↳ Legal
Privacy policy
Revexa · Last updated: September 2026
Revexa respects your privacy and complies with the EU General Data Protection Regulation (GDPR). This policy describes how we handle personal data in connection with the Leo service.
This is an English translation of the Swedish original. If the versions differ, the Swedish version applies.
1. Who we are
Revexa provides Leo, an AI driven service that reactivates dormant B2B leads through personal emails on behalf of our customers.
Contact: hey@revexa.io
2. What data we collect
About you as a visitor (the waitlist)
- First name (optional) and the email address you provide
About you as a customer (the company buying the service)
- Name, email address and company information
- Billing and payment information
- Communication with Revexa (email, meetings)
About leads that are contacted (your lead list)
- Name, email address and company details (provided by you as the customer via your CRM)
- Email correspondence and reply status
- Outcomes (meeting booked, not interested, come back later, etc.)
3. Legal basis
- The waitlist: consent (Art. 6.1a)
- Customer data: contractual necessity (Art. 6.1b)
- Lead data, outgoing emails: legitimate interest (Art. 6.1f)
- Billing data: legal obligation (Art. 6.1c)
Outgoing B2B emails to leads rely on legitimate interest (GDPR Art. 6.1f), the same legal basis as traditional B2B sales outreach.
4. How the data is used
- To deliver the Leo service
- To book meetings in your calendar
- To provide email history and reports
- To improve Leo's quality (anonymized data only)
- For billing and customer communication
- The waitlist: to contact you when we open the next round
5. Calendar integration and third party services
Google Calendar
Revexa uses the Google Calendar API with the "calendar.events" scope to read available times and create calendar events when booking meetings. We cannot delete calendars, access other users' calendars or read any other Google data.
Revexa's use of information from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only for meeting booking and is never shared with third parties. You can revoke access at any time via: Google account, Security, Third party apps with account access.
Microsoft Outlook Calendar
Revexa uses the Microsoft Graph API with the "Calendars.ReadWrite" permission to read and create calendar events. You can revoke access via: Microsoft account, Privacy, Apps and services.
Email tools
Waitlist email addresses are handled in our email tool with storage inside the EU/EEA under applicable data processing agreements.
6. The customer's responsibility as data controller
Your organization is the data controller for the lead list you provide. You are responsible for ensuring your contacts may be contacted under applicable law.
Revexa acts as a data processor and processes data strictly according to your instructions. A data processing agreement (DPA) is signed with every customer.
7. How the data is protected
- Personal data is stored encrypted in the EU (database and application hosting in the EU)
- Access is limited to authorized personnel
- Data processing agreements are signed with all subprocessors
8. Sub-processors and international transfers
We never sell or share data with third parties for their marketing.
To deliver the service we engage sub-processors (data processors). Our database and application hosting are in the EU. However, some sub-processors process personal data outside the EEA, primarily in the US. Such transfers only take place under a valid transfer mechanism under Chapter V of the GDPR: the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework or an adequacy decision.
Main sub-processors:
- Vercel (hosting) and Supabase (database) – EU
- Anthropic (AI that drafts messages and analyzes signals) – US, SCCs
- Data enrichment and prospecting (e.g. Apollo, LeadMagic) and Perplexity (company research) – US, SCCs
- Unipile (LinkedIn) and email delivery – EU; SendBlue and Claw Messenger (iMessage) and Slack – US, SCCs
- Stripe (payments) – US, Data Privacy Framework/SCCs
- CRM integrations you choose yourself (e.g. Pipedrive and Upsales in the EU, HubSpot and Salesforce in the US)
All sub-processors are bound by data processing agreements. A current list is provided on request.
9. How long we keep the data
- The waitlist: until you unsubscribe or request deletion
- Customer data: for the contract period plus 12 months
- Lead data (email correspondence): for the campaign period plus 90 days
- Billing data: 7 years (Swedish accounting law)
You can request deletion of your data at any time.
10. Your rights
Under the GDPR you have the right to:
- Request access to your personal data
- Request correction of inaccurate data
- Request deletion ("the right to be forgotten")
- Object to processing based on legitimate interest
- Request data portability
- Lodge a complaint with a supervisory authority. In Sweden this is the Swedish Authority for Privacy Protection (IMY)
Contact us: hey@revexa.io
11. Cookies
The site uses a minimum of first-party cookies, no advertising or third-party cookies:
- NEXT_LOCALE: stores your language choice (Swedish or English). 12 months.
- Session cookie: keeps you logged in to the customer platform. 24 hours, necessary.
- rv_src: stores which channel you first arrived from, for example LinkedIn. 90 days, never shared with third parties.
Visitor statistics (Vercel Analytics) are cookieless.
12. Contact and complaints
Revexa · Email: hey@revexa.io
Supervisory authority: the Swedish Authority for Privacy Protection (IMY): imy.se