Privacy Policy
Effective Date: 01-Sep-2026
Last Reviewed: 01-Sep-2026
Introduction
This Privacy Notice is issued by Rivvun AI Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808 (“we”, “us”, “our”). It explains how personal data is collected, used, processed, stored, and shared in connection with:
Scope and Roles
For the purposes of this Privacy Policy, “customers” refer to organisations or legal entities that license and use our software, and not individual end users unless expressly stated.
References to customers do not include individual users, employees, or representatives whose personal data may be processed in different capacities as described in this Policy.
• Visitors to our website
• Prospective customers submitting enquiries or requesting demonstrations
• Representatives of customers or business partners
In this capacity, we determine:
• The purposes for which personal data is collected
• The means by which such personal data is processed
We ensure that such processing is carried out in a lawful, fair, and transparent manner and that individuals are provided with appropriate privacy notices at the point of data collection.
In this context:
• Customers act as data controllers/data fiduciaries
• We process personal or any other data solely on their behalf and in accordance with their documented instructions
Our obligations include:
• Processing personal data only for agreed and lawful purposes
• Implementing appropriate technical and organisational security measures
• Assisting customers in fulfilling their legal obligations, including data subject rights requests and breach notifications
• Ensuring that sub-processors are engaged only under written agreements imposing equivalent data protection obligations
• Not engaging sub-processors without appropriate authorisation from customers (where contractually required)
What We Do as a Data Processor:
• Collect, use, share and retain personal data only for the purposes for which we have been authorised by the customer acting as data controller.
• Disclose clearly in this Privacy Notice and in our contracts what types of personal data we collect, and the purposes for which it is used or shared with third parties, in a manner that is easy to understand.
• Support access to and correction of personal data by the data subject or their authorised representative, by assisting the customer acting as data controller in fulfilling its obligations.
• Maintain a comprehensive security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of personal information against risks – such as unauthorized access or use, or unintended or inappropriate disclosure – using administrative, technological, and physical safeguards appropriate to the sensitivity of the information.
• Identify Personal Information for product development and improvements.
• Allow a successor entity to maintain the personal information, in the case of our merger or acquisition by another entity, provided the successor entity is subject to these same commitments for the previously collected personal information.
• Obtain third-party attestation of our alignment with applicable data protection regulations.
Personal Data We Collect
• Full name
• Business email address and telephone number
• Company name and job title
• Publicly available business profile information, such as a LinkedIn profile URL
• Marketing opt-in status and the date and time it was given or withdrawn
• Records of your engagement with us, including emails, meetings and demonstration notes
This data is collected through:
• Website forms
• Demo requests
• Business communications
• IP address
• Device type, browser type, and operating system
• Date and time of access
• Pages viewed and interaction patterns
This data is used for analytics, system administration, security monitoring, and service improvement.
(as a data processor on behalf of Clients)
• Employee or authorised user details
• Vendor, lessor, or counterparty information
• Financial or transactional data linked to identifiable individuals
• Hard copy documents (agreements, contracts, KYC verification etc.) uploaded in support of processing of application
We process such data strictly on behalf of our customers and do not determine the purposes or means of such processing.
Purpose of Processing
We process personal data for the following purposes:
• Facilitating onboarding and customer relationship management
• Delivering, operating, maintaining, and improving our Services
• Ensuring system integrity, security, and fraud prevention
• Complying with applicable legal, regulatory, and contractual obligations
Legal Basis for Processing
• Consent
• Contractual necessity
• Legal obligations
• Legitimate interests
Children’s Personal Data
GDPR Art. 8 requires parental or guardian consent before processing personal data of children under 16 (EU member states may lower this to 13).
We do not undertake behavioural monitoring of, or targeted advertising directed at, children.
Our website and Services are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected such data, we will delete it.
Sharing of Personal Data
We may share personal data with:
• Managed database and vector-store providers used to operate the Services
• Artificial intelligence and large language model providers, used to extract and interpret the content of documents submitted through the Services
• CRM and customer support tools
• Professional advisors (legal, audit, compliance)
• Regulatory authorities or law enforcement agencies, where required
We do not share personal data for third-party marketing purposes.
• Cloud hosting, compute and storage providers
• Managed database and vector-store providers
• Artificial intelligence and large language model providers
• Business application providers supporting customer relationship management and support
A current list of our sub-processors, naming each provider, is made available to customers under their data processing agreement and is available on request.
We notify customers before adding or replacing a sub-processor, in accordance with their data processing agreement.
Data Storage
We endeavour to protect user information to ensure that user account information is kept private. However, we cannot guarantee the security of user account information.
Like other online services, we cannot guarantee the security of any information the data subject or our customer transmits to us or store on the Site. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by unauthorized persons.
We may post a notice on the Site if a security breach occurs.
Where personal data is transferred across borders, such transfers are conducted using the safeguards described in Section 7 of this Notice.
Data Retention
We retain personal data only for as long as necessary, including:
Data Security
We implement appropriate technical and organisational measures, including:
• Access controls and authentication mechanisms
• System monitoring, logging, and audit trails
• Periodic vulnerability assessments and security reviews
Links to Third Party Sites or Apps
The Site may contain links to websites and apps operated and maintained by third parties, over which we have no control.
Privacy policies on linked sites may be different from our Privacy Policy. If you access such linked sites, it is at your own risk.
You should always read the privacy policy of a linked site before disclosing any information to such site.
Data Subject Rights
(1) Access (Art. 15)
(2) Rectification (Art. 16)
(3) Erasure / Right to be Forgotten (Art. 17)
(4) Restriction of processing (Art. 18)
(5) Data portability (Art. 20)
(6) Objection (Art. 21)
(7) Rights in relation to automated decision-making and profiling (Art. 22)
We maintain processes to respond to such requests within one (1) month as required under GDPR.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We acknowledge a request within 10 business days and respond within 45 calendar days, extendable by a further 45 days where necessary.
Where permitted, timelines may be extended in accordance with applicable legal provisions.
On withdrawal of consent, we immediately stop processing the related data and erase it, unless a legal retention obligation exists.
Erasure of data is notified to the data subject and, where applicable, to our customer.
Cookies and Tracking Technologies
We use cookies and similar technologies to improve user experience, analyse usage, and enhance security.
Users may manage cookies through browser settings.
Where required by law, consent will be obtained before placing non-essential cookies.
Data Breach Notification
In the event of a personal data breach:
Third-Party Processing and Sub-processors
Third-party processing is governed by written agreements ensuring:
• Security safeguards
• Compliance with applicable laws
Cross-Border Data Transfers
Cross-border transfers are carried out using appropriate safeguards, including Standard Contractual Clauses [SCCs] or equivalent mechanisms, and in compliance with applicable law.
Personal data may be transferred to jurisdictions outside the country of collection.
• Standard Contractual Clauses (SCCs)
• Supplementary technical and organisational measures where required
Such processing is governed by a data processing addendum incorporating standard contractual clauses where required.
Data Subject Requests
We will respond within timelines prescribed under applicable law.
Updates to this Privacy Notice
This Privacy Notice may be updated periodically.
Where changes are material, we will notify affected individuals by email or by a prominent notice on our website prior to the changes taking effect.
All updates will be published with a revised effective date.
Contact Information
For questions regarding this notice or additional information about our data handling security measures, contact us at privacy@rivvun.ai.
Individuals may also lodge complaints with:
- Relevant supervisory authorities in the European Union
- The Attorney General or privacy regulator of your State, where a United States State privacy law applies