Skip to content

Data Processing Agreement

Version 2026-07-27. This agreement forms part of the agreement between the customer and ReviveDB when ReviveDB processes personal data in customer backups.

Contact

Privacy and DPA requests can be submitted through our contact page.

1. Scope and duration

ReviveDB processes personal data only to create, store, verify, restore, make available and delete database backups as instructed through the service. Processing lasts for the customer relationship and the documented deletion period.

2. Processing details

The subject matter is managed database backup and recovery. Processing includes access, collection, copying, encryption, storage, restore testing, retrieval and deletion, weekly, daily or on demand according to the customer's plan. Data subjects may include the customer's users, customers, workers and other people represented in its database. Data may include any categories selected by the customer, potentially including special-category data.

3. ReviveDB obligations

  1. Process personal data only on documented customer instructions, including for international transfers, unless applicable law requires otherwise.
  2. Ensure authorised personnel are bound by confidentiality and maintain appropriate technical and organisational security measures.
  3. Use subprocessors only under equivalent written data-protection terms, give advance notice of material changes and allow reasonable objections.
  4. Assist with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations.
  5. Notify the customer of a personal-data breach without undue delay and provide available information needed for its assessment.
  6. At the customer's choice, delete or return personal data after the service ends unless law requires retention.
  7. Provide information reasonably necessary to demonstrate compliance and support proportionate audits under confidentiality safeguards.
  8. Inform the customer when an instruction appears to infringe applicable data-protection law.

4. Customer obligations

The customer determines whether ReviveDB is appropriate for its data, has a lawful basis for the underlying processing, provides required notices, uses authorised credentials and does not provide broader access than necessary. The person accepting this DPA confirms that they are authorised to act for the customer.

5. Subprocessors and transfers

Current subprocessors, purposes, locations and contract status are published on the subprocessors page. ReviveDB uses an applicable adequacy mechanism or current Standard Contractual Clauses plus necessary supplementary safeguards for processing or access outside the EEA.

6. Deletion and return

Managed backup objects, encrypted project credentials and related account metadata are deleted through the service controls and retention processes described in the Privacy Notice. Customer-controlled storage remains under the customer's custody.

7. Liability, precedence and acceptance

Liability follows the main agreement and mandatory law. This DPA prevails where it conflicts with the main agreement on personal-data processing. The customer accepts this version when an authorised user finishes connecting a database or explicitly accepts it in privacy settings. ReviveDB records the account, timestamp and document version. Contact us through the contact page for a copy.