revnu

── Legal

Data Processing Agreement

Last updated: October 7, 2026. How IT5 Inc. (d.b.a. Revnu) processes personal data for customers under the UK and EU GDPR.

This page is the Cover Page of Revnu's data processing agreement. It incorporates the Common Paper Data Processing Agreement Standard Terms, Version 1.1, which include the EU Standard Contractual Clauses and the UK Addendum for transfers out of the EEA and the UK. Where this Cover Page and the Standard Terms differ, this Cover Page controls.

To sign, email support@revnu.com with your company's legal name, address and a contact for data protection. We will send a countersigned copy. If you have your own DPA, send it and we will review it.

Key terms

Agreement
The Revnu Terms of Service, or the order form or sales agreement that applies to your plan.
Approved Subprocessors
The subprocessors listed in our Privacy Policy, and the full list we provide to you under a confidentiality agreement.
Provider Security Contact
support@revnu.com, with “security” in the subject.
Security Policy
Commercially reasonable efforts, including the measures in Annex II below. SOC 2 Type II is in progress.
Governing Law and Chosen Courts
The laws and courts of the State of Delaware, USA.

Restricted transfers

Governing Member State
EEA transfers: Ireland. UK transfers: England and Wales.

Annex I(A): List of parties

Data Exporter
The Customer named on the signature page, acting as Controller (or as Processor for its own clients).
Data Importer
IT5 Inc. (d.b.a. Revnu), a Delaware corporation, acting as Processor. Contact: support@revnu.com.

Annex I(B): Description of transfer

Service
Revnu, an AI growth service that researches a business, finds and contacts prospects, writes content, runs advertising and measures the results.
Categories of Data Subjects
Customer's personnel and users; Customer's prospects and business contacts; Customer's customers; visitors to Customer's websites where Revnu Tag is installed.
Categories of Personal Data
Names, job titles and employers; business email addresses, phone numbers and LinkedIn profiles; the content of messages and replies; CRM records Customer connects; website visit and advertising records, including click identifiers, IP addresses, browser user agents and consent states.
Special Category Data
None. Customer will not send special category data to Revnu.
Frequency of Transfer
Continuous, for as long as Customer uses the Service.
Nature and Purpose of Processing
Providing the Service on Customer's instructions: researching prospects, drafting and sending outreach, writing and publishing content, managing advertising, measuring outcomes, and supporting and securing the Service.
Duration of Processing
For the term of the Agreement, and afterwards only until the Customer Personal Data is deleted as the Standard Terms require.

Annex I(C): Competent supervisory authority

Supervisory authority
The supervisory authority of the Governing Member State, or for UK transfers, the UK Information Commissioner's Office.

Annex II: Technical and organisational measures

Encryption
All data encrypted in transit (TLS 1.2+) and at rest.
Credentials
Tokens for connected accounts are stored encrypted. API tokens are stored only as a hash.
Access control
Role-based access to production systems; administrative access is audit-logged.
Isolation
Each account's agent works in its own isolated computer. No account's data is given to another account's agent.
Model providers
AI model providers do not train on Customer data. On Managed plans they process it with zero data retention.
Incident response
Security reports to support@revnu.com are answered within one working day. Personal data breaches are notified as the Standard Terms require.
Deletion
Customer can request deletion at any time; we delete within 30 days of a request.

Common Paper Data Processing Agreement (Version 1.1), free to use under CC BY 4.0. See also: Privacy Policy and Terms of Service.