Revidence Logo

Privacy Policy

Last Updated: August 3, 2026

REVIDENCE — PRIVACY POLICY

1. Purpose and Scope

1.1 This Privacy Policy ("Policy") describes how Revidence, LDA. ("Revidence", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data in connection with the operation of the REVIDENCE platform ("Platform").

1.2 This Policy applies to all users of the Platform, including Clients, Providers, and visitors, and to personal data processed by Revidence as a data controller. Revidence also acts as a data processor for content that Users upload or exchange relating to their own matters (for example RFP details, proposals, case documents and messages) that may contain personal data of third parties; such processing is carried out on the User's behalf and is governed by the Data Processing Addendum referred to in the Terms.

1.3 This Policy forms an integral part of the Terms & Conditions of Use ("Terms"). In the event of any conflict, the Terms shall prevail, subject always to applicable data protection law.

2. Definitions

2.1 Capitalised terms not defined in this Policy shall have the meaning assigned to them in the Terms.

2.2 For the purposes of this Policy:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
  • "GDPR" means Regulation (EU) 2016/679.
  • "Data Subject" means the individual to whom Personal Data relates.

3. Data Controller

3.1 The data controller for the purposes of the GDPR is: Revidence, LDA., Alameda dos Oceanos 41 21º 2E, Parque das Nações, 1990-207 Lisbon, Portugal.

3.2 For data protection inquiries, users may contact: privacy@revidence.com

4. Categories of Personal Data Collected

4.1 Revidence may collect and process the following categories of Personal Data:

  • Identification data (e.g. name, email address)
  • Account and organisational data (e.g. company name, role)
  • Authentication data (managed via Firebase)
  • Billing and invoicing data
  • Technical data (e.g. IP address, browser type, device information)
  • Usage and activity logs
  • Communications submitted through the Platform

4.2 Revidence does not intentionally collect special categories of personal data as defined under Article 9 GDPR.

5. Sources of Personal Data

5.1 Personal Data is collected directly from users when they:

  • create or manage an account;
  • use Platform features;
  • communicate with Revidence;
  • submit billing or payment information.

5.2 Technical data may be collected automatically through cookies and similar technologies.

6.1 Revidence processes Personal Data for the following purposes, on the legal bases indicated:

  • Account creation and management — performance of a contract (Art. 6(1)(b));
  • Platform operation, security and fraud prevention — legitimate interests (Art. 6(1)(f));
  • Billing, invoicing and collection of the Platform Fee — performance of a contract (Art. 6(1)(b)) and compliance with a legal obligation (Art. 6(1)(c));
  • Customer support and service communications — performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f));
  • Compliance with legal, accounting and tax obligations — legal obligation (Art. 6(1)(c));
  • Analytics and Platform improvement, limited to pseudonymised usage data — consent (Art. 6(1)(a)), collected via the cookie banner and withdrawable at any time;
  • Marketing communications, where applicable — consent (Art. 6(1)(a)), with opt-out.

6.2 Where processing is based on consent, users may withdraw consent at any time.

7. Data Sharing and Recipients

7.1 Revidence shares Personal Data only with recipients necessary to operate the Platform:

  • Hosting and infrastructure — Linode / Akamai (European Union, Frankfurt);
  • Authentication — Firebase / Google;
  • Analytics — Google Analytics, limited to pseudonymised usage data and subject to consent;
  • Payment processing — Stripe;
  • Email delivery — Twilio SendGrid;
  • Accounting and invoicing — Sage;
  • Professional advisers (legal, tax, accounting);
  • Competent authorities, where legally required.

7.2 Revidence does not sell Personal Data. Where Revidence self-hosts supporting software on its own infrastructure, no Personal Data is disclosed to the software vendor.

7.3 Users acknowledge that Personal Data shared directly between Clients and Providers outside the Platform's core features is processed under their own responsibility.

8. International Data Transfers

8.1 Personal Data is primarily processed and stored within the European Union.

8.2 Certain processors process Personal Data in the United States — specifically Firebase/Google, Stripe and Twilio SendGrid. Where the recipient is certified under the EU–US Data Privacy Framework, the transfer is made on the basis of the European Commission's adequacy decision for that Framework. Where it is not, or ceases to be, certified, the transfer is made under the European Commission's Standard Contractual Clauses (SCCs) in that processor's terms. Hosting (Linode/Akamai) is within the European Union. Accounting (Sage) processes primarily within the EU/EEA; where Sage transfers Personal Data outside the EEA, it does so under the Standard Contractual Clauses incorporated in its data processing agreement.

8.3 A copy of the relevant safeguards may be requested at privacy@revidence.com.

9. Data Retention

9.1 Personal Data is retained for as long as the account remains active and thereafter for as long as necessary to meet legal, accounting and tax obligations (in Portugal, generally up to 10 years for invoicing and accounting records), to resolve disputes, and to enforce agreements.

9.2 Security and audit logs are retained for a rolling period of twelve (12) months, and optional analytics data is retained for up to fourteen (14) months, after which such data is automatically deleted or permanently anonymized.

9.3 Backup and archival copies may persist for a limited additional period under our security policies.

10. Data Subject Rights

10.1 Under the GDPR, Data Subjects have the right to:

  • access their Personal Data;
  • rectify inaccurate data;
  • erase data ("right to be forgotten");
  • restrict processing;
  • data portability;
  • object to processing;
  • withdraw consent.

10.2 Requests may be submitted to privacy@revidence.com and will be addressed within thirty (30) days.

10.3 Where you exercise your right to erasure, we delete or anonymize your personal data except where we are required or entitled to retain it — in particular to comply with legal, accounting and tax obligations, and to establish, exercise or defend legal claims. In those cases we keep only the data necessary for that purpose, for the applicable retention or limitation period, after which it is deleted or anonymized.

11. Data Security

11.1 Revidence implements appropriate technical and organisational measures to protect Personal Data, including those described in the Information Security Policy set out in the Terms.

12.1 The Platform may contain links to third-party websites. Revidence is not responsible for the privacy practices of such third parties.

13. Cookies and Tracking Technologies

13.1 Revidence uses cookies and similar technologies for:

  • essential platform functionality;
  • security;
  • analytics.

13.2 Users may accept, reject or manage non-essential cookies at any time through the cookie banner.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for Platform operation, such as managing user sessions, authentication (Firebase), and security. These are loaded by default and cannot be disabled. Duration: Session or up to 24 hours.
  • Analytics Cookies: Used to understand how Users interact with the Platform (Google Analytics) to help us improve performance and user experience. These are optional and will only be placed on your device if you provide explicit consent. Duration: Up to 14 months.

14. Children's Data

14.1 The Platform is not intended for individuals under the age of 18.

14.2 Revidence does not knowingly process Personal Data of minors.

15. Amendments to this Policy

15.1 Revidence may amend this Privacy Policy from time to time.

15.2 Material changes shall be notified to users in accordance with the Terms.

16. Governing Law and Supervisory Authority

16.1 This Policy is governed by the laws of Portugal.

16.2 Data Subjects have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) or with the supervisory authority of their habitual residence within the EU.

17. Contact Information

17.1 For all privacy-related matters, users may contact — Email: privacy@revidence.com · Address: Revidence, LDA., Alameda dos Oceanos 41 21º 2E, Parque das Nações, 1990-207 Lisbon, Portugal.