Last Updated: August 3, 2026
This Data Processing Addendum ("DPA") forms part of the Terms & Conditions ("Agreement") between Revidence, LDA., a company incorporated under the laws of Portugal, with its registered office at Alameda dos Oceanos 41 21º 2E, Parque das Nações, 1990-207 Lisbon, Portugal, registered under sole commercial registration and corporate identification number (NIPC) 518480232 ("Revidence", "Processor"), and the customer organization that accepts the Agreement ("Customer", "Controller"). It governs Revidence's processing of Personal Data on the Customer's behalf in the course of providing the REVIDENCE platform ("Services").
Where Revidence processes Personal Data as a controller (account, billing and platform-usage data), the Privacy Policy applies instead of this DPA. This DPA applies only where Revidence acts as a processor — i.e. to Customer Content: the RFPs, proposals, case documents, messages and related materials the Customer and its users upload or exchange through the Services, which may contain Personal Data of the Customer's own clients, matter contacts and other third parties.
Terms not defined here have the meaning given in the Agreement or in Regulation (EU) 2016/679 ("GDPR"). "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject" and "Personal Data Breach" have their GDPR meanings. "Customer Personal Data" means Personal Data within Customer Content that Revidence Processes on the Customer's behalf.
2.1 For Customer Personal Data, the Customer is the Controller and Revidence is the Processor. Where the Customer is itself a processor for a third party, Revidence acts as a sub-processor and the Customer warrants it has the authority to engage Revidence. 2.2 Revidence Processes Customer Personal Data only to provide the Services and only as set out in this DPA and the Agreement.
3.1 Revidence Processes Customer Personal Data only on the Customer's documented instructions, including as to international transfers, unless required by EU or Member State law (in which case Revidence informs the Customer first, unless the law prohibits it on public-interest grounds). 3.2 The Agreement, this DPA and the Customer's use/configuration of the Services constitute the Customer's complete documented instructions. Additional or different instructions must be agreed in writing. 3.3 Revidence informs the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law.
Revidence ensures that persons authorised to Process Customer Personal Data are bound by confidentiality obligations and Process it only as necessary to provide the Services.
Revidence implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. Revidence may update these measures provided the level of protection is not materially reduced.
6.1 The Customer grants general authorisation for Revidence to engage the Sub-processors listed in Annex III to Process Customer Personal Data. 6.2 Revidence imposes on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains liable for its Sub-processors' performance. 6.3 Revidence will give the Customer prior notice of any intended addition or replacement of a Sub-processor (by updating Annex III and/or notifying the Customer). The Customer may object on reasonable data-protection grounds within fifteen (15) days; the parties will work in good faith to resolve the objection, failing which the Customer may terminate the affected Services. 6.4 Software that Revidence self-hosts on its own infrastructure (e.g. its chat/notification service, search index and CRM) is not a Sub-processor, as no Personal Data is disclosed to a third party; such Processing occurs on the infrastructure listed in Annex III.
7.1 Taking into account the nature of the Processing, Revidence assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). 7.2 The Services allow the Customer and its users to access and correct Customer Content directly, to export the account data held for each user, and to remove or close individual items through the deletion features described in §10.2. Where responding to a request requires action beyond those features — including an export scoped to the Customer's organisation as a whole — Revidence provides reasonable assistance on the Customer's documented instruction. Where a Data Subject contacts Revidence about Customer Content, Revidence refers them to the Customer and does not respond substantively except on the Customer's instruction.
Revidence assists the Customer, taking into account the nature of Processing and information available to it, in ensuring compliance with security obligations, Personal Data Breach notification, data-protection impact assessments and prior consultation with supervisory authorities.
Revidence notifies the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides information reasonably available to it to help the Customer meet its own notification obligations.
10.1 On termination of the Services, and on the Customer's documented instruction, Revidence returns or deletes Customer Personal Data using the mechanisms described in §10.2, and provides reasonable assistance to give effect to that instruction, unless EU or Member State law requires continued storage. 10.2 The Customer acknowledges that the Services persist data by default (content is retained and referenced rather than routinely deleted). Deletion of specific Customer Personal Data occurs on the Customer's instruction or via the deletion features of the Services. Backup and archival copies are overwritten on the ordinary backup cycle.
11.1 Revidence makes available to the Customer information reasonably necessary to demonstrate compliance with Art. 28 (including this DPA, the Privacy Policy, the Information Security Policy and, where available, third-party reports/certifications). 11.2 The Customer may audit compliance no more than once per year (and after a Personal Data Breach) on reasonable prior written notice, during business hours, without unreasonable disruption, subject to confidentiality; a recent independent audit/certification report may be provided in satisfaction of an audit request.
12.1 Revidence primarily Processes Customer Personal Data within the EU/EEA. 12.2 Where a Sub-processor Processes Customer Personal Data outside the EEA (see Annex III), Revidence ensures an appropriate transfer mechanism under Chapter V GDPR applies. For Sub-processors in the United States, transfers are made on the basis of the European Commission's adequacy decision for the EU–US Data Privacy Framework where the Sub-processor is certified under that Framework; where it is not, or ceases to be, the European Commission's Standard Contractual Clauses (SCCs) in that Sub-processor's terms apply instead.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
This DPA takes effect when the Customer accepts the Agreement and continues while Revidence Processes Customer Personal Data. Clauses that by their nature should survive termination (including 10 and 11) survive.
This DPA is governed by the laws of Portugal and is subject to the dispute-resolution and jurisdiction provisions of the Agreement. In case of conflict between this DPA and the Agreement regarding Processing of Customer Personal Data, this DPA prevails.
This DPA is incorporated into the Agreement by Terms & Conditions §13.7 and applies to the Customer on acceptance of the Agreement. No signature is required for it to take effect. A countersigned copy of this DPA, in the form published here, is available to any Customer on request at privacy@revidence.com. The version published at revidence.com/policies/data-processing-addendum is the operative document; any copy supplied in another format (including PDF) is a convenience copy of that version, and the published version prevails in case of difference.
| Item | Detail |
|---|---|
| Subject matter | Provision of the REVIDENCE IP-procurement platform to the Customer |
| Duration | For the term of the Agreement and until deletion/return under §10 |
| Nature & purpose | Hosting, storage, transmission, display and management of Customer Content to operate RFPs, proposals, cases, messaging and related workflows |
| Types of Personal Data | Identification and contact data, professional/organisational data, and any Personal Data the Customer chooses to include in RFPs, proposals, case documents, files and messages |
| Categories of Data Subjects | The Customer's personnel and users; the Customer's clients and matter contacts; counterparties and other individuals referenced in Customer Content |
| Special categories | Not intended; the Customer must not upload Art. 9 data except as strictly necessary and lawful |
As set out in the Revidence Information Security Policy (Terms & Conditions §14), a copy of which is available to the Customer on request under §11.1, including, without limitation:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Linode / Akamai | Hosting & infrastructure | EU (Frankfurt) | — (EU) |
| Google / Firebase | Authentication | US | EU–US Data Privacy Framework (adequacy); SCCs in the processor's terms as fallback |
| Twilio SendGrid | Transactional email | US | EU–US Data Privacy Framework (adequacy) where certified; otherwise SCCs in the processor's terms |
Self-hosted on Revidence infrastructure (not Sub-processors): chat/notification service, search index, CRM. Stripe (payments), Sage (accounting) and Google Analytics relate to Revidence's controller-role Processing and are addressed in the Privacy Policy.