Data Processing Addendum
Last Updated: July 19, 2026
1. Introduction & Scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the "Customer") and Zensen Media LTD, the operator of Relvara("Relvara," "we," "our," or "us"). It is incorporated into the Terms of Service and applies where the Customer's use of the Services requires Relvara to process personal data on the Customer's behalf under applicable data-protection law.
No signature is required: the DPA takes effect automatically for any Customer whose use of the Services engages processor terms, and it binds both parties for the duration of the applicable subscription. If you require a countersigned copy for your own records, email privacy@relvara.ai.
2. Definitions
- Customer Data— the personal data that the Customer submits to, or that is generated within, the Services and that Relvara processes on the Customer's behalf. This is primarily the CRM contact, lead, client, and transaction data that the Customer manages in the Services.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Controller / Business — the party that determines the purposes and means of processing personal data, as defined under the GDPR and the CCPA/CPRA respectively.
- Processor / Service Provider — the party that processes personal data on behalf of the Controller/Business, as defined under the GDPR and the CCPA/CPRA respectively.
- Data Subject — the identified or identifiable individual to whom personal data relates.
- Subprocessor — a third party engaged by Relvara to process Customer Data in connection with the Services.
- Applicable Data Protection Law— all data-protection and privacy laws applicable to a party's processing of Customer Data, which may include the GDPR, the UK GDPR, and U.S. state privacy laws such as the CCPA/CPRA.
3. Roles of the Parties
With respect to Customer Data, the Customer acts as the Controller (or Business) and the Relvara acts as the Processor(or Service Provider). The Customer determines the purposes and means of processing Customer Data — the contact, lead, client, and transaction records it manages — and is responsible for the lawfulness of that data, including having a valid legal basis and any required notices or consents from its own contacts and leads.
Relvara processes Customer Data only to provide and support the Services on the Customer's behalf, as described in this DPA. Each party is responsible for complying with its own obligations under Applicable Data Protection Law.
4. Details of Processing (Annex I)
The following describes the subject matter and details of Relvara's processing of Customer Data.
4.1 Nature & Purposes of Processing
Relvara processes Customer Data to provide the Services, including customer relationship management (CRM), communications (email, SMS, and voice) initiated by the Customer, AI-assisted features, and related platform functionality, together with hosting, storage, security, support, and billing.
4.2 Duration of Processing
Relvara processes Customer Data for the duration of the Customer's subscription term, followed by the limited retention and deletion windows described in Section 11.
4.3 Categories of Data Subjects
The individuals whose personal data is processed are those whom the Customer manages within the Services — primarily the Customer's contacts, leads, clients, and other transaction participants.
4.4 Categories of Personal Data
- Identifiers such as names
- Contact details such as email address, phone number, and mailing address
- Property and real-estate transaction data
- Communications content (email, SMS, and recorded/transcribed calls the Customer initiates)
- Engagement data such as activity, status, and interaction history
The Services are not designed to process special categories of personal data (such as health, biometric, or government-identifier data), and the Customer should not submit such data to the Services.
5. Relvara's Obligations as Processor
When processing Customer Data on the Customer's behalf, Relvara will:
- Process only on documented instructions— Relvara processes Customer Data only on the Customer's documented instructions. Those instructions comprise the functionality of the Services, the Customer's own configuration and use of the Services, and any further written instructions the parties agree. Relvara will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, to the extent it is legally permitted to do so.
- Confidentiality — ensure that personnel authorized to process Customer Data are bound by appropriate obligations of confidentiality.
- Security — implement and maintain the technical and organizational measures described in Section 6.
- Assistance — assist the Customer with data-subject requests, assessments, and breach handling as described in Sections 7 and 8.
- Subprocessors — engage subprocessors only in accordance with Section 9.
- Return & deletion — return or delete Customer Data as described in Section 11.
- Annual review — review this DPA and the measures it describes at least annually and update them as appropriate to reflect changes in the Services or the law.
6. Security Measures (Annex II)
Relvara maintains technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using AES-256 at the infrastructure layer
- Row-level security to isolate each organization's data
- Role-based access controls limiting access to authorized personnel and roles
- Audit logging of significant system and access events
- Webhook signature verification for inbound integration events
- Application-layer encryption of connected-CRM credentials; OAuth access tokens are encrypted at rest (infrastructure-layer AES-256), with application-layer encryption being rolled out to them as part of our security roadmap
Relvara may update these measures from time to time provided that the updates do not materially reduce the overall level of protection for Customer Data.
7. Assistance & Data-Subject Requests
Taking into account the nature of the processing, Relvara will assist the Customer as follows:
- Data-subject requests— Relvara provides self-serve tools within the Services (including record access, editing, export, and deletion) and will provide reasonable additional assistance to help the Customer respond to requests from data subjects to exercise their rights of access, correction, deletion, portability, restriction, or objection. If Relvara receives such a request directly from a data subject relating to Customer Data, it will — unless legally required to act — direct that individual to the Customer.
- Assessments & DPIAs— at the Customer's reasonable request, Relvara will provide reasonable assistance with data-protection impact assessments (DPIAs) and any prior consultations with a supervisory authority, taking into account the nature of the processing and the information available to Relvara.
8. Personal Data Breach Notification
Relvara will notify the Customer without undue delay after confirming a personal data breach affecting Customer Data. The notification will include the information about the breach then reasonably available to Relvara, in order to help the Customer meet any obligations it has to notify supervisory authorities or affected data subjects. Relvara will take reasonable steps to mitigate the effects of, and to minimize any damage resulting from, the breach.
9. Subprocessors
The Customer provides a general authorization for Relvara to engage subprocessors to process Customer Data in connection with the Services. The current subprocessors are listed on our Subprocessors page.
- Advance notice — Relvara will give at least 30 days' advance notice of any addition or replacement of a subprocessor by updating the Subprocessors page (and by email on request, if the Customer subscribes to change notices).
- Right to object — during that notice period the Customer may object to a new subprocessor on reasonable data-protection grounds. The parties will work together in good faith to resolve the objection; if it cannot be resolved, the Customer may terminate the affected Services.
- Flow-down— Relvara imposes on each subprocessor data-protection obligations that are substantially equivalent to those in this DPA, and Relvara remains responsible to the Customer for each subprocessor's performance of those obligations.
10. CCPA Service-Provider Terms
To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the "CCPA"), applies to Customer Data, Relvara acts as a service provider and the Customer is the business. With respect to that Customer Data, Relvara will:
- Not sell or share Customer Data (as "sell" and "share" are defined under the CCPA).
- Not retain, use, or disclose Customer Data for any purpose other than the specific business purpose of performing the Services, or otherwise as permitted by the CCPA, including retaining, using, or disclosing it outside the direct business relationship between the parties.
- Not combine Customer Data with personal information it receives from, or on behalf of, another person, or collects from its own interaction with a consumer, except as permitted by the CCPA.
- Comply with the applicable obligations of a service provider under the CCPA and provide the same level of privacy protection the CCPA requires.
Relvara certifies that it understands the restrictions in this Section 10 and will comply with them.
11. Return & Deletion of Customer Data
- Self-serve export — the Customer may export its Customer Data at any time during the subscription term using the export tools available within the Services.
- Deletion— following deletion of the Customer's account, Relvara purges the Customer's database records within 30 days through a grace-window purge, except where retention is required by law or as described in our Privacy Policy. Uploaded files and media are removed from storage on a rolling basis after the database purge completes.
12. Audits & Attestations
On the Customer's written request, no more than once per year, Relvara will make available information reasonably necessary to demonstrate compliance with this DPA. This information consists of written summaries of Relvara's security measures and any relevant third-party attestations or audit reports of Relvara's infrastructure providers that are available to Relvara.
The parties agree that these materials, together with this DPA, ordinarily satisfy the Customer's audit and inspection rights. On-site or independent audits will be conducted only where required by Applicable Data Protection Law, on reasonable prior written notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt Relvara's operations or the security of other customers' data.
13. Google Workspace API Data
Where the Customer connects a Google Workspace account (such as Gmail or Google Calendar), Relvara's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is used only to provide and improve the user-facing features the Customer has connected; it is not used for advertising, is not sold, and is not used to train generalized or third-party AI models.
14. Order of Precedence
This DPA is incorporated into and forms part of the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Customer Data, this DPA controls; in all other respects the Terms of Service govern. This DPA is governed by the same law as the Terms of Service, the State of Ohio, United States, to the extent consistent with Applicable Data Protection Law.
15. Contact
Questions about this DPA or Relvara's processing of Customer Data can be directed to our privacy team:
Disclaimer: This Data Processing Addendum is provided for informational purposes and is intended to give a reasonable overview of how we process Customer Data on your behalf. It does not constitute legal advice. We recommend consulting a qualified attorney for compliance questions specific to your situation.