1. Data controller
- Identity: Raymardev
- NIF (Tax ID): 54093465H
- Address: Calle Picachos, 43, 35200 Telde, Las Palmas, Spain
- Email: support@rivelko.com
- Phone: +34 711 52 93 62
- Controller's website: https://raymartin.es
2. Data we collect
Depending on how you interact with Rivelko, we may collect the following personal data:
2.1. Registered users (Form owners)
- Account data: name, email address, profile picture (provided via Google OAuth or entered manually).
- Billing data: processed directly by Stripe. Rivelko does not store credit card details or bank data.
- Usage data: Forms created, conversation statistics, webhook configurations.
2.2. Visitors (people filling in Forms)
- Form responses:the data the Visitor voluntarily enters when answering the Form's questions (name, email, phone number, etc., as configured by the Form owner).
- Technical data: IP address (to control duplicate submissions), browser and session data.
- Conversations: in conversational Forms, the message history between the Visitor and the AI assistant.
3. Purposes of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Management of user accounts and authentication | Art. 6.1.b — Performance of a contract |
| Provision of the Service (creation and management of Forms) | Art. 6.1.b — Performance of a contract |
| Processing of payments and subscriptions | Art. 6.1.b — Performance of a contract |
| Sending Service notifications (email, webhooks) | Art. 6.1.b — Performance of a contract |
| Collection of Visitor responses on behalf of the Form owner | Art. 6.1.f — Legitimate interest of the owner |
| Generation of AI responses in conversational Forms | Art. 6.1.b — Performance of a contract |
| Fraud prevention and Service security | Art. 6.1.f — Legitimate interest |
4. Data processors (third parties)
To provide the Service, we share data with the following providers, all of which offer adequate data protection safeguards:
| Provider | Service | Location |
|---|---|---|
| Vercel Inc. | Application hosting and deployment | USA (DPF) |
| Neon Inc. | PostgreSQL database | USA (DPF) |
| OpenAI Inc. | Artificial intelligence engine | USA (DPF) |
| Stripe Inc. | Payment processing | USA (DPF) |
| Resend Inc. | Email delivery | USA (DPF) |
| Google LLC | OAuth authentication | USA (DPF) |
DPF = EU-U.S. Data Privacy Framework. These providers are certified under the EU-U.S. Data Privacy Framework, which the European Commission recognizes as providing an adequate level of protection.
5. International transfers
Data may be transferred to servers located in the United States. Such transfers are carried out under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of July 10, 2023) and, where applicable, standard contractual clauses approved by the European Commission.
6. Retention period
- Account data: for as long as the user keeps their account active. Upon account deletion, data is erased within a maximum of 30 days.
- Form responses and conversations: for as long as the Form owner keeps their account active. They are deleted along with the account or when the owner deletes the Form.
- Billing data: the minimum required under Spanish tax law (4 years pursuant to art. 66 of the Ley General Tributaria).
- Technical data (IP, logs): a maximum of 12 months.
7. Data subject rights
Under the GDPR and the LOPDGDD, you have the right to:
- Access: find out what personal data we process about you.
- Rectification: request correction of inaccurate data.
- Erasure:request deletion of your data (the "right to be forgotten").
- Objection: object to the processing of your data.
- Restriction: request restriction of processing.
- Portability: receive your data in a structured, commonly used format.
To exercise these rights, send an email to support@rivelko.com stating your request and attaching a copy of your identity document.
If you believe that the processing of your data does not comply with applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
8. Responsibility of the Form owner
Form owners who collect Visitors' personal data through Rivelko act as the data controller for that data. Rivelko acts as the data processor on behalf of the owner.
The Form owner is responsible for:
- Informing Visitors about the processing of their data in accordance with the GDPR.
- Obtaining the appropriate legal basis for collection.
- Handling Visitors' requests to exercise their rights of access, rectification and erasure.
9. Security
We apply appropriate technical and organizational measures to protect personal data, including:
- Encryption in transit (HTTPS/TLS) across all communications.
- Secure authentication via OAuth 2.0 and JWT tokens with HttpOnly cookies.
- Per-user data isolation (each user can only access their own Forms and responses).
- Domain validation on the widget's public endpoints.
- Encrypted or hashed passwords and API keys.
10. Changes
The Owner reserves the right to modify this Privacy Policy. Any changes will be published on this page with the corresponding update date. We recommend reviewing this policy periodically.