RRevvoHub
← Back to RevvoHub
ENSI

Documents

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Cookie Notice
  • Security
  • Contact

On this page

  • 1. Parties and scope
  • 2. What is processed
  • 3. Instructions
  • 4. The Controller's responsibilities
  • 5. Confidentiality
  • 6. Security
  • 7. Sub-processors
  • 8. Transfers outside the EEA
  • 9. Requests from data subjects
  • 10. Assistance
  • 11. Personal data breaches
  • 12. Return and deletion
  • 13. Information and audits
  • 14. The Processor's own processing
  • 15. Liability
  • 16. Precedence and law
  • Annex 1 — Details of the processing
  • Annex 2 — Technical and organisational measures
  • Annex 3 — Sub-processors
Legal

Data Processing Agreement

How Revvo Solutions processes personal data on behalf of a workshop, as required by Article 28 of the GDPR.

In effect from 8 October 2026Version 2026-10-08

In short. Your workshop decides what customer data goes into RevvoHub and why. We store and process it only to run the service for you, keep it secure, tell you if something goes wrong, help you answer your customers' requests, and delete it when you leave.

1. Parties and scope

This Data Processing Agreement ("DPA") is part of the Terms of Service between the workshop that holds a RevvoHub account (the "Controller") and Revvo Solutions, d.o.o., Gimnazijska cesta 15D, 1420 Trbovlje, Slovenia (the "Processor").

It applies to personal data that the Processor processes on the Controller's behalf when providing RevvoHub ("Customer Personal Data"). It is concluded in electronic form when the Controller accepts the Terms of Service, and stays in force for as long as the Processor processes Customer Personal Data.

Terms such as "personal data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meaning given in Regulation (EU) 2016/679 ("GDPR").

2. What is processed

The subject matter, nature, purpose and duration of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3. Instructions

The Processor processes Customer Personal Data only on the Controller's documented instructions. The Terms of Service, this DPA and the Controller's use of the functions of RevvoHub are those instructions. Further instructions can be given in writing to privacy@revvo-hub.com; if they go beyond what the service does, the parties agree on them first.

If the Processor believes an instruction infringes the GDPR or other data protection law, it tells the Controller without delay and may hold off acting on it until the matter is clarified.

If the law of the European Union or of a Member State obliges the Processor to process Customer Personal Data in some other way, it tells the Controller before doing so, unless that law forbids it.

4. The Controller's responsibilities

The Controller:

  • makes sure it has a lawful basis for the Customer Personal Data it records, and gives its customers and staff the information the GDPR requires;
  • is responsible for the accuracy of the data and for the instructions it gives;
  • does not enter special categories of personal data (for example health data) or data about criminal convictions into RevvoHub;
  • is responsible for the settings and instructions it gives the assistant in the customer app, and for what that assistant does in its name within them;
  • keeps access to its account secure and limited to people who need it.

5. Confidentiality

Everyone the Processor authorises to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law, and has access only to what they need for their work.

6. Security

The Processor applies the technical and organisational measures described in Annex 2, taking into account the state of the art, the cost of implementation, the nature of the processing and the risks to data subjects. It may update the measures over time, provided the overall level of protection does not go down.

7. Sub-processors

  • The Controller gives general authorisation for the Processor to use sub-processors. Those in use when this DPA is concluded are listed at https://revvo-hub.com/subprocessors.
  • The Processor announces a new or replacement sub-processor at least 14 days in advance, by email to the account's address or by notice in the app, and updates the list.
  • The Controller may object within that period on reasonable data protection grounds. The parties then look for a solution in good faith. If none is found, the Controller may end the contract before the change takes effect and is refunded fees paid for the unused period.
  • The Processor binds every sub-processor by contract to data protection obligations equivalent to those in this DPA, and remains liable to the Controller for the sub-processor's performance.

8. Transfers outside the EEA

The Processor transfers Customer Personal Data outside the European Economic Area only where Chapter V of the GDPR is satisfied: on the basis of an adequacy decision, or of the European Commission's Standard Contractual Clauses together with any supplementary measures that are needed. The sub-processor list states where each sub-processor processes data and which safeguard applies.

9. Requests from data subjects

RevvoHub includes functions with which the Controller can itself find, correct, export and erase the data of an individual customer. Where the Controller cannot deal with a request using those functions, the Processor helps on request, as far as it reasonably can.

If a data subject contacts the Processor directly about Customer Personal Data, the Processor forwards the request to the Controller without delay and does not answer it itself, other than to say that it has been forwarded.

10. Assistance

Taking into account the nature of the processing and the information available to it, the Processor helps the Controller meet its obligations concerning security of processing, breach notification, data protection impact assessments and prior consultation with the supervisory authority (Articles 32 to 36 GDPR).

11. Personal data breaches

The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the account's email address and contains, as far as known at the time:

  • what happened and what kinds of data and data subjects are affected, with approximate numbers;
  • the likely consequences;
  • what has been done and what is proposed to deal with the breach and limit its effects;
  • whom to contact for more information.

Information that is not available straight away is provided as it becomes known. The Processor takes reasonable steps to contain and remedy the breach and cooperates with the Controller's own investigation and notifications.

12. Return and deletion

  • During the contract the Controller can export Customer Personal Data at any time in a structured, commonly used, machine-readable format.
  • When the Controller deletes its workshop in the app, Customer Personal Data is erased from the live system at once. The Processor keeps only its own record that the account existed and was closed, as described in the Privacy Policy.
  • When the contract ends in any other way, the Controller can export the data for 30 days, after which the Processor deletes it.
  • Copies in backups are overwritten within a further 30 days and are not used for any other purpose in the meantime.
  • The Processor may keep data longer only where the law of the European Union or of a Member State requires it, and then only for that purpose.

13. Information and audits

The Processor makes available to the Controller the information needed to show that Article 28 of the GDPR is being complied with, including a description of its security measures and the audit reports and certifications its sub-processors publish.

Where that information is not enough, the Controller may carry out an audit, itself or through an independent auditor bound by confidentiality, no more than once a year (or more often if a supervisory authority requires it or after a personal data breach), with at least 30 days' written notice, during business hours, and without disrupting the service or exposing other customers' data. Each party bears its own costs; the Processor may charge for effort beyond one working day at a reasonable rate agreed beforehand.

14. The Processor's own processing

For a limited set of data the Processor is itself a controller: the details of account holders, records of acceptance of the Terms, security and technical logs, usage counts and billing records. That processing is described in the Privacy Policy and is not covered by this DPA.

15. Liability

Liability between the parties under this DPA follows the liability clause of the Terms of Service. Nothing in this DPA limits the rights of data subjects or either party's liability towards them under Article 82 of the GDPR.

16. Precedence and law

If this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails. Where Standard Contractual Clauses apply between the parties, they prevail over both. The governing law and jurisdiction are those of the Terms of Service.

Annex 1 — Details of the processing

Subject matterProviding the RevvoHub workshop management service to the Controller.
DurationThe term of the contract, plus the export and deletion periods in section 12.
Nature and purposeHosting, storing, organising, retrieving, displaying and backing up the data the Controller enters; showing the Controller's customers their own cars and jobs in the customer app; sending content to the AI provider when a user of the Controller asks the assistant a question, or when a customer of the Controller writes to the Controller's assistant in the customer app; letting that assistant book, move and cancel appointments and pass messages on, within the settings the Controller chooses; telling the Controller and its customers by email or push notification that something is waiting for them; deleting data on instruction or at the end of the contract.
Data subjectsThe Controller's customers (private individuals, and contact persons of business customers), including those who use the customer app; the Controller's owners and staff who use the service.
Types of personal dataName; contact details (email, phone, postal address); tax number where entered; vehicle data linked to a person (registration plate, VIN, make, model, mileage); service history (work orders, reported faults, notes, labour and parts, prices); free-text notes; content typed into the AI assistant; conversations between the Controller's customers and its assistant in the customer app, and the requests and decisions that come from them.
Special categoriesNone intended. The Controller undertakes not to enter any.
FrequencyContinuous, for as long as the service is used.

Annex 2 — Technical and organisational measures

Separation of customers

  • Every record carries the identifier of the workshop it belongs to. The database itself (row-level security) refuses to read or change a row that belongs to another workshop, independently of the application code.
  • Relations between records are checked against the same workshop identifier, so a record cannot be attached to another workshop's data.
  • Automated tests that try to cross from one workshop to another are run against the database rules.

Encryption

  • All connections to the service use TLS 1.2 or later.
  • Data is encrypted at rest (AES-256) by the hosting providers, including backups.
  • Passwords are stored only as salted hashes and are never visible to the Processor's staff.

Access control

  • Users sign in with an email address and password; email addresses are verified.
  • Session cookies cannot be read by scripts in the browser and are sent only over encrypted connections.
  • Access to production systems is limited to the few people who need it, protected by multi-factor authentication, and withdrawn when no longer needed.
  • Secrets such as API keys are held only on the server and are never sent to the browser.

Application security

  • Every request is checked for a valid session on the server; input is validated on the server.
  • Security headers, including a content security policy, limit what a page may load and run.
  • Dependencies are kept up to date and security fixes are applied promptly.
  • Logs are written without the content of customer records.

AI assistant

  • Content is sent to the AI provider only when a user sends a message.
  • Vehicle context sent to the provider leaves out the registration plate, the owner and the serial part of the VIN.
  • The provider is contractually barred from using the content to train its models and deletes it within 30 days.
  • In the customer app, the assistant works only within the settings the Controller chooses and reaches only the records of the customer it is talking to at the Controller's workshop. Every action it takes is checked again by the database. Customers' names, contact details, registration plates and VINs are not sent to the provider.

Notifications

  • Notification emails say only that something is waiting and link to the app; they do not contain messages or records.
  • Push notifications are encrypted end to end (Web Push), so the browser maker's push service cannot read them.

Availability and recovery

  • The database is backed up daily; backups are encrypted and stored separately from the live system.
  • The service runs on providers with redundant infrastructure and independent security audits (such as SOC 2 Type II).

Organisation

  • Staff and contractors with access to personal data are bound by confidentiality.
  • A written procedure covers detecting, assessing, containing and reporting security incidents.
  • Sub-processors are selected for their security standing and bound by data processing agreements.
  • Data is collected and kept only to the extent the service needs it; exports and deletion are available to the Controller in the app.

Annex 3 — Sub-processors

The current list is published at https://revvo-hub.com/subprocessors and forms part of this DPA.

RRevvoHub

Revvo Solutions, d.o.o. · info@revvo-hub.com

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Cookie Notice
  • Security
  • Contact
© 2026 RevvoHub. All rights reserved.