Privacy Policy

Last updated: 1 August 2026.

1. Who we are

Revv is a voice-to-CRM tool for field sales teams. A rep talks through a customer visit and Revv turns that into structured records in the company's CRM. The service is operated by GK Consulting (Chamber of Commerce number 96777052), based in Purmerend, the Netherlands. The app runs at app.userevv.com.

For anything in this policy, write to gokul@userevv.com.

2. Our two roles: controller and processor

For the data we need in order to run Revv as a business, such as your account, your login history and your invoices, we are the controller. Section 3 covers that data.

For what your reps actually record in the product, the visit transcripts and everything extracted from them, your organisation is the controller and we are the processor. That means we only handle it on your instructions. Section 4 covers that data.

3. Data we hold as controller

WhatWhyLegal basis
Account data: name, work email, organisation, roleCreating accounts, access control, team managementPerformance of our agreement with you
Audit log: who did what, when, from which IP addressSecurity, abuse prevention, proving what happened to your dataOur legitimate interest in a secure and accountable service
Usage and diagnostic data: visit counts, timings, error codesRunning the service, fixing faults, capacity planningPerformance of our agreement, and our legitimate interest in a working product
Support correspondenceAnswering your questionsPerformance of our agreement
Billing and contract recordsInvoicing and accountingLegal obligation under Dutch tax law
Server logsDiagnosing faultsOur legitimate interest in a working service

Our diagnostic and audit records deliberately hold no customer content. They record how long something took, whether it succeeded and which record it touched, never what was said in a visit.

How long we keep it. Billing and contract records are kept for seven years, because Dutch tax law requires it. Visit data is kept while your organisation is a customer, which section 8 explains. Everything else we keep only for as long as it is needed for the purpose described above, and no longer than the law requires or permits. You can ask us to delete your personal data at any time, and section 10 explains how.

4. Your content, which we hold as processor

When a rep captures a visit, Revv holds the transcript of what they said, the structured summary the AI derives from it, any answers to your organisation's own follow-up questions, and text read out of photos the rep takes. This content routinely names real people, because a rep talking about a meeting names the person they met.

Three things are worth stating plainly.

We never store audio. The rep's speech streams straight to our transcription provider and is discarded as it goes. There is no recording of the rep's voice on our servers, and an automated check fails our build if anyone adds one.

We never store photos. When a rep photographs a business card or an order form, the image is sent for text extraction and then dropped. Only the extracted text is kept.

Visit content is encrypted with a key belonging to your organisation alone. Transcripts, extracted summaries, follow-up answers and the access tokens for your CRM and calendar are all encrypted before they are written to the database, each organisation under its own key.

We do not use your content to train AI models, we do not sell it, and we do not share it with anyone beyond the sub-processors listed below.

When our support team can see your data

We can look at your data only to resolve a support request you raised, to investigate a security incident, or to look into a suspected breach of our terms. Every such access is written to an audit log with the person, the time, the reason and the record touched, and you can ask us for a copy of the entries that concern your organisation. Reading the contents of an encrypted transcript takes a separate, deliberate step that always leaves an audit entry. We cannot log in as one of your users.

5. Sub-processors

These are the companies that process data on our behalf. We will let customers know when this list changes.

ServicePurposeLocation
SupabaseThe database holding all visit and account dataEU (Frankfurt)
DeepgramTurning the rep's speech into text, and the spoken repliesUnited States
AnthropicUnderstanding the conversation, extracting the visit summary, reading text from photosUnited States
ClerkLogins and user accountsUnited States
NetlifyHosting the web applicationUnited States, global edge
ResendSending service and follow-up emailEU (Ireland)
ExpoDelivering push notifications to the mobile appUnited States
PostHogError and performance monitoring, so we find out when something breaksEU

Your CRM and your calendar are not sub-processors. You connect them yourself, we act on your instruction when we write to them, and what happens to the data once it is in your CRM is governed by your own agreement with that provider. Revv supports HubSpot, Salesforce, Microsoft Dynamics, Pipedrive and Zoho for CRM, and Google and Microsoft for calendar. Calendar access is read only. Any user can disconnect an integration at any time.

6. Where your data goes

Everything Revv stores itself sits in the European Union. The database holding your visits and account records is in Frankfurt, and the application refuses to start against a database outside the EU allowlist.

Processing is different. To turn speech into text and to understand what a rep said, we send that content to Deepgram and Anthropic, both of which are in the United States. Those transfers rely on the European Commission's standard contractual clauses in our agreements with each provider. Neither provider is permitted to use your content to train its models. Login data is handled by Clerk, also in the United States, on the same basis.

7. Recording, and telling your team

Revv captures a rep speaking. Your organisation decides to deploy it, so your organisation is responsible for telling your reps that it is in use and what it does with what they say, and for meeting any works council or employee consultation requirement that applies where you operate.

Revv is built for a rep summarising a visit afterwards, on their own. It is not built to record a meeting while it is happening, and our terms do not allow you to use it that way without the consent of everyone in the room.

8. How long we keep your content

We keep your visit data for as long as your organisation is a customer, and for a short period afterwards so you can get it back.

You stay in control of it. Anyone can delete an individual visit in the product, any user can erase their own visits, consents and account from Settings, and you can ask us to delete everything at any time.

When the contract ends we keep your data for 90 days so you can export it, then delete it. You can ask for earlier deletion at any point.

Two things outlive the rest. We keep audit records of who accessed what for longer than visit data, because they are what lets us show you exactly what happened to your information, and we strip personal identifiers out of them when someone exercises their right to erasure. Database backups are kept for seven days and then expire.

9. Security

If a breach affects your data we will tell you without undue delay, with enough detail for you to meet your own notification obligations.

10. Your rights

Under the GDPR you can ask us to:

For anything else, email gokul@userevv.com and we will respond within one month. We keep invoices and audit records that we are legally required to keep, but we remove personal identifiers from them.

If your name came up in a visit recorded by a company that uses Revv, that company decides what happens to it, so please contact them. Write to us and we will pass your request on without delay.

You can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the regulator in your own country.

11. Cookies and tracking

The Revv application sets only what it needs to keep you signed in and to remember your cookie choice. There are no advertising cookies and no trackers, and we do not currently run any third-party analytics inside the product. The banner you see on first visit records your preference for analytics so that we would honour it if we ever switched analytics on.

This website, userevv.com, sets no cookies and runs no analytics, which is why you see no banner here. It does load fonts and styling from Google and from a content delivery network, so your browser sends those services your IP address when a page loads. If we add analytics to this website we will say so in this section and add the provider to the list in section 5.

12. Automated decisions

Revv does not make automated decisions that have a legal or similarly significant effect on anyone. It drafts CRM records for a person to review.

13. Changes

When we change this policy we publish a new version number and date at the top. If a change matters to you, we will email your admin.