How it worksFor foundersFor RevOps leadersFor CROsInsightsAboutBook a call
Legal

Privacy Notice — Client Engagements

Last updated: 17 July 2026

Who we are

Sidoroff UG (haftungsbeschränkt), Klingenstraße 22 / E17, 04229 Leipzig, Germany (operating as RevWerk). Managing Director: Natalia Sidorova. Contact for privacy matters: hello@revwerk.de. No Data Protection Officer is appointed, as none is legally required.

Our two roles

We process personal data in two distinct capacities:

As controller — for our own business operations: managing prospect and client relationships, proposals, contracts, invoicing, and communication.

As processor (Art. 28 GDPR)— where an engagement requires us to access personal data inside a client's systems, or to host and process it on our own infrastructure in the operated mode (e.g. CRM contacts, lead and deal data, marketing data, intake responses), on the client's behalf and instructions. In this role we act only under a data processing agreement (DPA) concluded with the client; the client remains controller.

Data we process as controller

We process the following categories of data as controller:

Purposes and legal bases:

  • Responding to inquiries, preparing proposals, and conducting engagements — Art. 6(1)(b) GDPR (contract / pre-contractual steps).
  • Managing business relationships and following up with prospects — Art. 6(1)(f) GDPR (legitimate interest in B2B business development).
  • Invoicing, accounting, and tax obligations — Art. 6(1)(c) GDPR (legal obligation).

Workshops and grounding sessions

Delivery engagements typically include workshops and interviews with client staff. We process participants' names, roles, and the content of their contributions (notes only — sessions are not recorded or AI-transcribed) to build the agreed deliverables. Legal basis: Art. 6(1)(b)/(f) GDPR. Where the engagement's privacy mode requires it, contributions are captured in anonymised or attributed form as agreed with the client.

Retention (as controller)

  • Prospect data that does not lead to an engagement: deleted after 24 months from last contact.
  • Engagement records: duration of the relationship, then per statutory duties — commercial and business correspondence 6 years (§ 257 HGB, § 147 AO), accounting/invoice records 10 years.

Recipients and transfers (as controller)

We use processors for hosting (Hetzner Online GmbH, Germany) and email, scheduling, and document handling (Google Workspace, Google Ireland Limited), each under an Art. 28 DPA. We currently use no CRM, newsletter system, transactional email provider, or dedicated accounting/invoicing software. Processing takes place in the EU where possible; where a provider is outside the EU/EEA, transfers rely on an adequacy decision (e.g. EU–US Data Privacy Framework) and/or standard contractual clauses. We do not sell personal data.

How we handle personal data during delivery (as processor)

Depending on the engagement, delivery follows one of two modes. In both, the client remains controller and we act under an Art. 28 DPA.

Build & Transfer (client-hosted)

We build inside the client's environment: we work in client-controlled systems and do not copy personal datasets into our own infrastructure. Our access is scoped to the engagement and ends with it.

Operated service (hosted on our infrastructure)

For our operated offerings (Context Foundation intake and hosting, operated governance), we run the platform: the client's Context Foundation is stored in a database we manage, served to the client's AI tools via our MCP service, and intake answers (questionnaire and workshop responses, which may contain personal data such as names, roles, and statements of client staff, leads, or customers) transit and are stored on our infrastructure. For these services:

Common to both modes

Data subjects whose data we process in this role (e.g. a client's staff, leads, or customers) should direct requests to the respective client, who is the controller.

Your rights

As a prospect, client contact, or workshop participant, you have the rights under Art. 15–21 GDPR: access, rectification, erasure, restriction, portability, and objection to legitimate-interest processing; where processing rests on consent, you may withdraw it at any time (Art. 7(3)). Contact hello@revwerk.de. You may also complain to a supervisory authority; competent for us is the Sächsische Datenschutz- und Transparenzbeauftragte, Devrientstraße 5, 01067 Dresden, Germany.

No automated decision-making

We make no decisions producing legal or similarly significant effects on you by automated means (Art. 22 GDPR). Systems we build for clients are the client's responsibility as controller; our builds document human oversight where relevant.

Changes

We update this notice when our processing changes; the current version is available on request and at revwerk.de/legal/engagement-privacy.