Scope and who is responsible
This notice explains how Bilitech LLC (30 N Gould St Ste N, Sheridan, WY 82801, United States) (together "Rivet", "we") handle personal information in connection with Rivet: the website at rivet.global, the dashboard, mobile access and the API (the "Service"). Bilitech LLC is the controller for this processing.
It covers everyone whose information reaches us through a business workspace: the person who opens it, the company’s directors and beneficial owners, team members who are invited in, cardholders, and the payees and counterparties named in transactions. It also covers people who visit the site, contact us, or talk to sales.
The company that opens a workspace is itself a controller of the information it puts into the Service about its own staff and counterparties. It must have a lawful basis to share that information with us and must tell those people that we and our partners will process it. This notice is written so it can be given to them for that purpose.
What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity | Name, date of birth, nationality, residential address, government ID document and its number, a selfie or liveness check, role in the company, ownership percentage. | You, or the administrator who adds you; the identity-verification provider. |
| Company | Legal name, registration number, registered and operating addresses, incorporation documents, ownership structure, industry, expected activity, tax identifiers. | The person opening the workspace; public registers. |
| Contact and account | Work email, phone number, login credentials (hashed), multi-factor settings, role and permissions, preferences such as colour scheme. | You; your use of the Service. |
| Financial and transaction | Account details issued to the company, balances, payment instructions, payee names and account details, card numbers (tokenised), merchant, amount, currency, receipts and memos, blockchain addresses and transaction hashes. | Your use of the Service; partner institutions; payment networks. |
| Verification and risk | Results of sanctions, politically-exposed-person, adverse-media and fraud checks; risk scores; requests for information and your answers; case notes. | Identity-verification and screening providers; partner institutions; our compliance team. |
| Device and usage | IP address, approximate location derived from it, browser and device type, time zone, pages and actions in the dashboard, error logs. | Your browser and device, automatically. |
| Communications | Emails, support messages, sales enquiries and the details in them, call notes. | You. |
| Billing | Plan, invoices, payment-method type and last four digits, billing address. Full card numbers are held by our payment processor, not by us. | You; the payment processor. |
We do not knowingly collect information about anyone under 18, and the Service is not offered to them.
Why we use it, and the legal basis
Where data-protection law such as the GDPR or UK GDPR applies, we rely on one of the bases in the right-hand column. Where it does not, we use information for the purposes listed.
| Purpose | Basis |
|---|---|
| Verifying the company and the people behind it; screening against sanctions and fraud lists; ongoing monitoring of transactions. | Legal obligation (anti-money-laundering and sanctions law); legitimate interest in preventing fraud. |
| Opening and running the workspace: accounts, balances, cards, payouts, conversions, team roles and approvals. | Performance of the contract with the company; the company’s legitimate interest in running its business. |
| Sharing what a partner institution needs to provide its product. | Performance of the contract; legal obligation. |
| Billing the plan and issuing invoices. | Performance of the contract; legal obligation (tax and accounting records). |
| Keeping the Service secure, detecting abuse, and investigating incidents. | Legitimate interest in security; legal obligation. |
| Support, and responding to your questions and complaints. | Performance of the contract; legitimate interest. |
| Improving the Service by analysing how it is used, in aggregate. | Legitimate interest. Product analytics are first-party and aggregated. |
| Measuring whether a Google ad led to a visit or a sign-up. | Legitimate interest in understanding advertising; consent where required by local law. |
| Telling administrators about changes to terms, fees, products, security and outages. | Performance of the contract; legal obligation. |
| Marketing to business contacts who asked to hear from us, with an unsubscribe in every message. | Consent, or legitimate interest for existing customers; you can object at any time. |
| Responding to lawful requests from courts, regulators and law enforcement. | Legal obligation. |
We make some decisions automatically, such as declining a transaction that matches a sanctions list or exceeds a risk threshold. A decision that significantly affects you is reviewed by a person on request. Write to [email protected].
International transfers
We operate from the United States and use providers and partner institutions in the United States, the European Economic Area, the United Kingdom and the countries where a product is delivered. Your information will therefore be transferred to, stored and processed in countries other than your own, including ones whose data-protection law differs from yours.
Where the GDPR or UK GDPR applies to a transfer, we rely on an adequacy decision where one exists, and otherwise on the European Commission’s standard contractual clauses or the UK International Data Transfer Addendum, with additional safeguards where needed. A copy of the relevant clauses is available on request.
How long we keep it
| Information | Retained for |
|---|---|
| Verification records, transaction records, statements, audit logs and communications about them | At least five years after the workspace is closed or the relationship ends, or longer where a partner institution or a law requires it. |
| Invoices and billing records | Seven years, for tax and accounting law. |
| Account, profile and preference information | For the life of the workspace, then deleted or anonymised within 90 days except where it forms part of a record above. |
| Support and sales communications | Three years from the last message, unless part of a complaint or dispute. |
| Device and usage logs | Twelve months, then deleted or aggregated. |
| Information about an application that was declined or abandoned | Five years, as anti-money-laundering law requires. |
Backups roll off on their own schedule and may hold information for a short period after it is deleted from live systems.
How we protect it
Information is encrypted in transit and at rest. Access inside Rivet is limited to the people who need it for their role, is protected by multi-factor authentication, and is logged. Card numbers are tokenised by the card issuer and are never stored in full on our systems. Full payment-method details for billing are held by our payment processor. Identity documents are held by the verification provider and the partner institutions that require them, with access from our side limited to compliance staff.
No system is perfectly secure. If a breach affects your information in a way that is likely to put you at risk, we will tell the affected workspace’s administrators and, where required, you and the relevant authority, without undue delay.
Your rights
Depending on where you live, you may have the right to:
- ·Ask for a copy of the personal information we hold about you, and for details of how we use it.
- ·Ask us to correct information that is inaccurate or incomplete. Much of it you can correct yourself in the dashboard.
- ·Ask us to delete information, or to restrict or stop a particular use of it. We will do so unless we have to keep it. Most verification and transaction records fall under a legal retention period and cannot be deleted before it ends.
- ·Receive information you gave us in a portable format, or have it sent to another provider.
- ·Object to processing based on legitimate interests, and to direct marketing at any time.
- ·Withdraw consent where consent is the basis, without affecting processing done before you withdrew it.
- ·Ask for a person to review an automated decision that significantly affects you.
- ·Complain to a data-protection authority. For example, your national authority in the EEA, the Information Commissioner’s Office in the UK, or your state attorney general in the United States.
Write to [email protected]. We will need to confirm who you are before we act, and will respond within one month, or sooner where a shorter period applies. We do not charge for these requests unless they are clearly unfounded or excessive.
If you are a resident of California or another US state with a consumer-privacy law: we do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. The categories we collect, the purposes and the recipients are set out above. You have the rights to know, to delete, to correct and to non-discrimination described in this section, and you may use an authorised agent to exercise them.
People you add to a workspace
When an administrator invites a team member, names a beneficial owner, orders a card for someone or enters a payee, the company is giving us that person’s information. The company must have the right to do so and must tell the person. We use the information only to provide the Service to the company and to meet our legal obligations, and we treat it as described in this notice.
A team member can see and update their own profile in the dashboard. A beneficial owner or payee who wants to know what we hold about them can write to [email protected].
Changes to this notice
We will update this notice when our practices change. For a material change we will email the workspace’s administrators and show a notice in the dashboard before it takes effect. The version number and effective date at the top of this page always identify the current notice.
Contact
Privacy questions and requests: [email protected]. By post: Bilitech LLC, Attn: Privacy, 30 N Gould St Ste N, Sheridan, WY 82801, United States.
If you are in the EEA or the UK and would like the contact details of our representative there, ask at the same address.