Privacy notice
Last updated 20 September 2026
Rivon helps service businesses answer, qualify and quote enquiries. Doing that means handling personal data — about the people who use our dashboard, and about the customers who message them. This notice explains what we hold, why, and what you can ask us to do about it.
The short version
- All data is stored in the European Union (Frankfurt, Germany).
- We never score anyone's ability to pay, credit or financial standing.
- The assistant always says it is an assistant, at the start of every conversation. That cannot be switched off.
- No advertising cookies, no analytics trackers, no selling data to anyone.
- You can ask for a copy of your data, or its deletion, at any time — see Your rights.
1. Who we are
Rivon is a software service for service businesses — solar installers first — that answers incoming enquiries, works out whether a job is feasible, and prepares a quotation.
Rivon is currently operated by its founding team and is not yet incorporated as a company. We will name the legal entity here as soon as it is registered, and tell existing customers when we do. Until then, the contact point for anything in this notice, including any request about your data, is rivonna.ai@gmail.com.
We are in an early stage: Rivon is used by a small number of invited businesses while we build it. The practices described here apply from the moment any real personal data reaches the service.
2. Our two roles
Data protection law distinguishes between deciding why data is processed and merely handling it for someone else. Rivon does both, in different places, and it changes who you should talk to.
| Whose data | Our role | Who decides what happens to it |
|---|---|---|
| People who use the Rivon dashboard — business owners, managers, agents | Controller | We do. |
| People who message a business through WhatsApp, Messenger, Instagram or a web form | Processor | The business they contacted does. We act on that business's instructions and do not use the data for our own purposes. |
So if you messaged a solar installer and want your data removed, the quickest route is to ask that installer. You can also write to us at rivonna.ai@gmail.com and we will pass the request on and support it.
3. Data about business users
If you have a Rivon account, we hold:
| Category | What it includes |
|---|---|
| Account | Email address, a one-way hash of your password (never the password itself), your role, which business you belong to, and when the account was created and last changed. |
| Business configuration | What you enter to set the service up: business name and contact details, address, opening hours, services, rate cards, service areas, stock and crews. Mostly not personal data, though an address or a contact name can be. |
| Technical and security | IP address, browser type and timestamps in our server logs; records of sign-ins, failed sign-in attempts, password resets and session refreshes. |
| Correspondence | Emails and messages you send us, and our replies. |
4. Data about your customers
When someone contacts a business that uses Rivon, we handle the following on that business's behalf:
| Category | What it includes |
|---|---|
| Messages | The conversation itself — what the customer wrote, what the assistant replied, any photos or documents they sent, and the times. |
| Contact details | Whatever the channel provides: a phone number on WhatsApp, a platform-issued identifier and display name on Messenger or Instagram, and a name, email address or phone number if the customer gives one. |
| Enquiry details | What the job needs: postal code, property type, roof type, annual electricity consumption, whether a battery is wanted, timeframe, and whether the customer owns the property. |
| Qualification result | A score representing how well the enquiry fits the business, the inputs that produced it, and the version of the model used — so any score can be explained afterwards. |
| Outcome | Whether the job looks feasible, and the quotation prepared for it. |
Consent to be contacted, where a channel requires it, is recorded with the version of the wording that was shown, so it is always clear what was agreed to and when.
5. What we never do
These are design decisions built into the software, not just promises:
- We never assess anyone's ability to pay, payment history or financial standing. Our scoring looks only at how urgent and complete an enquiry is, and how well it fits what the business does. Creditworthiness assessment is deliberately out of scope.
- We never sell personal data, and we do not share it for anyone else's advertising.
- We never use one business's data for another. Every record is tagged with the business it belongs to, and the database enforces that separation independently of the application.
- We do not use your customers' conversations to train AI models.
- We never hide that a customer is talking to an assistant.
6. Why we may process it
Under the GDPR, each purpose needs a lawful basis. Ours are:
| What we do | Why | Lawful basis |
|---|---|---|
| Run your account and provide the service | You asked us to | Performance of a contract — Art 6(1)(b) |
| Keep the service secure, prevent abuse, keep logs | Protecting the service and its users | Legitimate interests — Art 6(1)(f) |
| Answer support requests | You contacted us | Legitimate interests / contract |
| Keep accounting and tax records | We are required to | Legal obligation — Art 6(1)(c) |
| Handle customer conversations | The business instructed us to | Determined by that business as controller — usually steps taken at the customer's own request, Art 6(1)(b), or legitimate interests |
7. Automated decisions and AI
Rivon uses automation in two places, and we think it matters that you understand exactly where.
Prices and feasibility are calculated, not generated. Every number in a quotation comes from arithmetic on the rate card the business entered. No language model produces a price, a system size or a feasibility verdict. The assistant writes the words around numbers that ordinary code has computed.
Scoring never decides anything on its own. An enquiry gets a score for intent, urgency, completeness and fit. It is a sorting aid for the business, not a verdict on a person. We store the inputs and the model version behind every score so it can be explained on request.
No enquiry is finally rejected by a machine. Where a job looks unfeasible, the outcome is either confirmed by a person at the business or recorded as provisional with a route to human review. You will not be turned away by software with nobody to appeal to.
The assistant identifies itself. At the start of every conversation, customers are told they are talking to an automated assistant, and that disclosure is logged. Businesses using Rivon cannot disable it. A human can take over a conversation at any point.
9. Where data is stored
Everything Rivon stores sits in the European Union — specifically Frankfurt, Germany. The database, the application servers, file storage and the web front end are all hosted there. Businesses are tagged with their region, and data belonging to an EU business stays in the EU.
10. How long we keep it
| What | How long |
|---|---|
| Your account and business configuration | While the account is open, then 30 days |
| Customer conversations, enquiries and quotations | As instructed by the business that owns them. Where no instruction is given, 24 months from the last message |
| Security and server logs | 90 days |
| Backups | 30 days, after which they are overwritten |
| Accounting records | As long as tax law requires |
A deletion request is honoured within backups' normal rotation: the live data goes immediately, and backup copies age out within 30 days.
11. How we protect it
- Everything travels over encrypted connections, and is encrypted at rest.
- Passwords are stored as one-way hashes using a modern algorithm. Nobody at Rivon can read your password.
- Access tokens for connected WhatsApp, Messenger and Instagram accounts are encrypted separately before they reach the database.
- Each business's data is separated at the database level as well as in the application, so a bug in one layer cannot expose another business's records.
- Session cookies are HTTP-only and cannot be read by scripts in the browser.
- Access to production systems is limited to the people who need it.
If a breach ever occurs that is likely to put people at risk, we will notify the relevant supervisory authority within 72 hours and tell those affected without undue delay.
12. Your rights
If you are in the EU or the UK, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, where there is no overriding reason to keep it.
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable form, or have it sent elsewhere.
- Objection — object to processing based on legitimate interests, including being profiled or scored.
- Withdraw consent at any time, where processing relies on it. This does not undo what was done beforehand.
- Complain to your national data protection authority. You can do this whether or not you contact us first.
Write to rivonna.ai@gmail.com. We respond within one month, and will tell you if a request needs longer. There is no charge unless a request is clearly excessive. If you contacted a business through Rivon rather than holding an account, see Our two roles first.
13. Deleting your data
Full instructions are on their own page: Delete your data. In short, email rivonna.ai@gmail.com with the subject line “Data deletion”, and:
- if you have a Rivon account, the email address on it; or
- if you messaged a business through WhatsApp, Messenger or Instagram, the phone number or account you messaged from, and roughly which business you contacted.
We will confirm receipt, give you a reference so you can check progress, and complete the deletion within 30 days. Live records go immediately; backup copies are overwritten on their normal 30-day cycle.
If you connected a Facebook Page or Instagram account to Rivon, you can also remove Rivon's access at any time from your Meta Business Settings, under connected business integrations. Doing so stops us acting on that account immediately. It does not by itself delete data already stored, so send the email as well if that is what you want.
15. Children
Rivon is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, tell us at rivonna.ai@gmail.com and we will delete it.
16. Changes to this notice
We update this notice when the service changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect rather than relying on you to check this page.
17. Contact us
For anything in this notice — a question, a request about your data, or a complaint — email rivonna.ai@gmail.com. We read everything that arrives there.
We have not appointed a data protection officer, as we are not required to. Requests go to the same address and are handled by the founding team.
This notice was last updated on 20 September 2026.