Compliance and security

Data Processing Addendum

The contractual terms that apply when Revup processes Customer Personal Data on a Customer's behalf.

Last updated:

On this page
  1. 1. Definitions
  2. 2. Scope and duration
  3. 3. Roles and responsibilities
  4. 4. Processing instructions
  5. 5. Confidentiality
  6. 6. Security
  7. 7. Security Incidents
  8. 8. Data Subject requests
  9. 9. Assistance and compliance information
  10. 10. Subprocessors
  11. 11. Return, deletion, and retention
  12. 12. Audits
  13. 13. U.S. state privacy terms
  14. 14. EEA, United Kingdom, and Switzerland
  15. 15. Restricted information and minors
  16. 16. Artificial intelligence
  17. 17. International government requests
  18. 18. Priority, liability, and changes
  19. 19. Contact
  20. Schedule 1 — Processing details
  21. Schedule 2 — Technical and organizational measures
  22. Schedule 3 — International Transfer Terms

This Data Processing Addendum, including its schedules and the International Transfer Terms incorporated below (the “DPA”), forms part of the agreement governing a Customer's use of the Revup Service (the “Agreement”) whenever Revup processes Customer Personal Data on the Customer's behalf.

The parties to this DPA are the Customer identified in the Agreement (“Customer”) and Revup Inc, a Connecticut corporation with an address at 320 Boston Post Rd, Suite 180, #1070, Darien, Connecticut 06820 (“Revup”). By entering the Agreement, Customer enters this DPA on behalf of itself and any Customer Affiliate authorized to use the Service under the Agreement. A separately signed copy is not required for this DPA to apply, although either party may request a countersigned copy.

This DPA applies only to Processing for which Revup acts as a Processor or Service Provider on Customer's behalf. Sections directed to a particular jurisdiction apply only to the extent the corresponding Data Protection Law applies.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

Affiliate means an entity that controls, is controlled by, or is under common control with a party.

Applicable Data Protection Law means a privacy, data-protection, or data-security law applicable to Revup's Processing of Customer Personal Data under the Agreement, including, where applicable:

  • the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), and other comprehensive U.S. state privacy laws;
  • Regulation (EU) 2016/679 (“EU GDPR”), the EU GDPR as incorporated into United Kingdom law (“UK GDPR”), and applicable national implementing or supplementary legislation; and
  • the Swiss Federal Act on Data Protection (“FADP”).

Controller means the person that determines the purposes and means of Processing, including a “business” or “controller” under Applicable Data Protection Law.

Customer Personal Data means Personal Data contained in Customer Data that Revup Processes on Customer's behalf to provide the Service. Customer Personal Data does not include information Revup Processes as an independent Controller, as described in Section 3.3.

Data Subject means the identified or identifiable person to whom Personal Data relates, including a “consumer” under Applicable Data Protection Law.

EEA means the European Economic Area.

Personal Data means information defined as “personal data,” “personal information,” “personally identifiable information,” or a similar protected term under Applicable Data Protection Law.

Process or Processing means any operation performed on Personal Data, whether or not by automated means.

Processor means a person that Processes Personal Data on behalf of a Controller, including a “service provider,” “contractor,” or “processor” under Applicable Data Protection Law.

Restricted Transfer means a transfer of Customer Personal Data from the EEA, United Kingdom, or Switzerland to a country or recipient not covered by an applicable adequacy decision or adequacy regulation, where the transfer would be prohibited without an authorized transfer mechanism.

Security Incident means a confirmed breach of Revup's security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Revup's possession or control. Security Incident does not include unsuccessful activity that does not compromise Customer Personal Data, such as unsuccessful login attempts, scans, pings, or blocked attacks.

Service means the Revup websites, platform, hosted and embedded promotions, APIs, and related services provided under the Agreement.

Standard Contractual Clauses or SCCs means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded.

Subprocessor means an Affiliate or third party engaged by Revup to Process Customer Personal Data on Customer's behalf in connection with the Service.

UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, template Addendum B.1.0 issued by the United Kingdom Information Commissioner's Office and effective March 21, 2022, as revised under its mandatory clauses.

2. Scope and duration

2.1 This DPA takes effect when Customer enters the Agreement and continues for as long as Revup Processes Customer Personal Data on Customer's behalf.

2.2 The subject matter, nature, purpose, and duration of the Processing; the categories of Data Subjects; and the types of Customer Personal Data are described in Schedule 1.

2.3 If the parties have entered another valid data-processing agreement covering the same Processing, the later agreement controls unless it states otherwise.

3. Roles and responsibilities

3.1 Customer-directed Processing

For Customer Personal Data, Customer is a Controller or Processor, as applicable, and Revup is Customer's Processor. Customer determines how its promotions operate, what information they collect, the purposes for collection, which integrations receive the information, public-display settings, promotion retention decisions, and the lawful bases and notices applicable to the Customer's use of the information.

If Customer acts as a Processor for another Controller, Customer:

  • represents that the relevant Controller has authorized Customer to appoint Revup as a Subprocessor;
  • serves as the sole point of contact for that Controller; and
  • remains responsible for giving Revup lawful instructions on the Controller's behalf.

3.2 Customer compliance

Customer is responsible for:

  • complying with Applicable Data Protection Law in its collection and use of Customer Personal Data;
  • providing legally sufficient promotion notices, privacy disclosures, and Official Rules;
  • establishing an applicable lawful basis and obtaining any required consent;
  • responding to Data Subject requests as Controller;
  • configuring data collection, public displays, messaging, integrations, access, and retention appropriately; and
  • ensuring its instructions to Revup are lawful.

3.3 Revup's independent Processing

This DPA does not govern Personal Data that Revup Processes as an independent Controller for its own customer-account administration, billing, security, fraud and abuse prevention, legal compliance, support operations, direct business communications, or service-level telemetry that does not contain or derive from Customer Content or Participant Data and does not identify a Participant. Revup's Privacy Policy governs that Processing.

Customer-selected integrations may independently act as Controllers or Processors after receiving information at Customer's direction. Customer is responsible for its relationship with those integrations and for the destination and use of information after the Customer-directed transfer.

4. Processing instructions

4.1 Revup will Process Customer Personal Data only:

  • to provide, secure, maintain, and support the Service;
  • to perform Customer's configurations, workflows, communications, exports, APIs, and integration instructions;
  • as described in the Agreement and this DPA;
  • as otherwise documented in writing by Customer and accepted by Revup; or
  • as required by applicable law.

The Agreement, Customer's use and configuration of the Service, this DPA, and any applicable order form constitute Customer's documented instructions.

4.2 If Revup is required by law to Process Customer Personal Data contrary to Customer's instructions, Revup will notify Customer before the Processing unless the law prohibits notice.

4.3 Revup will promptly inform Customer if, in Revup's reasonable opinion, a Customer instruction violates Applicable Data Protection Law. Revup may suspend the affected Processing until the parties resolve the issue.

4.4 Instructions outside the scope of the Service may require a written amendment, additional fees, or both. Revup is not required to build new functionality or materially change the Service to carry out an instruction unless the parties agree in writing.

5. Confidentiality

5.1 Revup will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and receive access only as necessary for their responsibilities.

5.2 Revup will not disclose Customer Personal Data to a third party except:

  • to an authorized Subprocessor;
  • at Customer's direction;
  • as permitted by the Agreement or this DPA; or
  • as required by law.

Where legally permitted, Revup will notify Customer before making a legally compelled disclosure.

6. Security

6.1 Revup will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Schedule 2.

6.2 Revup may update its security measures to reflect changes in technology, law, risk, and the Service, provided that an update does not materially decrease the overall protection of Customer Personal Data.

6.3 Customer is responsible for securely configuring and using the Service, including managing account users and permissions, protecting credentials and API keys, selecting appropriate form fields and retention settings, and using designated secure features for restricted information.

7. Security Incidents

7.1 Revup will notify Customer without undue delay after becoming aware of a Security Incident and, in any event, no later than 24 hours after Revup confirms that the incident affected Customer Data. The initial notice may be preliminary and Revup may provide information in phases as its investigation continues.

7.2 To the extent known and reasonably available, Revup's notice will describe:

  • the nature of the Security Incident;
  • the categories of affected Customer Personal Data and Data Subjects;
  • the likely consequences;
  • measures taken or proposed to contain, investigate, mitigate, and remediate the incident; and
  • a contact for follow-up.

7.3 Revup will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident and will reasonably assist Customer with legally required notifications. Notification is not an admission of fault or liability.

7.4 Customer is responsible for determining whether it must notify Data Subjects, regulators, or others. Where legally permitted, Customer will consult Revup before a notice identifies Revup or describes Revup's involvement, so Revup may correct factual inaccuracies.

8. Data Subject requests

8.1 Customer is responsible for receiving, verifying, and responding to requests concerning Customer-directed Participant Data. A Participant should submit a request to the specific Customer or promotion sponsor that collected the information.

8.2 The Service allows an authorized Customer to locate a Participant using supported identifiers and delete that Participant's information across retained promotions within the Customer's account, subject to product functionality and lawful exceptions.

8.3 Revup is not the primary request intake point for Customer-controlled Participant Data and will not search for or delete a Participant across unrelated Customer accounts merely because the same identifier appears in more than one Customer account. Each Customer remains a separate Controller responsible for its own Processing.

8.4 If Revup receives a request relating to Customer Personal Data, Revup will, unless prohibited by law:

  • direct the requester to the relevant Customer or promotion sponsor when reasonably identifiable;
  • notify Customer when appropriate; and
  • not independently respond on Customer's behalf unless required by law or authorized by Customer.

8.5 Taking into account the nature of the Processing, Revup will provide reasonable and technically feasible assistance for Customer to fulfill Data Subject requests. Assistance requiring work beyond standard Service functionality may be subject to reasonable fees disclosed in advance.

9. Assistance and compliance information

9.1 Taking into account the nature of the Processing and information available to Revup, Revup will provide reasonable assistance with Customer's obligations concerning:

  • security of Processing;
  • Security Incident notifications;
  • data-protection impact assessments; and
  • prior consultation with a competent authority.

9.2 Revup will make available information reasonably necessary to demonstrate its compliance with this DPA. Assistance that requires material work beyond the Service may be subject to reasonable fees disclosed in advance, except to the extent prohibited by Applicable Data Protection Law.

10. Subprocessors

10.1 Customer provides general written authorization for Revup to engage Subprocessors. Revup's current Subprocessor List is available at https://revup.com/subprocessors/ and identifies the provider, purpose, relevant data and Data Subjects, processing regions, activation conditions, and available transfer information.

10.2 Revup will enter binding written terms with each Subprocessor that impose data-protection obligations appropriate to the Subprocessor's Processing and no less protective than the applicable obligations imposed on Revup by this DPA, to the extent required by Applicable Data Protection Law. Electronic and self-service provider terms may satisfy this requirement when they are binding and contain the required protections.

10.3 Revup remains responsible for a Subprocessor's performance of the data-protection obligations Revup delegates to it, subject to the liability terms of the Agreement and the mandatory requirements of Applicable Data Protection Law.

10.4 Revup will notify Customer at least 30 days before a new or replacement material Subprocessor begins Processing Customer Personal Data. Notice may be sent to Customer's primary account email address, another contact designated by Customer, or through another written Service-related notice mechanism. Revup may make an emergency replacement on shorter notice when reasonably necessary to maintain security, availability, or legal compliance, and will provide notice as soon as reasonably practicable.

10.5 Customer may object within 15 days after receiving notice on reasonable grounds relating to the protection of Customer Personal Data. The parties will work in good faith to address the objection. If no commercially reasonable resolution is available, Customer may discontinue the affected feature or terminate the affected portion of the Service. If the affected Processing is essential to the Service, Customer may terminate the Agreement as its sole contractual remedy for the objection and remains responsible for charges accrued before termination.

11. Return, deletion, and retention

11.1 During the subscription term, Customer controls the retention of Customer Personal Data through available Service features and instructions. Customer may delete Participant Data and promotions and may request reasonable assistance where self-service deletion is unavailable.

11.2 Winner-claim information, including shipping details, affidavits, signatures, tax documents, and identity documents, is retained until Customer deletes it, deletes the applicable record or promotion, or gives another supported deletion instruction, subject to the termination process and legal exceptions below. Customer is responsible for choosing a retention period appropriate to the promotion and applicable law.

11.3 Upon termination or expiration of the Service, Customer may request return or deletion of Customer Personal Data. Customer should export information it needs before termination using available Service functionality. Revup will honor a verified return or deletion request within a commercially reasonable period, taking into account the amount, location, and technical characteristics of the data, unless retention is permitted or required by law.

11.4 If Customer does not request earlier return or deletion, Customer instructs Revup to retain Customer Personal Data for the post-termination period described in the Agreement and Privacy Policy, currently generally no longer than one year after account cancellation, and then delete or deidentify it subject to the exceptions below.

11.5 Customer Personal Data may remain in protected backups until overwritten through Revup's normal backup cycle. Backup copies will remain protected under this DPA, will not be restored for ordinary business use or individual recovery requests, and will be deleted or rendered inaccessible through the normal cycle.

11.6 Revup may retain information where and for as long as applicable law requires or permits, including billing, tax, audit, security, fraud-prevention, messaging-suppression, dispute, and legal-hold records. To the extent retained information remains Customer Personal Data, Revup will protect it under this DPA and Process it only for the applicable retention purpose.

12. Audits

12.1 Customer may request information reasonably necessary to verify Revup's compliance with this DPA no more than once in a 12-month period, unless a Security Incident, a competent authority, or Applicable Data Protection Law reasonably requires an additional review.

12.2 Revup may satisfy an audit request by providing relevant policies, security descriptions, questionnaires, summaries, certifications, or independent assessment reports then available. Revup does not currently represent that the Service has a SOC 2 or ISO 27001 certification.

12.3 If the information in Section 12.2 is not reasonably sufficient and Applicable Data Protection Law requires further inspection, Customer may request a scoped audit. The parties will agree in advance on scope, timing, duration, confidentiality, security safeguards, and an auditor that is independent, qualified, not a Revup competitor, and bound by confidentiality.

12.4 Audits must occur during normal business hours, avoid unreasonable disruption, and not expose another customer's information, Revup trade secrets, or information that would create security risk. Customer bears its audit costs and will reimburse Revup's reasonable documented costs for assistance beyond information Revup ordinarily makes available, except where prohibited by law.

13. U.S. state privacy terms

This Section applies when Customer Personal Data is governed by a U.S. state privacy law and Customer is a business, Controller, Processor, Service Provider, or Contractor under that law.

13.1 The parties intend that Revup act as Customer's Service Provider, Contractor, or Processor for Customer Personal Data. Customer discloses Customer Personal Data to Revup only for the limited and specified purposes in the Agreement, this DPA, and Schedule 1.

13.2 Revup will:

  • comply with applicable obligations imposed on a Service Provider, Contractor, or Processor;
  • provide the level of privacy protection required by Applicable Data Protection Law;
  • Process Customer Personal Data only for the limited purposes specified in the Agreement and this DPA or as otherwise permitted by Applicable Data Protection Law;
  • notify Customer if Revup determines it can no longer meet an applicable obligation; and
  • permit Customer to take reasonable and appropriate steps under this DPA to help ensure that Revup uses Customer Personal Data consistently with Customer's obligations.

13.3 Revup will not:

  • sell or share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by Applicable Data Protection Law;
  • retain, use, or disclose Customer Personal Data for a commercial purpose other than providing the Service or another purpose permitted by Applicable Data Protection Law; or
  • combine Customer Personal Data received from Customer with Personal Data received from another person or collected from Revup's own interaction with a Data Subject, except as necessary to provide the Service, for security or fraud prevention, at Customer's direction, or as otherwise permitted by Applicable Data Protection Law.

13.4 Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing, including by using the rights and remedies in this DPA. Revup certifies that it understands and will comply with the restrictions in this Section.

14. EEA, United Kingdom, and Switzerland

14.1 Processing subject to the EU GDPR, UK GDPR, or FADP is additionally governed by Schedule 3, the International Transfer Terms.

14.2 The International Transfer Terms are incorporated into this DPA and are also published in a readable standalone format as the Revup International Transfer Terms. The standalone publication does not create a separate or conflicting agreement; Schedule 3 controls if the texts differ.

14.3 If Revup later becomes an active participant in an applicable adequacy framework, the parties may rely on that framework for transfers within its scope. Unless and until Revup publicly confirms active participation, the parties will not treat Revup as certified and will rely on the transfer mechanisms in Schedule 3 where required.

15. Restricted information and minors

15.1 Customer must not use ordinary custom fields or uploads to collect:

  • payment-card numbers subject to PCI DSS;
  • financial-account credentials;
  • health information regulated by HIPAA;
  • biometric identifiers used for identification;
  • passwords for third-party accounts;
  • precise geolocation unless expressly supported and authorized; or
  • other information prohibited by the Agreement.

15.2 Customer may collect tax identifiers, government identity documents, affidavits, signatures, shipping information, and similar winner-verification information only through a Revup feature expressly designated for that purpose and only when Customer has a lawful basis, provides required notices, applies an appropriate retention period, and limits access to authorized personnel.

15.3 Customer must not create a promotion directed to children under 13 or knowingly instruct Revup to collect Personal Data from a child under 13. Customer is responsible for any higher age threshold, parental-consent requirement, or other protection applicable to minors under the law governing its promotion.

15.4 Customer must not instruct Revup to Process special-category, sensitive, criminal-conviction, or similarly regulated information unless the Processing is expressly supported by the Service, permitted by the Agreement, and authorized in writing by Revup. Customer remains responsible for establishing the required lawful basis and safeguards.

16. Artificial intelligence

16.1 Revup will not use Customer Content or Participant Data to train, fine-tune, develop, or improve a Revup or third-party artificial-intelligence or machine-learning model.

16.2 Revup will not permit an AI Subprocessor to use Customer Personal Data for the Subprocessor's own model training, fine-tuning, development, or improvement.

16.3 Customer-authored content may be sent to an AI provider only when Customer requests or enables a supported AI feature, such as automated translation, and the Processing is necessary to provide that feature. Customer must not submit personal, confidential, or regulated information to an AI feature unless the feature expressly supports that use and Customer is authorized to do so.

16.4 Customer determines the configuration, criteria, and use of Revup's eligibility, fraud, scoring, winner-selection, and similar tools and remains responsible for any decision concerning a Participant. If Customer's configured use constitutes automated decision-making producing legal or similarly significant effects under Applicable Data Protection Law, Revup will provide reasonable information and assistance, taking into account the nature of the Processing and information available to Revup, so Customer can meet applicable obligations.

17. International government requests

17.1 Unless prohibited by law, Revup will notify Customer of a legally binding request from a public authority for Customer Personal Data.

17.2 Where Revup reasonably concludes that a request is unlawful or exceeds the requesting authority's powers, Revup will challenge or seek to narrow the request where there are reasonable grounds to do so. Revup will disclose only the information it is legally required to disclose.

17.3 Revup will provide information reasonably necessary for Customer to assess Restricted Transfers, subject to confidentiality, security, and legal restrictions.

18. Priority, liability, and changes

18.1 If this DPA conflicts with the Agreement concerning Processing of Customer Personal Data, this DPA controls. If the SCCs or mandatory UK Addendum clauses conflict with this DPA or the Agreement, those mandatory clauses control for the applicable Restricted Transfer.

18.2 To the maximum extent permitted by Applicable Data Protection Law and the SCCs, each party's liability arising from this DPA is subject to the exclusions and limitations in the Agreement. Nothing in this Section limits rights that Data Subjects have under the third-party-beneficiary provisions of the SCCs or liability that applicable law prohibits the parties from limiting.

18.3 Revup may update this DPA to reflect changes in law, regulatory guidance, the Service, or Processing, provided that an update does not materially reduce the overall protection of Customer Personal Data. Revup will provide notice when required by the Agreement or Applicable Data Protection Law.

18.4 The governing-law and dispute provisions of the Agreement apply to this DPA except where mandatory transfer terms require otherwise.

19. Contact

Questions and notices concerning this DPA may be sent to:

Revup Inc
Attn: Legal
320 Boston Post Rd, Suite 180
#1070
Darien, CT 06820
Email: hello@revup.com


Schedule 1 — Processing details

1. Parties and roles

Customer / data exporter

Name and address: The Customer identified in the Agreement.
Contact: The Customer's primary account contact or another privacy contact provided to Revup.
Activities: Customer's use of the Service to create, operate, analyze, and administer promotions, forms, communications, integrations, and related customer activities.
Role: Controller or Processor, as applicable.

Revup / data importer

Name: Revup Inc
Address: 320 Boston Post Rd, Suite 180, #1070, Darien, CT 06820, United States
Contact: hello@revup.com
Activities: Providing, hosting, securing, maintaining, and supporting the Service according to Customer's instructions.
Role: Processor or Subprocessor, as applicable.

2. Categories of Data Subjects

Customer Personal Data may relate to:

  • Participants, entrants, voters, referrers, survey or quiz respondents, purchasers, winners, and prize claimants;
  • Customer personnel, authorized users, agencies, contractors, administrators, clients, and business contacts;
  • individuals included in Customer-uploaded audience or contact lists;
  • individuals whose information enters the Service through a Customer-configured integration, API, webhook, ecommerce connection, or import; and
  • other individuals whose Personal Data Customer lawfully submits to or causes Revup to Process through the Service.

3. Categories of Customer Personal Data

Depending on Customer's configuration and the features used, Customer Personal Data may include:

  • Identity and contact information: name, email address, phone number, mailing address, display name, profile details, and similar identifiers;
  • Account and authorization information: Customer user identity, account membership, role, authentication and session metadata, verification status, and access records;
  • Promotion and form information: eligibility responses, age or date of birth, country or region, demographics, preferences, survey and quiz responses, ratings, custom-field responses, entries, entry methods, referrals, social actions, passcodes, coupons, votes, scores, winner status, and fulfillment information;
  • Consent and communications information: marketing preferences, consent records and presented wording, email and SMS content, delivery status, opens, clicks, replies, unsubscribe and STOP/START events, and carrier events;
  • Commerce information: orders, products, amounts, currency, discounts, refunds, purchase and transaction status, merchant and payment-provider identifiers, and related fulfillment data; Revup does not receive or store payment-card numbers;
  • Uploaded and submitted content: photos, videos, documents, captions, public-gallery content, rules, designs, messages, and other Customer or Participant submissions;
  • Winner-claim information: shipping information, eligibility affidavits, signatures, tax forms and tax identifiers, government identity documents, and other information Customer lawfully requests through a designated winner-claim feature;
  • Technical and activity information: IP address, IP-derived location, browser, device, operating system, referring and landing pages, campaign parameters, timestamps, cookies or similar identifiers, API and webhook metadata, logs, and Service activity;
  • Verification, integrity, and security information: email or phone verification results, fraud and abuse indicators, duplicate-entry signals, blocklist results, entry and vote validation information, and account-security events; and
  • Integration information: connected-service identifiers, field mappings, destinations, and information exchanged with Customer-selected services.

4. Sensitive data and safeguards

Customer Personal Data may include information considered sensitive under Applicable Data Protection Law only where expressly supported by the Service and permitted under Section 15. Designated winner-claim documents receive restricted storage and access protections described in Schedule 2. Customer must not use ordinary custom fields or general-purpose uploads to circumvent these restrictions.

5. Nature and purpose

Revup Processes Customer Personal Data to provide the Customer-configured Service, including hosting promotions and forms; receiving and recording responses; administering entries, votes, referrals, prizes, and winner claims; supporting communications and verification; processing Customer-configured workflows, exports, APIs, and integrations; securing the Service; preventing fraud and abuse; providing support; and complying with Customer's lawful instructions.

6. Frequency and duration

Processing and transfers occur on an ongoing basis as initiated by Customer and Participants through use of the Service. Processing continues for the Agreement term and the retention period described in Section 11.

7. Subprocessors

Current Subprocessors and feature-dependent providers are identified at https://revup.com/subprocessors/.


Schedule 2 — Technical and organizational measures

Revup maintains measures designed to protect Customer Personal Data proportionate to the nature and risk of the Processing. The measures include, as applicable:

1. Infrastructure and data protection

  • Application and managed infrastructure hosted in the United States through Northflank.
  • Cloudflare content delivery, network-security, abuse-prevention, and file-storage services.
  • HTTPS/TLS encryption for data transmitted over public networks.
  • Encryption at rest for data stored in Revup's primary managed infrastructure.
  • Additional application-level encryption for sensitive integration credentials.
  • Password hashing using bcrypt rather than reversible password storage.
  • Restricted storage for designated sensitive winner documents.

2. Identity and access management

  • Unique account identities and account-membership checks.
  • Role- and permission-based access to Customer functions.
  • Optional two-factor authentication for Customer users and required two-factor authentication for Revup administrative access.
  • Session protections, source-IP throttling, escalating account lockouts, and action-specific authorization checks.
  • API secrets displayed only when created or regenerated, stored as hashes for later verification, revocable by authorized users, and subject to access checks and rate limits.
  • Personnel access limited according to role and need.

3. Application and network safeguards

  • Request and input validation.
  • Rate limiting and trusted-proxy-aware IP controls.
  • Duplicate-entry, fraud, abuse, and security blocklists.
  • Cloudflare Turnstile on supported higher-risk actions.
  • Controls designed to prevent unauthorized cross-account access.

4. Logging, monitoring, and availability

  • Application error, performance, and operational monitoring.
  • Worker-health checks for queue age, volume, stuck processing, and delivery failures.
  • Security and operational logging designed to support investigation and response.
  • Protected backups and normal backup overwrite cycles for service resilience.

5. Incident handling

  • Procedures to investigate, contain, mitigate, remediate, and communicate confirmed Security Incidents.
  • Customer notification commitments described in Section 7.

6. Subprocessor and data lifecycle controls

  • Data-protection terms for Subprocessors as required by Section 10.
  • Customer-controlled Participant deletion within an account using supported product functionality.
  • Time-limited handling of temporary uploads and generated exports according to Revup's operational retention processes.
  • Deletion, deidentification, and protected-backup handling as described in Section 11.

Schedule 3 — International Transfer Terms

1. Scope

This Schedule applies to Restricted Transfers of Customer Personal Data from the EEA, United Kingdom, or Switzerland to Revup in the United States. It also applies when Customer is itself a Processor and appoints Revup as a Subprocessor.

2. EU Restricted Transfers

2.1 For an EU Restricted Transfer, the SCCs are incorporated by reference and form part of this DPA. The official SCC text is available at:

https://commission.europa.eu/publications/publications-standard-contractual-clauses-sccs_en

2.2 The SCCs are completed as follows:

  • Customer is the data exporter and Revup is the data importer.
  • Module Two applies when Customer is a Controller and Revup is a Processor.
  • Module Three applies when Customer is a Processor and Revup is a Subprocessor.
  • Clause 7, the optional docking clause, does not apply.
  • Clause 9 uses Option 2, general written authorization, with the notice period in Section 10.4 of this DPA.
  • The optional language in Clause 11 does not apply.
  • In Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland.
  • Under Clause 18, disputes will be resolved by the courts of Ireland.
  • Annex I.A and Annex I.B are populated by Schedule 1.
  • Annex I.C is populated under Section 5 below.
  • Annex II is populated by Schedule 2.
  • Annex III does not apply because Clause 9 uses general written authorization. Revup's Subprocessor List referenced in Schedule 1, Section 7 remains the operative list of current Subprocessors.

2.3 By entering the Agreement, each party is deemed to have signed the SCCs and their Annex I signature block on the effective date of this DPA. On request reasonably necessary to demonstrate compliance, the parties will provide a separately signed copy.

3. United Kingdom Restricted Transfers

3.1 For a UK Restricted Transfer, the SCCs apply as modified by the Approved Addendum's mandatory Part 2, which the parties incorporate by reference. This refers to ICO template B.1.0 submitted under section 119A of the Data Protection Act 2018, including revisions made under its Section 18. The ICO's current guidance and official downloads are available at:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/

3.2 The UK Addendum is completed as follows:

  • Table 1 — Parties: Customer is the exporter and Revup is the importer, with the details in Schedule 1.
  • Table 2 — Selected SCCs, modules, and clauses: Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers, with the selections in Section 2.2 above.
  • Table 3 — Appendix information: Schedule 1 supplies Annex 1A and Annex 1B, and Schedule 2 supplies Annex II. Annex III does not apply because the parties selected general written authorization; Revup's Subprocessor List remains the operative list of current Subprocessors.
  • Table 4 — Ending the Addendum if the Approved Addendum changes: the importer may end the UK Addendum as described in Section 19 of its mandatory clauses.

3.3 By entering the Agreement, each party agrees to be bound by the UK Addendum. The UK Addendum controls over this DPA for a conflict concerning a UK Restricted Transfer.

4. Swiss Restricted Transfers

For a Swiss Restricted Transfer, the SCCs apply with the following adaptations to the extent necessary under the FADP:

  • references to the EU GDPR are interpreted to include the FADP;
  • references to the European Union, EU, and Member States are interpreted to include Switzerland;
  • the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
  • the term “personal data” includes personal data protected by the FADP;
  • references to EU or Member State law are interpreted to include applicable Swiss law; and
  • nothing limits a Data Subject's right under the SCCs to bring proceedings in Switzerland where the FADP permits.

Module Two applies when Customer is a Controller and Module Three applies when Customer is a Processor. For a transfer governed only by the FADP, Clause 17 is governed by Swiss law and disputes under Clause 18 may be brought before the competent courts of Switzerland. If the transfer is also governed by the EU GDPR, the EU selections in Section 2.2 apply without limiting rights available under the FADP. The remaining selections and annex information in Section 2.2 apply to Swiss Restricted Transfers to the extent compatible with the FADP.

5. Competent supervisory authority

For EU Restricted Transfers, the competent supervisory authority under Annex I.C of the SCCs is determined as follows:

  • If Customer is established in an EEA member state, the authority for that member state.
  • If Customer is not established in the EEA but has appointed an EU representative under Article 27, the authority where that representative is established.
  • If Customer is not established in the EEA and has not appointed an EU representative, the authority of an EEA member state where affected Data Subjects are located, as Customer identifies to Revup in writing.

For UK Restricted Transfers, the competent authority is the United Kingdom Information Commissioner's Office. For Swiss Restricted Transfers, it is the Swiss Federal Data Protection and Information Commissioner.

6. Local laws and transfer assessments

6.1 Each party will comply with Clause 14 of the SCCs and assess whether the laws and practices of the destination country prevent the data importer from fulfilling the SCCs, taking into account the specific circumstances of the transfer and relevant contractual, technical, and organizational safeguards.

6.2 Revup will provide Customer information reasonably necessary to complete a transfer impact assessment or United Kingdom data-protection test, subject to confidentiality, security, and legal restrictions.

6.3 If a party concludes that supplementary measures are reasonably necessary, the parties will cooperate in good faith to implement appropriate measures. Neither party is required to agree to a measure that materially changes the Service unless the parties enter a written amendment.

7. Government access

Revup will comply with Clauses 15 and 16 of the SCCs, including notice, review, challenge, data-minimization, documentation, and suspension obligations, subject to applicable legal restrictions.

8. Onward transfers

Revup will make onward Restricted Transfers only as permitted by the applicable SCC module, UK Addendum, FADP, and Section 10 of this DPA. Customer's authorization of a Subprocessor under Section 10 constitutes documented authorization for the related onward transfer.

9. Alternative transfer mechanisms

If a valid adequacy decision, adequacy regulation, Data Privacy Framework certification, or replacement transfer mechanism covers a transfer, the parties may rely on that mechanism. If the mechanism ceases to apply, the SCCs, UK Addendum, or another valid mechanism will apply as necessary without requiring a new signature, to the extent legally permitted.

10. Priority

The SCCs and mandatory UK Addendum clauses control over this DPA and the Agreement for any conflict concerning a Restricted Transfer. Otherwise, this DPA remains in effect.

Related document

International Transfer Terms

View document

Ready to launch your
first promotion?

Free trial No credit card required Cancel anytime