Who else touches your data
Published rather than supplied on request. Your procurement team should not have to sign something before finding out who is in the chain.
Supplied on request, not posted publicly
We give the complete sub-processor list — vendor, function, data categories, processing location and transfer basis — to any client or prospective client who asks, before signature and in writing. We do not post our vendor stack publicly, because publishing the exact tooling that holds client data is itself a security decision, and not one we make lightly.
Ask at privacy@revrepute.com and we will send it the same week.
What this page will carry
| Column | What it states |
|---|---|
| Sub-processor | Legal entity name, not a product brand |
| Purpose | The specific function it performs in delivering your service |
| Data categories | What it can actually see, not what its contract permits in the abstract |
| Processing location | Country of the region we have configured, not the vendor's headquarters |
| Transfer basis | Where processing sits outside your agreed region, the lawful mechanism relied on |
| Added | The date it joined the list, so you can see what changed since you signed |
How changes work
- We give clients 30 days' written notice before a new sub-processor starts processing.
- You may object within that window. If we cannot resolve the objection, you may terminate the affected service without penalty.
- Removals are published here too — a shorter list is also a change worth seeing.
- Subscribe to notifications by writing to privacy@revrepute.com.