Who else touches your data

Published rather than supplied on request. Your procurement team should not have to sign something before finding out who is in the chain.

Supplied on request, not posted publicly

We give the complete sub-processor list — vendor, function, data categories, processing location and transfer basis — to any client or prospective client who asks, before signature and in writing. We do not post our vendor stack publicly, because publishing the exact tooling that holds client data is itself a security decision, and not one we make lightly.

Ask at privacy@revrepute.com and we will send it the same week.

What this page will carry

Structure of the published sub-processor list
ColumnWhat it states
Sub-processorLegal entity name, not a product brand
PurposeThe specific function it performs in delivering your service
Data categoriesWhat it can actually see, not what its contract permits in the abstract
Processing locationCountry of the region we have configured, not the vendor's headquarters
Transfer basisWhere processing sits outside your agreed region, the lawful mechanism relied on
AddedThe date it joined the list, so you can see what changed since you signed

How changes work

  • We give clients 30 days' written notice before a new sub-processor starts processing.
  • You may object within that window. If we cannot resolve the objection, you may terminate the affected service without penalty.
  • Removals are published here too — a shorter list is also a change worth seeing.
  • Subscribe to notifications by writing to privacy@revrepute.com.

Read the data processing agreement