Data Processing Addendum
Last updated: June 27, 2026
REVPass DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) forms part of the Master Subscription Agreement, Terms of Service, Order Form, or other written agreement between RevPass LLC, a Wisconsin limited liability company (“RevPass”), and the customer identified in the applicable agreement or order form (“Customer”) governing Customer’s access to and use of the RevPass services (the “Agreement”).
This DPA applies where RevPass processes Customer Personal Data on behalf of Customer in connection with the Services.
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control to the extent of the conflict.
1. Definitions
“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party.
“Agreement” means the agreement between Customer and RevPass governing Customer’s use of the Services, including any applicable Master Subscription Agreement, Terms of Service, Order Form, statement of work, product-specific terms, security exhibit, or document incorporated by reference.
“Applicable Data Protection Laws” means all privacy, data protection, and cybersecurity laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and other U.S. state privacy laws.
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act and its implementing regulations.
“Controller” means the entity that determines the purposes and means of processing Personal Data. “Controller” includes equivalent terms under Applicable Data Protection Laws, including “Business.”
“Customer Personal Data” means Personal Data contained in Customer Data that RevPass processes on behalf of Customer to provide the Services.
“Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates. “Data Subject” includes equivalent terms under Applicable Data Protection Laws, including “consumer.”
“GDPR” means Regulation (EU) 2016/679.
“Personal Data” means information relating to an identified or identifiable natural person, and includes equivalent terms under Applicable Data Protection Laws, including “personal information” and “personal data.”
“Processing” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, combination, restriction, deletion, or destruction. “Process,” “Processes,” and “Processed” have corresponding meanings.
“Processor” means the entity that Processes Personal Data on behalf of a Controller. “Processor” includes equivalent terms under Applicable Data Protection Laws, including “service provider,” “contractor,” and “processor.”
“Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area, United Kingdom, or Switzerland to a country, recipient, or jurisdiction that requires a transfer mechanism under Applicable Data Protection Laws.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by RevPass. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial-of-service attacks, or other network attacks on firewalls or networked systems.
“Services” means the RevPass subscription services, platform, software, APIs, integrations, workflow automation tools, AI-assisted features, validation features, e-signature facilitation features, support services, and related functionality provided under the Agreement.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission under Commission Implementing Decision (EU) 2021/914, as updated or replaced from time to time.
“Subprocessor” means any third party engaged by RevPass to Process Customer Personal Data on behalf of Customer in connection with the Services.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office, as updated or replaced from time to time.
“UK GDPR” means the GDPR as incorporated into United Kingdom law.
2. Roles of the Parties
For Customer Personal Data processed in connection with the Services: (a) Customer is the Controller or Processor, as applicable; and (b) RevPass is the Processor or Subprocessor, as applicable.
Where Customer acts as a Processor on behalf of a third-party Controller, Customer represents and warrants that Customer has authority to instruct RevPass to Process Customer Personal Data and that Customer’s instructions to RevPass are authorized by the relevant Controller.
RevPass may act as an independent Controller or Business for limited Personal Data processed outside Customer’s instructions, including account administration, billing, fraud prevention, abuse prevention, security, compliance, business communications, service analytics, and legal recordkeeping. Such processing is governed by RevPass’s Privacy Policy, not this DPA.
3. Scope of Processing
RevPass will Process Customer Personal Data only to: (a) provide, operate, maintain, secure, support, and improve the Services; (b) perform the Agreement; (c) follow Customer’s documented instructions; (d) process actions, settings, automations, approvals, integrations, and workflows configured or authorized by Customer; (e) detect, prevent, and respond to security incidents, fraud, abuse, and technical issues; (f) comply with applicable law; (g) exercise legal rights or defend legal claims; and (h) perform other processing permitted by this DPA or Applicable Data Protection Laws.
The subject matter, duration, nature, purpose, categories of Customer Personal Data, and categories of Data Subjects are described in Annex I.
4. Customer Instructions
Customer instructs RevPass to Process Customer Personal Data as necessary to provide the Services and as described in the Agreement, this DPA, applicable Order Forms, product settings, user actions, support requests, API calls, integration configurations, autonomy settings, approval policies, validation rules, field mappings, and other documented instructions.
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Laws.
RevPass will promptly notify Customer if RevPass determines that Customer’s instruction violates Applicable Data Protection Laws, unless prohibited by law.
Customer acknowledges that the Services may include customer-configured automation, AI-assisted features, Salesforce write-back, Slack actions, DocuSign workflows, native electronic acceptance, validation workflows, MSA drift detection, and booking handoff features. Actions performed by RevPass within Customer’s configured permissions, credentials, OAuth scopes, field mappings, integration settings, autonomy settings, approval policies, validation rules, or other instructions are Customer-authorized instructions.
5. Customer Responsibilities
Customer is responsible for: (a) determining the purposes and means of Processing Customer Personal Data; (b) providing all required notices to Data Subjects; (c) obtaining all required consents, permissions, and legal bases; (d) ensuring that Customer Personal Data may lawfully be Processed by RevPass; (e) ensuring that Customer’s users are authorized to use the Services; (f) configuring roles, permissions, approval policies, validation rules, autonomy settings, field mappings, and integrations appropriately; (g) reviewing and approving outputs, records, validations, MSA drift results, Salesforce updates, e-signature workflows, and booking handoffs before relying on them; (h) ensuring that Customer’s use of the Services complies with Applicable Data Protection Laws; and (i) responding to Data Subject requests except where RevPass assistance is required under this DPA.
Customer will not submit Sensitive Personal Data to the Services unless expressly authorized in the Agreement or a separate written agreement. Unless expressly authorized, the Services are not intended to process protected health information, payment card data, government identifiers, children’s data, biometric data, precise geolocation, criminal history data, special-category data under GDPR, or similarly regulated sensitive data.
6. RevPass Confidentiality Obligations
RevPass will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations or professional or statutory obligations of confidentiality.
RevPass will restrict access to Customer Personal Data to personnel who need access to provide, secure, support, or maintain the Services.
7. Security Measures
RevPass will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
RevPass’s security measures are described in Annex II.
Customer acknowledges that security measures are subject to technical progress and development. RevPass may update or modify security measures from time to time, provided that such updates do not materially decrease the overall security of the Services.
Customer is responsible for securely configuring the Services, managing Authorized Users, reviewing permissions, securing credentials, using appropriate OAuth scopes, maintaining secure Connected Systems, and protecting Customer-controlled environments.
8. Subprocessors
Customer authorizes RevPass to engage Subprocessors to Process Customer Personal Data in connection with the Services.
RevPass will maintain a list of Subprocessors, including their processing functions and locations, at https://revpass.io/security or another location made available by RevPass.
RevPass will impose written data protection obligations on Subprocessors that are at least as protective as those in this DPA to the extent applicable to the nature of the services provided by the Subprocessor.
RevPass remains responsible for Subprocessor performance of data protection obligations as required by Applicable Data Protection Laws.
RevPass will provide notice of new Subprocessors by posting an updated Subprocessor list, email notice, in-product notice, or other reasonable method.
Customer may object to a new Subprocessor on reasonable data protection grounds by notifying RevPass in writing within 30 days after notice. The parties will work in good faith to resolve the objection. If RevPass cannot reasonably resolve the objection, Customer may terminate the affected Services by providing written notice, and RevPass will refund prepaid unused fees for the terminated portion of the Services.
9. AI Providers and AI-Assisted Processing
Customer acknowledges that the Services may use AI-assisted features, including large language models, machine learning models, natural-language processing, rules-based automation, and deterministic validation logic.
RevPass may use AI providers as Subprocessors where such providers Process Customer Personal Data on behalf of RevPass to provide the Services.
RevPass will not permit third-party foundation-model providers to train their general-purpose models on Customer Personal Data unless expressly authorized in writing by Customer.
RevPass may Process Customer Personal Data through AI-assisted features to provide Customer-requested functionality, including extraction, summarization, classification, validation, MSA term analysis, MSA drift detection, natural-language validation rules, Slack responses, nudge drafting, opportunity matching, document generation, and other Services functionality.
RevPass will use commercially reasonable measures designed to limit AI provider access to Customer Personal Data to what is reasonably necessary to provide the Services.
Customer is responsible for determining whether use of AI-assisted features is appropriate for Customer’s legal, compliance, contractual, operational, and business requirements.
10. Connected Systems
Customer may connect the Services to Salesforce, Slack, DocuSign, email systems, ERP systems, billing systems, storage systems, identity providers, and other Connected Systems.
Customer acknowledges that Connected Systems may be operated by Customer or third parties and may be governed by separate terms and privacy policies.
Where RevPass transmits Customer Personal Data to a Connected System at Customer’s instruction, Customer is responsible for that instruction and for the privacy, security, and legal consequences of the transfer, except to the extent RevPass acts in breach of this DPA.
Customer is responsible for reviewing and approving OAuth scopes, API permissions, field mappings, user permissions, integration settings, and data flows involving Connected Systems.
Connected Systems controlled by Customer are not Subprocessors of RevPass. Third-party services engaged by RevPass to provide the Services may be Subprocessors and will be listed in the Subprocessor list where required.
11. Assistance with Data Subject Requests
Taking into account the nature of the Processing, RevPass will provide reasonable assistance to Customer to help Customer respond to Data Subject requests under Applicable Data Protection Laws.
Such requests may include access, deletion, correction, portability, restriction, objection, opt-out, or similar rights.
If RevPass receives a Data Subject request relating to Customer Personal Data, RevPass will, unless legally prohibited, either: (a) direct the Data Subject to Customer; or (b) notify Customer and act only on Customer’s documented instructions.
Customer is responsible for verifying the identity and authority of the requester and determining whether and how to respond.
If Customer cannot access Customer Personal Data through the Services, RevPass will provide reasonable assistance upon written request.
RevPass may charge reasonable fees for assistance that is excessive, technically complex, outside ordinary support, or not required by Applicable Data Protection Laws.
12. Assistance with Compliance
Taking into account the nature of the Processing and information available to RevPass, RevPass will provide reasonable assistance to Customer with: (a) data protection impact assessments; (b) prior consultations with supervisory authorities; (c) security assessments; (d) risk assessments; (e) records of processing activities; (f) regulatory inquiries; and (g) other compliance obligations required under Applicable Data Protection Laws.
RevPass may charge reasonable fees for assistance that is outside ordinary support or not required by Applicable Data Protection Laws.
13. Security Incident Notification
RevPass will notify Customer without undue delay after becoming aware of a Security Incident.
To the extent known and available, RevPass’s notice will include: (a) a description of the nature of the Security Incident; (b) categories and approximate number of affected Data Subjects, where known; (c) categories and approximate number of affected records, where known; (d) likely consequences, where known; (e) measures taken or proposed to address the Security Incident; and (f) information reasonably necessary for Customer to meet applicable notification obligations.
RevPass will take reasonable steps to investigate, contain, mitigate, and remediate the Security Incident.
RevPass’s notification of or response to a Security Incident is not an admission of fault or liability.
Customer is responsible for determining whether a Security Incident requires notification to Data Subjects, regulators, customers, counterparties, or other third parties, unless Applicable Data Protection Laws require RevPass to provide such notification.
14. Audit Rights
RevPass will make available information reasonably necessary to demonstrate compliance with this DPA.
Such information may include security documentation, summaries of policies and controls, third-party audit reports, certifications, penetration test summaries, completed security questionnaires, or other documentation reasonably determined by RevPass.
If the information provided is insufficient to satisfy Customer’s obligations under Applicable Data Protection Laws, Customer may request an audit.
Audits must be: (a) conducted no more than once per calendar year, unless required by a regulator or following a confirmed Security Incident; (b) subject to reasonable prior written notice of at least 30 days; (c) conducted during normal business hours; (d) limited to systems, records, and personnel relevant to Customer Personal Data; (e) conducted in a manner that does not disrupt RevPass’s business operations; (f) subject to confidentiality obligations; and (g) conducted by Customer or an independent auditor that is not a competitor of RevPass.
Customer is responsible for audit costs unless the audit reveals material noncompliance by RevPass with this DPA.
RevPass may object to an auditor that is not independent, is a competitor, lacks appropriate qualifications, or refuses reasonable confidentiality restrictions.
15. Return and Deletion
Upon termination or expiration of the Agreement, or upon Customer’s written request, RevPass will delete or return Customer Personal Data in accordance with the Agreement and this DPA.
Customer may export Customer Personal Data during the Subscription Term using available export functionality.
After termination or expiration, RevPass will make Customer Personal Data available for export for 30 days unless otherwise stated in the Agreement, prohibited by law, or technically infeasible.
RevPass may retain Customer Personal Data to the extent required or permitted by law, including for legal compliance, security, fraud prevention, billing, tax, accounting, audit logs, backup retention, dispute resolution, enforcement of rights, and legitimate business records.
Backup copies will be deleted in accordance with RevPass’s ordinary backup lifecycle.
RevPass may retain aggregated, anonymized, or de-identified data that does not identify Customer, Customer’s users, Customer’s counterparties, or Data Subjects and cannot reasonably be re-identified.
16. De-Identified Data
RevPass may create and use aggregated, anonymized, or de-identified data derived from Customer Personal Data for analytics, benchmarking, product improvement, security, reporting, and business purposes, provided that RevPass: (a) takes reasonable measures to ensure the data cannot be associated with a Data Subject, Customer, Customer’s users, or Customer’s counterparties; (b) publicly commits, where required by law, to maintain and use such data only in de-identified form; and (c) does not attempt to re-identify such data except to test or validate de-identification measures or as permitted by law.
17. International Data Transfers
Customer authorizes RevPass and its Subprocessors to Process Customer Personal Data in the United States and any other country where RevPass or its Subprocessors operate, subject to Applicable Data Protection Laws.
For Restricted Transfers from the European Economic Area, the parties agree that the SCCs are incorporated into this DPA and apply as follows: (a) Module Two applies where Customer is a Controller and RevPass is a Processor; (b) Module Three applies where Customer is a Processor and RevPass is a Subprocessor; (c) Clause 7, Docking Clause: optional docking clause applies; (d) Clause 9, Use of Subprocessors: Option 2 applies, with notice period of 30 days; (e) Clause 11, Redress: optional language does not apply unless otherwise agreed; (f) Clause 17, Governing Law: the SCCs will be governed by the laws of Ireland; (g) Clause 18, Choice of Forum and Jurisdiction: the parties agree that the courts of Ireland will have jurisdiction for disputes arising from the SCCs; (h) Annex I of the SCCs is completed by Annex I of this DPA; (i) Annex II of the SCCs is completed by Annex II of this DPA; and (j) Annex III of the SCCs is completed by Annex III of this DPA.
For Restricted Transfers from the United Kingdom, the UK Addendum is incorporated into this DPA and applies to the SCCs.
For Restricted Transfers from Switzerland: (a) references to the GDPR include the Swiss FADP as applicable; (b) references to EU Member States include Switzerland as applicable; (c) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority where required; and (d) the SCCs will be interpreted to comply with the Swiss FADP.
If the SCCs, UK Addendum, or other transfer mechanism is updated, replaced, or invalidated, the parties will work in good faith to implement a valid transfer mechanism.
Except for the SCCs, the UK Addendum, or another mandatory transfer mechanism, this DPA is governed by the governing law stated in the Agreement.
18. CCPA / CPRA Service Provider and Contractor Terms
For Customer Personal Data subject to the CCPA, RevPass will act as a service provider or contractor, as applicable.
RevPass will not: (a) sell Customer Personal Data; (b) share Customer Personal Data for cross-context behavioral advertising; (c) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA, the Agreement, or as otherwise permitted by the CCPA; (d) retain, use, or disclose Customer Personal Data for a commercial purpose other than the business purposes specified in this DPA, the Agreement, or as otherwise permitted by the CCPA; (e) retain, use, or disclose Customer Personal Data outside the direct business relationship between RevPass and Customer except as permitted by the CCPA; and (f) combine Customer Personal Data with Personal Data received from another source or collected from RevPass’s own interaction with a Data Subject, except as permitted by the CCPA.
RevPass will comply with applicable obligations under the CCPA and provide the same level of privacy protection required of service providers and contractors under the CCPA.
RevPass will notify Customer if RevPass determines that it can no longer meet its obligations under the CCPA.
Customer has the right to take reasonable and appropriate steps to help ensure that RevPass uses Customer Personal Data in a manner consistent with Customer’s obligations under the CCPA.
Customer has the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
RevPass certifies that it understands the restrictions in this section and will comply with them.
19. Other U.S. State Privacy Laws
To the extent other U.S. state privacy laws apply to Customer Personal Data, RevPass will Process Customer Personal Data as a processor, service provider, contractor, or equivalent role under those laws.
RevPass will: (a) Process Customer Personal Data only on Customer’s instructions; (b) assist Customer with Data Subject requests as required by applicable law; (c) assist Customer with security, breach, and data protection assessments as required by applicable law; (d) impose appropriate confidentiality obligations on personnel; (e) use Subprocessors only as permitted by this DPA; (f) make available information reasonably necessary to demonstrate compliance; and (g) delete or return Customer Personal Data as required by this DPA and applicable law.
20. Confidentiality of Regulatory Requests
If RevPass receives a legally binding request from a government authority, court, law enforcement agency, or regulator for Customer Personal Data, RevPass will, unless legally prohibited: (a) promptly notify Customer; (b) direct the requesting authority to Customer where appropriate; (c) disclose only the Customer Personal Data legally required; and (d) reasonably cooperate with Customer’s efforts to challenge or limit the request.
21. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless otherwise required by Applicable Data Protection Laws or expressly stated in the Agreement.
22. Term
This DPA will remain in effect for as long as RevPass Processes Customer Personal Data.
The obligations that by their nature should survive termination will survive, including confidentiality, deletion, audit cooperation, Security Incident cooperation, and transfer obligations.
23. Order of Precedence
If there is a conflict between documents, the following order applies for data protection matters: (a) SCCs, UK Addendum, or other mandatory transfer mechanism; (b) this DPA; (c) the Agreement; (d) Order Form; and (e) documentation, policies, or product terms.
For non-data protection matters, the order of precedence in the Agreement applies.
Annex I — Details of Processing
A. List of Parties
Data Exporter / Customer: Customer identified in the Agreement or applicable Order Form. Address: Address stated in the Agreement or Order Form. Contact person: Customer contact stated in the Agreement or Order Form. Role: Controller or Processor, as applicable.
Data Importer / RevPass: RevPass LLC. Address: 708 Heartland Trl, 3rd Floor, Madison, WI 53717. Contact person: privacy@revpass.io / legal@revpass.io. Role: Processor or Subprocessor, as applicable.
B. Subject Matter of Processing
RevPass’s provision of a B2B revenue workflow platform for quote generation, order-form generation, approval routing, electronic acceptance, electronic signature facilitation, CRM validation, Salesforce synchronization, MSA drift detection, AI-assisted extraction and analysis, Slack workflow actions, booking handoff, analytics, support, security, and related services.
C. Duration of Processing
The Subscription Term under the Agreement plus any period necessary for post-termination export, deletion, backup retention, legal retention, security, dispute resolution, or compliance.
D. Nature and Purpose of Processing
RevPass may Process Customer Personal Data to: (a) create, manage, and authenticate users; (b) connect to Salesforce and other Connected Systems; (c) import, sync, and validate CRM records; (d) generate quotes and order forms; (e) route approvals; (f) facilitate electronic acceptance and e-signature workflows; (g) retrieve, store, and process signed documents; (h) extract data from PDFs, contracts, order forms, MSAs, and related documents; (i) match signed documents to CRM opportunities; (j) validate signed documents against Salesforce and Customer rules; (k) detect potential MSA drift; (l) generate validation results, issue flags, summaries, scores, and suggested fixes; (m) sync line items, files, status, and other authorized updates to Salesforce; (n) send Slack, email, or workflow notifications; (o) support booking and ERP handoff; (p) provide analytics, audit logs, reporting, and dashboards; (q) troubleshoot, secure, maintain, and improve the Services; (r) provide support; (s) comply with law and enforce the Agreement.
E. Categories of Data Subjects
Customer Personal Data may relate to: (a) Customer employees; (b) Customer contractors; (c) Customer representatives; (d) Authorized Users; (e) Salesforce users; (f) Slack users; (g) approvers; (h) sales representatives; (i) order management personnel; (j) managers; (k) signers; (l) Customer prospects; (m) Customer customers; (n) Customer counterparties; (o) account contacts; (p) opportunity contacts; (q) billing contacts; (r) legal or procurement contacts; and (s) individuals referenced in contracts, MSAs, order forms, quotes, approvals, audit trails, or support communications.
F. Categories of Customer Personal Data
Customer Personal Data may include: (a) name; (b) business email address; (c) business phone number; (d) job title; (e) employer or company name; (f) department or role; (g) user ID; (h) CRM account ID; (i) CRM opportunity ID; (j) CRM contact ID; (k) Salesforce ID; (l) Slack ID; (m) DocuSign or e-signature ID; (n) IP address; (o) timestamp; (p) login and usage metadata; (q) approval metadata; (r) signature metadata; (s) audit trail data; (t) quote and order-form metadata; (u) contract and MSA metadata; (v) pricing, billing, term, and deal information that may identify individuals; (w) support communications; (x) uploaded document content; (y) generated outputs; and (z) security logs.
G. Sensitive Data
The Services are not intended to process Sensitive Personal Data unless expressly authorized in writing.
Customer should not submit protected health information, payment card data, government identifiers, children’s data, biometric data, precise geolocation, criminal history data, special-category data under GDPR, or similarly regulated sensitive data unless expressly authorized by RevPass in writing and supported by appropriate contractual terms.
H. Frequency of Transfer
Continuous or as initiated by Customer, Authorized Users, configured integrations, scheduled syncs, API calls, automation settings, support requests, or Services functionality.
I. Processing Operations
Processing operations may include collection, receipt, access, retrieval, storage, hosting, transmission, display, organization, structuring, extraction, parsing, analysis, classification, summarization, comparison, validation, scoring, generation, synchronization, modification, deletion, return, logging, monitoring, support, and security processing.
Annex II — Technical and Organizational Measures
1. Access Controls
Role-based access controls; least-privilege access; unique user accounts; authentication controls; administrative access restrictions; periodic access review; prompt removal or modification of access when no longer required.
2. Encryption
Encryption in transit using TLS or equivalent protocols where supported; encryption at rest for databases, object storage, backups, and storage systems where supported; secure handling of secrets, API keys, OAuth tokens, and credentials.
3. Network and Infrastructure Security
Use of reputable cloud infrastructure providers; logical separation of environments where appropriate; firewall, network, or platform-level access controls; secure configuration of cloud resources; monitoring of infrastructure events where appropriate.
4. Application Security
Secure software development practices; code review or equivalent development controls; dependency management; vulnerability management; authentication and authorization checks; input validation and output handling where appropriate; logging of security-relevant events.
5. Logging and Monitoring
Logging of relevant user, system, security, and integration events; monitoring for suspicious activity where appropriate; audit trail functionality for relevant workflow actions; retention of logs in accordance with RevPass policies.
6. Data Segregation
Logical separation of Customer accounts or workspaces; access restrictions designed to prevent unauthorized cross-customer access; tenant-aware application controls where applicable.
7. Personnel Security
Confidentiality obligations for personnel; access to Customer Personal Data limited to personnel with a need to know; security awareness appropriate to personnel roles; onboarding and offboarding procedures.
8. Vendor and Subprocessor Management
Review of Subprocessors based on the nature of services provided; written agreements with Subprocessors; data protection obligations for Subprocessors; maintenance of a Subprocessor list.
9. Incident Response
Procedures for identifying, escalating, investigating, and responding to Security Incidents; mitigation and remediation steps where appropriate; customer notification procedures under this DPA.
10. Backup and Recovery
Backup or replication practices appropriate to the Services; restoration procedures where applicable; backup retention and deletion in accordance with RevPass policies.
11. Data Retention and Deletion
Retention practices based on account status, legal requirements, operational needs, and backup lifecycle; deletion or return of Customer Personal Data as described in this DPA; retention of limited logs, billing records, legal records, and security records where necessary.
12. AI and Automation Controls
Limiting AI provider processing to Services-related purposes; contractual or technical restrictions designed to prevent third-party foundation-model training on Customer Personal Data unless authorized; customer-configurable autonomy settings; auditability of key workflow actions where supported; human-review or approval workflows where configured by Customer.
Annex III — Subprocessors
RevPass may use Subprocessors to provide the Services. Customer authorizes RevPass to use the Subprocessors listed at https://revpass.io/security.
RevPass should maintain a current Subprocessor list that includes: (a) Subprocessor name; (b) processing function; (c) location of processing; (d) type of data processed; and (e) applicable service category.
Initial Subprocessor Categories
Cloud hosting and deployment provider: hosting, compute, deployment, application infrastructure.
Database provider: database hosting, storage, query processing, backups.
Object storage provider: storage of PDFs, signed documents, templates, exports, and related files.
AI model provider: extraction, summarization, classification, validation assistance, MSA term analysis, MSA drift detection, natural-language rules, workflow message drafting.
Email provider: transactional email, notifications, invitation emails, signing workflow emails.
Payment processor: billing, subscription payments, invoicing, tax records.
Logging and monitoring provider: application logs, error tracking, security monitoring, performance monitoring.
Authentication provider: user authentication, identity management, OAuth, single sign-on support where applicable.
E-signature provider: optional third-party e-signature envelope creation, status updates, signed-document retrieval, voiding, audit trail data.
CRM and productivity integration providers: customer-authorized data exchange with Salesforce, Slack, and similar Connected Systems.
Initial Known Vendor Candidates
Counsel and RevPass should verify the final vendor list before publication. Based on the current product architecture, likely vendors may include: Vercel, Supabase / Postgres, Cloudflare R2, Anthropic, Salesforce, Slack, DocuSign, Resend, Stripe, and Google / NextAuth-related identity services.
Connected Systems controlled or independently selected by Customer may not be RevPass Subprocessors in every case. Counsel should classify each vendor correctly before final publication.
Annex IV — UK Addendum Details
Table 1 — Parties
Exporter: Customer. Importer: RevPass.
Table 2 — Selected SCCs, Modules, and Clauses
Approved EU SCCs: SCCs incorporated under Section 17 of this DPA.
Modules: Module Two where Customer is Controller and RevPass is Processor. Module Three where Customer is Processor and RevPass is Subprocessor.
Table 3 — Appendix Information
Annex I of this DPA provides details of the parties and processing. Annex II of this DPA provides technical and organizational measures. Annex III of this DPA provides Subprocessor information.
Table 4 — Ending the Addendum
Either party may end the UK Addendum in accordance with its terms if the UK Addendum is replaced, amended, or no longer required under UK data protection law.
Annex V — Optional Product-Specific Data Notes
Salesforce Data
Where Customer connects Salesforce, RevPass may Process Salesforce account, opportunity, contact, user, product, line item, pricing, stage, close date, owner, signed-document, and metadata fields within the OAuth scopes and permissions authorized by Customer.
Customer is responsible for Salesforce permissions, field mappings, data accuracy, downstream automations, and authorized write-back settings.
Slack Data
Where Customer connects Slack, RevPass may Process Slack user identifiers, channel identifiers, message metadata, approval actions, button interactions, command text, and workflow responses as required to provide Slack-connected functionality.
Customer is responsible for Slack workspace permissions and user authorization.
E-Signature Data
Where Customer uses RevPass native acceptance or a third-party e-signature integration, RevPass may Process signer names, business email addresses, IP addresses, timestamps, document identifiers, signing status, audit trail metadata, and signed documents.
Customer is responsible for determining whether electronic signature is appropriate for each use case.
MSA and Contract Data
Where Customer uploads MSAs, contracts, quotes, order forms, amendments, or similar documents, RevPass may Process those documents and extracted terms to provide validation, drift detection, approval routing, recordkeeping, and related workflow functionality.
Customer is responsible for ensuring it has rights to upload and process those documents.
AI Extraction and Validation Data
Where Customer uses AI-assisted extraction, summarization, natural-language rules, or drift detection, RevPass may Process document text, metadata, structured deal data, CRM data, extracted fields, validation rules, and generated outputs.
RevPass will not permit third-party foundation-model providers to train their general-purpose models on Customer Personal Data unless expressly authorized in writing by Customer.
Customer is responsible for reviewing AI-assisted outputs before relying on them.