Effective: 2026.02.01
This DPA supplements the Terms of Service between RevOS
("Processor") and the Tenant ("Controller") and covers the
processing of Personal Data as defined by GDPR, DPDPA 2023, and CCPA.
1. Roles
Tenant is the Controller. RevOS acts as Processor on the
Controller's documented instructions.
2. Processing Details
3. Sub-processors
Controller consents to the sub-processors listed at
/trust/doc/sub-processors. RevOS
will give 30 days' notice of changes; Controller may object in writing.
4. Security Measures
See /trust/doc/information-security.
5. Data Subject Rights
RevOS provides in-app self-service (export / delete / rectify)
and commits to assisting Controller with DSARs within 10 business days.
6. Breach Notification
RevOS will notify Controller without undue delay and within 48
hours of confirming a Personal Data Breach.
7. International Transfers
Production data remains in India · Mumbai. Where sub-processors
process data outside India, transfers rely on Standard Contractual
Clauses (EU 2021/914) and equivalent DPDPA safeguards.
8. Audit Rights
Controller may audit RevOS's compliance annually, at Controller
expense, on 30 days' notice. RevOS will share its latest SOC 2
and ISO 27001 reports under NDA in lieu of on-site audits.
9. Deletion & Return
On termination, Tenant data is returned in a machine-readable format on
request and deleted from live systems within 30 days, from backups
within 90 days.
10. Governing Law
India. Jurisdiction: India (Courts of Mumbai, Maharashtra).
Signatories
Controller: Tenant signatory as recorded in legal_acceptances
(captured via web acceptance at signup).
Processor: RevOS · DPO: founding@revos.co.in
The incorporated legal entity named as Processor is disclosed on the signed Master Services Agreement.
