Data Processing Addendum

This DPA forms part of the Terms of Service where Revvify processes personal data on your behalf (you are the controller, Revvify is the processor).

Scope & roles

Revvify processes the personal data contained in the audiences, contacts, and leads you manage, solely to provide the service and per your documented instructions (your use of the product).

Sub-processors

We use infrastructure and service sub-processors including a cloud database and object store, Redis, Stripe (billing), and — only for the platform-credits AI tier — the AI provider you select. With BYO keys or MCP, AI processing runs on your own credentials. A current list is available on request.

Security measures

Multi-tenant isolation is enforced at the database layer (Postgres row-level security keyed on workspace). Third-party tokens and API keys are envelope-encrypted with a master key held outside the database and decrypted only inside workers at use time. Access is least-privilege and audited.

International transfers

Where data leaves the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.

Data subject requests & deletion

Export and deletion are self-serve (Settings → Security) and cascade across tenant data. On termination, we delete or return personal data on request, subject to legal retention.

Contact

dpo@revvify.io.