Legal
Data Processing Addendum
Effective July 22, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies whenever Mores processes personal data on your behalf. You do not need to sign it for it to apply — it is in force for every account. If your procurement process needs a countersigned copy, see section 13.
1. Roles, scope, and precedence
You are the controller. You decide whose data goes into Mores and what happens to it: which customers you ask for a review, which review platform you connect, and which replies get published. Under the GDPR and UK GDPR you are the controller; under the CCPA/CPRA you are the business.
We are the processor. We process that data only to run the service for you. Under the GDPR and UK GDPR we are the processor; under the CCPA/CPRA we are a service provider. Section 12 sets out the additional CCPA terms.
Where you are yourself acting for a client — an agency managing a practice's profile, for example — you confirm you have that client's authority to appoint us, and this DPA applies between us and you.
Terms used here have the meanings given in the GDPR. This DPA does not change the Privacy Policy, which describes the data we process as controller — your account, your billing, and how you use the product. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA wins; the Terms govern everything else, including the limitation of liability, which applies to this DPA as well.
2. What we process, and why
| Subject matter | Providing the Mores service described in the Terms of Service: importing your reviews, drafting replies, scoring drafts against Google's review-reply moderation rules, publishing the replies you approve, sending the review requests you instruct, and reporting on the result. |
|---|---|
| Duration | For as long as your account is open, plus the deletion window in section 10 below. |
| Nature and purpose | Storage, retrieval, structuring, analysis, transmission to the review platform you connect, transmission to the recipients you nominate, and erasure. We do not use your data to train our own models, and we do not sell, rent, or share it with advertisers. |
| Categories of personal data | Your account and business details; the contact name and email address of each customer you send a review request to, plus that contact's delivery and unsubscribe state; reviewer names and review text as the review platform publishes them; the reply drafts and moderation scores generated for you; and the OAuth credentials for the accounts you connect. |
| Categories of data subjects | You and your team members; your customers and patients, whether they are review-request recipients or reviewers whose reviews we import. |
| Special category data | None, by instruction. The Terms prohibit storing protected health information, payment card data, and government identifiers in the product, and our moderation check flags treatment and diagnosis language in a draft reply so it is not published. See section 6. |
3. Our commitments
We will:
- process personal data only on your documented instructions — this DPA, the Terms, and the actions you take in the product are those instructions — unless a law we are subject to requires otherwise, in which case we will tell you first unless that law forbids it;
- tell you if, in our opinion, an instruction you give us infringes data protection law;
- ensure the people who process your data are bound by confidentiality and are told what they may and may not do with it;
- implement and maintain the technical and organisational measures in section 6;
- not sell your data, not share it for cross-context behavioural advertising, and not use your review content or brand-voice samples to train our own models;
- assist you as described in sections 7 to 9, taking into account the nature of the processing and the information available to us.
4. Subprocessors
You give us general authorisation to engage subprocessors. The current list — every third party that touches customer data, what it does, and what it sees — is published and kept current on the Privacy Policy. We use no others.
We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
Changes.We will give you at least 30 days' notice by email before a new subprocessor starts processing your data. If you reasonably object on data protection grounds within that period, tell us and we will work with you on a change to the configuration or the feature; if we cannot resolve it, you may terminate the affected subscription and we will refund the unused prepaid remainder of the period.
5. International transfers
Mores is offered in the United States and Canada and is not offered to users established in the EU, the EEA, or Switzerland — see the Terms. This section applies where European data protection law nevertheless reaches data you put into the product.
Where a transfer of personal data out of the EEA, the UK, or Switzerland requires a transfer mechanism, the European Commission Standard Contractual Clauses of 4 June 2021 (Decision 2021/914) are incorporated into this DPA by reference, Module Two (controller-to-processor), with you as data exporter and us as data importer. Clause 7 (docking) does not apply; the section 4 general authorisation with 30 days' notice applies for Clause 9; Clause 11's optional independent dispute resolution does not apply; the governing law and forum are those of the Terms of Service where the Clauses permit that choice, and otherwise the Republic of Ireland. The Annexes are populated by sections 2, 4, and 6 of this DPA. For UK transfers the International Data Transfer Addendum (version B1.0) applies to those Clauses.
Our subprocessors operate in the United States. Their own transfer mechanisms are as published in their public terms; we do not restate them here, because they change and a stale restatement is worse than a pointer.
6. Security measures
| Measure | What it means in practice |
|---|---|
| Encryption in transit | All traffic to Mores and to every subprocessor runs over TLS. There is no unencrypted path into the product. |
| Encryption of connected-account credentials at rest | Google OAuth tokens and review-platform API keys are encrypted with AES-256-GCM using a key held outside the database before they are written. |
| Tenant isolation | Account data is separated by row-level security policies enforced in Postgres, so one customer's session cannot read another customer's rows even if application code asks it to. |
| Access control | Administrative access to production data is limited to the people who operate the service, over authenticated sessions, on a need-to-know basis. Service credentials are held as environment secrets, never in the repository. |
| Availability and recovery | The database is hosted on Supabase with managed backups; backup copies roll off on their own schedule and are fully replaced within 35 days. |
| Application-layer safeguards | Rate limiting on public endpoints, signed webhook payloads, and a moderation check that flags personal, health, and contact details in a draft reply before it can be published. |
What we do not claim, so nobody has to infer it: Mores is not SOC 2 certified and not ISO 27001 certified, has no published penetration-test report, is not HIPAA compliant, and we do not sign Business Associate Agreements. Do not put protected health information into the product. If your procurement process requires a certification we do not hold, we would rather tell you now than after the pilot.
We may change these measures as the product changes, but not in a way that materially reduces the protection of your data.
7. Personal data breach
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay, and in any case within 72 hours of becoming aware. The notice will describe what happened, the categories and approximate number of records and data subjects affected as far as we can tell, the likely consequences, and what we are doing about it — and we will follow up as we learn more rather than wait until the picture is complete.
Notifying you is not an admission of fault. Notifying supervisory authorities and data subjects is your decision as controller, and we will give you the information you need to make it.
8. Data-subject requests and assistance
You can access, correct, export, and delete most data yourself in the product, which is usually the fastest way to answer a request. Where you need more, we will assist you — taking into account the nature of the processing — with responding to access, correction, deletion, portability, restriction, and objection requests, and with data protection impact assessments and prior consultations.
If a data subject contacts us directly about data we process for you, we will not respond substantively ourselves. We will tell them to contact you, and we will pass the request to you promptly so you can answer it as controller.
9. Reviewers and review-request recipients
Two groups of people have data in Mores without ever having signed up for it, and they are entitled to a route in.
Reviewers. When you connect a review platform or import reviews, we store the review text, the star rating, the review date, and the reviewer name as the platform publishes it. We do not enrich it, we do not look the reviewer up anywhere else, and we do not contact them. The platform remains the source; you are the controller of the copy held in Mores.
Review-request recipients. When you send review requests, the contact details are the ones you supply. You are the controller of that list and you are responsible for having a lawful basis and any required consent before you send. We record and honour an unsubscribe state on your behalf, and we honour it permanently — an unsubscribe record is one of the few things we keep after deletion, because erasing it would mean emailing someone who asked us not to.
How either of them reaches a human. A reviewer or a recipient can write to privacy@mores.invalid. We will identify the customer whose account holds the data, tell them the request exists, and act on their instruction as controller — except for an unsubscribe request, which we action immediately and without waiting for anyone. We answer within 30 days.
10. Audit rights
On request, and no more than once in any 12-month period, we will provide the information necessary to demonstrate compliance with this DPA: a completed security questionnaire, our current subprocessor list, and a written description of our technical and organisational measures. That is the normal route, and for almost every customer it is enough.
Where the information above does not satisfy a requirement imposed on you by data protection law or by a supervisory authority, you may audit us — or appoint an independent auditor who is not our competitor to do it — on at least 30 days' written notice, during business hours, under a confidentiality agreement, in a way that does not disrupt the service, and at your cost. An audit may not extend to any other customer's data, and we may satisfy an audit request with a recent report covering the same scope.
If a supervisory authority requires an audit on a shorter timescale, we will cooperate on that timescale.
11. Deletion and return on termination
You can export your reviews and replies as CSV at any time while your account is open, and you should do that before you close it — the export is self-service precisely so you are never waiting on us for your own data.
On termination or on your written request, we delete the personal data we process for you within 30 days. Connected-account tokens are revoked and destroyed immediately on disconnect or deletion rather than waiting for that window. Backup copies roll off on their own schedule and are fully replaced within 35 days; until then they are inert and are not used for any purpose other than restoring the service.
Two things survive, and both are narrow: billing records, which tax and accounting law requires us to keep (typically seven years), and email suppression records — the addresses that unsubscribed or hard-bounced — which we keep indefinitely for the reason given in section 9. We will confirm deletion in writing if you ask.
12. CCPA / CPRA service-provider terms
This section applies where you are a business and we process personal information subject to the CCPA as amended by the CPRA. We are a service provider, and personal information is disclosed to us only for the limited and specified business purpose of providing the service described in the Terms.
We certify that we understand these restrictions and will comply:
- we do not sell or share personal information, and we accept no consideration of any kind for it;
- we do not retain, use, or disclose personal information for any purpose other than performing the service, or outside the direct business relationship between us — except where the CCPA expressly permits it, such as retaining records required by law;
- we do not combine personal information received from you with personal information from any other source, except as the CCPA permits a service provider to do;
- we will notify you if we determine we can no longer meet these obligations, and you may then take reasonable steps to stop and remediate the unauthorised use;
- we assist you with consumer requests to know, delete, correct, and opt out, as described in sections 8 and 9, and we pass the same obligations to our subprocessors.
You may take reasonable and appropriate steps to confirm we are using personal information in a manner consistent with your obligations — section 10 is how.
13. Acceptance and countersignature
This DPA is in force for every Mores account as part of the Terms of Service. No signature is required for it to apply, and you do not need to ask us for one before you can buy.
If your procurement process needs an executed copy, email privacy@mores.invalid with your legal entity name, registered address, and the name of the person who will sign for you. We will return this document countersigned. We will sign it as written; a materially amended version needs review and we will tell you plainly if we cannot agree to a change rather than leave the request sitting.
14. Changes and contact
If we change this DPA in a way that materially affects you, we will email account holders and update the effective date at the top of this page before the change takes effect. Subprocessor changes follow the separate notice period in section 4.
Questions, data requests, and audit requests: privacy@mores.invalid.