Last Updated: August 3, 2026
1.1 This Privacy Policy ("Policy") describes how Revidence, LDA. ("Revidence", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data in connection with the operation of the REVIDENCE platform ("Platform").
1.2 This Policy applies to all users of the Platform, including Clients, Providers, and visitors, and to personal data processed by Revidence as a data controller. Revidence also acts as a data processor for content that Users upload or exchange relating to their own matters (for example RFP details, proposals, case documents and messages) that may contain personal data of third parties; such processing is carried out on the User's behalf and is governed by the Data Processing Addendum referred to in the Terms.
1.3 This Policy forms an integral part of the Terms & Conditions of Use ("Terms"). In the event of any conflict, the Terms shall prevail, subject always to applicable data protection law.
2.1 Capitalised terms not defined in this Policy shall have the meaning assigned to them in the Terms.
2.2 For the purposes of this Policy:
3.1 The data controller for the purposes of the GDPR is: Revidence, LDA., Alameda dos Oceanos 41 21º 2E, Parque das Nações, 1990-207 Lisbon, Portugal.
3.2 For data protection inquiries, users may contact: privacy@revidence.com
4.1 Revidence may collect and process the following categories of Personal Data:
4.2 Revidence does not intentionally collect special categories of personal data as defined under Article 9 GDPR.
5.1 Personal Data is collected directly from users when they:
5.2 Technical data may be collected automatically through cookies and similar technologies.
6.1 Revidence processes Personal Data for the following purposes, on the legal bases indicated:
6.2 Where processing is based on consent, users may withdraw consent at any time.
7.1 Revidence shares Personal Data only with recipients necessary to operate the Platform:
7.2 Revidence does not sell Personal Data. Where Revidence self-hosts supporting software on its own infrastructure, no Personal Data is disclosed to the software vendor.
7.3 Users acknowledge that Personal Data shared directly between Clients and Providers outside the Platform's core features is processed under their own responsibility.
8.1 Personal Data is primarily processed and stored within the European Union.
8.2 Certain processors process Personal Data in the United States — specifically Firebase/Google, Stripe and Twilio SendGrid. Where the recipient is certified under the EU–US Data Privacy Framework, the transfer is made on the basis of the European Commission's adequacy decision for that Framework. Where it is not, or ceases to be, certified, the transfer is made under the European Commission's Standard Contractual Clauses (SCCs) in that processor's terms. Hosting (Linode/Akamai) is within the European Union. Accounting (Sage) processes primarily within the EU/EEA; where Sage transfers Personal Data outside the EEA, it does so under the Standard Contractual Clauses incorporated in its data processing agreement.
8.3 A copy of the relevant safeguards may be requested at privacy@revidence.com.
9.1 Personal Data is retained for as long as the account remains active and thereafter for as long as necessary to meet legal, accounting and tax obligations (in Portugal, generally up to 10 years for invoicing and accounting records), to resolve disputes, and to enforce agreements.
9.2 Security and audit logs are retained for a rolling period of twelve (12) months, and optional analytics data is retained for up to fourteen (14) months, after which such data is automatically deleted or permanently anonymized.
9.3 Backup and archival copies may persist for a limited additional period under our security policies.
10.1 Under the GDPR, Data Subjects have the right to:
10.2 Requests may be submitted to privacy@revidence.com and will be addressed within thirty (30) days.
10.3 Where you exercise your right to erasure, we delete or anonymize your personal data except where we are required or entitled to retain it — in particular to comply with legal, accounting and tax obligations, and to establish, exercise or defend legal claims. In those cases we keep only the data necessary for that purpose, for the applicable retention or limitation period, after which it is deleted or anonymized.
11.1 Revidence implements appropriate technical and organisational measures to protect Personal Data, including those described in the Information Security Policy set out in the Terms.
12.1 The Platform may contain links to third-party websites. Revidence is not responsible for the privacy practices of such third parties.
13.1 Revidence uses cookies and similar technologies for:
13.2 Users may accept, reject or manage non-essential cookies at any time through the cookie banner.
We use the following categories of cookies:
14.1 The Platform is not intended for individuals under the age of 18.
14.2 Revidence does not knowingly process Personal Data of minors.
15.1 Revidence may amend this Privacy Policy from time to time.
15.2 Material changes shall be notified to users in accordance with the Terms.
16.1 This Policy is governed by the laws of Portugal.
16.2 Data Subjects have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) or with the supervisory authority of their habitual residence within the EU.
17.1 For all privacy-related matters, users may contact — Email: privacy@revidence.com · Address: Revidence, LDA., Alameda dos Oceanos 41 21º 2E, Parque das Nações, 1990-207 Lisbon, Portugal.