Revalize and GDPR
CertReports found no public GDPR evidence for Revalize as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 12 Oct 2022
- Expires or valid through
- 23 Apr 2027
- Scope
- Revalize is a Business-to-Business company that provides a family of software products referred to generally as CPQ (Configure-Price-Quote). Non-HR: The nature and purpose of the Processing of Personal Data Revalize (i.e., a Data Processor) product(s) are used by its clients to prepare sales quotations to their existing and prospective customers. Each sales quotation may contain the personal contact information of a sales representative who prepares a quote and the personal contact information of a client’s (i.e., a Data Controller’s) customer who receives a quote. The types of Personal Data to be Processed. The types of Personal Data processed are: 1. Contact Information Contact information includes (but is not limited to) data elements such as: First Name, Last Name, email address and phone number. The categories of Data Subject to whom the Personal Data relates are: 2. The sales representatives employed by or contracted by the Data Controller who prepare sales quotations. 3. The existing and prospective customers of the Data Controller who receive sales quotations. How Revalize Processes and Protects Personal Data Revalize products are offered in a Web-hosted environment that is accessible from the World Wide Web. Personal Data collected by Revalize on behalf of its clients under the jurisdiction of GDPR is stored in encrypted databases that are hosted in Microsoft Azure data centers located in the United States today and potentially in Europe. Revalize applies protective measures to Confidential Information including Personal Data. Revalize annually verifies, using an external audit firm, that the protective measures it employs are (a) designed effectively and (b) operating effectively. The audit standard Revalize uses is the AICPA SOC2 Type 2. With respect to human resources data, data is processed for various employment and legal purposes including recruitment and staffing, compensation, benefits programs, payroll and administration purposes, performance management, compliance and risk management, training, workplace management, protection against and prevention of fraud, injury, theft, legal liability, and other business purposes. Data is disclosed to third parties as detailed in relevant privacy notices, including for legal and business reasons. We do not currently rely on the Swiss-US Data Privacy and UK Extension to transfer Swiss and UK personal data to the US.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Revalize, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification | Live pagesha256 7602973dd5 |
- Kind
- listing
- Issued or listed
- 24 May 2018
- Scope
- We collect personal data to provide leads to our clients.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | LeadMethod: Inactive | Live pagesha256 9e5e986451 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Revalize GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.