Services How it works Pricing Making Tax Digital
Back to homepage

Privacy Policy

Last updated:

1. Who we are

Rivt ("we", "us", "our") is a business systems and web design service based in Bristol, UK. We build and maintain bespoke business systems for small businesses — including websites, automations, follow-ups, payments, and marketing.

Data controller: Rivt is a trading name of Mr Lee Petford, a sole trader.
Contact: info@rivt.co.uk
Location: Bristol, United Kingdom

2. What this policy covers

This policy explains how we handle personal data for which we are the data controller — for example, when you visit this website, submit an enquiry, book a discovery call, or communicate with us directly.

When we build and operate business systems for our clients, we act as a data processor on their behalf and process their customers' data under a separate data processing agreement with each client. That processing is governed by our clients' own privacy policies, not this one.

3. What data we collect

We may collect the following personal data when you interact with our website or services:

  • Contact information — your name, business name, email address, and phone number when you submit an enquiry or book a call.
  • Communication data — the content of messages you send us via email, WhatsApp, SMS, or our contact forms, including any photos or files you choose to send.
  • Enquiry details — information you provide about your business and the problems you would like help with, including answers to questionnaires such as our Making Tax Digital readiness quiz.
  • Agreement data — where you accept a quote online, your name, the date, and your electronic signature.
  • Technical data — your IP address, browser type, operating system, and pages visited. This is collected automatically by our hosting provider and by anti-spam protection on our forms.
  • Usage data — aggregated, anonymised information about how visitors interact with our website, collected via privacy-friendly analytics.

We do not knowingly collect special category data (such as health information) through this website. Payment card details are entered directly with our payment provider and are never seen or stored by us (see section 7).

4. How we collect your data

We collect data through:

  • Enquiry, booking, quiz, and quote-acceptance forms on this website (powered by Fillout, which includes its own spam protection)
  • Direct email, WhatsApp, and SMS communications (WhatsApp and SMS are handled via our messaging provider, Twilio)
  • Automatic technical data collection by our hosting provider (Cloudflare)
  • Privacy-friendly website analytics

5. How we use your data

We use your personal data to:

  • Respond to your enquiries and arrange discovery calls
  • Provide and manage the services you have requested, including preparing and issuing quotes and invoices
  • Send you relevant updates about your project or our services (only where you have consented or it is necessary to fulfil a contract)
  • Improve our website and services using aggregated, anonymised analytics data
  • Keep our systems secure and prevent spam and fraud
  • Comply with our legal obligations

6. Legal basis for processing

Under UK GDPR and the Data Protection Act 2018, we process your personal data on the following legal bases:

  • Contract — processing is necessary to enter into or fulfil a contract with you.
  • Legitimate interests — responding to enquiries, improving our services, keeping our systems secure, and running our business, where these interests are not overridden by your rights.
  • Consent — where you have given us explicit consent (e.g. to send marketing communications). You may withdraw consent at any time.
  • Legal obligation — where we are required to process data to comply with the law.

7. Who we share your data with

We do not sell your personal data. We share it only with trusted service providers who help us operate our business, and only the minimum data necessary for each service:

  • Fillout (USA) — form processing for enquiries, bookings, quizzes, and quote acceptance. Fillout provides its own spam protection (Google reCAPTCHA) within its forms.
  • Airtable (USA) — our secure database for managing enquiries, projects, and communications
  • Twilio (USA) — sending and receiving WhatsApp and SMS messages
  • Meta Platforms (WhatsApp) (USA) — where you contact us via WhatsApp
  • Amazon Web Services (London, UK region) — hosting for our automation systems and encrypted backups
  • Cloudflare — website hosting, security, content delivery, and privacy-friendly, cookieless website analytics
  • Google (USA) — business email and calendar (Google Workspace) that we use to correspond with you
  • FreeAgent (UK) — invoicing and financial record-keeping
  • Stripe (USA) — card payment processing. When a payment is made, Stripe collects payment and billing details directly from the payer and processes them under Stripe's own privacy policy. We do not see or store card details.

All providers are required to handle your data securely and in accordance with applicable data protection law.

We may also disclose your data if required to do so by law or in response to valid legal requests.

8. International data transfers

We keep our core systems and backups within the United Kingdom wherever possible. However, some of the service providers listed above are based in, or store data in, countries outside the UK (primarily the United States).

Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — such as an adequacy decision by the UK government, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — so that your data continues to receive an equivalent level of protection.

9. How long we keep your data

We retain personal data only for as long as necessary for the purposes set out in this policy:

  • Enquiries that do not become projects — up to 12 months, then deleted.
  • Active or past client data — for the duration of our engagement and up to 6 years afterwards, in line with HMRC record-keeping requirements.
  • Message logs — WhatsApp and SMS activity is kept in a rolling log for 14 days and then automatically deleted, unless it forms part of a client project record.
  • Technical/log data — typically 30–90 days as determined by our hosting provider.

10. Cookies and analytics

We keep tracking to a minimum. Our website analytics are provided by Cloudflare, which is privacy-friendly and does not use cookies or collect any personally identifiable information — it only measures aggregated, anonymised traffic.

We do not use advertising or third-party tracking cookies. Any cookies we do use are strictly necessary for the website or embedded forms to function correctly. You can control cookies through your browser settings; disabling essential cookies may affect the functionality of the site.

11. How we keep your data secure

We take appropriate technical and organisational measures to protect your personal data. These include encrypted storage and backups, hosting our core systems in the UK, restricting access to authorised personnel, and using a secure password manager for credentials.

12. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where there is no legitimate reason to continue processing it.
  • Restriction — ask us to restrict how we process your data in certain circumstances.
  • Portability — request that we transfer your data to another organisation or directly to you.
  • Objection — object to processing based on legitimate interests or for direct marketing purposes.
  • Withdraw consent — where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at info@rivt.co.uk. We will respond within 30 days. There is no charge for most requests.

13. Children's privacy

Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected such data, please contact us and we will delete it.

14. Data breaches

We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, inform you without undue delay.

15. Complaints

If you are unhappy with how we have handled your data, please contact us first at info@rivt.co.uk and we will do our best to resolve it.

You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO):

16. Changes to this policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "last updated" date. We encourage you to review this policy periodically.