Skip to content
Back to home

Data Processing Agreement

How personal data is processed and the rights and responsibilities of the parties.

This Data Processing Agreement (“DPA”) governs how personal data is processed when RevFence services are used and sets out the rights and responsibilities of the parties in that respect.

01Roles of the parties

The Customer acts as the data controller for personal data relating to its own customers and users. RevFence is the data processor that processes this data on the Customer’s instructions.

RevFence processes personal data only to provide the service, maintain the security of the service and carry out the Customer’s instructions.

02Scope of processing

To enable the Customer to run its subscription cancellation and customer retention processes, RevFence carries out the following operations:

  • Runs the cancellation session.
  • Collects the cancellation reason.
  • Selects the appropriate retention offer according to the rules the Customer has set and shows it to the user.
  • Ensures that an accepted offer is applied through Stripe.
  • Reports the outcome of the operation to the Customer.

RevFence does not use personal data outside the Customer’s instructions or for its own independent commercial purposes.

03Types of data that may be processed

Depending on how the service is configured, the following data may be processed:

  • Customer and subscription identifiers
  • Technical identifiers such as Stripe Customer ID and Subscription ID
  • The customer’s email address
  • Subscription and plan information
  • Cancellation reason
  • Feedback submitted as free text
  • Information about offers shown and accepted
  • Result information about whether an offer was applied
  • Technical records necessary for the operation and security of the service

Payment card numbers, CVV/CVC codes and similar card details are not processed by RevFence.

04Security measures

RevFence takes technical and organizational measures appropriate to the structure of the service and the risks involved to protect the security of personal data.

These measures include:

  • Encryption of data in transit
  • Access and authorization controls
  • Keeping customer data separate from one another
  • Secure storage of passwords
  • API and webhook security controls
  • Rate limiting controls
  • Controls to prevent repeated operations and replay attacks
  • Keeping security and audit logs
  • Backup and recovery mechanisms
  • Monitoring of unauthorized access and unusual traffic

RevFence may update its security measures according to technological developments and operational needs.

05Subprocessors

RevFence may use trusted third-party service providers where needed to deliver the service.

The main categories of service providers that may be used are:

  • Stripe: Payment and subscription operations
  • Hosting providers: Application and data infrastructure
  • Email providers: Sending transactional emails
  • Security and monitoring providers: Service security and technical monitoring

The current list of subprocessors and information about them is published on RevFence’s Subprocessors page.

If a new subprocessor that will process personal data is engaged, the necessary notice is given in line with applicable law and the terms of the agreement.

06Personal data breach notification

If RevFence becomes aware of a personal data breach affecting the Customer’s personal data, it will notify the Customer without delay in accordance with applicable law and its contractual obligations.

The initial notice shares the information available at that time. To the extent possible, information is provided about the nature of the incident, the types of data that may be affected and the measures taken or planned.

07Return and deletion of data

If the Customer stops using the RevFence service, personal data may be exported, deleted from active systems or anonymized, in line with applicable law and the Customer’s instructions.

As a rule, personal data is deleted from active systems or anonymized within 30 days of the end of the agreement or of receiving a deletion request.

Data that must be kept for a further period because of legal retention obligations or as part of ordinary backup processes may be treated separately from this period.

08Requests from data subjects

The Customer is responsible for assessing and responding to personal data requests from its own customers and users.

RevFence provides the Customer with reasonable assistance, within the framework of applicable law, in fulfilling access, rectification, deletion and similar data protection requests.

09Transfers of data abroad

Where personal data must be transferred to service providers located abroad, RevFence uses transfer methods that comply with applicable data protection law.

Where necessary, standard contractual clauses or other appropriate data transfer mechanisms accepted by the law are applied.

10Updates to this agreement

RevFence may update this Data Processing Agreement from time to time to comply with changes in the service, the technologies used or applicable law.

Significant changes are announced through appropriate communication channels.

Contact details

Company:
SWAN TECHNOLOGIES LTD
Address:
Suite 10400 5 Brayford Square, London, United Kingdom, E1 0SG
Country:
United Kingdom
Email:
hello@revfence.com

Last updated: 19 September 2026