Recavo Data Processing Agreement (DPA)
Recavo Labs, LLC (“Recavo,” “Processor”) Effective date: July 1, 2026 Last updated: July 1, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between Recavo Labs, LLC and the customer identified in the Agreement (“Customer,” “Controller”). It governs Recavo’s processing of Customer Personal Data on Customer’s behalf and takes effect when Customer accepts the Agreement or otherwise uses the Service to process personal data about third parties.
Where Recavo processes Customer’s own account data as a controller (for example, billing details and login credentials), that processing is governed by the Privacy Policy, not this DPA.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. “Applicable Data Protection Law” means all privacy and data-protection laws applicable to the processing, including, as relevant, the EU General Data Protection Regulation (GDPR), the UK GDPR, and US state privacy laws. “Customer Personal Data” means personal data within the CRM content and other data that Customer submits to the Service and that relates to Customer’s prospects, contacts, and other data subjects. “Subprocessor” means a third party engaged by Recavo to process Customer Personal Data. “Controller,” “Processor,” “Data Subject,” “Personal Data Breach,” and “processing” have the meanings given under Applicable Data Protection Law.
2. Roles of the parties
With respect to Customer Personal Data, Customer is the Controller and Recavo is the Processor. Recavo processes Customer Personal Data only on Customer’s documented instructions, which include the Agreement, this DPA, and Customer’s use and configuration of the Service. Customer is responsible for the accuracy and lawfulness of Customer Personal Data and for having a valid legal basis to collect it and to instruct Recavo to process it. Recavo will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3. Scope, nature, and purpose of processing
Subject matter and duration. Recavo processes Customer Personal Data for the duration of the Agreement and until deletion in accordance with Section 10.
Nature and purpose. Recavo processes Customer Personal Data to provide and support the Service — a single-player CRM — including storing and displaying CRM records; generating AI pre-call briefs; transcribing voice notes to text; geocoding and route planning; capturing inbound email; sending transactional email; and securing and maintaining the Service.
Categories of Data Subjects. Customer’s prospects, leads, customers, and business contacts, and any individuals whose personal data Customer chooses to record.
Categories of Personal Data. Names, job titles, employers, business contact details (email, phone, address), meeting and call notes, deal and activity data, voice recordings and their transcripts, location/address data, and technical identifiers such as IP addresses associated with Customer’s use. Customer controls what it enters and should not submit special-category data unless it has a lawful basis to do so.
Special categories. The Service is not designed to process special categories of personal data, and Customer agrees not to use it for that purpose except at its own discretion and lawful basis.
4. Recavo’s obligations
Recavo will: (a) process Customer Personal Data only on Customer’s documented instructions, including for international transfers, unless required to act otherwise by law (in which case it will inform Customer unless legally prohibited); (b) ensure that persons authorized to process Customer Personal Data are bound by confidentiality; (c) implement the technical and organizational security measures described in Section 6; (d) respect the conditions in Section 5 for engaging Subprocessors; (e) assist Customer as described in Sections 7 and 8; and (f) make available information necessary to demonstrate compliance as described in Section 9.
5. Subprocessors
Customer provides general authorization for Recavo to engage Subprocessors to process Customer Personal Data. Recavo’s current Subprocessors, including each vendor’s legal entity, purpose, categories of data processed, and processing region, are listed in the Subprocessor List (“Annex III”), which is incorporated into this DPA.
Recavo imposes on each Subprocessor data-protection obligations no less protective than those in this DPA, and remains responsible for its Subprocessors’ performance. Recavo will make the Subprocessor List available and will update it when it adds or replaces a Subprocessor. Customer may subscribe to notifications of changes and may object on reasonable data-protection grounds; if Customer objects and the parties cannot resolve the concern, Customer may terminate the affected portion of the Service.
Note on data location. Recavo prefers US processing and selects US regions where offered at no extra cost. Some processing is global: Cloudflare operates in reverse-proxy mode on a non-Enterprise plan, so inbound traffic transits Cloudflare’s global anycast edge. Accordingly, processing occurs primarily in the United States and, for Cloudflare, may occur at global edge locations. See the Subprocessor List.
6. Security measures
Recavo maintains technical and organizational measures appropriate to the risk, described in Annex II below and in Recavo’s Security Spec, including: encryption of data in transit (TLS) and at rest; row-level security isolating each user’s data; scoped, authenticated database access; secrets held in a managed secret manager and never exposed to client code; rate limiting; error monitoring configured with default personal-data capture disabled; and scrubbing of personal data from logs before export to Recavo’s observability provider. Recavo may update these measures provided the level of protection is not materially reduced.
7. Assistance with Data Subject rights
Taking into account the nature of the processing, Recavo will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). The Service lets Customer access, correct, export, and delete records directly. Where Customer needs additional help, Recavo will provide reasonable assistance on request at privacy@recavolabs.com.
8. Personal Data Breach notification and assistance
Recavo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help Customer meet its own notification obligations. Taking into account the nature of processing and information available to Recavo, Recavo will also assist Customer with data-protection impact assessments and prior consultations with supervisory authorities where required.
9. Audit and demonstrating compliance
Recavo will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR (or equivalent), and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. To protect the security of Recavo’s multi-tenant environment and other customers, audits will be conducted on reasonable prior notice, no more than once per year absent a Personal Data Breach or regulator requirement, subject to confidentiality, and Recavo may satisfy audit requests by providing relevant documentation and responses to reasonable questionnaires.
10. Return and deletion of data
On termination of the Agreement, and at Customer’s choice, Recavo will delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. Where Customer does not elect return, Recavo will delete or de-identify Customer Personal Data within 90 days of termination, purging from backups on its normal backup-rotation cycle. Voice audio is retained only as needed to produce and store transcripts. This Section survives termination.
11. International transfers
Where processing involves transferring Customer Personal Data out of the European Economic Area, United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum, where relevant) are incorporated by reference and apply to that transfer, with Customer as data exporter and Recavo as data importer, and with the annexes populated by the information in this DPA and the Subprocessor List. Recavo flows down equivalent transfer protections to its Subprocessors.
12. General
This DPA is governed by the law of the State of Florida and the dispute-resolution terms of the Agreement, except to the extent Applicable Data Protection Law requires otherwise; nothing in this DPA or the Agreement limits rights that Data Subjects or supervisory authorities have under mandatory law. If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. If any provision is unenforceable, the remainder stays in effect. This DPA, together with its Annexes, is the parties’ complete agreement on the processing of Customer Personal Data.
For any matter under this DPA, contact privacy@recavolabs.com.
Annex I — Description of processing
- Data exporter / Controller: Customer (the account holder identified in the Agreement).
- Data importer / Processor: Recavo Labs, LLC.
- Categories of Data Subjects: Customer’s prospects, leads, customers, and business contacts, and other individuals Customer records.
- Categories of Personal Data: Names, job titles, employers, business contact details, notes and activity, deal data, voice recordings and transcripts, location/address data, and technical identifiers (e.g., IP addresses).
- Special categories: None intended; not designed for special-category data.
- Frequency: Continuous, for the duration of the Agreement.
- Nature and purpose: Providing the Recavo CRM Service as described in Section 3.
- Retention: For the term of the Agreement and deletion per Section 10.
Annex II — Technical and organizational security measures
Encryption in transit (TLS) and at rest; per-user row-level security; scoped, authenticated database access; managed secret storage with no client-side exposure of secrets; rate limiting and abuse prevention; error monitoring with default PII capture disabled; scrubbing of personal data from logs before export to the observability provider; access controls and confidentiality obligations for authorized personnel; and breach detection and response. See Recavo’s Security Spec for detail.
Annex III — Subprocessors
The authoritative, current list of Subprocessors is the Subprocessor List, incorporated into this DPA by reference.
Related documents: Terms of Service · Privacy Policy · Cookie Policy · Subprocessor List