This Privacy Policy explains how Future era d.o.o. (“we”, “us”, “our”), the operator of the Review Intelligence platform available at brandreviews.ai (the “Service”), collects, uses, stores, and shares personal data. We take privacy seriously — this policy is written to be readable. If anything is unclear, contact us at info@brandreviews.ai.
01 Who we are
Future era d.o.o. is a company registered in Croatia.
Company / OIB number: HR93674206295
Contact email: info@brandreviews.ai
Data protection contact: info@brandreviews.ai
For data we process on behalf of our business customers (see Section 4), we act as a data processor and the customer is the data controller. For data about our own users, visitors, and customers, we act as the data controller.
02 Scope
This policy applies to:
- Visitors to our website and marketing pages.
- Users of the Review Intelligence dashboard (our customers and their authorised team members).
- Personal data contained in the Google Business Profile content we process on our customers’ behalf.
03 The data we collect
3.1 Account and user data
When you create or use a dashboard account, we collect your name, email address, organisation details, authentication credentials, and your settings and preferences.
3.2 Google Business Profile data
With your explicit authorisation through Google’s secure OAuth consent flow, we access data from your Google Business Profile, including:
- Business locations, addresses, and account metadata.
- Customer reviews, star ratings, review text, and review timestamps.
- Reviewer display names and any other information Google includes in a review.
We only request the access needed to provide the Service, using the business.manage scope. We never ask for your Google password — authorisation happens entirely on Google’s systems, and you can revoke our access at any time from your Google Account permissions.
3.3 Usage and technical data
We collect standard technical data such as IP address, browser type, device information, log data, and how you interact with the dashboard, to operate, secure, and improve the Service.
04 How we use Google user data
The data we receive from Google APIs is used solely to provide and improve the Review Intelligence features you have signed up for: importing and analysing your reviews, generating sentiment, themes, insights, reports, and recommendations.
- We do not use Google user data for serving advertising.
- We do not sell Google user data.
- We do not transfer or disclose Google user data except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
- We only allow humans to read Google user data with your affirmative agreement for specific messages, when necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymised.
05 Automated and AI processing
A core part of the Service is the automated analysis of review content. To do this, review text and related data are processed through automated pipelines and large language model (LLM) providers to extract sentiment, themes, product and staff mentions, summaries, and recommendations.
This processing is automated. AI-generated insights, predictions, and recommendations are provided for guidance only and may contain errors — they should not be relied upon as the sole basis for business or legal decisions.
06 Legal bases for processing (GDPR)
Where we act as a controller, we rely on the following legal bases under the EU General Data Protection Regulation (GDPR):
- Contract — to provide the Service you have signed up for.
- Legitimate interests — to secure, maintain, and improve the Service, and to communicate with you, balanced against your rights.
- Consent — where required, for example for certain cookies or marketing communications. You may withdraw consent at any time.
- Legal obligation — where we must process data to comply with the law.
Where we act as a processor of our customers’ data, our customer is responsible for establishing the legal basis for the underlying processing.
07 Sub-processors and third parties
We use trusted third-party providers to deliver the Service. These may include:
- Hosting and database infrastructure (PostgreSQL hosting).
- AI / LLM providers used to analyse review content (such as OpenAI and OpenRouter).
- Email delivery providers used to send reports and notifications.
- Google (Google Business Profile APIs), as the source of review and location data.
Each provider only receives the data necessary to perform its function and is bound by appropriate data protection terms. A current list of sub-processors is available on request at info@brandreviews.ai.
08 International data transfers
Some of our providers (including certain AI/LLM providers) may process data outside the European Economic Area, including in the United States. Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
09 Data retention
We retain personal data only as long as necessary for the purposes described in this policy, to provide the Service, and to meet legal, accounting, or reporting requirements. Review and analytics data is retained for the duration of your account and for a reasonable period afterwards, unless you request earlier deletion. When data is no longer needed, we delete or anonymise it.
10 Security
We apply technical and organisational measures to protect personal data, including encryption of stored access tokens, tenant data isolation, access controls, and secure transmission. No system is completely secure, but we work to protect your data and to respond promptly to any incident.
11 Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with a supervisory authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP).
To exercise any of these rights, contact us at info@brandreviews.ai. If your data is processed on behalf of one of our business customers, we may direct your request to that customer as the data controller.
12 Cookies
Our website and dashboard use cookies and similar technologies that are strictly necessary for the Service to function (such as authentication and session cookies), and, where you consent, cookies for analytics and preferences. You can manage non-essential cookies through your browser or our cookie controls.
13 Children
The Service is intended for business use and is not directed at children under 16. We do not knowingly collect personal data from children.
14 Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15 Contact
Questions about this policy or your data? Contact us at:
Future era d.o.o.
Poljana V. Njegovana 1, 10 000 Zagreb, Croatia
info@brandreviews.ai