Legal

Privacy Policy

Last updated: July 23, 2026

What we collect

We collect only what the service needs to work:

  • account data — name, email, authentication details;
  • organization data — company details, members, roles and settings;
  • financial data you bring in — invoices, clients, bank transactions synced read-only through regulated open-banking providers, or imported by you;
  • documents you upload — receipts, contracts, statements;
  • usage and technical data — logs needed for security and reliability.

How we use it

We use your data to provide the service: syncing and categorizing transactions, matching receipts, generating reports and powering the AI assistant. We also use it for billing, support and security.

We do not sell your data, and we do not use it for advertising.

AI processing

Some features send relevant excerpts of your data to AI model providers under data-processing agreements. Your data is not used to train their models. Access is always scoped to your organization, and every AI action is logged.

Processors and sharing

We share data only with processors needed to run the service, under GDPR-compliant agreements:

  • payments — Stripe;
  • bank connectivity — regulated PSD2 open-banking providers;
  • hosting and storage — EU-based cloud infrastructure;
  • transactional email, document OCR and AI model providers.

Your rights

Under the GDPR you can request access, correction, deletion, portability, or restriction of processing, and you can object to processing based on legitimate interest. Write to privacy@rivantir.com and we will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority.

Retention and security

We keep your data while your organization is active and as long as the law requires afterwards. Data is encrypted in transit and at rest, scoped to your organization, and bank connections are strictly read-only — Rivantir never holds credentials that could move money.