Data processing agreement

A summary of what our DPA commits us to. The executable version is issued with every proposal — you should not have to ask for it after signing.

Effective date: 6 September 2026

Roles

You are the controller of your customers' personal data. RevRepute LLC is your processor. We process personal data only on your documented instructions, and we tell you if an instruction appears to us to breach applicable law.

Scope of processing

The categories of data, categories of data subject, purposes and duration are set out in a schedule specific to your engagement — not left to a generic clause. Typical categories are contact details, order or account references, and the content of the customer's own message.

Confidentiality

Every person we authorise to process your data is under a written confidentiality obligation that survives the end of their engagement with us.

Security measures

Role-based access granted per client account; encryption in transit and at rest; managed workstations with full-disk encryption and no removable media; logged access to customer records; access review on any change of role and same-day revocation on departure. The full technical and organisational measures schedule forms part of the agreement.

Sub-processors

We supply the sub-processor list in full before signature and give you notice before adding one, with a right to object. We publish the list to prospective clients on request rather than posting our vendor stack publicly; see the sub-processors page for what it contains.

International transfers

Data residency for your engagement is named in the schedule. Transfers outside that region happen only on a lawful basis stated in the agreement and disclosed to you in advance.

Personal data breach

We notify you within 24 hours of becoming aware of a personal data breach affecting your data, with what we know at that point, and we keep you updated as we learn more. We do not wait until the investigation is complete to tell you.

Assisting you

We help you respond to data subject requests and to any regulator, within the timescales the law gives you rather than ones that suit us.

Audit

You may audit our compliance, directly or through an appointed auditor, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise.

Return and deletion

On termination we return your data in a machine-readable format and delete our copies within 30 days, retaining only what law requires us to keep. Deletion is confirmed to you in writing.