GDPR & Compliance
Last updated: 31 July 2026
Cloudexp OÜ developed Säuts to help businesses collect Google reviews in a lawful, transparent, and responsible manner.
The Service is designed in accordance with the European Union General Data Protection Regulation (GDPR), applicable Estonian legislation, and the principle that Personal Data should only be processed to the extent necessary to provide the Service.
This page explains how Säuts supports GDPR compliance and outlines the primary responsibilities of both Cloudexp OÜ and our customers.
Roles in Personal Data Processing
The parties involved in using Säuts have different responsibilities under the GDPR.
Your Business
The business using Säuts to send review invitations to its customers is generally the Data Controller.
As the Data Controller, your organisation is responsible for:
- deciding whose Personal Data is entered into the Service;
- determining the purposes and means of processing;
- ensuring that an appropriate legal basis for processing exists;
- responding to requests from Data Subjects;
- complying with applicable data protection legislation.
Cloudexp OÜ (Säuts)
Cloudexp OÜ generally acts as the Data Processor.
We process Personal Data only:
- on our customer's documented instructions;
- to the extent necessary to provide the Service;
- in accordance with our Data Processing Agreement (DPA).
We do not sell customer data, use customer data for our own marketing purposes, or process Personal Data for purposes unrelated to providing the Service.
Data Minimisation
Säuts is designed in accordance with the GDPR principle of Data Minimisation.
The Service requires only the information necessary to send review invitations and operate the platform.
Typically, the following Personal Data is processed:
- customer's first name;
- mobile phone number;
- message delivery information;
- link click statistics;
- opt-out (STOP) status.
As a general rule, Säuts does not require or process:
- national identification numbers;
- dates of birth;
- residential addresses;
- payment card information;
- health information;
- special categories of Personal Data as defined by the GDPR.
Legal Basis
Your organisation is responsible for ensuring that an appropriate legal basis exists before Personal Data is processed through Säuts.
Cloudexp OÜ does not determine or verify the legal basis for processing your customer data.
In most cases, Säuts is intended to be used within an existing customer relationship where the business is permitted under applicable law to send post-service communications or review invitations.
We recommend ensuring that your organisation has an appropriate legal basis before using the Service.
Existing Customer Relationships
Säuts is designed for communication with customers after goods have been delivered or services have been provided.
The Service is not intended for:
- cold SMS campaigns;
- purchased contact databases;
- unsolicited bulk marketing;
- spam or unlawful direct marketing.
We recommend using Säuts only in connection with existing customer relationships and only where permitted by applicable law.
Data Subject Rights
The GDPR grants individuals a number of rights regarding their Personal Data.
These include, among others, the right to:
- receive information about the processing of their Personal Data;
- access their Personal Data;
- request correction of inaccurate information;
- request deletion where legally applicable;
- request restriction of processing;
- object to processing in certain circumstances;
- exercise the right to data portability where applicable.
Because your organisation is generally the Data Controller, Data Subjects should submit such requests directly to your organisation.
Cloudexp OÜ assists its customers in fulfilling these obligations to the extent required under our Data Processing Agreement (DPA).
Google's Review Policies
Säuts is designed to help businesses collect reviews in a manner that complies with Google's review policies and promotes authentic customer feedback.
The Service is not intended to facilitate practices that violate Google's policies.
When using Säuts:
- all eligible customers receive an equal opportunity to leave a review;
- no incentives, discounts, or rewards are offered in exchange for reviews;
- customer reviews are never edited or influenced by Säuts;
- businesses cannot selectively request reviews only from customers expected to leave positive feedback.
Review Gating
Review gating is the practice of requesting Google reviews only from customers who are likely to provide positive feedback, while directing dissatisfied customers elsewhere.
Säuts does not support review gating.
Our goal is to help businesses collect genuine, balanced, and trustworthy reviews from all appropriate customers.
Opt-Out Mechanism
Every review invitation sent through Säuts includes a clear and simple method for recipients to opt out of future review invitations.
If a recipient chooses to opt out, Säuts will respect that preference and will not send additional review invitations to that phone number unless the opt-out is removed by the customer in accordance with applicable law.
Subprocessors
Cloudexp OÜ relies on carefully selected third-party service providers to operate the Service.
Each Subprocessor processes Personal Data only to the extent necessary to provide the Service and in accordance with applicable data protection requirements.
A current list of our Subprocessors is available on our Subprocessors page.
International Data Transfers
Where a service provider processes Personal Data outside the European Economic Area (EEA), such transfers are carried out only where appropriate safeguards exist under the GDPR.
Depending on the circumstances, these safeguards may include:
- European Commission adequacy decisions;
- the European Commission's Standard Contractual Clauses (SCCs);
- other lawful transfer mechanisms recognised under the GDPR.
Our Commitments
Cloudexp OÜ is committed to:
- processing Personal Data solely for the purpose of providing the Service;
- acting only on our customer's documented instructions;
- implementing appropriate technical and organisational security measures;
- maintaining the confidentiality of customer data;
- notifying customers without undue delay of Personal Data breaches where required under the GDPR;
- assisting customers, where reasonably possible, in fulfilling their GDPR obligations.
Customer Responsibilities
As a customer of Säuts, you are responsible for ensuring that:
- you are legally entitled to process the Personal Data entered into the Service;
- an appropriate legal basis exists for such processing;
- Data Subjects are informed where required by applicable law;
- the Service is used only for lawful purposes;
- Säuts is not used for spam, unsolicited marketing, or practices that violate Google's review policies.
Related Documentation
For additional information, please refer to the following documents:
- Terms of Service;
- Privacy Policy;
- Data Processing Agreement (DPA);
- Cookie Policy;
- Security;
- Subprocessors.
Contact
If you have any questions regarding GDPR compliance or the processing of Personal Data, please contact us.
Cloudexp OÜ
Registry Code: 16263842
Registered Address:
Juurdeveo tn 18-9
Kesklinn, Tallinn
Harju County 11313
Estonia
Email:
Website:
This GDPR & Compliance page provides a general overview of how Säuts supports compliance with applicable data protection laws. It does not constitute legal advice and does not replace each customer's responsibility to assess and ensure its own compliance with applicable legislation.