Trust
Security & data protection
Revynex reads your CRM and billing data to write your brief. Here is exactly how that data is handled.
Data handling
Revynex connects to HubSpot, Salesforce, Pipedrive and Stripe via read-only OAuth scopes wherever the provider supports them. We never write back to your CRM or billing system without your explicit approval.
Encryption
Data is encrypted in transit (TLS) between Revynex and every connected provider, and at rest in the underlying database.
Analytics
Product analytics run on PostHog’s EU-hosted infrastructure, separate from your CRM and billing data.
Subprocessors
The following third parties process data on Revynex’s behalf. Certifications listed belong to the named subprocessor, not to Revynex.
| Subprocessor | Purpose | Location | Note |
|---|---|---|---|
| Emergent | Application hosting | United States and India | SOC 2 Type I certified (Emergent's own certification); Type II in progress. |
| MongoDB Atlas | Primary database | To be confirmed | |
| PostHog | Product analytics | European Union | EU-hosted instance. |
| Resend | Transactional email | To be confirmed | |
| AI model provider | Brief generation (analysis and drafting) | To be confirmed | Exact provider(s) pending final confirmation. |
Data retention
We retain your connected data for as long as your account is active plus the history window your plan includes. On cancellation or deletion request, your data is removed from production systems within 30 days.
GDPR
Revynex is not yet formally certified as GDPR compliant. We follow GDPR-aligned practices — data minimization, deletion on request, and a Data Processing Agreement (DPA) available on request — and we disclose our subprocessors’ processing locations truthfully, including where data is currently processed in the United States and India via our hosting subprocessor. A dedicated compliance review is on our roadmap ahead of our first EU enterprise customer.
Questions
For security or data questions, or to request a DPA, contact security@revynex.io.