Legal
Privacy Policy
Last updated: July 23, 2026
What we collect
We collect only what the service needs to work:
- account data — name, email, authentication details;
- organization data — company details, members, roles and settings;
- financial data you bring in — invoices, clients, bank transactions synced read-only through regulated open-banking providers, or imported by you;
- documents you upload — receipts, contracts, statements;
- usage and technical data — logs needed for security and reliability.
How we use it
We use your data to provide the service: syncing and categorizing transactions, matching receipts, generating reports and powering the AI assistant. We also use it for billing, support and security.
We do not sell your data, and we do not use it for advertising.
AI processing
Some features send relevant excerpts of your data to AI model providers under data-processing agreements. Your data is not used to train their models. Access is always scoped to your organization, and every AI action is logged.
Processors and sharing
We share data only with processors needed to run the service, under GDPR-compliant agreements:
- payments — Stripe;
- bank connectivity — regulated PSD2 open-banking providers;
- hosting and storage — EU-based cloud infrastructure;
- transactional email, document OCR and AI model providers.
Your rights
Under the GDPR you can request access, correction, deletion, portability, or restriction of processing, and you can object to processing based on legitimate interest. Write to privacy@rivantir.com and we will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority.
Retention and security
We keep your data while your organization is active and as long as the law requires afterwards. Data is encrypted in transit and at rest, scoped to your organization, and bank connections are strictly read-only — Rivantir never holds credentials that could move money.