GDPR
Our data protection framework: the roles we act in, the rights you hold, and what we can evidence if you ask.
Last updated 13 September 2026
Scope of this statement
This statement explains how Riff Apps (“Riff Apps”, “we”, “us”, “our”), registered in England and Wales, company number [company number], registered office [registered office address] meets its obligations under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR where it applies to our processing.
It sits alongside our privacy policy, which describes the specific data we hold. This page is about the framework: our roles, your rights, and what we can evidence if you ask.
Controller or processor
We act in two capacities, and the distinction matters for where you direct a request.
| Situation | Our role | Who to contact |
|---|---|---|
| You enquire, or work with us as a client | Controller | Us |
| We operate our own products | Controller | Us, via that product's notice |
| We build or run an application for a client | Processor | That client, as controller |
Where we are a processor, we act only on the controller's documented instructions, under a written agreement meeting Article 28. We will tell a controller if we think an instruction breaches data protection law.
How we apply the principles
The seven principles in Article 5 are not a poster on the wall; each one has a practical consequence in how we build.
- Lawfulness, fairness and transparency — the lawful basis for a feature is identified and recorded before it is built, and users are told in plain language what happens to their data.
- Purpose limitation — data collected for one purpose is not quietly repurposed for another.
- Data minimisation — a feature gets the fields it needs and no more. Optional fields are genuinely optional.
- Accuracy — users can correct their own details in the product wherever that is feasible.
- Storage limitation — every category of data has a retention period set when it is first collected, and deletion is automated where possible.
- Integrity and confidentiality — encryption, access control, logging and testing, proportionate to the sensitivity of the data.
- Accountability — we keep records of processing, decisions and assessments, and can produce them.
Lawful bases
We rely on consent, contract, legal obligation and legitimate interests, depending on the processing. We do not use consent as a catch-all: where consent is the basis, it is specific, informed, given by a clear affirmative action, recorded, and as easy to withdraw as to give.
Where we rely on legitimate interests, we carry out and document a balancing assessment weighing our interest against the rights of the people concerned. You can ask for a summary of any assessment that affects you.
Special category data is processed only where an Article 9 condition applies, with additional safeguards and a documented policy where the Data Protection Act requires one.
Your rights in detail
| Right | What it means |
|---|---|
| Access | A copy of your personal data and an explanation of how it is used. |
| Rectification | Correction of data that is inaccurate or incomplete. |
| Erasure | Deletion where the data is no longer needed, consent is withdrawn, or processing was unlawful. |
| Restriction | Processing paused while a dispute about accuracy or legitimate interests is resolved. |
| Portability | Data you gave us, in a structured, machine-readable format, transferable to another provider. |
| Objection | A right to object to processing based on legitimate interests, and an absolute right to object to direct marketing. |
| Automated decisions | Not to be subject to a solely automated decision with legal or similarly significant effect, and to obtain human intervention where one is made. |
How to exercise them
Email Contact@Riff-Apps.com. No particular form of words is needed. We will acknowledge promptly and respond within one month, extendable by two further months for complex requests, in which case we will explain why within the first month.
Requests are free. We may ask you to verify your identity before releasing data, and we may decline a request that is manifestly unfounded or excessive, explaining our reasoning and your right to complain.
Automated decisions and profiling
We design against solely automated decisions that have a legal or similarly significant effect on someone. Where a product scores, ranks, matches or classifies people, a human reviews any consequential outcome and can overturn it, and the person affected can ask for that review.
Our AI transparency statement explains what the models do, how they are evaluated and where the human sits in each product.
Impact assessments and privacy by design
We carry out a data protection impact assessment before processing that is likely to be high risk — including large-scale profiling, special category data, systematic monitoring, data about children, and the use of innovative technology such as AI in a new context.
An assessment identifies the necessity and proportionality of the processing, the risks to individuals, and the measures taken to reduce them. Where a high risk remains after mitigation, we consult the Information Commissioner's Office before proceeding.
Privacy by design means these questions are settled during architecture, not retrofitted. Default settings are the most privacy-protective ones.
Sub-processors
We use a small number of sub-processors, each engaged under a written contract imposing equivalent obligations to our own. Where we act as a processor for a client, we maintain a list of sub-processors for that engagement and give advance notice of any change, so the client has an opportunity to object.
Ask us at any time for the current list relating to your engagement.
International transfers
Transfers outside the UK rely on adequacy regulations where they exist. Otherwise we use the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment considering the law and practice of the destination country and any supplementary technical measures needed.
Personal data breaches
We maintain a breach response plan covering detection, containment, assessment, notification and review, and we keep an internal log of all breaches whether or not they are notifiable.
As a controller, we notify the Information Commissioner's Office within 72 hours where a breach is likely to result in a risk to people's rights, and we notify affected individuals without undue delay where the risk is high. As a processor, we notify the controller without undue delay and support their response.
Complaints
Raise a concern with us first at Contact@Riff-Apps.com. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), or to the supervisory authority in your EU member state where the EU GDPR applies, and to seek a judicial remedy.