Data Processing Addendum
DPA for Customer Personal Data.
This DPA forms part of the agreement between the Customer and AMETRINE LABS DESENVOLVIMENTO DE SOFTWARE NAO CUSTOMIZAVEL LTDA, CNPJ 68.046.497/0001-12. It is an executable contractual draft when incorporated by an Order or electronic acceptance, subject to the transfer and counsel confirmations identified in REVORY’s launch records.
- Version
- 2026.07.22-draft
- Effective
- July 22, 2026
- Provider
- Ametrine Labs
1. Scope and incorporation
This DPA applies when Ametrine Labs processes Customer Personal Data as processor/operator to provide REVORY. It is incorporated into the Terms and applicable Order. Capitalized terms not defined here have the meaning in the Terms.
2. Roles
Customer is controller and Ametrine Labs is processor/operator for Customer Personal Data. Each party is independently responsible for data it processes as controller, including Ametrine Labs account, security, billing, support and operational data.
3. Customer instructions
Customer instructs Ametrine Labs to process Customer Personal Data to provide, secure and support the purchased service, perform documented export/deletion requests and comply with law. The agreement and Customer’s configured use are documented instructions. Additional instructions require written agreement and may incur reasonable cost.
4. Legality of instructions
Ametrine Labs will notify Customer if it reasonably believes an instruction violates applicable data-protection law, unless prohibited, and may pause the affected processing while the parties resolve it. Ametrine Labs does not provide legal advice.
5. Customer responsibilities
Customer is responsible for its notices, lawful basis, data accuracy, data-subject communications, permissions, supported-purpose limits and instructions. Customer will not provide health data, full payment-card data, credentials or other data prohibited by the Terms.
6. Purpose limitation
Ametrine Labs will process Customer Personal Data only for the documented purposes and will not sell it, use it for third-party advertising or combine it for unrelated profiling.
7. Confidentiality of personnel
People authorized to process Customer Personal Data are subject to confidentiality duties and receive access only as needed for their functions.
8. Security measures
Ametrine Labs will maintain appropriate technical and organizational measures described in Annex II, considering the nature, scope, context, purposes and risks of processing. Measures may evolve without materially reducing overall protection during an Order.
9. Subprocessors
Customer authorizes the subprocessors listed in Annex III and the public Subprocessor Notice. Ametrine Labs will impose data-protection obligations appropriate to the service and remains responsible for their performance to the extent required by applicable law and this DPA.
10. Subprocessor changes
Material additions or replacements will be published in the Subprocessor Notice or notified through the service/email before they process Customer Personal Data when reasonably practicable. Customer may object on reasonable data-protection grounds; the parties will seek a practical solution, which may include disabling an optional feature or terminating the affected service.
11. International transfers
Where processing crosses borders, the parties will use a mechanism permitted by LGPD and ANPD Resolution CD/ANPD No. 19/2024 when required. Annex IV records the present status. This DPA alone does not represent that a specific mechanism or ANPD standard clauses have been completed where additional execution is legally required.
12. Data-subject requests
Taking into account the nature of processing, Ametrine Labs will provide reasonable technical and organizational assistance for Customer to respond to requests. If Ametrine Labs receives a request about Customer Personal Data, it will direct the requester to Customer where appropriate and will not answer substantively unless authorized or legally required.
13. Government requests
Ametrine Labs will assess binding government demands, disclose only what is legally required and notify Customer in advance where law permits.
14. Security incidents
After becoming aware of a confirmed security incident affecting Customer Personal Data, Ametrine Labs will notify Customer without undue delay. Notice will include available information on nature, affected data/subjects, likely consequences and measures taken or proposed, and may be supplied in phases. Notice is not an admission of fault.
15. Incident cooperation
The parties will reasonably cooperate on containment, investigation, remediation and legally required communications. Customer is responsible for determining its notification duties as controller; Ametrine Labs will provide available information needed for that assessment.
16. Impact assessments and consultation
Ametrine Labs will provide reasonable information about its processing to assist Customer with a legally required data-protection impact assessment or prior consultation, to the extent the information is not otherwise available and relates to REVORY processing.
17. Records and accountability
Ametrine Labs maintains records reasonably necessary to demonstrate processing instructions, subprocessors, security operations, legal acceptance and relevant audit events, subject to confidentiality and security restrictions.
18. Audit information
Upon reasonable written request, Ametrine Labs will first provide available policies, summaries and questionnaire responses. If these are insufficient for a legal audit requirement, the parties may agree to a scoped audit no more than annually, during business hours, by an independent professional under confidentiality, without access to other customers or sensitive security information. Customer bears reasonable costs unless material noncompliance is found.
19. Return, export and deletion
During access, Customer can use available export and analysis-deletion controls. At termination or written instruction, Ametrine Labs will delete or return Customer Personal Data within the product’s supported controls and agreed process, unless law requires retention. Backup copies may remain until ordinary overwrite and will stay protected and isolated from ordinary use.
20. Retention configuration
The analysis-retention setting defaults to 365 days and may be set to 30, 90, 180 or 365 days. It covers the categories implemented by the retention job. Account, billing, acceptance, security, support and backup categories follow their necessary legal/operational periods and are not assigned an invented uniform deadline by this DPA.
21. Bounded AI
If Customer enables an AI-assisted feature, the disclosed AI provider is a conditional subprocessor for the limited context described in the Privacy Notice. AI does not approve financial findings or replace Customer review. Customer may use deterministic mapping where the interface permits.
22. No sale or independent monetization
Ametrine Labs does not sell Customer Personal Data or use it to advertise to data subjects. Service reliability and security measurement will use aggregated or minimized operational data where practicable.
23. Liability
The liability allocation in the Terms applies to this DPA, subject to mandatory data-protection law. Nothing limits data-subject or authority rights that cannot be limited by contract.
24. Duration
This DPA begins with the applicable agreement or electronic incorporation and continues while Ametrine Labs processes Customer Personal Data, including protected retention required after service access ends.
25. Conflict
For processing of Customer Personal Data, this DPA prevails over conflicting Terms. A valid transfer addendum or mandatory standard clauses prevail for the covered transfer. An Order controls only if it expressly identifies the DPA provision it changes and the change is lawful.
26. Governing law
Brazilian law governs this DPA. The forum and mandatory-right exceptions in the Terms apply. The parties will cooperate with the ANPD and other competent authorities as legally required.
27. Electronic execution and contact
This DPA may be incorporated and accepted electronically with retained version evidence. Data-protection notices may be sent to support@revory.app.
Annex I — Processing details
Subject matter: self-service ingestion, data-quality review, canonicalization and Quote Recovery analysis. Duration: the agreement plus protected retention. Nature: collection, parsing, structuring, storage, comparison, deterministic analysis, optional bounded AI, display, export and deletion. Purposes: deliver, secure and support REVORY. Data subjects: Customer personnel, customers, leads and business contacts represented in authorized exports. Data types: identifiers, business contact data, estimates, dates, statuses, activities, values, relationship IDs, provenance and support/audit data. Sensitive data is not intended or supported. Frequency: when Customer imports, reviews, refreshes, exports or deletes data.
Annex II — Confirmed technical and organizational measures
Measures include authenticated server-side workspace authorization; logical tenant scoping; password verification, throttling and session revocation; managed OAuth when configured; managed encryption in transit and database encryption at rest; production secret management; CSV/XLSX content, size, formula and archive controls; deterministic mapping and human confirmation; explicit external-ID matching; visible unmatched/conflicting records; transactional/idempotent persistence; signed Stripe webhooks with replay ledger; audit/evidence events; configurable retention; workspace export and analysis deletion; managed database backup/restore capability; and incident-response contacts. REVORY does not represent independent certification.
Annex III — Authorized subprocessors
The current authorized list and conditional status are maintained in the versioned Subprocessor Notice: Vercel (hosting and operational telemetry), Neon (managed PostgreSQL), Stripe (billing), Resend (transactional email), Google (optional OAuth) and OpenAI (optional bounded AI). The Notice is incorporated by reference and identifies purposes, data boundaries and provider links.
Annex IV — International transfer status
Cross-border processing may occur through the providers in Annex III. The parties intend to rely only on a mechanism permitted by LGPD and ANPD Resolution CD/ANPD No. 19/2024. The specific production mechanism, exporter/importer details and any required ANPD standard clauses require final legal confirmation and, if selected, must be completed or incorporated as required before reliance. This Annex is transparent status disclosure, not a declaration that an unexecuted mechanism is complete.