Revopush Data Processing Agreement

Effective date: July 24, 2026 Last updated: July 24, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between REVOPUSH LTD, company number 16237196, of 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Revopush"), and the customer receiving the Services ("Customer").

This DPA applies to Revopush's Processing of Customer Personal Data on behalf of Customer. It is incorporated into the Revopush Terms of Service, a signed Master Services Agreement, or another agreement that expressly incorporates it (the "Agreement").

1. Definitions

Applicable Data Protection Law means data protection and privacy law applicable to the Processing under the Agreement, including, where applicable, the UK GDPR, the Data Protection Act 2018, the EU GDPR, and US state privacy laws.

Customer Personal Data means Personal Data Processed by Revopush on behalf of Customer in connection with the Services. It does not include personal data for which Revopush independently determines the purposes and means of Processing.

Controller, Data Subject, Personal Data, Personal Data Breach, Processing, and Processor have the meanings given under Applicable Data Protection Law.

Subprocessor means a third party appointed by or on behalf of Revopush to Process Customer Personal Data.

EU SCCs means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.

UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, as amended or replaced.

2. Scope, roles, and instructions

Customer is the Controller and Revopush is the Processor of Customer Personal Data, except where Customer acts as a Processor for another Controller, in which case Revopush acts as Customer's Subprocessor.

Customer instructs Revopush to Process Customer Personal Data:

  • to provide, secure, maintain, monitor, and support the Services;
  • as configured or initiated by Customer and its authorised users;
  • as documented in the Agreement and this DPA; and
  • as otherwise documented in writing and agreed by the parties.

Revopush will Process Customer Personal Data only on those documented instructions unless required by applicable law. Where legally permitted, Revopush will inform Customer before Processing required by law.

Customer is responsible for ensuring that its instructions, collection and use of Customer Personal Data, and use of the Services comply with Applicable Data Protection Law. Customer will provide required notices and obtain any required consents or other lawful basis.

The subject matter, duration, nature, purposes, data types, and categories of Data Subjects are described in Schedule 1.

3. Confidentiality and personnel

Revopush will ensure that personnel authorised to Process Customer Personal Data:

  • access it only where necessary for their role;
  • are informed of its confidential nature; and
  • are subject to an appropriate statutory or contractual duty of confidentiality.

Revopush remains responsible for its personnel's compliance with this DPA.

4. Security

Taking into account the state of the art, implementation cost, nature and scope of Processing, and risk to individuals, Revopush will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

The current categories of measures are described in Schedule 2 and the Security Statement. Revopush may update measures as technology and risk change, provided the overall protection of Customer Personal Data is not materially reduced.

Customer is responsible for securely configuring and using the Services, managing authorised users, protecting credentials, and evaluating whether the Services and measures are appropriate for its Processing.

5. Subprocessors

Customer gives Revopush general written authorisation to appoint the Subprocessors listed on the Subprocessors page.

Revopush will:

  • enter into a written agreement requiring each Subprocessor to protect Customer Personal Data to a standard materially consistent with this DPA;
  • remain responsible for a Subprocessor's performance of those data-protection obligations to the extent required by Applicable Data Protection Law; and
  • provide reasonable advance notice of a new or replacement Subprocessor where required, normally by email to the account owner or another agreed channel.

Customer may object promptly to a change on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If Revopush cannot provide a commercially reasonable alternative, Customer may terminate only the affected Services by written notice before the Subprocessor begins relevant Processing. Any refund is limited to prepaid fees for the unused terminated period.

6. Data Subject requests

Taking into account the nature of the Processing, Revopush will provide reasonable assistance through appropriate technical and organisational measures to help Customer respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.

If Revopush receives a request relating to Customer Personal Data, Revopush will, where legally permitted, direct the requester to Customer or notify Customer. Revopush will not respond on Customer's behalf unless instructed or legally required.

Customer is responsible for responding to requests and for verifying the requester's identity and entitlement.

7. Personal Data Breaches

Revopush will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent information is reasonably available, the notice will describe:

  • the nature of the breach;
  • the categories of affected data and Data Subjects;
  • the likely consequences;
  • measures taken or proposed to address and mitigate the breach; and
  • a contact for follow-up.

Information may be provided in phases as it becomes available. Revopush will take reasonable steps to contain, investigate, remediate, and mitigate the breach and will provide reasonable cooperation to help Customer meet applicable notification duties.

A notice is not an admission of fault or liability. Customer is responsible for determining whether it must notify a regulator, Data Subject, or other party.

8. Compliance assistance

Taking into account the nature of Processing and information available to Revopush, Revopush will provide reasonable assistance with:

  • security obligations applicable to Customer Personal Data;
  • Personal Data Breach assessments and notifications;
  • data-protection impact assessments; and
  • prior consultation with a supervisory authority where required.

If assistance requires material work beyond the standard Services, the parties may agree reasonable fees in advance, except where the work is required because Revopush breached this DPA.

Revopush will inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. Revopush may suspend the affected Processing while the parties resolve the issue.

9. Return and deletion

During the term, Customer may access or export Customer Data using available Service functionality.

On termination or expiry of the affected Services, and on Customer's written choice where required by Applicable Data Protection Law, Revopush will delete or return Customer Personal Data within a reasonable period, unless applicable law requires retention.

Customer Personal Data in backups will be protected and isolated from ordinary use and will be deleted through Revopush's normal backup expiry cycle, unless restoration is required for disaster recovery. If restored, the data will remain subject to this DPA.

Revopush may retain limited information necessary to demonstrate compliance, resolve disputes, prevent fraud, or meet legal obligations.

10. Information and audits

Revopush will make available information reasonably necessary to demonstrate compliance with this DPA, which may include current policies, security documentation, questionnaires, and independent assurance reports when available.

If that information is not reasonably sufficient, Customer may request an audit subject to the following conditions:

  • no more than once in any 12-month period, unless a competent authority requires otherwise or a confirmed Personal Data Breach reasonably justifies an additional audit;
  • at least 30 days' written notice where practicable;
  • scope, timing, duration, and auditor agreed in advance;
  • performance during normal business hours without unreasonable disruption;
  • no access to another customer's data, privileged information, or information that would create a security risk;
  • the auditor is independent and bound by confidentiality; and
  • Customer bears its costs and reimburses Revopush's reasonable costs, unless the audit identifies a material breach by Revopush.

Remote document review will be used before an on-site inspection. An on-site inspection is permitted only where legally required and a remote review cannot reasonably provide sufficient assurance.

11. International transfers

Customer authorises Revopush and its Subprocessors to Process Customer Personal Data in the countries described on the Subprocessors page, subject to this section.

If a transfer of Customer Personal Data requires an appropriate safeguard:

  • for data protected by the EU GDPR, the EU SCCs apply using Module 2 (Controller to Processor), or Module 3 where Customer is a Processor, as appropriate;
  • for data protected by UK data protection law, the UK Addendum applies to the relevant EU SCCs; and
  • the parties will reasonably cooperate to complete required transfer details and assessments.

The Agreement and Schedules to this DPA provide the information needed to complete the parties, Processing, and security annexes. The optional docking clause applies; the optional independent dispute-resolution clause does not. General authorisation for Subprocessors applies. The law and courts selected in the Agreement apply where the relevant clauses permit that selection.

If a valid adequacy mechanism or another lawful transfer basis applies, the parties may rely on that mechanism instead.

12. US state privacy laws

Where a US state privacy law applies and Customer is a "business", "controller", or equivalent entity, Revopush acts as Customer's "service provider", "processor", or equivalent for Customer Personal Data.

Revopush will not sell or share Customer Personal Data for cross-context behavioural advertising, retain, use, or disclose it outside the business purposes specified in the Agreement, or combine it with personal data received from another person except as permitted by applicable law. Customer may take reasonable and appropriate steps to help ensure Processing is consistent with those obligations.

13. Liability, term, and order of precedence

This DPA remains effective while Revopush Processes Customer Personal Data.

The liability limitations and exclusions in the Agreement apply to this DPA to the maximum extent permitted by law. This DPA does not create unlimited liability.

If documents conflict regarding data protection, the order of precedence is:

  1. mandatory terms of the EU SCCs or UK Addendum;
  2. this DPA;
  3. an Order Form, but only where it expressly identifies the provision it changes and the change is legally permitted;
  4. the main Agreement; and
  5. public informational policies.

14. General

The governing law, courts, notices, assignment, severability, and other general provisions of the Agreement apply to this DPA. If the Agreement does not specify governing law and courts, the laws of England and Wales apply and the courts of England and Wales have exclusive jurisdiction, subject to mandatory transfer-clause rights.

Revopush may update this DPA to reflect changes in law or Processing. Revopush will provide reasonable notice of a material adverse change. An update will not materially reduce the protection of Customer Personal Data during a current paid subscription term unless required by law.

Schedule 1: Details of Processing

ItemDescription
Subject matterProcessing Customer Personal Data to provide, secure, maintain, monitor, and support the Revopush OTA update Services
DurationThe term of the affected Services plus the limited return, deletion, legal-retention, and backup-expiry periods described in this DPA
Nature of ProcessingCollection, receipt, hosting, organisation, retrieval, consultation, transmission, logging, support access, security analysis, deletion, and other operations initiated by Customer or necessary to provide the Services
PurposesAccount administration; OTA bundle and asset delivery; application, deployment, and release management; authentication; support; service security; abuse prevention; troubleshooting; monitoring; and compliance with documented instructions or law
Data SubjectsCustomer's authorised users, employees, contractors, support contacts, and users of Customer applications that request or receive OTA updates
Personal DataBusiness contact and account identifiers; IP address; device, operating-system, browser, app, and SDK information; deployment and release identifiers; OTA request and delivery logs; diagnostic and security events; Customer-selected technical metadata; and Personal Data that Customer elects to include in bundles, assets, or support materials
Sensitive dataNot intended. Customer must not submit special-category data, health information, full payment card data, government identifiers, or similarly sensitive regulated data without Revopush's prior written agreement
FrequencyContinuous or event-driven, depending on Customer's use of the Services
Customer obligationsProvide lawful instructions, notices, and legal bases; minimise data; configure the Services securely; and avoid prohibited sensitive data

Schedule 2: Technical and Organisational Measures

Revopush maintains measures appropriate to its risk profile, including the following categories:

Control areaMeasures
Governance and riskAssigned security responsibilities, documented policies and procedures, risk-based review, and periodic policy maintenance
Access controlRole- and need-based access, identity-provider authentication, administrative protection including MFA where supported, access review, and removal following role change or offboarding
Network and infrastructureAzure-hosted infrastructure, Cloudflare edge protection, restricted production access, and logical separation of environments and services as appropriate
EncryptionHTTPS/TLS for data in transit and Azure-provided encryption controls for Customer Data at rest
Development and changeVersion control, risk-appropriate review and testing, controlled deployment, and tracking of material changes
Vulnerability managementAutomated dependency and repository scanning for in-scope systems, risk-based assessment, patching, and remediation prioritisation
Logging and monitoringOperational, security, error, and access information appropriate to detecting service issues and events requiring investigation
Incident responseDocumented identification, triage, containment, investigation, remediation, recovery, communication, and follow-up processes
Availability and recoveryManaged backup, replication, and recovery capabilities appropriate to the relevant systems, with restricted access and managed expiry cycles
Vendor managementRisk-based provider selection and review, purpose-limited integrations, written data-protection terms, and maintained Subprocessor transparency
Data minimisation and deletionCollection limited to Service needs, configurable Customer inputs, restricted support access, end-of-service deletion or return, and backup expiry
Physical securityReliance on cloud and service providers' physical and environmental controls for hosted infrastructure

Schedule 3: Transfer Information

Data exporter: Customer identified in the Agreement or account registration. Data importer: REVOPUSH LTD, company number 16237196, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: [email protected] Exporter role: Controller, or Processor where Customer processes data for another Controller. Importer role: Processor or Subprocessor. Transfer frequency and details: As described in Schedule 1. Subprocessors: As listed on the Subprocessors page. Security measures: Schedule 2. Competent supervisory authority: Determined under the applicable EU SCCs or UK Addendum.