Privacy policy
What personal data Riff Apps collects, why we hold it, who we share it with and the rights you have over it.
Last updated 13 September 2026
Who we are
This site is operated by Riff Apps (“Riff Apps”, “we”, “us”, “our”), registered in England and Wales, company number [company number], registered office [registered office address]. We can be reached at Contact@Riff-Apps.com.
This policy explains what we do with personal data when you visit riff-apps.com, contact us, or work with us as a client. Our own products — such as Riff and TeachWise AI — have their own privacy notices covering the data they process, and those notices apply when you use them.
We are the controller for the data described in this policy. When we build or run software for a client, that client is normally the controller and we act as their processor under a written data processing agreement.
What we collect
When you visit this site
This site does not run advertising or analytics trackers. Our hosting provider processes technical information as a normal part of serving the site — including your IP address, the pages requested, the time of the request, and your browser type — in server logs used for security and reliability.
Fonts, images, scripts and stylesheets are served from our own domain, so simply loading a page does not share your details with a third-party content network.
When you contact us
Our enquiry form opens a message in your own email application. Nothing reaches us until you choose to send it. When you do, we receive your name, email address, any organisation you give, the topic you selected and the content of your message.
When you become a client
We hold business contact details for the people we work with, records of the work, correspondence, and the billing information needed to invoice and be paid.
What we do not collect
We do not buy personal data from data brokers, we do not build advertising profiles, and we do not ask for special category data (such as health or biometric data) in the course of a business enquiry.
Why we use it, and our lawful basis
| Purpose | Data | Lawful basis |
|---|---|---|
| Replying to your enquiry | Name, email, organisation, message | Legitimate interests — responding to someone who has asked us to |
| Delivering a project | Contact details, project records, correspondence | Performance of a contract |
| Invoicing and accounts | Billing details, transaction records | Legal obligation — tax and company law |
| Keeping the site secure and available | Server log data | Legitimate interests — protecting our service |
| Occasional updates about our work | Name, email | Consent — withdrawable at any time |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not. You can object at any time using the details below.
AI and your data
We use AI tools in our own work — for drafting, code assistance and analysis. Two rules apply without exception:
- We do not put client confidential information or end-user personal data into a general-purpose AI tool that is outside an agreed processing arrangement.
- We do not permit client or end-user content to be used to train third-party models, and we choose providers whose commercial terms reflect that.
Where a product we build uses AI to process personal data, that use is documented in the product's own privacy notice, along with what the model does, what it does not decide on its own, and how a person can challenge an output. Our AI transparency statement sets out the approach in full.
Who we share it with
We do not sell personal data. We share it only with service providers who help us operate, each under a contract that limits them to our instructions:
| Provider | Purpose | Where processed |
|---|---|---|
| Vercel Inc. | Website hosting and delivery | EU / US |
| Email provider | Receiving and storing correspondence | UK / EU |
| Accounting software | Invoicing and statutory records | UK / EU |
We will also disclose data where we are legally required to — see our law enforcement guidelines — or where necessary to establish or defend legal claims. If our business is ever sold or restructured, data may transfer with it, and you will be told before that changes how your data is used.
International transfers
Some providers process data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with an assessment of the protections in the destination country.
You can ask us for details of the safeguard applied to any particular transfer.
How long we keep it
| Record | Kept for |
|---|---|
| Enquiries that do not become projects | 12 months from last contact |
| Client project records and correspondence | 6 years after the engagement ends |
| Invoices and accounting records | 6 years, as required by UK tax law |
| Server access logs | Up to 30 days |
| Mailing list details | Until you unsubscribe |
When a retention period ends, records are deleted or anonymised.
How we protect it
Data is encrypted in transit and at rest. Access is restricted to the people who need it, on named accounts protected by multi-factor authentication, and reviewed when someone joins or leaves a project. Dependencies are scanned automatically and patched to a defined schedule by severity.
We maintain an incident response plan. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.
Your rights
You have the right to access your data, have it corrected, have it deleted, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent is what we relied on.
To exercise any of these, email Contact@Riff-Apps.com. We will respond within one month and will not charge you. We may ask for enough information to be confident we are dealing with the right person. Our GDPR statement explains each right in more detail.
If we are processing your data on behalf of a client — for example, as users of an application we built for them — please direct your request to that organisation. We will pass on anything that reaches us and support them in responding.
Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from children through it. Products we build that are intended for younger users apply age assurance and additional protections appropriate to their audience, described in their own notices.
Complaints and changes
If you are unhappy with how we have handled your data, tell us first at Contact@Riff-Apps.com and we will try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.
We review this policy at least annually. If we make a material change we will update the date at the top of this page and, where the change affects you significantly, tell you directly.