Legal

Privacy Policy

Effective Date: March 2026  ·  Rivvun AI
Section 01

Introduction

This Privacy Notice is issued by Rivvun AI Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808 (“we”, “us”, “our”). It explains how personal data is collected, used, processed, stored, and shared in connection with:

Website Interactions and Enquiries
Website interactions and enquiries.
Rivvun AI Application
Rivvun AI application through Integration with client’s Enterprise Systems and chosen LLM Providers.
Applicable Data Protection Laws
We are committed to protecting personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and applicable United States State privacy laws, including the California Consumer Privacy Act (CCPA).
Section 02

Scope and Roles

For the purposes of this Privacy Policy, “customers” refer to organisations or legal entities that license and use our software, and not individual end users unless expressly stated.

References to customers do not include individual users, employees, or representatives whose personal data may be processed in different capacities as described in this Policy.

2.1 Data Controller
We act as a data controller in relation to personal data that we collect directly from individuals, including:

• Visitors to our website
• Prospective customers submitting enquiries or requesting demonstrations
• Representatives of customers or business partners

In this capacity, we determine:

• The purposes for which personal data is collected
• The means by which such personal data is processed

We ensure that such processing is carried out in a lawful, fair, and transparent manner and that individuals are provided with appropriate privacy notices at the point of data collection.
2.2 As Data Processor
We act as a data processor when providing our Rivvun AI software and related services to our customers, being organisations or legal entities that use our software for managing data processing, analysis and related reporting obligations.

In this context:

• Customers act as data controllers/data fiduciaries
• We process personal or any other data solely on their behalf and in accordance with their documented instructions

Our obligations include:

• Processing personal data only for agreed and lawful purposes
• Implementing appropriate technical and organisational security measures
• Assisting customers in fulfilling their legal obligations, including data subject rights requests and breach notifications
• Ensuring that sub-processors are engaged only under written agreements imposing equivalent data protection obligations
• Not engaging sub-processors without appropriate authorisation from customers (where contractually required)

What We Do as a Data Processor:

• Collect, use, share and retain personal data only for the purposes for which we have been authorised by the customer acting as data controller.
• Disclose clearly in this Privacy Notice and in our contracts what types of personal data we collect, and the purposes for which it is used or shared with third parties, in a manner that is easy to understand.
• Support access to and correction of personal data by the data subject or their authorised representative, by assisting the customer acting as data controller in fulfilling its obligations.
• Maintain a comprehensive security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of personal information against risks – such as unauthorized access or use, or unintended or inappropriate disclosure – using administrative, technological, and physical safeguards appropriate to the sensitivity of the information.
• Identify Personal Information for product development and improvements.
• Allow a successor entity to maintain the personal information, in the case of our merger or acquisition by another entity, provided the successor entity is subject to these same commitments for the previously collected personal information.
• Obtain third-party attestation of our alignment with applicable data protection regulations.
Section 03

Personal Data We Collect

3.1 Data Collected Directly from Individuals
We collect limited personal data necessary for business communication and service delivery, including:

• Full name
• Business email address and telephone number
• Company name and job title
• Publicly available business profile information, such as a LinkedIn profile URL
• Marketing opt-in status and the date and time it was given or withdrawn
• Records of your engagement with us, including emails, meetings and demonstration notes

This data is collected through:

• Website forms
• Demo requests
• Business communications
3.2 Data Collected Automatically
When individuals interact with our website or services, we may collect:

• IP address
• Device type, browser type, and operating system
• Date and time of access
• Pages viewed and interaction patterns

This data is used for analytics, system administration, security monitoring, and service improvement.
3.3 Data Collected Directly from Client’s Customers
(as a data processor on behalf of Clients)
As part of our Services, we process personal data uploaded or input by customers, which may include:

• Employee or authorised user details
• Vendor, lessor, or counterparty information
• Financial or transactional data linked to identifiable individuals
• Hard copy documents (agreements, contracts, KYC verification etc.) uploaded in support of processing of application

We process such data strictly on behalf of our customers and do not determine the purposes or means of such processing.
Section 04

Purpose of Processing

We process personal data for the following purposes:

Purposes of Processing
• Managing enquiries and providing product demonstrations
• Facilitating onboarding and customer relationship management
• Delivering, operating, maintaining, and improving our Services
• Ensuring system integrity, security, and fraud prevention
• Complying with applicable legal, regulatory, and contractual obligations
Compatible Processing
We do not process personal data for purposes incompatible with those stated above without appropriate notice and, where required, consent.
Section 05

Legal Basis for Processing

Under GDPR
We rely on one or more of the following legal bases:

• Consent
• Contractual necessity
• Legal obligations
• Legitimate interests
Section 06

Children’s Personal Data

GDPR Art. 8 requires parental or guardian consent before processing personal data of children under 16 (EU member states may lower this to 13).

We do not undertake behavioural monitoring of, or targeted advertising directed at, children.

Our website and Services are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected such data, we will delete it.

Section 07

Sharing of Personal Data

We may share personal data with:

Authorized Categories of Recipients
• Cloud hosting and infrastructure providers
• Managed database and vector-store providers used to operate the Services
• Artificial intelligence and large language model providers, used to extract and interpret the content of documents submitted through the Services
• CRM and customer support tools
• Professional advisors (legal, audit, compliance)
• Regulatory authorities or law enforcement agencies, where required
Recipient Obligations
All recipients are bound by contractual obligations to ensure confidentiality, security, and compliance with applicable data protection laws.

We do not share personal data for third-party marketing purposes.
Sub-Processor Categories
We engage sub-processors in the following categories:

• Cloud hosting, compute and storage providers
• Managed database and vector-store providers
• Artificial intelligence and large language model providers
• Business application providers supporting customer relationship management and support

A current list of our sub-processors, naming each provider, is made available to customers under their data processing agreement and is available on request.

We notify customers before adding or replacing a sub-processor, in accordance with their data processing agreement.
Section 08

Data Storage

Administrative, Technological and Physical Safeguards
We maintain reasonable administrative, technological and physical safeguards designed to improve the integrity, privacy, confidentiality, and security of your information.
Customer Data Hosting
Customer data is hosted in the cloud region contracted with the customer, on infrastructure operated by providers holding current SOC 2 or ISO 27001 attestations.
User Roles
User roles are clearly defined to manage the access level.
Password and Account Security
Data is protected by a password for the data subject's privacy and security. They may help protect against unauthorized access to these account and personal information by selecting and protecting password appropriately and limiting access to computer and browser by signing off after finishing accessing account.

We endeavour to protect user information to ensure that user account information is kept private. However, we cannot guarantee the security of user account information.
Security Limitations
Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

Like other online services, we cannot guarantee the security of any information the data subject or our customer transmits to us or store on the Site. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by unauthorized persons.
Security Information
For additional information about the security measures, we use in connection with our Site and Services, contact us at privacy@rivvun.ai.
Security Systems Breach
If we learn of a security systems breach, then we will notify the data subject or our customer electronically so that they can take appropriate protective steps.

We may post a notice on the Site if a security breach occurs.
Backups and Archived Pages
Once the data subject or our customer information is removed from the Site, copies of this information, other than Data, may remain stored in backup systems or cached and archived pages.
Linked Sites and Services
We are not responsible for the practices employed by websites, applications or services linked to or from our Site.
Local Regulatory Requirements
Any information collected through the Services is stored and processed as per the local regulatory requirement.

Where personal data is transferred across borders, such transfers are conducted using the safeguards described in Section 7 of this Notice.
Section 09

Data Retention

We retain personal data only for as long as necessary, including:

Enquiry and Contact Data
3 years from the last meaningful engagement, unless converted into a business relationship. Marketing consent and opt-out records are retained as evidence of compliance.
Customer Data
As per contractual terms and customer instructions.
Legal and Compliance Data
As required under applicable laws.
End of Retention Period
Upon expiry of retention periods, personal data is securely deleted, anonymised, or archived.
Section 10

Data Security

We implement appropriate technical and organisational measures, including:

Security Measures
• Encryption in transit and at rest
• Access controls and authentication mechanisms
• System monitoring, logging, and audit trails
• Periodic vulnerability assessments and security reviews
Access Restriction
Access to personal data is restricted on a need-to-know and least privilege basis.
Section 11

Links to Third Party Sites or Apps

The Site may contain links to websites and apps operated and maintained by third parties, over which we have no control.

Privacy policies on linked sites may be different from our Privacy Policy. If you access such linked sites, it is at your own risk.

You should always read the privacy policy of a linked site before disclosing any information to such site.

Section 12

Data Subject Rights

Under GDPR
Individuals have the following rights under GDPR:

(1) Access (Art. 15)
(2) Rectification (Art. 16)
(3) Erasure / Right to be Forgotten (Art. 17)
(4) Restriction of processing (Art. 18)
(5) Data portability (Art. 20)
(6) Objection (Art. 21)
(7) Rights in relation to automated decision-making and profiling (Art. 22)

We maintain processes to respond to such requests within one (1) month as required under GDPR.
Under United States State Privacy Laws
Where a US State privacy law such as the California Consumer Privacy Act applies, individuals have the right to know what personal information is collected and the purposes for which it is used; to access a copy of it; to request correction or deletion; to opt out of any sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We acknowledge a request within 10 business days and respond within 45 calendar days, extendable by a further 45 days where necessary.

Where permitted, timelines may be extended in accordance with applicable legal provisions.
Identity Verification
We verify the identity of the requester before responding, and we have processes in place to act against impersonation and the filing of false requests.
Consent Withdrawal
Individuals may withdraw consent at any time where processing is based on consent. Such withdrawal will not affect prior lawful processing.

On withdrawal of consent, we immediately stop processing the related data and erase it, unless a legal retention obligation exists.

Erasure of data is notified to the data subject and, where applicable, to our customer.
To exercise these rights, contact privacy@rivvun.ai. We will respond within timelines prescribed under applicable law.
Section 13

Cookies and Tracking Technologies

We use cookies and similar technologies to improve user experience, analyse usage, and enhance security.

Users may manage cookies through browser settings.

Where required by law, consent will be obtained before placing non-essential cookies.

Section 14

Data Breach Notification

In the event of a personal data breach:

Containment and Mitigation
We will take prompt steps to contain and mitigate the breach.
Supervisory Authority Notification
Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33), where feasible, or explain any delay.
Customer Notification
Notify affected customers without undue delay so that they may meet their own notification obligations as data controller.
Individual Notification
Inform affected individuals where there is a risk to their rights and freedoms.
Section 15

Third-Party Processing and Sub-processors

Third-party processing is governed by written agreements ensuring:

Contractual Safeguards
• Confidentiality
• Security safeguards
• Compliance with applicable laws
Sub-Processor Responsibility
We remain responsible for ensuring that sub-processors meet required standards.
Section 16

Cross-Border Data Transfers

Cross-border transfers are carried out using appropriate safeguards, including Standard Contractual Clauses [SCCs] or equivalent mechanisms, and in compliance with applicable law.

Personal data may be transferred to jurisdictions outside the country of collection.

EEA-Originating Data
Where personal data originates from the European Economic Area (EEA), we implement appropriate safeguards, including:

• Standard Contractual Clauses (SCCs)
• Supplementary technical and organisational measures where required
Large Language Model Provider Processing
Where document content is submitted to a large language model provider for extraction and interpretation, we use the provider's enterprise service offering, which allows us to control the hosting region in which that processing takes place and contractually prevents the provider from using the content for model training or for any purpose other than returning a result to us.

Such processing is governed by a data processing addendum incorporating standard contractual clauses where required.
Transfers from Other Jurisdictions
Transfers from other jurisdictions are undertaken in accordance with the safeguards required by the applicable law of that jurisdiction.
Section 17

Data Subject Requests

Data Subject Requests
Email: privacy@rivvun.ai

We will respond within timelines prescribed under applicable law.
Section 18

Updates to this Privacy Notice

This Privacy Notice may be updated periodically.

Where changes are material, we will notify affected individuals by email or by a prominent notice on our website prior to the changes taking effect.

All updates will be published with a revised effective date.

Section 19

Contact Information

For questions regarding this notice or additional information about our data handling security measures, contact us at privacy@rivvun.ai.

Privacy Contact — Manish Chugh, CISO
Email: manish.chugh@rivvun.ai

Individuals may also lodge complaints with:

  • Relevant supervisory authorities in the European Union
  • The Attorney General or privacy regulator of your State, where a United States State privacy law applies