This page is the Cover Page of Revnu's data processing agreement. It incorporates the Common Paper Data Processing Agreement Standard Terms, Version 1.1, which include the EU Standard Contractual Clauses and the UK Addendum for transfers out of the EEA and the UK. Where this Cover Page and the Standard Terms differ, this Cover Page controls.
To sign, email support@revnu.com with your company's legal name, address and a contact for data protection. We will send a countersigned copy. If you have your own DPA, send it and we will review it.
Key terms
- Agreement
- The Revnu Terms of Service, or the order form or sales agreement that applies to your plan.
- Approved Subprocessors
- The subprocessors listed in our Privacy Policy, and the full list we provide to you under a confidentiality agreement.
- Provider Security Contact
- support@revnu.com, with “security” in the subject.
- Security Policy
- Commercially reasonable efforts, including the measures in Annex II below. SOC 2 Type II is in progress.
- Governing Law and Chosen Courts
- The laws and courts of the State of Delaware, USA.
Restricted transfers
- Governing Member State
- EEA transfers: Ireland. UK transfers: England and Wales.
Annex I(A): List of parties
- Data Exporter
- The Customer named on the signature page, acting as Controller (or as Processor for its own clients).
- Data Importer
- IT5 Inc. (d.b.a. Revnu), a Delaware corporation, acting as Processor. Contact: support@revnu.com.
Annex I(B): Description of transfer
- Service
- Revnu, an AI growth service that researches a business, finds and contacts prospects, writes content, runs advertising and measures the results.
- Categories of Data Subjects
- Customer's personnel and users; Customer's prospects and business contacts; Customer's customers; visitors to Customer's websites where Revnu Tag is installed.
- Categories of Personal Data
- Names, job titles and employers; business email addresses, phone numbers and LinkedIn profiles; the content of messages and replies; CRM records Customer connects; website visit and advertising records, including click identifiers, IP addresses, browser user agents and consent states.
- Special Category Data
- None. Customer will not send special category data to Revnu.
- Frequency of Transfer
- Continuous, for as long as Customer uses the Service.
- Nature and Purpose of Processing
- Providing the Service on Customer's instructions: researching prospects, drafting and sending outreach, writing and publishing content, managing advertising, measuring outcomes, and supporting and securing the Service.
- Duration of Processing
- For the term of the Agreement, and afterwards only until the Customer Personal Data is deleted as the Standard Terms require.
Annex I(C): Competent supervisory authority
- Supervisory authority
- The supervisory authority of the Governing Member State, or for UK transfers, the UK Information Commissioner's Office.
Annex II: Technical and organisational measures
- Encryption
- All data encrypted in transit (TLS 1.2+) and at rest.
- Credentials
- Tokens for connected accounts are stored encrypted. API tokens are stored only as a hash.
- Access control
- Role-based access to production systems; administrative access is audit-logged.
- Isolation
- Each account's agent works in its own isolated computer. No account's data is given to another account's agent.
- Model providers
- AI model providers do not train on Customer data. On Managed plans they process it with zero data retention.
- Incident response
- Security reports to support@revnu.com are answered within one working day. Personal data breaches are notified as the Standard Terms require.
- Deletion
- Customer can request deletion at any time; we delete within 30 days of a request.
Common Paper Data Processing Agreement (Version 1.1), free to use under CC BY 4.0. See also: Privacy Policy and Terms of Service.
