PRIVACY POLICY

Privacy Policy

How Riveon AG collects, uses and protects personal data under Swiss and European law.

Last updated: 14 April 2026  ·  Governing law: Switzerland (FADP) & EU (GDPR)

01

Data Controller

The controller responsible for the processing of personal data in connection with this website and Riveon's services is:

ControllerRiveon AG
Chamerstrasse 170
6300 Zug
Switzerland
UIDCHE-108.045.739
02

Scope & Guiding Principles

This Privacy Policy describes how Riveon AG processes personal data in connection with its website, its compute and infrastructure services, and its AI-based contact channels. It applies in addition to any contractual data processing agreements in force between Riveon AG and its customers.

Riveon processes personal data in accordance with the Swiss Federal Act on Data Protection (FADP / revDSG, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR). We process personal data only where we have a valid legal basis, limit processing to what is necessary, and apply data minimisation, purpose limitation and transparency as guiding principles.

03

Categories of Personal Data

Depending on how you interact with Riveon, we may process the following categories of personal data:

Contact dataName, company, role, email address, telephone number, postal address, and any information you voluntarily provide when contacting us.
Communication dataContent of emails, chat messages, call transcripts and recordings (where applicable and consented to), metadata such as timestamps and duration.
Technical dataIP address, device and browser information, referrer URL, pages visited, time of access, and similar log data generated when you use this website.
Contract dataInformation required to negotiate, conclude and perform contracts, including billing address, purchase orders and service usage data.
Compliance dataInformation required to meet sanctions, export-control, KYC/KYB and anti-money-laundering obligations applicable to our business.
04

Purposes & Legal Bases

We process personal data for the following purposes and on the following legal bases:

Website operationProviding and securing the website, preventing abuse and ensuring technical stability. Legal basis: legitimate interest (Art. 31 FADP / Art. 6(1)(f) GDPR).
Customer communicationResponding to inquiries, providing information, and operating the AI hotline and chat channels. Legal basis: pre-contractual measures / legitimate interest / consent where required.
Contract performanceNegotiating, concluding and performing agreements for Riveon's services. Legal basis: contractual necessity (Art. 6(1)(b) GDPR).
Legal & complianceMeeting statutory obligations under tax, accounting, sanctions and data-protection law. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
SecurityProtecting Riveon's infrastructure, data and personnel, investigating incidents. Legal basis: legitimate interest.
05

AI & Voice Processing

Riveon operates conversational and voice-based AI systems as part of its customer-facing services. This section describes the specific processing involved, in line with Art. 50 of the EU AI Act and the transparency requirements of the FADP.

Who you are speaking to

At the beginning of each interaction with our chat or hotline, users are informed that the system may be operated by an AI assistant. A human agent can be requested at any time.

What is processed

Voice input is transcribed in real time; the transcript and any AI-generated responses are stored to operate the service. Call recordings are only retained where the user has explicitly consented.

Where it is processed

Processing takes place within the EU/EEA and Switzerland. Selected sub-processors may rely on infrastructure located in third countries; transfers are safeguarded in accordance with Section 7 below.

No training on your data

Riveon does not use customer voice or chat content to train foundation models. Contracts with model providers prohibit such use without separate, explicit consent.

Human oversight

Decisions with legal or similarly significant effect on individuals are reviewed by a human before taking effect. The AI assistant does not enter into binding contracts on behalf of Riveon AG.

No impersonation

AI-generated voices are clearly identified as synthetic. Riveon does not clone or impersonate real individuals and does not produce deceptive audio, image or video content.

06

Recipients & Processors

Personal data is only shared with third parties where this is necessary for the purposes described above, permitted by law, or expressly authorised by you. Typical recipients include group companies, carefully selected service providers (for example hosting, telephony, conversational AI and analytics providers), auditors, legal and tax advisors, and public authorities where required.

All processors act on Riveon's documented instructions and are bound by written data-processing agreements that comply with Art. 9 FADP and Art. 28 GDPR.

07

International Data Transfers

Where personal data is transferred to a country outside Switzerland or the EEA that does not offer an adequate level of data protection, Riveon relies on appropriate safeguards such as the European Commission's Standard Contractual Clauses (2021/914) in combination with the Swiss addendum issued by the Federal Data Protection and Information Commissioner (FDPIC), supplemented by technical and organisational measures where necessary.

08

Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, to comply with statutory retention obligations (in particular under Swiss commercial and tax law, typically ten years), or to preserve evidence within applicable limitation periods. Once the retention period expires, data is deleted or irreversibly anonymised.

09

Security

Riveon applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These measures include encryption in transit and at rest, strict access controls, logging and monitoring, regular security reviews, and staff confidentiality obligations. We continuously review and improve our security posture in line with the state of the art and the specific risks of our operations.

10

Your Rights

Subject to applicable law, you have the following rights in relation to your personal data:

Information & accessThe right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy and related information.
RectificationThe right to request correction of inaccurate or incomplete personal data.
ErasureThe right to request deletion of your personal data where the legal conditions are met.
RestrictionThe right to request that the processing of your personal data be restricted under certain conditions.
PortabilityThe right to receive personal data you provided in a structured, commonly used and machine-readable format where applicable.
ObjectionThe right to object to processing based on legitimate interests, including profiling.
Withdraw consentWhere processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of prior processing.
ComplaintThe right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland or with the competent EU supervisory authority.

To exercise any of these rights, please contact us using the address listed in Section 1. We may need to verify your identity before responding.

11

Cookies & Tracking

This website uses only cookies and similar technologies that are strictly necessary for the operation of the site, for basic security, and for remembering your cookie preferences. Riveon does not use advertising cookies and does not track users across third-party websites. Where any optional analytics or functional cookies are introduced in the future, they will only be set after you have given your prior consent via a cookie banner.

12

Changes to this Policy

Riveon may update this Privacy Policy from time to time to reflect changes in our services, in applicable law or in our processing activities. The current version is always available on this page and is identified by the "Last updated" date at the top. Material changes will be communicated appropriately.