REVIME DATA PROCESSING AGREEMENT
Last updated: 16.09.2026
This Data Processing Agreement ("DPA") forms part of the Revime Terms of Service or another written agreement between the parties governing the use of Revime (the "Agreement").
This DPA applies where Vitalij Borysovyč Ševerov, OSVČ, trading as Revime ("Revime", "Processor", "we", "us", or "our") processes personal data on behalf of a client business using the Services ("Client", "Controller", or "you").
Processor:
Vitalij Borysovyč Ševerov, OSVČ, trading as Revime
IČO: 21853193
Registered address: Komenského 1058/39, 323 00 Plzeň - Bolevec, Czech Republic
Privacy contact: privacy@revime.app
Legal contact: legal@revime.app
Controller:
The business, sole proprietor, legal entity, or other person acting in a business capacity that has accepted the Revime Terms of Service or otherwise uses the Services as a client.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given to them in Regulation (EU) 2016/679 (GDPR).
"Client Customer" means an individual customer, recipient, or contact of the Controller whose personal data is processed through the Services.
"Services" means Revime, including revime.app, related dashboards, public token-protected customer pages, communication workflows, reminder scheduling, consent management, and related integrations.
"Subprocessor" means any third party engaged by Revime to process personal data on behalf of the Controller.
2. Roles of the Parties
For Client Customer data processed through the Services, the Client is the Controller and Revime is the Processor.
The Client determines the purposes and lawful basis of processing, including whether and how Client Customers should receive reminders or communications.
Revime processes personal data only to provide the Services, to follow documented instructions from the Client, and as otherwise permitted by this DPA or required by law.
3. Subject Matter and Duration
The subject matter of processing is the provision of the Services, including customer reminder management, automated message scheduling, communication delivery, consent and opt-out management, token-protected customer preference pages, support, security, and related operational processing.
The duration of processing is the duration of the Agreement, plus any period necessary for deletion, return, retention of compliance records, backup deletion cycles, or legal obligations.
4. Nature and Purpose of Processing
Revime processes personal data to:
- import, store, and manage Client Customer data, including data imported from a Google Sheet the Controller connects;
- identify relevant reminder dates;
- create and maintain reminder schedules and a review queue;
- apply communication rules, frequency limits, consent checks, opt-out suppression, and preferred-channel logic;
- send reminders via SMS, WhatsApp, and Telegram when the Controller enables automated sending, or otherwise facilitate client-initiated sending;
- store Instagram and Viber identifiers where provided, so the Controller can open a client-initiated conversation;
- provide public token-protected pages for Client Customers to manage dates, consent, opt-out, and preferred channels;
- maintain consent, opt-out, delivery, and compliance logs;
- provide support, troubleshooting, security, and auditability;
- comply with applicable law and documented instructions.
5. Categories of Personal Data
The personal data processed may include:
- Client Customer name;
- mobile phone number;
- Telegram identifier, Instagram handle, Viber identifier, or other channel-specific messaging identifier where applicable;
- important dates such as birthdays, anniversaries, holidays, or other reminder dates;
- purchase-related information or preference information provided by the Client, including data imported from a connected Google Sheet;
- preferred communication channel;
- opt-in, opt-out, and consent status;
- consent timestamps and withdrawal timestamps, together with IP address and user-agent captured when consent is given or withdrawn;
- reminder schedules;
- message content generated or configured for reminder purposes;
- message delivery status and technical delivery metadata;
- communication history and related operational logs;
- updates made by Client Customers through token-protected public pages;
- security logs, audit logs, and technical metadata necessary to provide and protect the Services.
6. Categories of Data Subjects
The data subjects are Client Customers, including individuals who purchased from, contacted, or otherwise provided their details to the Controller in connection with the Controller’s flower shop, salon, retail, or similar business.
7. Controller Responsibilities
The Controller is responsible for:
- ensuring that personal data is collected lawfully;
- determining and documenting an appropriate lawful basis for processing and communications;
- providing privacy notices to Client Customers;
- ensuring that communications sent through the Services comply with applicable privacy, electronic communications, marketing, telecommunications, consumer protection, and anti-spam laws;
- ensuring that Client Customer data uploaded to the Services is accurate and appropriate;
- responding to Client Customer requests unless handled by Revime on documented instruction;
- ensuring that no prohibited or special-category data is uploaded unless expressly agreed in writing.
Revime does not provide legal advice and does not determine whether any specific message or campaign is lawful for the Controller.
8. Processor Obligations
Revime shall:
- process personal data only on documented instructions from the Controller, including this DPA, the Agreement, product configuration, and use of the Services;
- ensure that persons authorized to process personal data are subject to confidentiality obligations;
- implement appropriate technical and organizational measures under Article 32 GDPR;
- assist the Controller with data subject requests, security obligations, breach notifications, data protection impact assessments, and prior consultations where applicable and reasonably possible;
- delete or return personal data at the end of the Services as described in this DPA;
- make available information reasonably necessary to demonstrate compliance with Article 28 GDPR;
- inform the Controller if, in Revime’s opinion, an instruction infringes GDPR or other applicable EU or Member State data protection law.
9. Documented Instructions
The Controller instructs Revime to process personal data as necessary to provide the Services, including import from a Google Sheet the Controller connects, reminder scheduling, consent management, customer preference pages, and message delivery.
Revime may refuse or suspend processing where it reasonably believes an instruction violates applicable law, third-party provider terms, platform policies, security requirements, or this DPA.
10. Security Measures
Revime shall implement appropriate technical and organizational measures, which may include:
- encryption in transit using TLS;
- access controls and least-privilege access;
- authentication controls;
- separation of client data where technically appropriate;
- logging and monitoring;
- secure hosting and database infrastructure;
- backup and recovery measures;
- administrative controls for access to production data;
- confidentiality obligations for persons with access to personal data;
- periodic review of security practices.
11. Subprocessors
The Controller grants Revime general authorization to engage Subprocessors to provide the Services.
Revime shall impose data protection obligations on Subprocessors that are materially equivalent to those in this DPA. Revime remains responsible to the Controller for the performance of Subprocessors’ data protection obligations.
Current Subprocessors and service providers may include:
Cloudflare, Inc. — DNS, CDN, security, traffic routing, and email forwarding — United States / global — SCCs or other lawful transfer mechanism where applicable.
Vercel Inc. — application hosting and deployment — United States / EU — SCCs or other lawful transfer mechanism where applicable.
Supabase Inc. — database hosting, storage, and authentication — Germany / EU infrastructure, provider incorporated in the United States — SCCs or other lawful transfer mechanism where applicable.
Google Cloud / Google LLC — cloud infrastructure and compute — Germany / EU infrastructure, provider incorporated in the United States — SCCs or other lawful transfer mechanism where applicable.
Google LLC (Google Sheets API) — read-only import of Client Customer and order data from a spreadsheet the Controller connects — United States / global — SCCs or other lawful transfer mechanism where applicable.
Twilio Inc. — SMS and WhatsApp message delivery — United States / global communications infrastructure — SCCs or other lawful transfer mechanism where applicable.
Telegram Messenger Inc. — Telegram bot message delivery — global communications infrastructure — SCCs or other lawful transfer mechanism where applicable.
Sentry, Inc. — application monitoring, error tracking, diagnostics, troubleshooting, and incident investigation — United States / global infrastructure — SCCs or other lawful transfer mechanism where applicable.
Revime may update the Subprocessor list from time to time. Where required, Revime will provide reasonable notice of material changes by email, in-product notice, or publication on its website.
If the Controller objects to a new Subprocessor on reasonable data protection grounds, the parties will attempt to resolve the objection in good faith. If no reasonable resolution is available, the Controller may stop using the affected Services.
12. International Transfers
Where personal data is transferred outside the European Economic Area to a country that is not subject to an adequacy decision, Revime shall ensure that the transfer is protected by appropriate safeguards, such as Standard Contractual Clauses, adequacy decisions, data processing terms, or another lawful transfer mechanism.
Where required, the relevant Standard Contractual Clauses are incorporated by reference and apply to the transfer. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail for the affected transfer.
13. Data Subject Requests
Taking into account the nature of the processing, Revime shall assist the Controller, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under GDPR.
If Revime receives a request directly from a Client Customer relating to data processed on behalf of the Controller, Revime may:
- forward the request to the Controller;
- instruct the data subject to contact the Controller;
- respond where authorized by the Controller or where required by law.
Revime will not independently decide how to respond to Client Customer rights requests where it acts as Processor, unless required by law.
14. Personal Data Breach
Revime shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller.
The notification shall include, where available:
- the nature of the breach;
- categories and approximate number of affected data subjects and records;
- likely consequences;
- measures taken or proposed to address the breach;
- contact point for follow-up.
Revime shall reasonably cooperate with the Controller in investigating, mitigating, and documenting the breach.
15. Return and Deletion
Upon termination or expiry of the Agreement, or upon documented request, Revime shall delete or return personal data processed on behalf of the Controller, unless retention is required by law or necessary for compliance records, dispute prevention, security, or legitimate legal protection.
Customer records are deleted within 30 days after a valid deletion request or account deletion instruction, unless retention is required by law or necessary for compliance records. Salon account deletion is currently requested by emailing hello@revime.app.
Consent records, unsubscribe records, delivery logs, and related compliance records (including IP address and user-agent captured at consent or withdrawal) may be retained for up to 3 years.
Routine page-visit IP addresses and ordinary technical logs that are not stored as consent evidence may be retained for up to 30 days, unless needed for security or incident investigation.
Security logs and audit logs may be retained for up to 3 years or as reasonably necessary for security, fraud prevention, and legal protection.
Backups may persist for a limited period before automatic deletion according to backup cycles.
16. Audit Rights
Revime shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR.
The Controller may request an audit no more than once per year, unless a personal data breach or material compliance concern justifies additional review. Audits must be subject to reasonable prior notice, confidentiality obligations, normal business hours, and a scope that does not unreasonably disrupt Revime’s operations or compromise the security or confidentiality of other clients.
Where appropriate, Revime may satisfy audit obligations by providing documentation, security summaries, Subprocessor information, or third-party certifications instead of allowing on-site inspection.
17. Assistance with DPIAs and Prior Consultation
Revime shall reasonably assist the Controller with data protection impact assessments and prior consultation with supervisory authorities where required under Articles 35 and 36 GDPR, taking into account the nature of processing and information available to Revime.
18. Special-Category Data and Children’s Data
The Controller must not upload or process through the Services special-category data, criminal records, or data relating to children under 16 unless Revime expressly agrees in writing.
This includes health data, biometric data, political opinions, religious beliefs, sexual orientation data, and criminal-offence data.
19. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where such limitations or exclusions are prohibited by applicable law.
20. Order of Precedence
In case of conflict:
- Standard Contractual Clauses prevail for international transfers;
- this DPA prevails over the Agreement regarding processing of personal data on behalf of the Controller;
- the Agreement governs all other matters.
21. Governing Law and Jurisdiction
This DPA is governed by the laws of the Czech Republic, unless mandatory data protection law provides otherwise.
The courts of Prague, Czech Republic, will have jurisdiction over disputes arising out of or relating to this DPA, except where mandatory law provides otherwise.
22. Contact
For data protection matters, contact:
Vitalij Borysovyč Ševerov, OSVČ, trading as Revime
IČO: 21853193
Komenského 1058/39, 323 00 Plzeň - Bolevec, Czech Republic
Email: privacy@revime.app