Legal
Effective Date: June 13, 2026 — Last Updated: June 13, 2026
Our standard DPA template for GDPR and CCPA compliance. Premium customers may negotiate custom terms.
Need a Signed DPA?
The full agreement terms are below. For a countersigned copy, contact our legal team.
"Data Controller" means the Revyr Labs customer (the entity or individual using the Services). "Data Processor" means Revyr Labs, a sole proprietorship. "Data Subject" means the individual to whom Personal Data relates. "Personal Data" has the meaning defined in GDPR and other applicable Data Protection Laws. "Data Protection Laws" means the GDPR, CCPA, and any other data protection or privacy legislation applicable to the processing of Personal Data under this DPA.
Revyr Labs acts as a Data Processor and processes Personal Data only on behalf of and in accordance with the Data Controller's documented instructions. Revyr Labs will not process Personal Data for any other purpose, including its own commercial purposes, unless required by applicable law.
The Data Processor shall process Personal Data solely to provide the Ferqon Server and related services described in the agreement between the parties. Processing shall be limited to what is necessary for these purposes and for compliance with applicable law.
The Data Processor shall: (a) process Personal Data in accordance with Data Protection Laws; (b) implement appropriate technical and organizational measures to protect Personal Data; (c) assist the Data Controller in responding to data subject requests; (d) notify the Data Controller of any personal data breach without undue delay and in any case within 72 hours of becoming aware; (e) ensure persons authorized to process Personal Data are subject to confidentiality obligations.
The Data Processor may engage subprocessors to process Personal Data on the Data Controller's behalf, provided that the Data Processor maintains an up-to-date list at /legal/subprocessors and gives the Data Controller an opportunity to object to new subprocessors before they are engaged. The Data Processor shall remain fully liable to the Data Controller for the acts and omissions of any subprocessor.
The Data Processor shall assist the Data Controller in fulfilling its obligations to respond to data subject requests, including requests for access, rectification, erasure, restriction of processing, data portability, and objection to processing.
The Data Processor shall maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. Such measures include encryption of data at rest and in transit, access controls, regular security assessments, and incident response procedures.
The Data Processor may transfer Personal Data to countries outside the EEA, UK, or Switzerland only if such transfers are adequately protected under Data Protection Laws, including through the use of Standard Contractual Clauses (SCCs) approved by the European Commission or an equivalent lawful transfer mechanism.
The Data Controller may audit the Data Processor's compliance with this DPA upon reasonable notice and during business hours. The Data Processor shall cooperate with such audits and provide reasonable access to relevant information, including applicable security certifications and audit reports, subject to confidentiality obligations.
Upon termination of the agreement, the Data Processor shall return or securely delete all Personal Data in its possession, except where retention is required by applicable law. The Data Processor shall certify destruction in writing upon the Data Controller's request.
This DPA shall remain in effect for the duration of the agreement between the parties and thereafter until all Personal Data has been returned or deleted in accordance with Section 10. Sections that by their nature should survive termination shall survive.
Premium Customization
Premium customers may negotiate custom DPA terms. Contact your account manager or email legal@revyrlabs.com to discuss your requirements.
List of third-party services we use to operate Revyr Labs.
View subprocessors →Complete privacy and data handling details.
View privacy policy →