Privacy Notice — Client Engagements
Last updated: 17 July 2026
Who we are
Sidoroff UG (haftungsbeschränkt), Klingenstraße 22 / E17, 04229 Leipzig, Germany (operating as RevWerk). Managing Director: Natalia Sidorova. Contact for privacy matters: hello@revwerk.de. No Data Protection Officer is appointed, as none is legally required.
Our two roles
We process personal data in two distinct capacities:
As controller — for our own business operations: managing prospect and client relationships, proposals, contracts, invoicing, and communication.
As processor (Art. 28 GDPR)— where an engagement requires us to access personal data inside a client's systems, or to host and process it on our own infrastructure in the operated mode (e.g. CRM contacts, lead and deal data, marketing data, intake responses), on the client's behalf and instructions. In this role we act only under a data processing agreement (DPA) concluded with the client; the client remains controller.
Data we process as controller
We process the following categories of data as controller:
| Category | Examples | Source |
|---|---|---|
| Contact and role data | Name, work email, phone, company, role, company size | You, your employer, the website contact form, or public professional profiles |
| Communication data | Emails, call and meeting notes, workshop notes | Our interactions with you |
| Contract and billing data | Contracting entity, signatories, invoicing details | The engagement contract |
Purposes and legal bases:
- Responding to inquiries, preparing proposals, and conducting engagements — Art. 6(1)(b) GDPR (contract / pre-contractual steps).
- Managing business relationships and following up with prospects — Art. 6(1)(f) GDPR (legitimate interest in B2B business development).
- Invoicing, accounting, and tax obligations — Art. 6(1)(c) GDPR (legal obligation).
Workshops and grounding sessions
Delivery engagements typically include workshops and interviews with client staff. We process participants' names, roles, and the content of their contributions (notes only — sessions are not recorded or AI-transcribed) to build the agreed deliverables. Legal basis: Art. 6(1)(b)/(f) GDPR. Where the engagement's privacy mode requires it, contributions are captured in anonymised or attributed form as agreed with the client.
Retention (as controller)
- Prospect data that does not lead to an engagement: deleted after 24 months from last contact.
- Engagement records: duration of the relationship, then per statutory duties — commercial and business correspondence 6 years (§ 257 HGB, § 147 AO), accounting/invoice records 10 years.
Recipients and transfers (as controller)
We use processors for hosting (Hetzner Online GmbH, Germany) and email, scheduling, and document handling (Google Workspace, Google Ireland Limited), each under an Art. 28 DPA. We currently use no CRM, newsletter system, transactional email provider, or dedicated accounting/invoicing software. Processing takes place in the EU where possible; where a provider is outside the EU/EEA, transfers rely on an adequacy decision (e.g. EU–US Data Privacy Framework) and/or standard contractual clauses. We do not sell personal data.
How we handle personal data during delivery (as processor)
Depending on the engagement, delivery follows one of two modes. In both, the client remains controller and we act under an Art. 28 DPA.
Build & Transfer (client-hosted)
We build inside the client's environment: we work in client-controlled systems and do not copy personal datasets into our own infrastructure. Our access is scoped to the engagement and ends with it.
Operated service (hosted on our infrastructure)
For our operated offerings (Context Foundation intake and hosting, operated governance), we run the platform: the client's Context Foundation is stored in a database we manage, served to the client's AI tools via our MCP service, and intake answers (questionnaire and workshop responses, which may contain personal data such as names, roles, and statements of client staff, leads, or customers) transit and are stored on our infrastructure. For these services:
| Area | Details |
|---|---|
| Hosting | Infrastructure hosted in Germany (EU) with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; backups and access controls under our management. |
| Server-side AI processing | Synthesis runs on our systems against AI model providers under our account — currently Anthropic and OpenAI, each a named sub-processor. No new sub-processor is introduced without the client's approval per the DPA. |
| Processing records | We keep technical logs of processing operations on our platform for security, supervision, and quality assurance for the duration of the engagement; they are deleted with the engagement data per retention below. Where we use engagement data to improve our own methods and tooling, we anonymise it first; anonymised material may be retained and used for internal process improvement beyond the engagement. |
| Retention and exit | Platform data (Foundation content, intake data, processing records) is retained for the duration of the engagement. On termination, the client receives a full export (Markdown) of their Foundation, and personal data is deleted per the DPA within 30 days (backup copies expire automatically within 90 days). |
| Ownership | The Foundation's content belongs to the client; export is available on demand at any time. |
Common to both modes
| Safeguard | Details |
|---|---|
| DPA before access | Documented instructions, confidentiality, deletion/return on completion (Art. 28(3) GDPR). |
| Data minimisation and purpose limitation | Scopes limited to the agreed purpose; no scope creep into unrelated personal data. |
| Documented data flows | Data dictionary and data-flow documentation in the handoff (supports the client's Art. 30 records). |
| Security (Art. 32) | Scoped, least-privilege permissions; secrets handling; logging and traceability of agent actions; no unbounded write access. |
| Data subject rights support | We assist the client in fulfilling access, deletion, and rectification requests concerning data on our infrastructure, and forward any data subject request we receive to the client controller. |
Data subjects whose data we process in this role (e.g. a client's staff, leads, or customers) should direct requests to the respective client, who is the controller.
Your rights
As a prospect, client contact, or workshop participant, you have the rights under Art. 15–21 GDPR: access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing; where processing rests on consent, you may withdraw it at any time (Art. 7(3)). Contact hello@revwerk.de. You may also complain to a supervisory authority; competent for us is the Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 5, 01067 Dresden, Germany.
No automated decision-making
We make no decisions producing legal or similarly significant effects on you by automated means (Art. 22 GDPR). Systems we build for clients are the client's responsibility as controller; our builds document human oversight where relevant.
Changes
We update this notice when our processing changes; the current version is available on request and at revwerk.de/legal/engagement-privacy.