1. Roles
This Data Processing Addendum (“DPA”) supplements the Rivora Finance Terms of Service when a business customer submits personal data to Rivora for processing on its behalf. The customer determines the purposes of processing and Rivora processes the data to provide the service, subject to applicable law.
2. Processing instructions
Rivora will process Customer Data only to provide, secure, support and maintain Rivora; follow documented customer instructions; prevent fraud or abuse; and comply with law. Rivora will not sell Customer Data to advertisers.
3. Confidentiality and security
Rivora will use reasonable technical and organizational safeguards appropriate to the nature of the service. Personnel and contractors with access to protected Customer Data should be subject to confidentiality obligations appropriate to their role.
4. Subprocessors
Rivora may use subprocessors to provide infrastructure and related services. Current categories include web hosting/deployment, database/authentication, identity providers and support infrastructure. Current providers may include Netlify, Supabase, Google and Microsoft depending on the customer’s configuration. Rivora remains responsible for selecting and configuring subprocessors appropriate to the service.
5. Data subject requests
When reasonably possible, Rivora will assist a business customer with requests to access, correct, export or delete personal data processed through the customer’s workspace. Rivora may refer a requester to the relevant business customer when that customer controls the record.
6. Security incidents
Rivora will investigate confirmed security incidents affecting Customer Data and will notify affected business customers as required by applicable law or contract, taking into account the nature and scope of the incident.
7. Return and deletion
Customers should export data they need before ending service. Following termination and subject to legal obligations and backup cycles, Rivora may delete or de-identify Customer Data after a reasonable retention period.
8. International use
Customers are responsible for determining whether their use of Rivora is lawful in the jurisdictions where they operate or where their customers are located. Additional transfer terms may be required for certain international deployments.
9. HIPAA
This DPA is not a Business Associate Agreement. Unless Rivora separately signs a BAA and expressly enables a HIPAA-appropriate service configuration, customers must not submit PHI or use Rivora as a system of record for regulated healthcare information.