Version 1.0-draft-2026-07-08 · Effective 2026-07-08

RevenueOS Inc. — Data Processing Addendum

Version 1.0 · Published: July 8, 2026

Draft prepared for counsel review — not yet executed

Contents

  1. Incorporation; Deemed Entry; Order of Precedence
  2. Roles of the Parties; Scope
  3. Processing Instructions
  4. Confidentiality of Processing
  5. Security
  6. Subprocessors
  7. International Transfers
  8. Data Subject Request Assistance
  9. Deletion and Return of Personal Data
  10. Personal Data Breach
  11. Impact Assessments and Prior Consultation
  12. Government and Legal Access Requests
  13. Audits and Demonstration of Compliance
  14. US State Privacy Law Service-Provider Terms
  15. Liability; Term; Survival
  • Annex I: Processing Details
  • Annex II: Technical and Organizational Measures
  • Annex III: Subprocessors
  • Annex IV: Pooled Intelligence Consent Addendum

1. Incorporation; Deemed Entry; Order of Precedence

1.1 Incorporation; Deemed Entry. This Data Processing Addendum ("this DPA") is the "DPA" defined in and incorporated into the RevenueOS Terms of Service (the "Terms") between RevenueOS Inc. ("RevenueOS") and Customer. This DPA is deemed entered into by the parties, without further signature, on the earliest moment the Terms become binding under Section 1.2 of the Terms — execution of an Order Form referencing the Terms, indication of assent through the Services, or first use of the Services. RevenueOS publishes the then-current version of this DPA at a stable URL on its website (www.revenueos.app/dpa).

1.2 Order of Precedence. This DPA forms part of the Agreement. If there is a conflict among the documents comprising the Agreement, the order of precedence in Section 1.3 of the Terms controls: this DPA prevails over the Terms and the Documentation as to the processing of personal data, each document solely to the extent of the conflict, and an Order Form prevails over this DPA only where it expressly states that it amends the Terms. Where the SCCs apply under Section 7, the SCCs prevail over this DPA to the extent of any conflict.

1.3 Definitions. Capitalized terms used but not defined in this DPA — including "Customer," "Client," "Customer Data," "Prospect," "Prospect Data," "Aggregated Statistics," "Usage Data," "Order Form," "Subscription Term," "Services," "Third-Party Platform," and "Documentation" — have the meanings given in the Terms and are used in this DPA without redefinition. In addition:

  • "Data Protection Laws" means all data protection and privacy laws applicable to the parties' processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US State Privacy Laws.
  • "Personal Data" means personal data or personal information (as defined in applicable Data Protection Laws) contained within Customer Data that RevenueOS processes on Customer's behalf under the Agreement. Personal Data does not include data for which RevenueOS is an independent controller under Section 2.4.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, or its then-current successor instrument.
  • "Subprocessor" means a third party engaged by RevenueOS to process Personal Data in the provision of the Services.
  • "US State Privacy Laws" means the comprehensive US state privacy laws applicable to the parties' processing as in effect from time to time, including the California Consumer Privacy Act as amended, together with its regulations ("CCPA"), and the comparable laws of other US states.

The terms "controller," "processor," "processing," and "data subject" have the meanings given in applicable Data Protection Laws, and "business," "service provider," "sell," and "share" have the meanings given in the CCPA.

2. Roles of the Parties; Scope

2.1 Customer as Controller. As allocated in Section 5.2 of the Terms, Customer is the controller of Prospect Data and other Personal Data submitted to the Services, and RevenueOS processes that Personal Data as Customer's processor, acting on Customer's documented instructions under Section 3.

2.2 Customer as Processor for Clients. Where Customer uses the Services on behalf of Clients under Section 6 of the Terms, Customer acts as a processor for the relevant Client and RevenueOS acts as Customer's subprocessor. Customer warrants that: (a) it has obtained the rights, authorizations, and consents described in Section 6.1 of the Terms, including any authorization required for RevenueOS's engagement as subprocessor; (b) its instructions to RevenueOS are consistent with its agreements with each Client; and (c) Customer is RevenueOS's sole point of contact and sole source of instructions with respect to Client Personal Data.

2.3 Scope. This DPA applies to RevenueOS's processing of Personal Data as processor or subprocessor. The subject matter, nature, purpose, and duration of the processing, and the categories of data subjects and Personal Data, are described in Annex I.

2.4 Independent Controller Processing. RevenueOS is an independent controller — and this DPA does not apply — with respect to: (a) account, registration, and User relationship data that RevenueOS processes to establish and administer Customer's account and the business relationship; (b) billing and payment data; (c) personal data of visitors to RevenueOS's websites; and (d) Usage Data as described in Section 13 of the Terms. That processing is governed by the RevenueOS Privacy Policy, not this DPA.

2.5 EU and UK Representative Scoping. The Services are offered solely for business use and are directed at businesses in the United States. RevenueOS has no establishment in the EU or the UK. Whether the appointment of a representative under Article 27 of the GDPR or of the UK GDPR is required, in view of the actual scope of processing carried out for customers, is under review with counsel; RevenueOS will publish representative contact details if and when a representative is appointed.

3. Processing Instructions

3.1 Documented Instructions. RevenueOS will process Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by applicable law — in which case RevenueOS will inform Customer of that legal requirement before processing, unless the law prohibits doing so on important grounds of public interest. Customer's documented instructions consist of: (a) the Agreement, including this DPA and each Order Form; (b) the Documentation; and (c) Customer's configuration of, and use of the features within, the Services.

3.2 Instructed Processing Operations. Without limiting Section 3.1, Customer expressly instructs RevenueOS to perform: (a) randomized assignment of Prospects and Messages among Messaging Angles, including assignment of Prospects to Control Cohorts and adaptive allocation, as described in Section 4.1 of the Terms; (b) the exchange of data with each Third-Party Platform that Customer connects, as described in Section 7.1 of the Terms; (c) any cross-Client configuration that Customer applies, as described in Section 6.3 of the Terms; and (d) where Customer has opted into the Pooled Intelligence Program, the computation of Aggregated Statistics as described in Section 12 of the Terms and Annex IV.

3.3 Infringing Instructions. RevenueOS will promptly inform Customer if, in RevenueOS's opinion, an instruction infringes applicable Data Protection Laws, and may suspend performance of the affected instruction until Customer confirms or modifies it. RevenueOS is not obligated to perform a legal review of Customer's instructions.

4. Confidentiality of Processing

4.1 Authorized Persons. RevenueOS will ensure that the persons it authorizes to process Personal Data — its personnel and permitted subcontractors — are bound by written or statutory obligations of confidentiality and process Personal Data only as necessary to provide the Services and perform the Agreement.

5. Security

5.1 Measures. RevenueOS will implement and maintain commercially reasonable technical and organizational measures designed to protect Personal Data against Personal Data Breaches, as described in Annex II, taking into account the nature of the processing and the information available to RevenueOS.

5.2 Changes to Measures. RevenueOS may update the measures described in Annex II from time to time, provided that updates do not materially degrade the overall protection of Personal Data.

5.3 Customer Responsibilities. Customer is responsible for its own secure use of the Services, including the credential and API-key responsibilities in Section 3.6 of the Terms, its configuration choices within the Services, and the security of Customer's Sending Infrastructure and connected Third-Party Platforms.

6. Subprocessors

6.1 General Authorization. Customer provides general written authorization for RevenueOS to engage Subprocessors to provide the Services. The Subprocessors currently engaged are listed in Annex III, which RevenueOS also maintains at a stable URL on its website.

6.2 Notice of Changes. RevenueOS will provide notice of the intended addition or replacement of a Subprocessor at least thirty (30) days before the new Subprocessor processes Personal Data, by email to Customer's account administrators.

6.3 Objection Right. Customer may object to an intended addition or replacement on reasonable data-protection grounds by written notice within the notice period. The parties will discuss the objection in good faith, and RevenueOS may propose a commercially reasonable alternative that avoids the objected-to processing. If no alternative is agreed before the change takes effect, Customer may terminate the affected Order Form on written notice and receive a pro-rata refund of prepaid, unused fees for the terminated remainder of the Subscription Term, as Customer's exclusive remedy for the objection.

6.4 Flow-Down; Responsibility. RevenueOS will impose on each Subprocessor, by written contract, data-protection obligations no less protective in substance than those in this DPA, to the extent applicable to the services the Subprocessor provides. As stated in Section 21.3 of the Terms, RevenueOS remains responsible for its Subprocessors' performance and for RevenueOS's own obligations under the Agreement.

7. International Transfers

7.1 Processing Location. RevenueOS is a United States company and provides the Services from the United States. Personal Data is processed and stored in the United States and in the Subprocessor locations listed in Annex III.

7.2 EU Transfers; SCCs. Where the GDPR applies to a transfer of Personal Data from Customer (as data exporter) to RevenueOS (as data importer) in a country not covered by an adequacy decision, the SCCs are incorporated into this DPA by reference and are deemed executed by the parties upon entry into this DPA, completed as follows: (a) Module Two (controller to processor) applies where Customer acts as a controller, and Module Three (processor to processor) applies where Customer acts as a processor for its Clients; (b) Clause 7 (docking clause) is included; (c) in Clause 9(a), Option 2 (general written authorisation) applies, with the time period specified in Section 6.2; (d) the optional language in Clause 11(a) is not included; (e) in Clauses 17 and 18, the SCCs are governed by the law of Ireland and disputes are resolved before the courts of Ireland; and (f) Annexes I, II, and III of this DPA serve as the completed Appendix (Annexes I, II, and III) to the SCCs.

7.3 SCC Precedence; Successor Clauses. To the extent of any conflict between the SCCs and this DPA or any other part of the Agreement, the SCCs control. If the European Commission adopts updated or additional standard contractual clauses applicable to the parties' transfers — including any clauses adopted for data importers whose processing is directly subject to the GDPR — the updated clauses automatically supersede the SCCs incorporated in Section 7.2 from the date compliance with them is required, completed with the information in Annexes I, II, and III.

7.4 UK Transfers. Where the UK GDPR applies to a restricted transfer, the SCCs as incorporated in Section 7.2 apply as amended by the UK Addendum, which is deemed executed upon entry into this DPA and completed with the information in Annexes I, II, and III; for Table 4 of the UK Addendum, either party may end the UK Addendum as set out in its Section 19. The parties acknowledge that the European Commission's adequacy decisions for the UK have been renewed through 27 December 2031, and that the UK Information Commissioner may issue successor transfer instruments; Section 7.3 applies correspondingly to UK successor instruments.

7.5 Swiss Transfers. Where the Swiss Federal Act on Data Protection applies to a transfer, the SCCs as incorporated in Section 7.2 apply with the adaptations customary for Switzerland: references to the GDPR are read as references to the FADP insofar as transfers are subject to it, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and data subjects habitually resident in Switzerland may enforce their rights in Switzerland.

7.6 Data Privacy Framework. Certain Subprocessors are certified under the EU-U.S. Data Privacy Framework, the UK Extension to it, or the Swiss-U.S. Data Privacy Framework, as indicated in Annex III. RevenueOS relies on such certification where it covers the relevant processing, and on the SCCs (or another valid transfer mechanism) in any event, so that a valid transfer mechanism remains in place for each onward transfer if a certification, or the framework itself, ceases to be valid.

8. Data Subject Request Assistance

8.1 Assistance Obligation. Taking into account the nature of the processing, RevenueOS will assist Customer, by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Laws ("DSRs").

8.2 In-Product DSR Tooling. Where enabled for Customer's workspace, the Services provide a tenant-scoped DSR intake and execution surface: (a) each DSR recorded through the Services is stamped at intake with a thirty (30) day response deadline, aligned to the GDPR's one-month response window; (b) access and portability requests are fulfilled through a subject-scoped export of the relevant Prospect's records within Customer's tenant; (c) erasure requests are fulfilled through a subject-scoped deletion of the relevant Prospect's records within Customer's tenant, with a durable audit record written before any data is erased; and (d) rectification, restriction, and objection requests are recorded and tracked in the Services and remain open for fulfillment by Customer, which performs them manually.

8.3 Further Assistance. RevenueOS will provide commercially reasonable further assistance with DSRs that cannot be resolved through the Services, including the rectification, restriction, and objection requests described in Section 8.2(d) where Customer cannot fulfill them itself. If a data subject contacts RevenueOS directly regarding processing under the Agreement, RevenueOS will, to the extent legally permitted, direct the data subject to Customer and notify Customer, and will not respond substantively on Customer's behalf except as instructed by Customer or required by law.

8.4 Customer Responsibility. As stated in Section 11.4 of the Terms, Customer is responsible for the substance of responses to data subjects and for meeting statutory deadlines, including verifying the requester's identity and determining whether an exemption or refusal ground applies.

9. Deletion and Return of Personal Data

9.1 During the Term. During each Subscription Term, Customer may retrieve Personal Data through the Services and may delete Personal Data through the Services' features and documented instructions, including the DSR tooling described in Section 8.

9.2 Return on Termination. For thirty (30) days following expiration or termination of the Agreement, RevenueOS will make Customer Data available for export in a commonly used format on Customer's request, as stated in Section 10.5 of the Terms.

9.3 Deletion; Retained Categories. After the export window, RevenueOS will delete the Personal Data it processes on Customer's behalf by executing its tenant deletion cascade, except that the following categories of records are retained: (a) audit logs and audit-chain checkpoints — the accountability and tamper-evidence records of privileged operations, including the record that an erasure itself was performed; (b) data-subject-request records — accountability evidence that a request was received and fulfilled; (c) records of acceptance of the Terms; (d) Pooled Intelligence consent ledger records — evidence of consent and withdrawal decisions; (e) invoices and billing records, retained for statutory periods; and (f) Aggregated Statistics previously computed, as described in Sections 12.4 and 12.5 of the Terms. Retained records are kept only for as long as needed for their retention purpose, are not used for any other purpose, and remain protected under the Agreement.

9.4 Backups. Copies of Personal Data in routine platform backups persist pending scheduled destruction in the ordinary course of the backup cycle. Backup copies are not restored to active systems except for disaster recovery; if a restoration occurs, RevenueOS re-applies previously executed deletions to the restored data.

9.5 Legal Retention. RevenueOS may retain Personal Data to the extent and for the period required by applicable law, and will protect such data in accordance with this DPA and process it only for the purpose of the legal requirement.

10. Personal Data Breach

10.1 Notice. RevenueOS will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming a Personal Data Breach affecting Personal Data processed on Customer's behalf. Notice will be delivered by email to Customer's account administrators and to the notice contact on the Order Form or account, if different.

10.2 Content; Updates. The notice will describe, to the extent then known: the nature of the Personal Data Breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures RevenueOS has taken or proposes to take to address the breach and mitigate its possible adverse effects; and a contact point for further information. Information may be provided in phases as RevenueOS's investigation proceeds, and RevenueOS will update Customer as material new information becomes available and will take reasonable steps to contain and remediate the breach.

10.3 No Admission; Roles. A notice under this Section 10 is not an acknowledgment of fault or liability. Customer is responsible for any notification to supervisory authorities or data subjects that Data Protection Laws require of Customer; RevenueOS will provide reasonable cooperation and information to support those notifications and will not notify authorities or data subjects on Customer's behalf unless required by law or agreed in writing.

11. Impact Assessments and Prior Consultation

11.1 Assistance. Taking into account the nature of the processing and the information available to RevenueOS, RevenueOS will provide reasonable assistance to Customer with data protection impact assessments, and with prior consultation of supervisory authorities, where required of Customer under Data Protection Laws and related to Customer's use of the Services. RevenueOS maintains its own internal assessment of the protections applied in the Pooled Intelligence Program and will make relevant summaries available on request under Section 13.

12. Government and Legal Access Requests

12.1 Notification. If RevenueOS receives a legally binding request from a public authority (including a law-enforcement or national-security authority) or a court for access to or disclosure of Personal Data, RevenueOS will promptly notify Customer, unless legally prohibited from doing so. If prohibited, RevenueOS will use reasonable efforts to obtain a waiver of the prohibition so that it can communicate as much information as possible, as soon as possible, and will document those efforts.

12.2 Review; Challenge; Minimization. RevenueOS will assess the legality of each demand individually and will not disclose Personal Data in response to a demand with which it is not legally compelled to comply. Where RevenueOS concludes, after careful assessment, that there are reasonable grounds to consider a demand unlawful or overbroad, RevenueOS will challenge the demand, including seeking interim measures where available, to the extent such a challenge is reasonable. In all cases, RevenueOS will disclose only the minimum amount of Personal Data necessary to comply with the demand.

12.3 Records; SCC Obligations. RevenueOS will document each demand received and its response. Where the SCCs apply, RevenueOS will comply with the obligations of Section III of the SCCs (Clauses 14 and 15), including notifying Customer if RevenueOS becomes aware of laws or practices that prevent it from fulfilling its obligations under the SCCs and providing the information contemplated by Clause 15.

13. Audits and Demonstration of Compliance

13.1 Information; Written Audits. RevenueOS will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. Customer's audit rights are satisfied in the first instance through: (a) RevenueOS's written responses to Customer's reasonable information-security and data-protection questionnaires; and (b) summaries of RevenueOS's then-current technical and organizational measures (Annex II) and of any third-party security assessments that RevenueOS actually possesses. Customer may exercise this right no more than once in any twelve (12) month period, and additionally following a confirmed Personal Data Breach affecting Customer's Personal Data.

13.2 Inspections. Where the information provided under Section 13.1 is demonstrably insufficient to demonstrate compliance with this DPA, following a confirmed Personal Data Breach affecting Customer's Personal Data, or where required by a supervisory authority or by the SCCs, Customer — or an independent auditor mandated by Customer that is not a competitor of RevenueOS and is bound by confidentiality obligations — may conduct an audit, including an inspection, of the processing activities covered by this DPA. Any inspection requires at least thirty (30) days' prior written notice, occurs during normal business hours, is at Customer's expense, is limited in frequency to once in any twelve (12) month period except following such a breach or where an authority requires it, and must be conducted in a manner that does not compromise the security or confidentiality of RevenueOS's other customers' data. Audit outputs are RevenueOS's Confidential Information under Section 15 of the Terms.

13.3 No Certification Claims. RevenueOS does not represent that it holds any particular third-party certification, attestation, or audit report, and nothing in this DPA constitutes such a representation.

14. US State Privacy Law Service-Provider Terms

14.1 Roles. For Personal Data subject to US State Privacy Laws, Customer is the "business" or "controller" and RevenueOS acts as Customer's "service provider" or "processor," processing Personal Data only for the business purpose of providing the Services described in the Agreement.

14.2 Restrictions. RevenueOS will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including this DPA, or as otherwise permitted for service providers under US State Privacy Laws; (c) retain, use, or disclose Personal Data outside the direct business relationship between RevenueOS and Customer; or (d) combine Personal Data received from, or on behalf of, Customer with personal information received from or on behalf of another person, or collected from RevenueOS's own interactions with consumers, except as permitted for service providers by the CCPA regulations (Cal. Code Regs. tit. 11, § 7050). The Pooled Intelligence Program is designed to operate within that exception: it runs only on Customer's opt-in and produces aggregate, noise-protected statistical parameters as described in Annex IV.

14.3 Certification; Compliance Notice; Remediation. RevenueOS certifies that it understands the restrictions in this Section 14 and will comply with them. RevenueOS will notify Customer without undue delay if it determines that it can no longer meet its obligations under applicable US State Privacy Laws, and Customer may then take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data, including through the instruction, assistance, and audit rights in this DPA.

14.4 Consumer Requests. RevenueOS will assist Customer in responding to verifiable consumer requests under US State Privacy Laws through the tooling and assistance described in Section 8. Because RevenueOS does not sell or share Personal Data, no opt-out of sale or sharing arises with respect to Personal Data; RevenueOS's handling of opt-out preference signals for data it processes as a controller is described in its Privacy Policy.

15. Liability; Term; Survival

15.1 Liability. Each party's liability arising out of or relating to this DPA — including, as between the parties, the SCCs — is subject exclusively to Section 19 of the Terms, including the enhanced cap in Section 19.3, and nothing in this DPA creates an independent or additional cap or a separate body of liability; this Section does not limit any rights a data subject may have directly under the SCCs.

15.2 Term. This DPA takes effect as described in Section 1.1 and continues for as long as RevenueOS processes Personal Data under the Agreement. It terminates automatically upon expiration or termination of the Agreement, except that it survives and continues to apply to Personal Data retained under Section 9 until that data is deleted or destroyed.

15.3 Updates. RevenueOS may update this DPA by publishing a revised version with a version-number change and providing notice consistent with Section 21.7 of the Terms; updates required by Data Protection Laws or by changes to the transfer instruments referenced in Section 7 may take effect as stated in the notice.


Annex I: Processing Details

This Annex I also serves as Annex I to the SCCs (list of parties and description of transfer) and supplies the corresponding tables of the UK Addendum.

  • Parties. Data exporter: Customer, contact details as stated on the Order Form or account — a controller (Module Two) or, where acting for its Clients under Section 2.2, a processor (Module Three). Data importer: RevenueOS Inc., [registered / notice address]; contact: legal@revenueos.app — a processor.
  • Subject matter. RevenueOS's provision of a measurement and proof layer for outbound sales programs, as described in Section 3.2 of the Terms: assignment of Prospects and Messages among Messaging Angles (including randomized controlled assignment with Control Cohorts and adaptive allocation); ingestion of engagement and outcome events from Customer's connected Sending Infrastructure and business systems; computation of Statistical Outputs; and dashboards, experiment management, and proof readouts.
  • Nature and purpose of the processing. Hosting, storage, organization, assignment and orchestration, measurement and attribution computation, analysis, display, export, and deletion of Personal Data as necessary to provide the Services; where Customer has opted in, computation of Aggregated Statistics as described in Annex IV.
  • Duration. The Subscription Term, plus the export and deletion periods described in Section 9 of this DPA.
  • Categories of data subjects. Prospects; Customer's Users; personnel of Customer's Clients.
  • Categories of Personal Data. Business-contact data (such as name, business email address, employer, job title, and business phone number where supplied); engagement and outcome events relating to outbound programs (such as sends, deliveries, opens, replies, meetings, and opportunity outcomes); message-content metadata and campaign configuration attributable to identifiable individuals; and identity and activity data of Users within the Services.
  • Special categories of data. None intended. Customer is instructed not to submit special categories of personal data, or data of comparable sensitivity (including criminal-offense data), to the Services, which are not designed for such data.
  • Frequency of the transfer. Continuous, for the duration of the Agreement.
  • Retention criteria. As described in Section 9 of this DPA and Section 10.5 of the Terms.
  • Subprocessor transfers. As described in Annex III; the subject matter, nature, and duration of Subprocessor processing correspond to each Subprocessor's function listed there.
  • Competent supervisory authority. Determined in accordance with Clause 13 of the SCCs; for restricted transfers under the UK Addendum, the UK Information Commissioner.

Annex II: Technical and Organizational Measures

This Annex II also serves as Annex II to the SCCs. RevenueOS maintains the following technical and organizational measures. They are stated as actually implemented, without certification claims, and are calibrated to RevenueOS's current scale of operations.

  • Encryption in transit: TLS for data in transit between clients, the application, and the datastore.
  • Encryption at rest: platform-provided encryption at rest on the managed database platform hosting the primary datastore.
  • Tenant isolation: application-layer tenant isolation applied on every data-access path, with database row-level-security policies defined at the database layer as an additional backstop.
  • Access control: authentication through a managed identity provider; role- and attribute-gated authorization for administrative and privileged operations; least-privilege service credentials.
  • Audit logging: durable audit logging of privileged operations — including data-subject-request execution and erasures — written before the privileged operation proceeds. Audit records are additionally sealable through an out-of-band tamper-evidence mechanism whose KMS-backed signing operates over cryptographic hash values only; no Personal Data content is sent to the key-management service.
  • Telemetry hygiene: redaction of personal data from application telemetry and operational logs.
  • Legal-evidence ledgers: append-only, immutable records of Terms acceptance and Pooled Intelligence consent decisions, with immutability enforced at the database.
  • Data-subject-request tooling: tenant-scoped DSR intake with deadline tracking, subject-scoped export, and subject-scoped erasure with audit-before-erasure, as described in Section 8.
  • Deletion: a tenant deletion cascade with the documented retention carve-outs in Section 9; re-application of previously executed erasures following any restoration from backup.
  • Secrets management: credentials and keys held in platform secret stores; no secrets in source control.
  • Pooled-statistics protections (where elected): a minimum cohort of five distinct participating customers (k-anonymity floor) and centrally applied differential-privacy noise (Laplace mechanism) on Aggregated Statistics releases, as described in Annex IV.
  • Personnel and subcontractors: confidentiality obligations under Section 4 and Subprocessor flow-down under Section 6.
  • Onward-transfer measures. For onward transfers to Subprocessors, the measures each Subprocessor applies are described in that Subprocessor's own security documentation, referenced through the resources listed in Annex III.

Annex III: Subprocessors

This Annex III lists the Subprocessors engaged as of the version date of this DPA, and also serves as Annex III to the SCCs. Category labels use the terms of Section 11.2 of the Terms. Changes follow the notice and objection process in Section 6. "Transfer mechanism" states the mechanism RevenueOS relies on for that vendor consistent with Section 7.6: certification under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. framework, as applicable) where the vendor holds it, and standard contractual clauses in any event.

  • Clerk, Inc. — identity (user authentication and account identity); personal data touched: Users' names, email addresses, and authentication metadata; region: United States; transfer mechanism: Data Privacy Framework where certified, SCCs in any event.
  • Supabase, Inc. — database (managed primary datastore); personal data touched: all categories described in Annex I (primary storage); region: United States (hosting region pinned at provisioning); transfer mechanism: SCCs.
  • Stripe, Inc. — payments (payment processing and invoicing); personal data touched: billing contact and payment information of Customer personnel authorizing payment (data RevenueOS processes as an independent controller under Section 2.4(b); Stripe is listed for transparency); region: United States; transfer mechanism: Data Privacy Framework where certified, SCCs in any event.
  • Twilio Inc. (SendGrid) — email-event processing (transactional email dispatch and engagement-event processing); personal data touched: recipient email addresses and message and event metadata; region: United States; transfer mechanism: SCCs (Twilio Inc. is DPF-certified; the SCCs are the operative mechanism for the SendGrid services).
  • Fly.io, Inc. — application hosting (backend compute); personal data touched: all categories described in Annex I, in processing and in transit; region: United States; transfer mechanism: Data Privacy Framework where certified, SCCs in any event.
  • Vercel Inc. — application hosting (frontend delivery); personal data touched: data transmitted through and rendered by the web application; region: United States, with global edge delivery; transfer mechanism: Data Privacy Framework where certified, SCCs in any event.
  • OpenAI, LLC — AI-inference (model inference for content-analysis and drafting features); personal data touched: text submitted for inference, which may include Prospect business-contact data and message content; region: United States; transfer mechanism: SCCs. By default, OpenAI does not use API inputs or outputs to train or improve its models, and retains API data only for limited abuse-monitoring purposes, in each case per OpenAI's then-current enterprise privacy commitments.
  • Anthropic, PBC — AI-inference (model inference for content-analysis and drafting features); personal data touched: text submitted for inference, which may include Prospect business-contact data and message content; region: United States; transfer mechanism: SCCs. By default, Anthropic does not use commercial API inputs or outputs to train its models, per Anthropic's commercial terms.
  • Upstash, Inc. — caching (managed cache and queueing); personal data touched: queued job payloads and cached operational data, which may include Prospect identifiers; region: United States (region selected at creation); transfer mechanism: Data Privacy Framework where certified, SCCs in any event.
  • Exclusions. RevenueOS does not currently engage a third-party error-monitoring or observability Subprocessor for Personal Data; any future engagement will follow Section 6 before Personal Data flows to it. Any cryptographic signing of audit material is performed through a managed cloud key-management service that receives hash values only and no Personal Data content, and such a service is therefore not a Subprocessor.

Annex IV: Pooled Intelligence Consent Addendum

This Annex IV is the consent mechanism referred to in Section 12.1 of the Terms and forms part of this DPA. It governs Customer's participation, if elected, in the Pooled Intelligence Program described in Section 12 of the Terms.

  • Consent mechanism. Participation is off by default. Customer opts in at the workspace level through the in-product legal-settings surface, by the action of an authorized administrator, or through an Order Form provision. Each opt-in and each withdrawal is recorded in an append-only, immutable consent ledger, and the latest recorded decision controls. A workspace with no recorded decision does not participate, and no outcome data from a non-participating workspace enters the Program's computations.
  • What is computed. Where Customer participates, RevenueOS computes Aggregated Statistics in the form of aggregate Bayesian posteriors / sufficient statistics: per-Messaging-Angle aggregate statistical parameters derived from participating customers' outcome data. No Prospect personal data, no verbatim Campaign Content, and no information identifying Customer or its Clients enters the published statistics, which carry no customer identifier.
  • Protections. Aggregated Statistics are computed only across cohorts comprising a minimum number of distinct participating customers, and in no event fewer than five (the k-anonymity floor); a release for a cohort below the floor carries no population signal. Calibrated statistical noise is applied to each release under central differential privacy — a centrally applied Laplace mechanism — as described in the Documentation, consistent with Section 12.2 of the Terms.
  • Withdrawal. Customer may withdraw from the Program at any time through the same in-product surface or by written notice. Withdrawal is recorded in the consent ledger and takes effect prospectively by the structure of the computation: RevenueOS ceases deriving new Aggregated Statistics from Customer's data as of the next computation cycle. Aggregated Statistics already computed are aggregate, noise-protected statistical parameters designed so that individual contributions cannot be isolated or extracted, and they may continue to be used as described in Sections 12.3 through 12.5 of the Terms.
  • Activation conditions. Cross-customer computation activates only after RevenueOS's internal data-protection gate sequence for the Program is complete, including its impact-assessment sign-off and the technical privacy-budget controls that assessment requires. Customer's consent under this Annex IV is necessary for, but not by itself sufficient to begin, pooling of Customer's data.
  • Relationship to instructions. Where Customer has opted in, the computation described in this Annex IV constitutes Customer's documented instruction under Section 3.2(d). Where Customer acts on behalf of Clients, Customer warrants that it is authorized to give this instruction with respect to the relevant Client data.

— End of Data Processing Addendum —

RevenueOS Inc. · Version 1.0 · Last updated July 8, 2026