Data Processing Addendum
The data-processing responsibilities, service providers, security measures, overseas handling, incident support, and deletion arrangements that apply to customer personal information.
Last updated 31 Aug 2026
Scope and roles
In this Addendum, "Revo" means the partnership B.J GAY & D.A KENNELLY (ABN 50 967 858 509).
This Data Processing Addendum applies when a signed customer agreement incorporates it and Revo processes personal information for the customer in providing the service.
The customer determines why and how its tenant information is used and is the controller or equivalent responsible party. Revo acts as its processor or service provider for that information. Revo may separately act as a controller for account administration, billing, security, fraud prevention, legal compliance, and its own business records.
Processing details
The subject matter is the operation and support of Revo for the term of the customer agreement and any limited retention period required after it ends. Processing includes collecting, importing, organising, storing, retrieving, displaying, generating, transforming, transmitting, securing, supporting, exporting, and deleting information.
The purpose is to provide identity and tenant administration, CRM sync, campaign and artwork workflows, AI-assisted features, supplier ordering, delivery, billing, analytics, security, and support.
People may include customer personnel, agents, office and network administrators, property vendors, contacts associated with listings and campaigns, suppliers, delivery recipients, and support contacts. Information may include identity and business contact data, account roles, listing and property data, campaign contacts, images, content, artwork, order and delivery details, billing references, support records, and technical activity data.
Documented instructions
Revo will process customer personal information only to provide the contracted service, follow the customer's documented configuration and lawful instructions, protect the service, or comply with law. The customer agreement, this Addendum, authorised user actions, and written support requests form the documented instructions.
The customer is responsible for the lawfulness, accuracy, and scope of its instructions and for giving notices and obtaining permissions required for the information it supplies.
Security and confidentiality
Revo uses role and tenant access controls, network-scoped storage, managed encryption, restricted service credentials, audit records, supplier callback verification, monitoring, and controlled administrative access appropriate to the platform and the risks of processing.
People authorised to handle customer personal information must do so only as needed for their role and under confidentiality obligations. Revo reviews access and can revoke it when it is no longer required.
Service providers and subprocessors
Revo uses Vercel for application hosting, Supabase for database, authentication, and storage, Inngest for workflow orchestration, Resend for email, Anthropic for AI features, Stripe for billing and marketplace payments, Google Analytics for pageview analytics, and Sentry when error monitoring is configured.
Google Analytics pageview data may include browser and device metadata, pseudonymous identifiers, and cookie or session information in addition to page URLs, titles, and referrers.
Each provider receives the categories of information involved in its configured function. Stripe and Google may also process some information as independent controllers under their own terms.
Revo remains contractually responsible for the performance of processing obligations it delegates to a subprocessor, without limiting either party's statutory obligations. The signed customer agreement sets out any notice and objection process for a material new subprocessor.
Data location and overseas processing
Revo's primary Supabase database, authentication service, object storage, and Vercel application runtime are configured in Sydney, Australia.
Outside Australia, the main disclosed processing location is the United States. Google and Stripe also use global infrastructure and may process information in other countries described in their privacy notices, so email, workflow, AI, payment, analytics, monitoring, support, and service control information may be processed or accessed overseas. Australian primary hosting is not a promise that every processing activity stays in Australia.
Data incidents and customer assistance
Revo will notify the customer without undue delay after becoming aware of a security incident reasonably likely to affect customer personal information, provide the information then available, and update the customer as relevant facts are confirmed. This does not limit either party's own obligations under the Notifiable Data Breaches scheme.
Taking account of the nature of processing, Revo will provide reasonable assistance with verified access, correction, deletion, portability, privacy assessment, regulator, and data-breach requests. Additional work outside normal support may be subject to the customer agreement.
Assurance, audits, and government requests
On reasonable request, Revo will provide information available to demonstrate its compliance with this Addendum. Any audit must protect other customers, avoid security risk and service disruption, and follow the notice, confidentiality, scope, and cost terms in the customer agreement.
If Revo receives a legally binding request for customer personal information, it will notify the customer where legally permitted and will disclose only what it is legally required to provide.
Return, retention, and deletion
During the agreement, authorised users may export information through available product features. On termination or a verified written instruction, Revo will return or delete customer personal information as described in the customer agreement.
Revo may retain limited information where required by law, for billing and audit records, to establish or defend legal claims, or in protected backups until they expire through the normal backup cycle. Retained information remains protected and is not used for another purpose.