Response · Infrastructure Security · Compliance & Certifications

Cross-Border Transfer Safeguards

All cross-border data transfers to the United States are conducted under Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent GDPR-compliant transfer mechanisms maintained by our Sub-Processors (Microsoft Azure, AWS, MongoDB Atlas, Cloudflare, Sentry, OpenAI, Chargebee). Our DPA covers these transfer mechanisms.

Article 30 Compliance & Inquiries

This public register is a summary. The full internal RoPA is maintained by the Security Officer (Tatvam Cloud Solutions, Inc). For GDPR Article 30 compliance inquiries, DPA requests, or data subject rights:

Tatvam Cloud Solutions, Inc

Attn: Security & Privacy

[email protected]