1. Who we are
Riftion (“Riftion”, “we”, “us”) designs, builds and operates intelligent systems for clients worldwide and runs its own products, including Markproov, codexward and Seedassay. For the processing described in this Policy, Riftion is the controller (also called “data controller” or veri sorumlusu under KVKK, “business” under the California Consumer Privacy Act and “personal information handler” under China's PIPL).
Contact, including data protection requests: hello@riftion.com
When we build or operate systems for a client, we usually act as a processor (a “service provider” under US state privacy laws, a “data processor” under KVKK) on the client's behalf. In that case the client's own privacy notice applies, and our processing is governed by our contract and data processing agreement with that client. Our products may publish their own privacy notices, which apply in addition to this Policy.
2. Personal data we collect
Information you give us
- Identity and contact data: name, business email address, phone number, company, job title, country.
- Enquiry data: the content of your messages, the solution or product you are interested in, and any files you send.
- Business relationship data: contract, billing, invoicing and payment records, and communications with client, partner and supplier representatives.
Information collected automatically
- Technical data recorded in server logs by our hosting provider when you visit the Site: IP address, browser and device type, operating system, referring URL, pages requested, and date and time of access.
- Cookies and similar technologies, as described in our Cookie Policy. The Site does not use advertising or cross-site tracking technologies.
What we do not collect
The Site has no user accounts. When you send the contact or quote form, our server passes your message to our mailbox (hello@riftion.com, hosted by our hosting provider) and keeps no copy of it. To prevent abuse, it keeps only short-lived request counters linked to a one-way hash of your IP address, deleted within 48 hours; your IP address is not included in the message. We do not intentionally collect special categories of personal data or sensitive personal information (for example health, biometric, religious or political data, or precise geolocation). Please do not send such information to us.
3. How we use personal data and our legal bases
We use personal data only for the purposes below. Where the GDPR, UK GDPR, KVKK, Brazil's LGPD or a similar law requires a legal basis, the basis we rely on is shown next to each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Reply to enquiries and prepare proposals (for example a Spark engagement) | Identity, contact and enquiry data | Steps taken at your request before entering a contract; our legitimate interest in responding to business enquiries |
| Deliver, manage and invoice client engagements and product subscriptions | Business relationship data | Performance of a contract; compliance with legal obligations |
| Operate, secure and improve the Site, prevent abuse and fraud | Technical data | Legitimate interest in running a secure and reliable website |
| Remember your cookie choice on your own device, so we respect it | Consent record: your choice, its date and the policy version (kept only in your browser) | Compliance with legal obligations (cookie and data protection rules require us to respect your choice) |
| Remember your RIOSBOT details on your own device | Name and email (kept only in your browser) | Consent, given by allowing Preferences in the consent bar or the Privacy preferences panel, and withdrawable any time under Cookie Settings |
| Send updates or news you asked for | Contact data | Consent, which you can withdraw at any time |
| Meet accounting, tax, audit and regulatory duties; respond to lawful requests from authorities | Relevant records | Compliance with legal obligations |
| Establish, exercise or defend legal claims | Relevant records | Legitimate interest; establishment, exercise or protection of a right |
Under KVKK, the corresponding conditions are those in Article 5(2): processing that is necessary for the conclusion or performance of a contract, compliance with a legal obligation, the establishment, exercise or protection of a right, and our legitimate interests, and your explicit consent where the law requires it. Where we rely on legitimate interests, we have balanced them against your rights, and you may object at any time.
4. Automated decision-making and AI
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not use the personal data you send us through the Site or by email to train artificial intelligence models.
When we design or run AI systems for clients, the client decides how personal data is used and we follow their documented instructions. We build in human oversight, transparency and evaluation, and we apply the obligations of the EU Artificial Intelligence Act and comparable rules where they apply to a system.
5. RIOSBOT, our website assistant
RIOSBOT is an automated assistant on our Contact page. It answers questions about Riftion's products, services and support with ready-made answers taken from this website. It does not use artificial intelligence, and no person reads the chat. For anything it cannot answer, contact us directly.
- Your name and email: you give them before the chat starts. They stay in your browser and are not sent to our servers or to anyone else. Only if you allow the Preferences category does your browser remember them on your device for next time (see the Cookie Policy).
- Your messages: RIOSBOT finds its answer inside your browser. Your messages are not sent to our servers or to any third party, and they are not stored: the conversation disappears when you close or reload the page.
- Legal basis: remembering your details on your device relies on your consent (Preferences), which you can withdraw at any time under Cookie Settings.
- If this changes: before RIOSBOT sends any message to our servers or to an AI service, we will update this section.
6. Who we share personal data with
- Service providers that process data on our behalf and under contract: website hosting and content delivery, email and collaboration tools, cloud infrastructure, and accounting and payment services. They may use the data only to provide their services to us.
- Professional advisers such as lawyers, auditors, accountants and insurers, under a duty of confidentiality.
- Public authorities, courts and regulators where we are legally required to disclose data or need to protect our rights, our clients or others.
- A buyer or successor if Riftion is involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different privacy policy.
We do not sell personal data, and we do not share it for cross-context behavioral advertising or process it for targeted advertising, as those terms are defined in the California Consumer Privacy Act and other US state privacy laws.
7. International data transfers
Riftion works with clients across the USA, Europe, the UK, Türkiye, the Middle East, Russia and Asia, so your data may be processed in a country other than your own. When we transfer personal data across borders we use the safeguard required by the law that protects it, for example:
- an adequacy decision of the European Commission, the UK Government or another competent authority;
- the European Commission's Standard Contractual Clauses (2021/914), with a transfer impact assessment where required;
- the UK International Data Transfer Agreement or the UK Addendum to the EU clauses;
- for data subject to KVKK, the standard contracts published by the Personal Data Protection Board, notified to the Personal Data Protection Authority within five business days of signature as required by Article 9 of Law No. 6698 as amended in 2024;
- the standard clauses, contracts, certifications or assessments required by other laws, such as Brazil's LGPD, China's PIPL and the Saudi Personal Data Protection Law;
- any data localisation requirement that applies, for example under Russian Federal Law No. 152-FZ.
You can ask us for more information about the safeguard used for your data by writing to hello@riftion.com.
8. How long we keep personal data
- Enquiries that do not lead to an engagement: up to 24 months after our last contact.
- Client, contract and billing records: for the duration of the relationship and afterwards for the period required by applicable accounting, tax and limitation laws, which is usually between 5 and 10 years depending on the country.
- Server logs: only as long as needed for security and troubleshooting.
- Marketing preferences: until you withdraw consent or unsubscribe.
9. How we protect personal data
We apply technical and organisational measures appropriate to the risk, such as encryption in transit, access controls based on least privilege, supplier due diligence and confidentiality obligations. No system is completely secure. If a personal data breach occurs, we will notify the competent authorities and affected individuals where and within the time the law requires, for example within 72 hours to supervisory authorities under the GDPR and UK GDPR, and as soon as possible under KVKK.
10. Your rights
Depending on where you live, you may have the right to:
- know whether we process your personal data and get access to a copy of it;
- have inaccurate or incomplete data corrected;
- have your data deleted;
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing that happened before;
- opt out of the sale of personal data, targeted advertising and certain profiling;
- not be subject to decisions based solely on automated processing;
- appeal our decision on your request, and complain to a data protection authority.
To exercise a right, email hello@riftion.com. We will verify your request, may ask for information to confirm your identity, and will reply within the time your law allows (for example one month under the GDPR, 30 days under KVKK and 45 days under the CCPA, extendable where permitted). Requests are free of charge unless they are manifestly unfounded or excessive. You may use an authorised agent where your law allows it. We will not discriminate against you for exercising your rights.
11. Regional information
European Economic Area and Switzerland
The GDPR and the Swiss Federal Act on Data Protection apply. You may complain to the supervisory authority in the country where you live or work, or where an alleged infringement took place.
United Kingdom
The UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations, as amended by the Data (Use and Access) Act 2025, apply. You may complain to the Information Commissioner's Office (ico.org.uk).
Türkiye
Under Article 11 of KVKK you may learn whether your data is processed and request information about it, learn the purpose of processing and whether data is used accordingly, know the third parties in Türkiye or abroad to whom data is transferred, request correction, deletion or destruction and notification of these actions to third parties, object to a result against you arising exclusively from automated analysis, and claim compensation for damage caused by unlawful processing. Submit your application in writing or by the methods set out in the Communiqué on the Procedures and Principles of Application to the Data Controller, including registered electronic mail (KEP), secure electronic signature, mobile signature or an email address you have previously notified to us. We respond free of charge within 30 days. You may complain to the Personal Data Protection Board (kvkk.gov.tr).
United States
Residents of California and of other states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia) may have the rights listed above, including the rights to know, access, correct, delete and port their data, to opt out of sale, targeted advertising and profiling, to limit the use of sensitive personal information, and to appeal a refusal. In the last 12 months we collected identifiers, professional or employment-related information and internet or network activity information, from you and from your device, for the business purposes listed in section 3. We did not sell or share personal information. We honour Global Privacy Control signals as an opt-out request. We extend these rights to US residents even where a state law's thresholds would not require it.
Canada
PIPEDA and, for Québec residents, Law 25 apply. You may contact the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
Brazil
You have the rights in Article 18 of the LGPD, including confirmation, access, correction, anonymisation, portability, deletion, information about sharing and revocation of consent. You may complain to the ANPD.
Middle East
Where they apply, we comply with the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, the data protection laws of the DIFC and ADGM, the Saudi Personal Data Protection Law (supervised by SDAIA), and the data protection laws of Qatar, Bahrain, Oman and other countries in the region.
Russia
Where Federal Law No. 152-FZ “On Personal Data” applies, we process data of Russian citizens in line with its consent, localisation and cross-border transfer requirements. You may contact Roskomnadzor.
Asia-Pacific
- China: the Personal Information Protection Law (PIPL), including rights to access, copy, correct, delete and port data and to receive an explanation of processing rules.
- Japan: the Act on the Protection of Personal Information (APPI); you may contact the Personal Information Protection Commission.
- South Korea: the Personal Information Protection Act (PIPA); you may contact the Personal Information Protection Commission.
- India: the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, as their provisions come into force, including the rights to access, correction, erasure, grievance redressal and nomination, and recourse to the Data Protection Board of India.
- Singapore: the Personal Data Protection Act 2012; you may contact the Personal Data Protection Commission.
- Australia and New Zealand: the Privacy Act 1988 and the Australian Privacy Principles; the New Zealand Privacy Act 2020.
- Other laws where they apply, including those of Hong Kong, Indonesia, Malaysia, the Philippines, Thailand and Vietnam.
Africa
Where they apply, we comply with South Africa's POPIA, Nigeria's Data Protection Act 2023, Kenya's Data Protection Act 2019, Egypt's Law No. 151 of 2020 and other national laws.
12. Children
The Site and our services are intended for businesses and professionals. They are not directed to children, and we do not knowingly collect personal data from anyone under 16, or under the higher age set by local law (for example 18 under India's DPDP Act). If you believe a child has sent us personal data, contact us and we will delete it.
13. Third-party websites
The Site may link to websites and services we do not control, including those of our products and partners. Their own privacy policies apply to them.
14. Changes to this Policy
We may update this Policy to reflect changes in our practices or in the law. We will post the new version on this page with a new “Last updated” date and, where the change is significant, tell you through another appropriate channel.
15. Contact
Questions, requests or complaints about this Policy: hello@riftion.com. Where the law requires us to appoint a data protection officer or a representative in the EU, the UK or another country, their details will be listed on this page.
