PRIVACY POLICY
NexTech Advisors, LLC, doing business as Rivvet AI (“Rivvet,” “we,” “us,” or “our”), is a Utah limited liability company that provides AI-powered marketing automation, AI receptionist, and Hosted Commerce Services to business clients. This Privacy Policy applies to rivvetai.com, app.rivvetai.com, and all Rivvet AI Services.
1. WHO WE ARE
NexTech Advisors, LLC, doing business as Rivvet AI (“Rivvet,” “we,” “us,” or “our”) is a Utah limited liability company that provides AI-powered marketing automation, AI receptionist, and Hosted Commerce services to businesses. Our registered address is in the State of Utah. Questions about this Privacy Policy may be directed to support@rivvetai.com.
2. SCOPE
This Privacy Policy applies to: (a) visitors to our websites (rivvetai.com, app.rivvetai.com, demo.rivvetai.com, and associated subdomains); (b) individuals whose information is processed through our services on behalf of our business clients; and (c) our business clients and their authorized users.
This Privacy Policy does not apply to third-party websites, services, or applications that may be linked from our websites, or to our employees and contractors, who are subject to separate internal privacy policies. Where Rivvet hosts a consumer-facing application on behalf of a business client (a “Hosted Commerce Services” client), that client's own consumer-facing privacy policy, not this Policy, is the primary disclosure to that client's end consumers; this Policy describes Rivvet's role as a service provider/processor for that data.
3. DATA WE COLLECT
3.1 Information You Provide Directly.
When you contact us, request a demo, or sign up for our services, we may collect: name; business name and address; email address; phone number; job title; and payment and billing information (processed via Stripe - we do not store full credit card numbers).
3.2 Information Collected Automatically.
When you visit our websites, we may automatically collect: IP address; browser type and version; operating system; referring URLs; pages viewed and time spent; and device identifiers. We use cookies and similar tracking technologies as described in Section 6.
3.3 Client Data We Process on Behalf of Business Clients.
When we provide services to our business clients, we process data they provide to us or that their customers interact with through our AI Agents or Hosted Commerce Services, including: business customer names, phone numbers, and email addresses; appointment and scheduling information; call recordings and transcripts (where legally permitted and disclosed); consumer-submitted content such as photos and quote information for Hosted Commerce Services; and communications exchanged through our AI systems. We process this data as a service provider/data processor on behalf of our clients, who are the data controllers for this information.
3.4 AI Interaction Data.
Our AI Agents collect data from interactions they conduct on behalf of our clients, including call transcripts, chat logs, email response data, and appointment booking data. This data is associated with our clients’ customer records, not with Rivvet’s own user accounts.
4. HOW WE USE DATA
We use collected data to:
- Deliver, operate, and improve our AI marketing, AI receptionist, and Hosted Commerce services
- Process transactions and send billing communications
- Respond to inquiries and provide customer support
- Send service-related communications (onboarding, updates, security notices)
- Send marketing communications, subject to your opt-out rights
- Analyze usage patterns to improve platform performance
- Comply with legal obligations
- Enforce our agreements and protect our legal rights
We do not use Client Data (data processed on behalf of business clients) for our own marketing purposes, or for any purpose other than delivering the contracted services. We do not train or fine-tune AI models on Client Data. As of the effective date of this Policy, we do not use Client Data to improve our AI systems in any form, identifiable or otherwise. If we use Client Data to improve our systems in the future, any such use will be limited to de-identified or aggregated data that does not identify, and cannot reasonably be used to re-identify, any individual.
5. HOW WE SHARE DATA
5.1 Service Providers and Subprocessors.
We share data with third-party service providers who assist us in operating our platform. These subprocessors are contractually required to protect data and use it only for the purposes we specify. The categories of subprocessors we use are described in Section 10; a complete list of named subprocessors is available to business clients through our Data Processing Agreement, and to any individual upon written request to support@rivvetai.com.
5.2 Business Clients.
Data collected through AI Agent interactions or Hosted Commerce Services is shared with the relevant business client on whose behalf the service operates. Clients are responsible for their own use of this data under their agreements with their customers.
5.3 Legal Requirements.
We may disclose data if required by law, court order, or government authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 Business Transfers.
If Rivvet is acquired, merges with another company, or sells substantially all of its assets, data may be transferred as part of that transaction. We will provide notice before data is subject to a materially different privacy policy.
5.5 No Sale of Personal Information.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
6. COOKIES & TRACKING TECHNOLOGIES
We use cookies and similar technologies to: maintain session state and authentication; analyze website traffic and usage patterns; and improve user experience. You may control cookies through your browser settings. Disabling cookies may affect some website functionality. We honor the Global Privacy Control (GPC) browser signal and treat it as a valid request to opt out of the sale or sharing of personal information. Where our applications detect the GPC signal, we record the opt-out and persist it to the account and device, and a stored opt-out is not removed if the signal is later absent. Because we do not sell or share personal information and do not run advertising or cross-context behavioral tracking technologies on our websites or applications, there is currently no sale or sharing activity for the signal to suppress; the opt-out is recorded and would govern any future change. We do not respond to the legacy “Do Not Track” (DNT) signal, which GPC supersedes.
7. DATA RETENTION
We retain personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements. Specifically:
- Client account data: retained for the duration of the client relationship plus 3 years
- Call recordings and transcripts: retained for 90 days unless the client requests shorter retention
- Website visitor data: retained for 24 months
- Billing records: retained for 7 years as required by applicable tax and accounting laws
Consumer-submitted content for Hosted Commerce Services (for example, photos, images, and quote data submitted through a client's hosted consumer application): retained according to the retention terms specified in the applicable Order and our Data Processing Agreement, and in any event no longer than necessary to deliver the Services or as required by law.
Consent and privacy-preference records: retained for as long as necessary to demonstrate compliance with applicable law, even where the underlying data associated with a request has otherwise been deleted. Where this applies, the deletion confirmation sent to the affected individual identifies what was retained and why.
Upon termination of a client contract, we will export Client Data upon written request within 30 days and delete it from our systems within 90 days of contract end, subject to legal retention requirements.
8. SECURITY
We implement commercially reasonable technical and organizational security measures to protect data, including: encryption in transit (TLS 1.2+) and at rest; access controls and authentication requirements; regular security monitoring; and vendor security assessments for subprocessors. No security measure is 100% effective. In the event of a data breach affecting your personal information, we will notify affected parties as required by applicable law.
9. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to Know: request information about the categories and specific pieces of personal information we have collected about you
- Right to Delete: request deletion of personal information we have collected, subject to certain exceptions
- Right to Correct: request correction of inaccurate personal information
- Right to Opt Out of Sale/Sharing: we do not sell or share personal information for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request, as described in Section 6.
- Right to Limit Use of Sensitive Personal Information: we do not use sensitive personal information beyond what is necessary to provide our services
- Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights
To exercise your rights, submit a request to support@rivvetai.com. We will respond within 45 days. We may need to verify your identity before processing your request.
10. CATEGORIES OF SUBPROCESSORS
We engage third-party subprocessors in the following categories to help us deliver our services. All subprocessors are contractually required to protect data and use it only for the purposes we specify, and are located in, and process data in, the United States unless we notify you otherwise.
- AI language model providers (AI Agent and Hosted Commerce Services reasoning)
- Voice AI providers (speech synthesis and recognition for AI Receptionist)
- Telephony and SMS providers (call and text routing)
- Cloud infrastructure, database, and application hosting providers
- Content delivery network (CDN), DNS, and security providers
- Workflow automation providers
- Transactional email delivery providers
- Payment processing providers
- Frontend/website hosting providers
Clients may request the complete named subprocessor list, and at least thirty (30) days' advance notice of any change to it, as provided in our Data Processing Agreement. Consumers may request the complete named list by emailing support@rivvetai.com.
11. INTERNATIONAL DATA TRANSFERS
Our services are operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. By using our services, you consent to this transfer. We take steps to ensure that such transfers comply with applicable data protection laws.
12. CHILDREN’S PRIVACY
Our services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete it.
13. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will post the updated policy at rivvetai.com/legal/privacy with a new “Effective Date.” For material changes, we will provide additional notice via email to clients or a prominent notice on our website. Continued use of our services after the effective date constitutes acceptance of the updated policy.
14. CONTACT US
For questions, complaints, or to exercise your privacy rights: NexTech Advisors, LLC (DBA Rivvet AI) · support@rivvetai.com · rivvetai.com/legal/privacy