Data Processing Addendum
This DPA forms part of the Terms of Service where Revvify processes personal data on your behalf (you are the controller, Revvify is the processor).
Scope & roles
Revvify processes the personal data contained in the audiences, contacts, and leads you manage, solely to provide the service and per your documented instructions (your use of the product).
Sub-processors
We use infrastructure and service sub-processors including a cloud database and object store, Redis, Stripe (billing), and — only for the platform-credits AI tier — the AI provider you select. With BYO keys or MCP, AI processing runs on your own credentials. A current list is available on request.
Security measures
Multi-tenant isolation is enforced at the database layer (Postgres row-level security keyed on workspace). Third-party tokens and API keys are envelope-encrypted with a master key held outside the database and decrypted only inside workers at use time. Access is least-privilege and audited.
International transfers
Where data leaves the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
Data subject requests & deletion
Export and deletion are self-serve (Settings → Security) and cascade across tenant data. On termination, we delete or return personal data on request, subject to legal retention.
Contact
dpo@revvify.io.