Skip to main content
This page describes the processing Reelevant performs as a data processor, in the structure usually expected in a DPA annex or a record of processing activities (Article 30 GDPR). The signed DPA and its annexes prevail over this page.

Data Lifecycle

Nature and Purpose

Data Subjects

  • Customers and prospects of the controller who receive its marketing communications
  • Visitors of the controller’s website or app, when the optional web or mobile collection is deployed
  • The controller’s own users of the Reelevant platform (account data: name, professional email, role)

Categories of Personal Data

No special category data (Article 9) is required by the service. The controller should not map such fields into its Datasources.
Use an opaque identifier in the Content URL. The identifier is visible in the email HTML, in browser history and in logs, so it must never be an email address, a phone number or a name.

Retention

Recipients and Location

No personal data is transferred outside the EU. See Vendor Management for the full vendor list.

Security Measures

A summary of the technical and organisational measures. Full details are on Security & Compliance and in the Trust Centre.

Data Subject Rights

The controller remains the point of contact for data subjects. Reelevant assists as follows: Requests to Reelevant go to security@reelevant.com.

Checklist for the Controller

  • Add Reelevant as a processor in your record of processing, with the purposes above
  • Mention personalisation of marketing communications and open and click measurement in your privacy notice
  • If you deploy the web tag, add Reelevant as a recipient in your CMP and load the tag only after consent
  • Choose an opaque customer identifier for the Content URLs
  • Map only the fields your Use Cases need in each Datasource

Documents Available

Next Steps

How Reelevant Works for DPOs

The three phases, who does what, and the controller and processor roles.

Security & Compliance

Certifications, encryption, access control and incident response.