Legal
Privacy notice
Last updated 30 September 2026
REVNIA helps service businesses follow up on the enquiries they receive. That means it holds personal information about the people who use it and about their customers. This notice explains, in plain language, what we hold, why, who else touches it, and what you can ask us to do.
Who we are
The operator of REVNIA provides REVNIA (“we”, “us”). You can reach our Information Officer about anything in this notice.
- Operator
- Company name to be published
- Registration number
- to be published
- Address
- to be published
- Information Officer
- to be published
- Privacy contact
- support@revnia.co.za
Two kinds of information, two roles
Your account. When you sign up or are invited to a workspace, we decide how your account details are used, so we are the responsible party for them.
Your customers' enquiries. The leads, messages, notes and quotes a business keeps in REVNIA belong to that business. The business is the responsible party and we act as its operator: we process that information only to provide REVNIA to the business, on its instructions. If you contacted a business and want to know what it holds about you, ask that business first. We will help it respond.
What we hold
- Account details: your name, work email and role. Your password is stored only as a salted scrypt hash, never in readable form. If you turn on two-factor sign-in, its secret is encrypted.
- Sign-in records: the browser and IP address of each signed-in device, so you can see your sessions and sign them out. Sessions end after 30 days.
- Workspace data a business adds: enquiries and contact details, messages, qualification answers, notes, appointments, quotes, outcomes and marketing sources.
- Connection details: tokens for WhatsApp, Facebook lead ads or other integrations a business connects. These are encrypted (AES-256-GCM).
- Activity and usage: an audit log of important changes (who did what, and when), monthly usage counts for plan limits, and product events such as “a quote was sent” or “a deal was won” so we can see whether REVNIA is helping. Product events never contain your customers' personal details.
We don't use third-party advertising or analytics trackers on this website or in the product.
Why we use it
- To run REVNIA for the business: capture, qualify and prioritise enquiries, remind the team to follow up, and report on revenue.
- To keep accounts secure, investigate abuse and keep an audit trail.
- To send the emails the product needs: sign-in help, invitations and the alerts each person chooses.
- To support you when you ask for help, and to meet our legal obligations.
We don't sell personal information. We don't contact a business's customers for our own purposes. We don't use workspace data to train AI models.
Who else processes it
- Hosting: hosting provider and location to be published.
- Email delivery: an email provider sends sign-in, invitation and alert emails on our behalf.
- AI (optional): when a business turns AI features on, text needed to qualify an enquiry and draft a reply is sent to Anthropic, which processes it in the United States. That is the customer's enquiry and later messages, and for a draft also their first name, suburb, what the team has recorded about the job and recent notes on that lead. Phone numbers, email addresses and ID numbers are removed from this text first. Passwords and connection tokens are never sent. A business can switch AI off in its settings; REVNIA then uses its built-in rules only.
- Meta (only if a business connects it): WhatsApp messages and Facebook or Instagram lead-form answers pass between Meta and REVNIA under the business's own agreement with Meta.
How long we keep it
- Account and workspace data are kept while the business uses REVNIA.
- A business can export or anonymise any lead's personal information at any time, and can mark people as do-not-contact.
- When a business closes its account, we delete its workspace within 30 days of confirming the request. Copies can remain in backups until they are overwritten.
- Demo workspaces contain only fictional people and are deleted automatically after 24 hours.
- Expired sessions and technical delivery records are deleted automatically.
How we protect it
Connections are encrypted in transit. Each business's data is kept separate and is only visible to its own team, according to their roles. Passwords are hashed, secrets are encrypted, two-factor sign-in is available, sign-in attempts are rate-limited and important changes are logged. If we become aware of a security compromise affecting personal information, we will tell the affected businesses and, where the law requires, the Information Regulator, as soon as reasonably possible.
Your rights
You can ask us what personal information we hold about you, and ask us to correct it, delete it or stop using it. Contact support@revnia.co.za. We may need to confirm who you are first. If your information is in a business's workspace, we will pass your request on to that business.
If you are unhappy with how we handled your information, you can complain to the Information Regulator (South Africa) at inforegulator.org.za.
Changes to this notice
If we change this notice in a way that matters, we will tell workspace owners by email before the change takes effect. The date at the top shows when it last changed. Our terms of service cover the rest of our agreement with businesses.
See also Terms of service.