All policies

Data Processing Addendum

The processor terms, for customers who need one on file. Template — review before signing. · Last updated 2026-09-28

This Addendum forms part of the Terms of Service between [LEGAL ENTITY NAME] ("Processor") and the customer ("Controller"). It applies where the Processor processes personal data on the Controller's behalf under UK GDPR, EU GDPR, or both.

1. Roles and subject matter

The Controller determines the purposes and means of processing prospect data. The Processor processes it only on the Controller's documented instructions, which for these purposes are the Terms of Service, this Addendum, and the configuration the Controller sets in the Service.

2. Nature and duration

  • Subject matter: provision of the rivomi prospecting and outreach service.
  • Duration: for the term of the Terms of Service, plus the 30-day deletion window.
  • Categories of data subject: LinkedIn users who publicly engage with content the Controller has chosen to monitor, and people the Controller contacts.
  • Categories of personal data: name, public profile URL and identifier, headline, job title, employer, industry, company size, location, public profile summary, public comments and reactions, message content exchanged with the Controller, and derived scores and drafts.
  • Special category data: none is requested or required. The Controller must not configure the Service to target special category data.

3. Processor obligations

  • Process only on documented instructions, and tell the Controller if an instruction appears to breach applicable law.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the Controller with data subject requests, impact assessments and consultations with supervisory authorities, taking into account the nature of the processing.
  • Notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach.
  • Delete or return personal data at the end of the service, per section 7.
  • Make available the information needed to demonstrate compliance and allow audits, per section 8.

4. Sub-processors

The Controller gives general authorisation for the sub-processors listed on this page. The Processor will give at least 30 days' notice before adding or replacing one, and the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate without penalty. The Processor remains liable for its sub-processors' acts and omissions.

5. International transfers

Where personal data is transferred outside the UK/EEA, the parties incorporate the EU Standard Contractual Clauses (Module Two, controller to processor) and, for UK transfers, the UK International Data Transfer Addendum, in each case with the docking clause enabled and the Processor as data importer.

6. Security measures

  • Data isolated per workspace at the database level; every query is scoped to the workspace and the isolation is verified by an automated test suite on every change.
  • Encryption in transit (TLS 1.3) and at rest. LinkedIn credentials, where stored, are additionally encrypted with AES-GCM under a separate key.
  • Access control: role-based within a workspace; staff access to production requires a named platform-admin role, and every such action is written into the customer's own audit log.
  • Logging: an immutable per-workspace audit log of configuration changes, approvals, exports and deletions.
  • Backups: 30-day point-in-time recovery plus weekly off-database snapshots.
  • Secrets held in the platform secret store, never in source control.

7. Deletion and return

The Controller can export all workspace data as CSV at any time from within the Service. On termination or on request, data is deleted within 30 days, and from backups within a further 60 days as they age out.

8. Audit

The Processor will respond to reasonable written information requests within 30 days. On-site audits may be requested once in any 12-month period, on 30 days' notice, during business hours, and subject to confidentiality — or satisfied by an independent report where one is available.

9. Liability

Liability under this Addendum is subject to the limitations in the Terms of Service, except where applicable data protection law does not permit that.

Changes

We may update this document. Material changes are announced in the product and by email to workspace owners at least 14 days before they take effect. The date at the top is the version in force.

Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Questions about this document: [legal@yourdomain].

Sub-processors

Everyone we send customer data to, and why. Changes are announced 30 days in advance.

ProviderPurposeLocationData
CloudflareApplication hosting, database (D1), object storage, CDN, DDoS protectionGlobal (edge)All service data
UnipileLinkedIn account connection, invitations, messages, inbox syncEU (France)LinkedIn account credentials/session, message content, contact identifiers
ApifyPublic LinkedIn profile and post data collectionEU (Czechia) / USPublic profile URLs and the profile data returned
ScrapeCreatorsPublic LinkedIn post metadata and profile enrichmentUSPublic profile and post URLs and the data returned
Google (Vertex AI / Gemini)Scoring prospects, drafting messages, reading company websitesUS / EUProspect profile text, your company profile, post text
ResendTransactional and notification emailUS / EUAccount email addresses and message content
PostHogWebsite and product analytics, session replay, error reportsUSPages viewed, clicks, referrer and campaign parameters, device and approximate location, account and workspace identifiers; replays with form inputs and workspace data masked