Sub-processors
RevQA uses the following third-party services to operate the platform. Customer data may be transmitted to each as part of that operation.
| Sub-processor | Purpose | Data categories | Region | Policy |
|---|---|---|---|---|
| Firecrawl | Fallback web-page content extraction for signal scanning — receives only the public URLs we fetch (only when the optional integration is enabled) | Public web-page URLs; no customer or prospect data | United States | Privacy policy |
| Anthropic | Claude API — every AI-generated cadence email, RFP scan, deep-dive dossier, and prep brief | Workspace product context, prospect names/titles, account names, signal evidence | United States | Privacy policy |
| Supabase | Postgres database, authentication, OAuth identity provider | Accounts, profiles, workspace data, audit logs, encrypted CRM credentials | EU (Frankfurt) | Privacy policy |
| Stripe | Subscription billing, payment processing, customer portal | Customer email, billing address, payment method, subscription status | United States / Ireland | Privacy policy |
| Fly.io | Application hosting (compute + bandwidth) | Request logs, IP addresses, ephemeral runtime state | Amsterdam (EU) | Privacy policy |
| Sentry | Error and performance monitoring | Stack traces, request URLs, browser metadata, sanitized exception context | Germany / United States | Privacy policy |
| LangFuse | LLM-call observability (per-call latency, tokens, prompt/completion text) | AI prompt content and completions, workspace ID for attribution | EU (Frankfurt) — cloud.langfuse.com | Privacy policy |
| Exa | Web search index powering account discovery, signal scanning, and deep-dive research | Search queries containing account/company names and market topics; no CRM contact data | United States | Privacy policy |
| Apollo.io | Contact enrichment — resolving prospect/company details and detecting champion job changes | Prospect names, job titles, work emails, company names | United States | Privacy policy |
| Lusha | Optional contact enrichment (customer-connected API key) — revealing work emails and direct dials | Prospect names, job titles, company names | United States | Privacy policy |
| Google sign-in (OAuth) and, when connected, Gmail send for outreach | Account email, profile name, OAuth tokens (and email content when Gmail is connected) | United States | Privacy policy |
Cross-border transfers from the EEA are covered by each sub-processor's Standard Contractual Clauses (SCCs) under their commercial terms. RevQA verifies each provider publishes SCCs as part of onboarding new sub-processors.
Notification of changes
We notify customers of new sub-processors at least 14 days before they begin processing customer data. Customers may object to a new sub-processor during this notice period.
Contact
Questions about our sub-processors or data processing practices: privacy@revqa.app.