Legal

Privacy Policy

Last updated: July 27, 2026

Who is responsible

Rivantir is operated by EAST WOLF INTERACTIVE S.R.L., a company registered in Bucharest, Romania (CUI RO36600723). We are the data controller for the personal data described here. For any privacy question, or to exercise your rights, write to privacy@rivantir.com.

What we collect

We collect only what the service needs to work:

  • account data — name, email, authentication details;
  • organization data — company details, members, roles and settings;
  • financial data you bring in — invoices, clients, bank transactions synced read-only through regulated open-banking providers, or imported by you;
  • documents you upload — receipts, contracts, statements;
  • usage and technical data — logs needed for security and reliability.

How we use it

We use your data to provide the service: syncing and categorizing transactions, matching receipts, generating reports and powering the AI assistant. We also use it for billing, support and security.

We do not sell your data, and we do not use it for advertising.

AI processing

Some features send relevant excerpts of your data to AI model providers under data-processing agreements. Your data is not used to train their models. Access is always scoped to your organization, and every AI action is logged.

Processors and sharing

We share data only with processors needed to run the service, under GDPR-compliant agreements:

  • payments — Stripe, and Paddle.com as merchant of record for purchases it processes;
  • bank connectivity — regulated PSD2 open-banking providers;
  • hosting and storage — EU-based cloud infrastructure;
  • transactional email, document OCR and AI model providers.

International transfers

Our infrastructure and storage are EU-based. Some processors — such as Paddle and certain AI model providers — may process data outside the European Economic Area. When they do, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses.

Your rights

Under the GDPR you can request access, correction, deletion, portability, or restriction of processing, and you can object to processing based on legitimate interest. Write to privacy@rivantir.com and we will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority.

Retention and security

We keep your data while your organization is active and as long as the law requires afterwards. Data is encrypted in transit and at rest, scoped to your organization, and bank connections are strictly read-only — Rivantir never holds credentials that could move money.