- Who we are
- Our role and your workspace's role
- What we collect
- Phone permissions the app asks for
- How we use data
- AI features
- Who we share data with
- How long we keep data
- Security
- Where data is stored
- Your rights and choices
- Children
- Changes to this policy
- Contact
Who we are
Rivenza is a customer messaging platform made up of the dashboard at rivenza.app and the Rivenza mobile apps for iOS and Android (together, the "Service"). It is operated by TechMaxima India Private Limited, a company registered in Chennai, Tamil Nadu, India ("we", "us"). This policy applies to the Service and to this website.
Our role and your workspace's role
The Service is used through workspaces. A workspace is set up by a business or agency (the "workspace owner") for its own team and its customers. The workspace owner decides which channels to connect, who may sign in, and what customer data enters the Service. For that content, the workspace owner is the data controller and we process it on their instructions under our agreement with them.
For the data we need to run your account and the Service itself, such as your login details, device information and usage records, we are the data controller.
What we collect
- Account data
- Name, email address, phone number, role, profile picture and language preference. Passwords are stored as salted hashes and are never readable by us.
- Workspace content
- Conversations and attachments received and sent on connected channels, contacts and their attributes, notes, tickets, bot flows, knowledge base material and campaign content. This is created by the workspace's customers and team, and controlled by the workspace owner.
- Device and app data
- Device model, operating system version, app version, app identifier, language, time zone, push notification token, IP address and the times you use the Service.
- Usage records
- Which features are used and when, message counts, API calls and similar records needed to operate, secure and bill the Service.
- Error and performance reports
- If the app or dashboard fails, a report with the error, the device type and the app state at that moment is sent to our own error-tracking server. Reports do not include message content.
- Support correspondence
- What you send us when you write to support, so we can answer and keep a record.
Phone permissions the app asks for
Each permission is requested only when you first use the feature that needs it, and the app works without it apart from that feature.
- Notifications
- To alert you to new messages and assignments. We store the push token issued by Apple or Google for your device.
- Camera and photos
- To attach photos, videos and documents you choose to a conversation. Nothing is uploaded until you send it.
- Microphone
- For voice messages and calls. Audio is sent only while you record or are on a call.
- Contacts
- Only if you use "sync device contacts". The entries you select are added to your workspace's contact hub. We do not read your address book otherwise.
- Keyboard (AI Keyboard)
- The keyboard sends the text you ask it to draft, rewrite or translate to the Service to produce the result, and receives the result back. It does not record or store keystrokes typed in other apps, and the operating system prevents it from reading secure fields such as passwords. On iPhone, the "Allow Full Access" setting is required for the keyboard to reach the network.
- Phone and calls (iPhone CallKit, Android foreground service)
- To ring and hold a WhatsApp call like a normal phone call. Call audio goes through Meta's WhatsApp infrastructure; we do not record calls.
How we use data
- To provide the Service: deliver and display messages, run bots, sync contacts and produce reports for the workspace.
- To send notifications you have opted into.
- To generate AI suggestions when you or your workspace's bots use an AI feature (see below).
- To keep the Service secure, prevent abuse and spam, and enforce our terms and the policies of the messaging platforms we connect to.
- To answer support requests and send service notices about your account or workspace.
- To measure and improve the Service using aggregated usage records.
We do not sell personal data. We do not use workspace content for advertising, and we do not show advertising in the Service.
AI features
AI features such as AI agents, reply drafts, summaries, translations and the AI keyboard send the relevant text, together with the workspace's knowledge base material and configured instructions, to AI model providers we contract with (currently OpenAI, Anthropic and Google) through their business APIs. Those API terms do not allow the providers to use the data to train their models. Text is sent only when an AI feature is used, and the result is returned to the workspace. Each AI response in a conversation is logged with the sources it drew on so the workspace can review it.
Who we share data with
We share personal data only as needed to run the Service:
- The workspace owner and its team. Content in a workspace is visible to the members the owner has invited, according to their roles.
- Messaging platforms. Meta Platforms (WhatsApp, Instagram, Facebook Messenger), Telegram, and SMS and voice carriers through Twilio, to deliver the messages and calls you send and receive. Their own policies apply to what happens on their networks.
- Infrastructure providers. Amazon Web Services for hosting, storage and email delivery; Google (Firebase Cloud Messaging) and Apple for push notifications.
- AI model providers as described above.
- Integrations the workspace owner connects, such as a CRM or spreadsheet, which receive the data the owner's bot flows or settings send to them.
- Legal requirements. When required by law, a court order or a regulator, or to protect the rights and safety of users and the Service.
- Business transfers. If TechMaxima India Private Limited is part of a merger or acquisition, data may transfer to the successor under this policy.
How long we keep data
- Account data: for as long as your account exists, then deleted within 90 days of closure.
- Workspace content: for as long as the workspace owner keeps it. The owner can delete conversations and contacts at any time. When a workspace is closed, its content is deleted from active systems within 90 days.
- Usage and billing records: up to 7 years where required by tax and accounting law.
- Error reports: 90 days.
- Backups: roll off on a fixed schedule within 30 days after deletion from active systems.
Security
Data is encrypted in transit with TLS and at rest on our storage. Access to production systems is restricted to named staff with multi-factor authentication and is logged. Workspaces are isolated from one another. We review access and dependencies regularly and act on vulnerability reports sent to support@rivenza.app. No system is perfectly secure; if a breach affects your data we will notify the workspace owner and, where required, you and the relevant authority without undue delay.
Where data is stored
The Service is hosted on Amazon Web Services in the Asia Pacific (Mumbai) region, India. Messaging platforms, push notification services and AI providers process data in their own regions, which may include the United States and the European Union. Where data leaves the country it was collected in, we rely on the contractual safeguards those providers offer, including standard contractual clauses for data from the European Economic Area and the United Kingdom.
Your rights and choices
Depending on where you live, including under India's Digital Personal Data Protection Act 2023, the EU and UK GDPR, and state laws in the United States, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it.
- For content in a workspace, contact the workspace owner first, since they control it. We will help them respond.
- For your account data, write to support@rivenza.app from your registered email address. We confirm within 7 days and complete requests within 30 days.
- You can turn off notifications, revoke any phone permission and remove the AI keyboard in your phone's settings at any time.
- You may complain to your local data protection authority. We would appreciate the chance to resolve the issue first.
Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, write to us and we will delete it.
Changes to this policy
We may update this policy as the Service or the law changes. The effective date at the top shows the current version. For material changes we notify workspace owners by email and show a notice in the dashboard before the change takes effect.
Contact
TechMaxima India Private Limited
Chennai, Tamil Nadu, India
support@rivenza.app