Logo
Pricing Login

Privacy Policy

Effective date: 07.13.2026

Last updated: 07.13.2026

This English-language Privacy Policy is the controlling version. Any translation is provided for convenience only.

1. About Rivyns and this Policy

Rivyns is a business-to-business recruitment technology platform operated by DerekhPath LLC, a California Limited Liability Company, with a registered address at 262 El Granada Blvd Half Moon Bay, CA 94019 (referred to in this Policy as “Rivyns,” “we,” “us,” or “our”). References in the product to “Powered by DerekhPath” are product attribution and do not change the identity of the operator stated above.

Rivyns helps customer organizations (each, a “Customer”) source potential candidates, maintain candidate records, manage recruitment pipelines and positions, create interview materials, document interviews, and use artificial intelligence-assisted recruitment features. A Customer’s workspace in the Service is referred to as its “Organization,” and a person whom a Customer permits to access or administer that Organization is an “Authorized User.”

This Privacy Policy explains how Rivyns collects, uses, stores, discloses, and otherwise processes personal information through its websites, public pages, platform, support channels, and related services. “Personal information” includes “personal data” and similar terms used by applicable privacy laws.

This Policy should be read together with the Rivyns Terms of Service. A customer organization’s own privacy notice may also apply to its recruitment activities and Customer-controlled records.

2. Beta Service status

Rivyns is currently offered as a Beta Service, meaning a pre-release and actively developed version of the Rivyns platform. As the platform develops, features, integrations, workflows, data fields, providers, and ways of interacting with the Service may change. Not every feature is available to every user or in every region.

This Policy describes the current principal categories of personal-information processing. We may update it as the product changes. If a change materially affects the purposes for which personal information is used or the way it is processed, the updated disclosure will apply prospectively, and Rivyns will provide additional notice where required by applicable law. The Beta Service status does not limit privacy rights or obligations imposed by applicable law.

3. Whose information we process

Depending on how Rivyns is used, we may process information relating to:

  • visitors to Rivyns websites and public pages;
  • people who create or use a Rivyns account;
  • organization creators, administrators, invited team members, billing contacts, and other customer representatives;
  • candidates and potential candidates whose information is entered, uploaded, imported, or generated by a customer;
  • people whose professional information appears in a Rivyns Global Profile;
  • interview participants, including candidates, interviewers, recruiters, and hiring personnel;
  • people who contact Rivyns for support or submit a privacy or security request; and
  • people represented in security, fraud-prevention, diagnostic, legal, and operational records.

Rivyns is not a consumer social network. General candidate account registration is not currently a principal function of the Service. A candidate does not need a Rivyns account to submit a privacy request.

4. Our roles and Customer roles

Our privacy role depends on the processing activity and applicable law.

Rivyns generally acts as a controller for processing that it determines independently and as a processor or service provider when it processes Customer-controlled data on documented Customer instructions. Where the California Consumer Privacy Act applies, these roles may be described as a business or service provider.

4.1 Processing determined by Rivyns

Rivyns generally determines the purposes and means of processing for:

  • account registration, authentication, email verification where used, and account administration;
  • platform operation, security, fraud and abuse prevention, support, billing, and legal compliance;
  • service communications and operational records;
  • Global Profiles and platform-led professional sourcing or enrichment;
  • Rivyns-controlled AI functionality;
  • service analytics and improvement activities determined by Rivyns; and
  • privacy requests relating to Global Profiles or other Rivyns-controlled records.

4.2 Customer-controlled processing

A customer organization generally determines the purposes and use of personal information in its own workspace, including:

  • local candidate profiles and customer-uploaded resumes or documents;
  • positions, pipelines, stages, comments, notes, evaluations, and hiring decisions;
  • interview records and customer-specific assessments;
  • customer instructions and recruitment criteria; and
  • Authorized User roles and permissions within the customer’s Organization.

For these activities, the Customer is generally responsible for selecting an appropriate lawful basis, providing required notices, obtaining consent where consent is required, managing its Authorized Users, applying appropriate retention periods, and making recruitment and employment decisions. Rivyns processes the information to provide, secure, and support the Service under the customer agreement and documented instructions.

These role descriptions do not remove any responsibility that applicable law places directly on Rivyns. The same information may be processed in different roles for different purposes, particularly where a Customer-controlled record is linked to a separate Global Profile.

5. Information we collect and process

The categories of information depend on the person, feature, Customer configuration, and source.

5.1 Website, device, and service-use information

We may process:

  • IP address, browser type, operating system, device and request information;
  • pages, features, and links used, together with dates, times, and referring pages;
  • authentication, session, security, anti-abuse, and request-integrity information;
  • cookie identifiers and information stored in localStorage or sessionStorage;
  • interface preferences, such as an active Organization, selected views, filters, tabs, and navigation state;
  • application, diagnostic, security, and error information; and
  • communications with Rivyns support or personnel.

5.2 Account, user, and Organization information

We may process:

  • name, email address, username, phone number, and other profile information provided by the user;
  • optional profile details such as location, address, date of birth, or gender where provided through an available field;
  • password hashes and authentication records, but not a readable copy of the password;
  • email-verification status, login and session information, and account status;
  • Organization names, business contact details, addresses, and billing contacts;
  • Organization memberships, invitations, administrative roles, permissions, and access settings;
  • subscription, plan, billing-status, and service-communication information; and
  • actions taken by Authorized Users in the Service where recorded for operation, support, security, or compliance.

5.3 Customer-controlled candidate records

Customer-controlled candidate records may include:

  • identity and contact information;
  • location, professional-profile links, and contact-availability information;
  • employment history, employers, job titles, dates, responsibilities, and seniority;
  • education, skills, credentials, certifications, licences, keywords, and industries;
  • salary expectations, relocation preferences, and professional interests;
  • resumes, cover letters, portfolios, work samples, and other uploaded documents;
  • position and pipeline records, activities, comments, notes, and communications;
  • interview schedules, participants, questions, responses, text or transcripts, comments, criteria, scores, and summaries;
  • evaluations, AI-assisted outputs, alignment information, and suggested points for human validation; and
  • offers, hiring dates, start dates, and recruitment or hiring statuses.

The Customer determines the recruitment purpose for these records. The employer’s or recruiting organization’s own privacy notice may also apply.

5.4 Global Profile information

Rivyns may maintain platform-level professional profiles that are separate from Customer-controlled records. A Global Profile may contain identity and contact information, professional-profile URLs, employment and education history, skills, credentials, professional interests, source information, imported resume information, and AI-assisted professional inferences. Section 8 explains Global Profiles in more detail.

5.5 AI inputs, outputs, and related information

Depending on the feature, AI-assisted processing may involve:

  • resumes and structured resume information;
  • employment history, education, skills, credentials, and professional-profile information;
  • position descriptions, role definitions, keywords, and Customer instructions;
  • interview text or transcripts, questions, responses, comments, criteria, and existing scores;
  • candidate notes, professional preferences, location, and relocation information; and
  • account, Customer, position, or workflow context needed to provide the requested feature.

Outputs may include structured resume data, summaries, scores, priorities, alignment reports, suggested interview materials, comments, criterion-level assessments, and points for human validation.

5.6 Interview information

Customers may store interview schedules, participant identities, questions, candidate responses, text or transcripts, comments, criteria, scores, and AI-assisted summaries in Rivyns.

Rivyns does not itself record interview audio or video. If a Customer records or transcribes an interview outside Rivyns and imports the resulting text, that Customer is responsible for providing any required notice and obtaining any required consent. Rivyns is not designed to perform facial, voice, emotion, or biometric analysis, and Customers must not use the Service to infer protected traits.

5.7 Billing information

Rivyns uses Stripe for subscription and payment services. Rivyns may receive or process billing-contact information, Stripe customer and transaction identifiers, subscription and invoice information, plan and payment status, amounts, dates, and related transaction metadata.

When Stripe-hosted payment functionality is used, payment-card details are generally submitted directly to and processed by Stripe. Stripe’s own privacy notice applies to its independent processing.

5.8 Support, security, and legal information

We may process support requests, account communications, privacy and security reports, records of suspected misuse, fraud indicators, access and security events, legal correspondence, and information reasonably necessary to establish, exercise, or defend legal rights.

5.9 Sensitive information

Free-text fields, resumes, interview materials, and uploaded documents may contain information that is sensitive or specially protected under some laws. Customers should not submit health, disability, race or ethnicity, religion, sexual orientation, union membership, criminal-history, biometric, government-identifier, financial, or other highly sensitive information unless it is necessary for a lawful recruitment purpose and the Customer has the required authority, notices, and permissions.

Rivyns may restrict, remove, or delete information that is improperly submitted or used through the Service.

6. Sources of information

We may obtain personal information:

  • directly from account users, Customer representatives, support requesters, and other people who communicate with Rivyns;
  • from Customer organizations and their Authorized Users;
  • from recruiters, interviewers, hiring managers, and other recruitment participants;
  • from resumes, cover letters, portfolios, work samples, transcripts, and other uploaded or imported documents;
  • from professional-profile URLs and publicly accessible professional sources;
  • from RocketReach and other approved professional-data or enrichment providers;
  • from Stripe and other providers involved in billing or payments;
  • from hosting, email, security, support, monitoring, and infrastructure providers;
  • from use of Rivyns, including cookies, browser storage, server requests, logs, and diagnostic events; and
  • from AI-assisted analysis and other inferences generated through the Service.

Public availability of information does not by itself constitute consent or remove a person’s privacy rights.

Rivyns may receive professional information without collecting it directly from the person concerned. Where applicable law requires an additional direct notice, Rivyns or, where the Customer is responsible for the collection, the relevant Customer will provide that notice in the manner and within the period required by law. Publication of this Policy does not necessarily replace a direct notice required for a particular processing activity.

7. How we use information

Depending on Rivyns’s role, we may use personal information to:

  • create, authenticate, administer, and secure accounts;
  • create and manage Organizations, memberships, permissions, and service access;
  • provide Customer-requested sourcing, applicant-tracking, document, interview, and recruitment-workflow features;
  • maintain Customer-controlled records on Customer instructions;
  • process subscriptions, payments, billing events, and related communications;
  • provide support, diagnose problems, and communicate about the Service;
  • prevent fraud, abuse, unauthorized access, and security incidents;
  • source, create, maintain, and make available professional Global Profiles;
  • perform authorized professional-data enrichment;
  • provide AI-assisted features described in this Policy;
  • comply with law, respond to lawful requests, resolve disputes, and protect legal rights; and
  • measure and improve service performance, reliability, usability, and quality using service-use information, feedback, and appropriately aggregated or de-identified information.

7.1 Lawful bases under European and UK data protection law

Where European Economic Area or United Kingdom data protection law applies, the lawful basis depends on the processing purpose and Rivyns’s role.

We may rely on:

  • Contract, where processing is necessary to provide an account or service requested by the individual or to take steps at that individual’s request;
  • Legitimate interests, such as account administration, service operation, support, security, fraud prevention, legal claims, service improvement, and, where appropriate, professional sourcing, enrichment, and Global Profiles;
  • Legal obligations, where processing is necessary to comply with applicable law; and
  • Consent, where consent is legally required or a feature is genuinely optional and consent is the appropriate basis.

Where we rely on legitimate interests, we consider whether the processing is necessary and balanced against the rights and reasonable expectations of the affected person.

A Customer determines the lawful basis for its own recruitment records and hiring activities. When Rivyns acts as a processor, it processes personal data on documented Customer instructions and does not select a separate Article 6 lawful basis on the Customer’s behalf. Processing of special-category information requires an additional condition under applicable law.

8. Global Candidate Profiles

Rivyns may maintain platform-level professional profiles called Global Profiles. A Global Profile may exist even if the person has no Rivyns account and has never directly interacted with Rivyns.

8.1 Sources and contents

Global Profile information may come from RocketReach, Customer-provided information, imported resumes, approved data providers, and publicly accessible professional sources. Rivyns may combine information from more than one source.

A Global Profile may include:

  • name and general location;
  • personal or work contact information;
  • professional-profile URLs;
  • current and previous employment;
  • education, skills, credentials, certifications, and professional keywords;
  • professional interests or relocation information where available;
  • structured information extracted from an imported resume;
  • source and provenance information; and
  • AI-assisted summaries, alignment information, or other professional inferences used in a recruitment workflow.

8.2 Accuracy and meaning of a profile

Global Profiles may be incomplete, outdated, duplicated, incorrectly matched, or otherwise inaccurate. The existence of a Global Profile does not mean that the person:

  • has applied for a position;
  • is actively seeking work;
  • has agreed to be contacted;
  • has confirmed that the information is accurate; or
  • endorses Rivyns or any Customer.

Customers must independently verify important information and determine whether any contact or recruitment use is lawful.

8.3 Relationship with Customer-controlled records

A Global Profile and a Customer-controlled candidate record are separate records. When a Customer adds a Global Profile to its workspace, Rivyns may create a separate Customer-controlled record. Certain information may be used or synchronized between linked records where necessary to provide a Customer-requested feature, perform authorized enrichment, or maintain data consistency, subject to applicable law, source restrictions, and the customer agreement.

A Customer must have the right to provide information it submits to Rivyns. Rivyns does not receive an unrestricted right to use all Customer Data for Global Profiles. Unrelated Customer Data is not used to create or expand a Global Profile without an appropriate basis. Information about a source may be retained where reasonably necessary for provenance, correction, source-restriction, and privacy-request purposes.

Deleting a Customer-controlled record does not necessarily delete a separate Global Profile, and deleting a Global Profile does not necessarily delete a Customer’s independent hiring record. A privacy request may relate to one or both types of record.

8.4 Product scope and background checks

Rivyns is not designed for credit, insurance, housing, tenant screening, or background checks. Customers must not use Rivyns for those purposes unless a separate, expressly supported, and legally compliant program is made available. Rivyns does not guarantee the accuracy or completeness of third-party professional data, and Customers must independently verify information that is important to a decision.

9. AI-assisted features

Rivyns uses the OpenAI API and may use other approved AI providers to support features such as resume structuring, matching, scoring, prioritization, summaries, alignment reports, position content, interview materials, interview comments, and suggested points for human validation.

AI-assisted features may process resumes, employment history, education, skills, credentials, positions, interview text, notes, Customer instructions, and related workflow context. Depending on the function, identifiable information may be transmitted to an AI provider. Information is not necessarily anonymized before transmission. Rivyns seeks to limit the information sent to what is reasonably necessary for the requested function.

AI output may be inaccurate, incomplete, inconsistent, biased, or outdated. An AI-generated statement, score, priority, or inference is not a verified fact. AI-assisted processing may affect how a candidate profile is prioritized, displayed, or reviewed within a Customer’s sourcing workflow.

Rivyns does not make the Customer’s final interview, hiring, rejection, promotion, or other employment decision. Customers must provide meaningful human review, verify material information, consider relevant context and accommodations, and remain responsible for the final decision. Customers must not use AI output as the sole basis for an adverse employment decision or use the Service for unlawful discrimination.

Because Rivyns is a Beta Service, AI models, providers, prompts, supporting logic, and output formats may change. The same or similar inputs may produce different outputs.

Rivyns does not use identifiable Customer Data, including Customer-controlled Candidate Data, to train general-purpose or shared models unless the Customer separately and expressly agrees. Processing that is necessary to generate a requested output is not, by itself, model training.

Where applicable law provides a right to object to qualifying profiling, opt out of qualifying automated decision-making, obtain human review, or contest a decision, requests may be submitted as described in Section 15.

10. How information is shared

We may disclose personal information, as appropriate for the relevant purpose, to:

  • Customer organizations and their Authorized Users;
  • recipients selected or directed by an Authorized User;
  • OpenAI and other approved AI providers;
  • RocketReach and other approved professional-data sources or enrichment providers;
  • Stripe and other billing or payment providers;
  • Resend and other email-delivery providers;
  • Cloudflare, including Turnstile where enabled, and other security or traffic-management providers;
  • Sentry and other error-monitoring or diagnostic providers where enabled;
  • cloud hosting, object-storage, database, cache, queue, infrastructure, and backup providers;
  • professional advisers, auditors, insurers, and financing sources subject to appropriate duties;
  • regulators, courts, law-enforcement bodies, and other parties where disclosure is required or permitted by law;
  • parties involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable safeguards; and
  • other recipients with the person’s direction, consent, or as disclosed when the information is collected.

RocketReach and another professional-data source may process information for its own purposes under its own privacy notice and may not act only as a processor on Rivyns’s instructions. A professional-data source may have a different privacy role from a service provider acting only on Rivyns’s instructions.

We do not give service providers an unrestricted right to use personal information for unrelated purposes. You may contact support@rivyns.com for current information about material service providers used for relevant processing.

Rivyns may make certain Global Profiles available to authorized business Customers for recruitment purposes. Making Global Profiles available to business Customers may be treated as a regulated disclosure under some United States state laws. Where a law requires an opt-out or another control, Rivyns will provide the applicable method and honour qualifying requests.

11. Cookies and technical data

Rivyns uses cookies and similar technologies primarily to operate and secure the Service. These may include:

  • authentication and session cookies;
  • technologies used for cross-site request-forgery protection and request integrity;
  • security, anti-abuse, and traffic-management technologies;
  • localStorage or sessionStorage used for interface state, Organization context, selected views, filters, tabs, and navigation preferences; and
  • Cloudflare Turnstile where enabled to help distinguish legitimate use from automated abuse.

When a browser requests externally hosted scripts, stylesheets, fonts, or similar assets, the external provider may receive IP address, browser, and request information needed to deliver the asset.

If Rivyns introduces non-essential cookies or similar technologies, we will provide notice and choices where required by applicable law.

12. International processing and transfers

Rivyns and its providers may process personal information in the United States and other countries. Privacy laws in those countries may differ from the laws where the person lives.

Where applicable law requires a transfer safeguard, Rivyns will use an appropriate mechanism. Depending on the transfer, this may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or International Data Transfer Agreement, or another lawful mechanism.

Contact support@rivyns.com to request information about a transfer safeguard relevant to your personal information.

13. Data retention

Retention periods vary depending on the information category, purpose, Customer instructions, service relationship, legal obligations, source restrictions, privacy requests, and the need to resolve disputes or protect the Service.

13.1 Accounts and Organizations

Account and Organization information may be retained while the account or Organization is active and for a reasonable period after closure for support, security, fraud prevention, dispute resolution, and legal or accounting obligations.

13.2 Customer-controlled records

Customer-controlled candidate records and documents may be retained according to Customer instructions, the service relationship, the customer agreement, and applicable recruitment or employment-record obligations. A Customer may be required to retain a hiring record even where another record concerning the same person is deleted from Rivyns-controlled systems.

13.3 Global Profiles

A Global Profile may be retained while Rivyns has a lawful professional-sourcing purpose, the information remains sufficiently relevant to that purpose, an applicable lawful basis continues to exist, and a qualifying deletion or objection request does not require earlier action.

13.4 AI records

AI inputs, outputs, and related metadata may be retained for as long as reasonably necessary for Customer access, service operation, troubleshooting, security, audit, dispute resolution, and legal obligations. Retention by an AI provider may also depend on the AI feature and the applicable provider terms and settings.

13.5 Billing records

Billing, subscription, invoice, and transaction information may be retained as required for tax, accounting, payment, fraud-prevention, chargeback, and dispute purposes.

13.6 Logs and operational records

Security, access, diagnostic, support, and application records may be retained for a reasonable period appropriate to security, troubleshooting, abuse prevention, service reliability, and legal needs.

13.7 Backups

Information deleted from active systems may remain in backups until those backups are overwritten through the ordinary backup cycle. Backup copies are not used for ordinary business purposes and may be retained longer where required for security, legal, or disaster-recovery purposes.

13.8 Suppression information

Rivyns may retain minimal identifiers or other limited information where reasonably necessary to honour an opt-out, objection, or deletion request, prevent routine re-import, document the request, or comply with law. Suppression information is not intended to be used as an active sourcing profile.

14. Security

Rivyns uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Service and the information processed. Depending on the environment and feature, these measures may include:

  • account authentication and password hashing;
  • email verification where used;
  • role-based access and permission controls;
  • cross-site request-forgery protection and other web-request security controls;
  • restricted administrative access;
  • time-limited file links where configured;
  • monitoring, diagnostic logging, and security records where used;
  • backups and recovery measures;
  • security controls provided by infrastructure and service providers; and
  • secure development and change-management practices.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Suspected security issues may be reported to support@rivyns.com.

15. Privacy rights and requests

Depending on applicable law and Rivyns’s role, a person may have rights to:

  • access personal information and obtain information about its processing;
  • correct inaccurate or incomplete information;
  • delete personal information;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of a qualifying sale or sharing of personal information;
  • opt out of qualifying targeted advertising, profiling, or automated decision-making;
  • request human review of a qualifying automated decision;
  • appeal a denied request where applicable law provides an appeal right;
  • receive non-discriminatory treatment for exercising a privacy right; and
  • complain to a privacy, data-protection, consumer-protection, or other competent regulator.

These rights are not absolute and may differ by jurisdiction and processing context.

15.1 How to submit a request

Submit a request by emailing support@rivyns.com. A candidate does not need a Rivyns account.

We may ask for information reasonably necessary to locate the relevant record and verify the requester. Depending on the request, useful identifying information may include a name, current or former professional email address, telephone number, professional-profile URL, employer, or the Customer Organization involved. Please do not send government identifiers or other highly sensitive information unless Rivyns specifically requests it through an appropriate method.

We will respond within the period required by applicable law. A request may be denied or limited where an applicable exception permits, including where identity cannot reasonably be verified or another person’s rights would be adversely affected. Authorized-agent requests will be handled where required by law.

15.2 Customer-controlled records

If a request concerns a Customer-controlled hiring or recruitment record, Rivyns may direct the requester to the relevant Customer. Rivyns will assist the Customer as required when acting as its processor or service provider, while the Customer generally decides how to respond to the request concerning its own record.

15.3 Global Profiles and other Rivyns-controlled records

Rivyns evaluates requests concerning Global Profiles and other independently controlled records. Depending on the request and applicable law, actions may include access, correction, deletion, restriction, objection handling, or suppression.

Where required by applicable law, Rivyns will take reasonable steps to communicate a qualifying request to relevant service providers or recipients. Deletion from active systems does not necessarily result in immediate removal from backups, which are addressed through ordinary backup cycles.

A requester may ask whether Rivyns holds a Global Profile, request available information about source categories, or ask for correction, deletion, restriction, objection, or suppression.

15.4 Additional rights under United States state laws

Residents of certain United States states may have additional rights where the relevant law applies to Rivyns and the processing activity. These may include rights to know, access, correct, delete, obtain a portable copy, opt out of qualifying sale or sharing, opt out of targeted advertising or qualifying profiling, appeal a decision, and receive non-discriminatory treatment.

Making certain Global Profiles available to business Customers may be treated as a regulated disclosure under some state laws. Where a law requires an opt-out or another control, Rivyns will provide the applicable method and honour qualifying requests. Questions or requests may be submitted to support@rivyns.com; additional methods will be provided where legally required.

16. Children

Rivyns business accounts are intended for people aged 18 or older. The Service is not directed to children.

A Customer must not add information about a minor candidate, intern, or student unless it has a lawful recruitment purpose and all required authority, notices, and parent or guardian permissions. Rivyns may restrict or delete information about a minor that appears to have been submitted improperly.

17. Changes to this Policy

We may update this Policy as the Beta Service, providers, features, law, or processing activities change. The “Last updated” date identifies the current version.

For a material change, Rivyns may provide notice through email, a notice within the Service, or a notice on the relevant page. Additional or direct notice will be provided where required by applicable law. Changes apply prospectively from the stated effective date. Updating this Policy does not by itself authorize an incompatible retroactive use of personal information.

18. Contact information

Rivyns operator: DerekhPath LLC

Entity type and jurisdiction: California Limited Liability Company

Registered address: 262 El Granada Blvd Half Moon Bay, CA 94019

Privacy requests and questions: support@rivyns.com

Support: support@rivyns.com

Security reports: support@rivyns.com

© 2024–2026. Powered by DerekhPath