This Privacy Notice is issued by Rivvun AI Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808 (“we”, “us”, “our”). It explains how personal data is collected, used, processed, stored, and shared in connection with website interactions and enquiries, as well as the Rivvun AI application through integration with client’s Enterprise Systems and chosen LLM Providers. We are committed to protecting personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act, 2023 (DPDP Act). For the purposes of this Privacy Policy, “customers” refer to organisations or legal entities that license and use our software, and not individual end users unless expressly stated. References to customers do not include individual users, employees, or representatives whose personal data may be processed in different capacities.
Section 01
Scope and Categories of Data Collection
Data Controller / Data Fiduciary
We act as a data controller (under GDPR) / data fiduciary (under DPDP Act) in relation to personal or other data that we collect directly from individuals. This includes visitors to our website, prospective customers submitting enquiries or requesting demonstrations, and representatives of customers or business partners. In this capacity, we determine the purposes and means of processing, ensuring it is carried out in a lawful, fair, and transparent manner.
Data Processor Role
We act as a data processor when providing our Rivvun AI software and related services to our customers (organisations or legal entities using our software). In this context, customers act as data controllers/data fiduciaries, and we process data solely on their behalf and per their documented instructions. Our obligations include implementing appropriate security measures, assisting with data subject rights/breach notifications, and managing sub-processors under written agreements with customer authorization.
Data Collected Directly from Individuals
We collect limited personal data necessary for business communication and service delivery, including full name, email address, and phone number. This data is collected through website forms, demo requests, and business communications.
Data Collected Automatically
When individuals interact with our website or services, we may collect IP addresses, device type, browser type, operating system, date and time of access, and pages viewed or interaction patterns. This data is used for analytics, system administration, security monitoring, and service improvement.
Data Processed on Behalf of Clients
As part of our Services, we process personal data uploaded or input by customers, which may include employee or authorised user details, vendor, lessor, or counterparty information, financial or transactional data linked to identifiable individuals, and hard copy documents (agreements, contracts, KYC verification, etc.) uploaded to support application processing. We process such data strictly on behalf of our customers and do not determine the purposes or means of processing.
Section 02
How We Use Your Information
We process personal data for specific operational purposes and under established legal frameworks:
Purposes of Processing
Data is utilized for managing enquiries and product demonstrations, facilitating onboarding and customer relationship management, delivering, operating, maintaining, and improving our Services, ensuring system integrity, security, and fraud prevention, and complying with applicable legal, regulatory, and contractual obligations. We do not process data for incompatible purposes without appropriate notice and consent where required. We also identify Personal Information for product development and improvements.
Legal Basis Under GDPR
We rely on one or more of the following legal bases: Consent, Contractual necessity, Legal obligations, and Legitimate interests.
Legal Basis Under DPDP Act
We process personal data based on consent obtained through clear affirmative action or legitimate uses permitted under applicable law. Before obtaining consent, we provide a notice specifying data categories, processing purpose, rights exercise, and consent withdrawal paths. This notice is standalone (not bundled with T&Cs) and available in English or any Eighth Schedule language on request.
Children’s Personal Data
GDPR Art. 8 requires parental or guardian consent before processing personal data of children under 16 (EU member states may lower this to 13). The DPDP Act S.9 prohibits processing children's personal data (under 18) without verifiable parental consent, and completely prohibits behavioural monitoring and targeted advertising directed at children. Our website and services clearly state whether data is collected from minors.
Section 03
Disclosure of Personal Information
We share personal data only with authorized categories of recipients under strict contractual compliance standards:
Authorized Categories of Recipients
We may share personal data with cloud hosting and infrastructure providers, CRM and customer support tools, professional advisors (legal, audit, compliance), and regulatory authorities or law enforcement agencies where required. All recipients are contractually bound to ensure confidentiality, security, and compliance with data laws. We do not share personal data for third-party marketing purposes.
Third-Party Processing & Sub-processors
Third-party processing is governed by written agreements ensuring confidentiality, security safeguards, and compliance with laws. We remain responsible for ensuring sub-processors meet required standards. A current list of sub-processors is available upon request. We collect, use, share, and retain data only as authorized by data controllers or data subjects.
Business Successors
In the case of our merger or acquisition by another entity, we allow a successor entity to maintain the personal information, provided the successor entity is subject to these same commitments for the previously collected personal information.
Section 04
International Data Transfers
Personal data may be transferred to jurisdictions outside the country of collection. Cross-border transfers are carried out using appropriate safeguards, including Standard Contractual Clauses [SCCs] or equivalent mechanisms, and in compliance with applicable law:
EEA Originating Data
Where personal data originates from the European Economic Area (EEA), we implement Standard Contractual Clauses (SCCs) along with supplementary technical and organisational measures where required.
Transfers from India
Transfers from India are undertaken in accordance with applicable law under the DPDP Act. Cross-border movements generally rely on the robust security and transfer protections outlined in Section 7 of this Notice.
Section 05
Data Security and Retention
Data Security Measures
We implement a comprehensive security program with technical and organisational measures. This includes encryption in transit and at rest, strict access controls and authentication mechanisms on a need-to-know/least-privilege basis, system monitoring, logging, and audit trails, and periodic vulnerability assessments. We maintain administrative, technological, and physical safeguards and obtain third-party attestation of our alignment with applicable regulations.
Data Hosting & Accounts
All data is securely and exclusively hosted in SOC2 compliant data centres. User roles are clearly defined to manage access levels, and data is protected by a password for data subject/principal/controller privacy. Users can protect against unauthorized access by selecting strong passwords and signing off after finishing. We endeavour to protect account privacy; however, we cannot guarantee absolute security against hardware/software failures or unauthorized entry. Data is stored and processed as per local regulatory requirements.
Data Breach Notification
In the event of a personal data breach, we take prompt steps to contain and mitigate the incident. We will notify the relevant supervisory authority within 72 hours of becoming aware under GDPR Art. 33. Notification to the Data Protection Board of India is required under DPDP Act S.8(6) in the prescribed manner (or we will notify data principals/controllers electronically to allow protective steps). We may post a notice on the Site and inform affected individuals directly if there is a risk to their rights and freedoms.
Data Retention
We retain personal data only for as long as necessary: Enquiry/contact data is kept up to [6–12 months], unless converted into a business relationship; Customer data is retained as per contractual terms and customer instructions; and Legal/compliance data is held as required by laws. Upon expiry, personal data is securely deleted, anonymised, or archived. Remnants may temporarily remain stored in backup systems or cached/archived pages.
Section 06
Your Privacy Rights
Rights Under GDPR
Individuals have the following rights under GDPR: Access (Art. 15), Rectification (Art. 16), Erasure / Right to be Forgotten (Art. 17), Restriction of processing (Art. 18), Data portability (Art. 20), Objection (Art. 21), and rights relating to automated decision-making and profiling (Art. 22). We maintain processes to respond to requests within one (1) month.
Rights Under DPDP Act
Data Principals have the Right to obtain a summary of personal data processed and activities (S.11), Right to correction, completion, updating, and erasure (S.12), Right of grievance redressal (S.13) with prompt acknowledgment, and Right of Nomination to designate an individual to exercise data rights in the event of death or incapacity (S.14). A mechanism is provided for Data Principals to register nominations. Requests are addressed within reasonable or legally prescribed timelines. Processes exist to act against impersonation and false grievances.
Consent Withdrawal & Corrections
Individuals may withdraw consent at any time where processing is based on consent, without affecting prior lawful processing. On withdrawal, we immediately stop processing related data and erase it unless a legal retention obligation exists. Erasure is notified to the data subject/principal and/or customer. We support access and correction of data by assisting the Data Controller / Data Fiduciary in fulfilling rights obligations.
Section 07
Third-Party Links & Cookies
Cookies and Tracking Technologies: We use cookies and similar technologies to improve user experience, analyse usage, and enhance security. Users may manage cookies through browser settings. Where required by law, consent will be obtained before placing non-essential cookies.
Links to Third Party Sites or Apps: The Site may contain links to websites and apps operated and maintained by third parties, over which we have no control. Privacy policies on linked sites may be different from ours. Accessing such linked sites is at your own risk, and you should always read the privacy policy of a linked site before disclosing information. We are not responsible for the practices employed by websites, applications, or services linked to or from our Site.
Section 08
Updates to This Statement
This Privacy Notice may be updated periodically. Where changes are material, we will notify affected individuals by email or by a prominent notice on our website prior to the changes taking effect. All updates will be published with a revised effective date.
Section 09
Contact Information
For questions regarding this notice or additional information about our data handling security measures, contact us at privacy@rivvun.ai:
Individuals may also lodge complaints with:
- Relevant supervisory authorities in the European Union
- Data Protection Board of India