Data Processing Addendum
Effective Date: May 6, 2026 Last Updated: August 5, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service or other written agreement (the "Agreement") between Reverge LLC ("Reverge," "we," "us," or "our") and the customer identified in the Agreement ("Customer," "you," or "your") and governs the processing of Personal Information by Reverge in connection with providing the Services.
This DPA is designed for business-to-business customers operating in the United States. It does not address GDPR, UK GDPR, or other non-US data-protection laws, and Reverge does not market the Services to customers subject to those laws.
If there is a conflict between this DPA and the Agreement, this DPA controls as to the subject matter of this DPA.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement or in applicable US state privacy laws (defined below). The following definitions apply:
- "Applicable Privacy Laws" means US state privacy laws applicable to Customer's processing of Personal Information, including the California Consumer Privacy Act / California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.) ("CCPA"), the Virginia Consumer Data Protection Act (Va. Code § 59.1-575 et seq.), the Colorado Privacy Act (Colo. Rev. Stat. § 6-1-1301 et seq.), the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and similar US state laws as enacted and amended.
- "Customer Personal Information" means Personal Information that Reverge processes on Customer's behalf in providing the Services.
- "Personal Information" has the meaning given in the CCPA and includes equivalent terms ("personal data," "personally identifiable information") under other Applicable Privacy Laws.
- "Process" / "Processing" means any operation performed on Personal Information, such as collecting, recording, organizing, storing, using, disclosing, transmitting, or deleting.
- "Sub-processor" means any third party engaged by Reverge to Process Customer Personal Information.
- "Security Incident" means a confirmed unauthorized acquisition, access, use, or disclosure of Customer Personal Information processed by Reverge.
The terms "Business," "Service Provider," "Sale," "Share," "Consumer," "Sensitive Personal Information," and "Contractor" have the meanings given in the CCPA. The terms "Controller" and "Processor" have the meanings given in other Applicable Privacy Laws and are treated as equivalents to "Business" and "Service Provider" for purposes of this DPA.
2. Roles of the Parties
For Customer Personal Information processed under the Agreement:
- Customer is the "Business" (or "Controller") and determines the purposes and means of Processing.
- Reverge is the "Service Provider" (or "Processor") and Processes Customer Personal Information solely on Customer's behalf and in accordance with Customer's documented instructions.
The Agreement (including the Services Customer has selected, the configuration choices Customer makes in the Platform, and any written instructions Customer gives Reverge) constitutes Customer's documented instructions for Processing.
3. Scope and Purpose of Processing
3.1 Subject Matter
Reverge Processes Customer Personal Information solely to provide, operate, secure, support, and improve the Services for Customer, and as otherwise permitted under this DPA.
3.2 Categories of Data Subjects
Customer Personal Information may relate to:
- Customer's employees, contractors, and authorized users.
- Customer's customers, leads, prospects, and contacts.
- Individuals whose information appears in Customer Data, content, or connected third-party services Customer authorizes.
3.3 Categories of Personal Information
Depending on Customer's use of the Services, Customer Personal Information may include:
- Identifiers (name, email, phone, account credentials, IP address, online identifiers).
- Commercial information (purchase history, products of interest, transaction records).
- Internet/network activity (interactions with content, email engagement, ad performance).
- Geolocation (general business location, region).
- Professional/employment information (job titles, company affiliation).
- Inferences drawn from the foregoing (audience segments, persona attributes).
Customer agrees not to upload to the Services: Sensitive Personal Information (as defined under CCPA), government-issued identifiers, full payment card numbers (outside our Stripe payment flow), protected health information subject to HIPAA, financial account numbers, biometric data, geolocation data sufficient to identify a specific natural person's precise location, or content of children under 13. The Services are not designed or warranted to handle these categories.
3.4 Duration
Processing continues for the term of the Agreement and any post-termination retention period described in the Privacy Policy or this DPA.
4. Reverge Obligations as Service Provider
Reverge will:
4.1 Process Only on Documented Instructions
Process Customer Personal Information only as needed to provide the Services, as instructed by Customer through the Agreement and Platform configuration, or as required by applicable law (in which case Reverge will, where legally permitted, notify Customer before processing).
4.2 No Sale or Share
Not Sell or Share Customer Personal Information as those terms are defined under the CCPA, and not Process Customer Personal Information for cross-context behavioral advertising.
4.3 No Combining or Independent Use
Not retain, use, or disclose Customer Personal Information:
- For any purpose other than the specific purpose of providing the Services, including not for any commercial purpose other than providing the Services to Customer.
- Outside the direct business relationship between Reverge and Customer.
- To Process Customer Personal Information in combination with Personal Information received from another source, except as permitted under CCPA Regulations (e.g., to detect security incidents or perform services on behalf of multiple businesses where each is the source of the same data).
4.4 Confidentiality
Ensure that personnel authorized to Process Customer Personal Information are bound by confidentiality obligations.
4.5 Security
Implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect Customer Personal Information from Security Incidents, as further described in Annex B.
4.6 Assistance with Consumer Rights
Provide reasonable assistance to Customer in responding to verified consumer requests under Applicable Privacy Laws (access, correction, deletion, portability, opt-out of Sale/Share, limit use of Sensitive Personal Information). Customer is responsible for verifying consumer identity and determining whether to honor a request. Where Customer's requested assistance exceeds the self-service tools and standard features Reverge makes generally available, Reverge may charge reasonable fees for additional work.
4.7 Assistance with Compliance
Provide reasonable cooperation, on Customer's request, with Customer's reasonable efforts to comply with Applicable Privacy Laws, including assistance with privacy impact assessments where required. Reverge may charge reasonable fees for assistance that exceeds documentation it makes generally available.
4.8 Notification of Inability to Comply
Notify Customer if Reverge determines that it can no longer meet its obligations under Applicable Privacy Laws or this DPA. On such notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Information.
4.9 Right to Audit Reverge Compliance
Customer has the right to take reasonable and appropriate steps to ensure that Reverge uses Customer Personal Information consistently with Customer's obligations under Applicable Privacy Laws. Reverge will satisfy this obligation by making available, on Customer's reasonable written request and not more than once per 12-month period (except in the event of a confirmed Security Incident affecting Customer Personal Information):
- A summary of Reverge's information-security program.
- Responses to a reasonable security questionnaire (with reasonable scope).
- Where available, third-party audit reports (e.g., SOC 2) under NDA.
Customer's audit rights do not include on-site inspections except where required by law.
5. Customer Obligations
Customer will:
- Comply with Applicable Privacy Laws in its collection, use, and disclosure of Customer Personal Information.
- Provide all required notices to data subjects and obtain all required consents for Reverge's Processing under this DPA, including for any communications Customer sends through the Services.
- Have a lawful basis to provide Customer Personal Information to Reverge.
- Not instruct Reverge to Process Customer Personal Information in a manner that would violate Applicable Privacy Laws.
- Verify the identity of any consumer making a rights request before instructing Reverge to act on it.
- Not upload to the Services any of the categories restricted under Section 3.3.
Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Information and the means by which Customer acquired it.
6. Sub-processors
6.1 General Authorization
Customer provides general written authorization for Reverge to engage Sub-processors to Process Customer Personal Information in connection with providing the Services. The current list of Sub-processors is set out in Annex A.
6.2 Sub-processor Obligations
Reverge will:
- Enter into a written agreement with each Sub-processor that imposes data-protection terms substantially as protective as those in this DPA, to the extent applicable to the services provided by the Sub-processor.
- Remain liable to Customer for the acts and omissions of Sub-processors with respect to Customer Personal Information.
6.3 Changes to Sub-processors
Reverge may add or replace Sub-processors. Reverge will provide notice of new Sub-processors by updating the list in Annex A and, on Customer's written request, by notifying Customer at least 15 days before the new Sub-processor begins Processing Customer Personal Information. Customer may object on reasonable data-protection grounds; if Customer objects in good faith, the parties will work together to find a mutually acceptable resolution. If no resolution is reached, Customer's sole remedy is to terminate the affected Services without further refund obligation beyond any applicable termination terms in the Agreement.
7. Security Incidents
7.1 Notification
Reverge will notify Customer without undue delay, and in any case within 72 hours after confirming, a Security Incident affecting Customer Personal Information.
7.2 Information Provided
The notification will include, to the extent known at the time:
- The nature of the Security Incident.
- The categories and approximate volume of Customer Personal Information affected.
- The likely consequences of the Security Incident.
- Measures taken or proposed to address the Security Incident and mitigate harm.
Reverge will provide updates as more information becomes available.
7.3 Customer Responsibilities
Customer is responsible for determining whether the Security Incident triggers any notification obligation Customer has under Applicable Privacy Laws and for making any required notifications. Reverge will provide reasonable assistance.
7.4 No Admission
Reverge's notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
8. International Transfers
Reverge processes Customer Personal Information primarily in the United States. Certain public-data-collection Sub-processors identified in Annex A may process publicly available business information in the United States or the European Union. The Services are not intended for personal information of data subjects outside the United States, and Customer agrees not to use the Services to Process such information unless the parties enter into a separate written addendum addressing applicable cross-border transfer requirements.
9. Data Return and Deletion
9.1 During the Term
Customer may export Customer Personal Information through Platform features made available for that purpose during the term of the Agreement.
9.2 On Termination
On termination or expiration of the Agreement, Reverge will, at Customer's choice:
- Return Customer Personal Information in a commercially reasonable format on Customer's reasonable written request made within 30 days of termination, or
- Delete Customer Personal Information in accordance with the retention periods described in the Privacy Policy.
If no choice is made within 30 days, Reverge may delete Customer Personal Information in accordance with the retention periods described in the Privacy Policy.
9.3 Backups and Logs
Customer Personal Information contained in routine backups, audit logs, and security logs may persist beyond deletion of active records and will be deleted in the ordinary course as backups age out (typically within 35 days for backups; longer for security logs as required for legitimate operational and security purposes).
9.4 Legal Holds
Reverge may retain Customer Personal Information to the extent required by applicable law or for the establishment, exercise, or defense of legal claims, in which case Reverge will continue to protect the information under this DPA until deletion.
10. Aggregated and De-identified Data
Reverge may create and use aggregated or de-identified information derived from Customer Personal Information (information that does not identify, and cannot reasonably be linked to, a particular individual or household) for any lawful purpose, including improving the Services, building benchmarks, and operating analytics. Reverge will:
- Take reasonable measures to ensure such information cannot be associated with a consumer or household.
- Publicly commit to maintain and use the information only in de-identified form and not to attempt to re-identify it.
- Contractually obligate any recipients of de-identified information to comply with the foregoing.
This Section is consistent with the de-identified-data exception under the CCPA and similar provisions under other Applicable Privacy Laws.
11. Liability
Each party's liability arising out of or related to this DPA is subject to, and counts toward, the limitations, exclusions, and aggregate caps on liability set forth in the Agreement (including Section 14 of the Terms of Service). This DPA does not create separate, additional, or unlimited liability beyond the Agreement, and any claim arising under this DPA is treated as a claim arising under the Agreement for purposes of those limitations and caps. The disclaimers and limitations in the Agreement apply to all claims under this DPA, including claims relating to Sub-processors, Security Incidents, and rights-request assistance.
12. Term, Conflict, and Miscellaneous
12.1 Term
This DPA is effective on the Effective Date and remains in effect for the term of the Agreement, plus any period during which Reverge continues to Process Customer Personal Information after termination.
12.2 Conflict
If this DPA conflicts with the Agreement, this DPA controls solely as to the subject matter of this DPA.
12.3 Updates
Reverge may update this DPA from time to time to reflect changes in Applicable Privacy Laws, Sub-processors, or Reverge's data-protection practices, by providing reasonable notice (typically 30 days). Updates that materially reduce Customer's protections will not take effect during the then-current term of the Agreement without Customer's consent.
12.4 Severability
If any provision of this DPA is found unenforceable, the rest remains in effect.
12.5 Governing Law
This DPA is governed by the laws of the State of California, without regard to conflict-of-laws rules.
12.6 Counterparts; Electronic Acceptance
This DPA may be accepted electronically (including by clickthrough) and in counterparts, each of which is an original.
Annex A — Sub-processors
The following Sub-processors are authorized as of the Effective Date:
| Sub-processor | Purpose | Location of Processing |
|---|---|---|
| Vercel, Inc. | Application hosting, edge infrastructure, and privacy-focused page-view analytics | United States |
| Cloudflare, Inc. | Authorization server and request routing for external AI assistant connections; stores connection authorization records and hashed connection credentials | Globally distributed edge network; primary storage in the United States |
| Supabase, Inc. | Managed Postgres database, authentication, file storage | United States |
| Stripe, Inc. | Payment processing and subscription billing | United States |
| Resend (Resend Labs, Inc.) | Transactional and product emails | United States |
| Functional Software, Inc. (Sentry) | Error tracking and performance monitoring | United States |
| PostHog Inc. | Product analytics, event capture, and session replay | United States |
| Google LLC (Gemini API) | AI processing of Customer-submitted inputs (primary provider) | United States (primary); limited abuse-monitoring logs may be stored or cached in other countries where the provider maintains facilities |
| OpenAI, L.L.C. (OpenAI API) | AI processing of Customer-submitted inputs (fallback provider for reliability and continuity) | United States (primary); limited retention may occur in other countries where the provider or its subprocessors maintain facilities |
| Google LLC (Places, GA4, GBP, Ads, PageSpeed APIs) | Marketing data sources for diagnostic and integration features | United States |
| Apify Technologies s.r.o. | Public-data collection infrastructure (e.g., business directory and review-site collection) | United States / EU (data processed in connection with US-targeted Services) |
| Bright Data Ltd. | Public-web data collection (search-result fallback for business discovery) | United States / EU |
| DataForSEO LLC | Public SEO / Google Business Profile data collection | United States |
| Brave Software, Inc. | Public web-search data (business and competitor discovery) | United States |
| Exa Labs, Inc. | Public web-search and content extraction (business and competitor discovery) | United States |
Reverge maintains the current list of Sub-processors and will update this Annex when Sub-processors are added or changed. Customer may request the most current list at privacy@reverge.com.
Annex B — Technical and Organizational Measures
Reverge maintains an information-security program that includes the following measures, which may be updated to reflect industry standards and the evolving threat landscape:
Access Control
- Role-based access control to production systems and Customer Personal Information on a least-privilege basis.
- Multi-factor authentication for personnel access to production systems and Sub-processor consoles.
- Periodic review of personnel access; prompt deprovisioning on role change or separation.
- Row-level security in the production database (Supabase RLS) to enforce tenant isolation.
Encryption
- TLS 1.2 or higher for all data in transit between users and the Services and between the Services and Sub-processors.
- Encryption at rest for the production database, file storage, and backups (managed by hosting and database Sub-processors).
Secure Development
- Source-controlled codebase with peer review on changes.
- Dependency scanning and update process.
- Separation of development, staging, and production environments.
Logging and Monitoring
- Application error and performance logging via Sentry.
- Product analytics and session-replay logging via PostHog (with masking of password and payment fields).
- Hosting and database access logs retained per Sub-processor defaults.
Incident Response
- Documented procedures for detecting, escalating, and responding to Security Incidents.
- 72-hour notification to Customer for confirmed Security Incidents affecting Customer Personal Information (per Section 7).
Personnel
- Confidentiality obligations for all personnel.
- Security awareness for personnel with access to Customer Personal Information.
- Background checks where permitted by law.
Vendor Management
- Pre-engagement security review of Sub-processors.
- Contractual data-protection terms with Sub-processors.
Physical Security
- Production infrastructure is hosted in commercial cloud data centers (Vercel, Supabase, and other Sub-processors). Physical security is administered by those providers under their respective security programs.
Business Continuity
- Routine backups of the production database, retained on a rolling basis.
- Restoration procedures tested periodically.
Signature
This DPA may be accepted by:
- Clickthrough acceptance in the Platform.
- Email confirmation from an authorized Customer representative to legal@reverge.com.
- Counterparty signature on this document.
Reverge LLC By: ____________________________ Name: ____________________________ Title: ____________________________ Date: ____________________________
Customer By: ____________________________ Name: ____________________________ Title: ____________________________ Company: ____________________________ Date: ____________________________
*This DPA is provided for general use and does not constitute legal advice. Reverge recommends consultation with independent counsel before publishing or signing.*