1. Who We Are & How to Contact Us
Controller (for account, website, and marketing data):
Revvy.io
Email: support@revvy.io (Attn: Privacy)
For data subject rights under applicable laws (e.g., GDPR, CPRA, PIPEDA), see Section 11.
2. Scope of This Policy
This Policy applies to:
- Visitors to our website and those who engage with us via marketing, support, or trials.
- Users and administrators of Revvy accounts or subscriptions.
- Processing of metadata, logs, deployment artifacts, and related information (“Customer Content”) submitted to or generated via our Services.
It does not apply to third‑party websites or services we don’t control. See Section 15.
3. Key Terms
- Customer – An organization with a contract to use Revvy’s Services.
- Customer Content – Salesforce org metadata, logs, component data, commit/branch info, job results, etc.
- Personal Information (PI) – Data that can identify or relate to an individual.
- Processor / Service Provider – Revvy, when processing Customer Content on behalf of a Customer.
- Controller / Business – Revvy, when processing account, website, and marketing data.
4. What We Collect
A. Customer Content (Processor Role)
Examples: Salesforce org IDs, deployment logs, metadata, commits, pipeline configs.
Sources: Data you or your users submit or generate in Revvy.
Use: To provide and maintain the Services per Customer’s instructions.
B. Account, Website & Marketing Data (Controller Role)
- Account/Billing: Names, roles, email, login info, subscription plans.
- Support: Chat/email logs, ticket data, session call notes.
- Usage: IP, browser/OS, clicks, crash logs, page visits.
- Cookies/Trackers: Analytics and preference tools (see Section 8).
We may combine data from multiple sources to improve service quality and security.
5. How We Use Information
A. Customer Content
- Deliver, maintain, and support the Services.
- Run user‑requested actions (e.g., deployments).
- Ensure performance and security.
- Comply with Customer contracts and legal obligations.
B. Account & Marketing Data
- Set up accounts, authenticate users, process payments.
- Monitor system performance and usage.
- Communicate updates or training material.
- Comply with regulations and detect fraud.
We do not use Customer Content for marketing or unrelated profiling.
6. Legal Basis (EEA/UK/Swiss Residents)
We process data based on:
- Contractual necessity (account setup, billing).
- Legitimate interests (security, usability).
- Consent (for marketing or analytics where required).
- Legal obligation.
We process Customer Content solely on Customers’ documented instructions.
9. Security
We apply strong security measures including encryption in transit, role‑based access controls, vulnerability scanning, and incident response. While no system is 100% secure, we actively monitor and respond to potential risks.
10. Data Retention
- Customer Content: Retained based on contractual terms and customer configurations. Deleted upon request or termination (subject to backups/legal holds).
- Marketing & Account Data: Retained only as needed for legitimate business or legal purposes.
11. Your Rights
Depending on your jurisdiction, you may:
- Access, correct, delete, or port your Personal Data.
- Object to processing or withdraw consent.
- File a complaint with a relevant authority.
How to exercise your rights: Email support@revvy.io with your name, request, and verification info. If your data is within Customer Content, contact your organization’s admin. We’ll support their response.
12. International Transfers
We may process data in the U.S. or other countries. For transfers from the EEA/UK/Switzerland, we use Standard Contractual Clauses (SCCs), Data Protection Addendums (DPAs), and additional safeguards.
13. Children’s Privacy
We do not knowingly collect data from children under 13 (or under 16 in certain jurisdictions). Contact us if you believe a child has submitted data.
14. Data Processing Terms
We offer a Data Processing Agreement (DPA) to Customers, including GDPR SCCs, UK Addendum, and sub‑processor terms. Request a copy at support@revvy.io.
15. Third‑Party Links & Integrations
External links and integrations are governed by third‑party policies. We are not responsible for their privacy practices.
16. Changes to This Policy
We may update this Policy. Material changes will be communicated via the website or email. Your continued use of the Services indicates acceptance.
17. CPRA “Notice at Collection” (California Residents)
Category | Examples | Purpose | Shared With |
---|---|---|---|
Identifiers | Name, email, IP, account ID | Account setup, communication | Service Providers |
Customer Records | Billing info, tickets | Billing, support | Service Providers |
Network Activity | Pages viewed, logs, session data | Improve product, troubleshoot | Service Providers |
Geolocation (coarse) | IP‑based region | Regional settings, security | Service Providers |
Professional Info | Title, company, team | Role‑based access, admin tools | Service Providers |
Inferences (limited) | Feature usage trends | Analytics, product improvements | Service Providers |
We do not use sensitive personal data for profiling or cross‑context behavioral advertising.
18. Contact
Questions or requests about this Privacy Policy? Email support@revvy.io (Attn: Privacy).