Legal

Data processing agreement

Effective 11 September 2026

This data processing agreement ("DPA") applies automatically to every Rivilo customer account and forms part of the Terms of service. A signed copy is available on request via getintouch@rivilo.app.

1. Parties and roles

Controller: the customer, being the organisation or person that holds the Rivilo account and decides which mailboxes, channels and content Rivilo processes.

Processor: Future Ready Design B.V., trading as Rivilo, Raadhuisstraat 20-22, 1016 DE Amsterdam, The Netherlands, KvK 92339867.

Where Rivilo processes personal data of the customer's own users for account, billing and security purposes, Rivilo acts as an independent controller as described in the Privacy policy. This DPA covers all other processing.

2. Subject matter, nature and purpose

Rivilo processes personal data on the controller's behalf in order to: read the mailboxes, channels and documents the controller connects; turn client requests into cards on boards; draft replies and documents for the controller's approval; post updates to the controller's chat channels; and retain the context the controller asks Rivilo to remember. Processing is automated, with human access by the processor only as set out in section 6.

3. Duration

This DPA applies for as long as the controller holds a Rivilo account and until the data has been deleted or returned under section 11.

4. Types of personal data and categories of data subjects

  • Data subjects: the controller's team members and users; the controller's clients, prospects, suppliers and other correspondents; participants in meetings the controller records.
  • Personal data: names, email addresses, job titles and organisations; the content and metadata of emails, chat messages, meeting transcripts and documents the controller connects; cards, notes and decisions the controller's team creates; calendar entries.
  • The controller shall not use Rivilo to process special categories of personal data (GDPR Art. 9) or data relating to criminal convictions.

5. Controller's instructions

Rivilo processes personal data only on the controller's documented instructions, which consist of the Terms, this DPA, the settings the controller chooses in the application (which mailboxes, boards, channels and models to use) and the actions the controller approves. Rivilo will inform the controller if an instruction, in its opinion, infringes the GDPR. Rivilo never sends, signs or charges anything on the controller's behalf without a person approving it.

6. Confidentiality and access

Persons authorised by Rivilo to process personal data are bound by confidentiality. Human access to the controller's content is limited to the founder and any engineer under confidentiality obligations, and only for support the controller has requested, for security or abuse investigations, or where required by law. Rivilo does not read the controller's content to train models or for any purpose of its own.

7. Security measures (GDPR Art. 32)

Taking into account the state of the art and the risks involved, Rivilo implements at least the following measures:

  • encryption of data in transit (TLS) and at rest, on Google Cloud infrastructure in the EU (europe-west1);
  • per-user OAuth tokens with the least-privilege scopes named in the Privacy policy; tokens are revoked when a connection is disconnected;
  • owner-scoped access rules enforced in the database, so that team members only see boards they have been given access to;
  • logging of application errors without storing mailbox content in logs;
  • separation of customer data by account identifier; no shared credentials across customers;
  • regular dependency updates and review of the security rules on change.

Rivilo does not currently hold a SOC 2 or ISO 27001 certification and has not yet commissioned an external penetration test. Rivilo will inform the controller when this changes.

8. Subprocessors

The controller gives general authorisation for the subprocessors listed in the Privacy policy (Google Cloud / Firebase, Mistral AI, Anthropic PBC, Microsoft, Slack, Fireflies.ai, Resend, Netlify), each engaged only where the controller uses the related feature. Rivilo imposes data protection obligations on each subprocessor equivalent to those in this DPA and remains liable for their performance. Rivilo notifies the controller by email at least 14 days before adding or replacing a subprocessor that processes the controller's content; the controller may object on reasonable grounds within that period, in which case the parties will seek a solution and, failing that, the controller may terminate the affected service.

9. International transfers

Personal data is stored within the European Union. AI processing via Anthropic, and Fireflies where connected, or where transactional email is delivered via Resend, personal data may be transferred to the United States. Such transfers take place under the EU Standard Contractual Clauses (Commission Decision 2021/914) or an applicable adequacy decision, and Rivilo will provide copies of the relevant terms on request.

10. Assistance to the controller

Rivilo assists the controller, taking into account the nature of the processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) and, where relevant, with data protection impact assessments and prior consultation. Requests received directly by Rivilo from the controller's data subjects are forwarded to the controller without undue delay.

11. Deletion and return

At the end of the service, or on the controller's request, Rivilo deletes or returns all personal data processed on the controller's behalf within 30 days and deletes existing copies, unless retention is required by law. Disconnecting a mailbox or channel in the application revokes Rivilo's access to it immediately; mailbox content itself is never copied in full and remains in the controller's own mailbox.

12. Personal data breaches

Rivilo notifies the controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the controller's data, by email to the account holder. The notification describes the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact. Rivilo cooperates with the controller in the controller's notifications to supervisory authorities and data subjects.

13. Audit

Rivilo makes available to the controller the information necessary to demonstrate compliance with this DPA, including this document, the Privacy policy and, on request, a written description of the measures in section 7 and copies of subprocessor terms. The controller may, at its own cost and with at least 30 days written notice, conduct or mandate an audit once per calendar year, during business hours, in a manner that does not unreasonably disrupt Rivilo's operations, subject to confidentiality.

14. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of service, without prejudice to the parties' liability under the GDPR towards data subjects and supervisory authorities. In case of conflict between this DPA and the Terms, this DPA prevails for matters of data protection.

15. Governing law

This DPA is governed by the laws of the Netherlands. Disputes are submitted to the competent court in Amsterdam.

16. Contact

Future Ready Design B.V. (Rivilo) · Raadhuisstraat 20-22, 1016 DE Amsterdam · getintouch@rivilo.app