Law enforcement
How authorities should request data from Riff Apps, what a valid request needs, and what we will and will not disclose.
Last updated 13 September 2026
Purpose of these guidelines
These guidelines are for law enforcement agencies and other authorities seeking data from Riff Apps (“Riff Apps”, “we”, “us”, “our”), registered in England and Wales, company number [company number], registered office [registered office address]. They explain what we need in order to act, and what we will and will not do.
We take both obligations seriously: cooperating properly with lawful investigations, and protecting our users from disclosure that is not lawfully required.
This page is not legal advice and does not waive any right or defence available to us or to the people whose data we hold.
How to reach us
Send requests to Contact@Riff-Apps.com with “Law enforcement request” in the subject line.
Requests must come from an official government or agency email address and be on headed paper, signed and dated. We do not accept requests by telephone or social media, and we cannot verify a request made from a personal account.
What a valid request needs
We disclose data only where we are legally compelled to, or where a narrow emergency exception applies. Please include:
- the legal instrument relied on — for UK requests, typically a court order, warrant, or a notice under the Investigatory Powers Act 2018 or Schedule 2 of the Data Protection Act 2018;
- the identity, rank and contact details of the requesting officer, and the agency and case reference;
- precise identifiers for the account or data sought — a username, registered email address, or transaction reference. We cannot act on a name alone;
- a defined date range, kept as narrow as the investigation allows;
- the specific categories of data sought, rather than a request for “all data”;
- whether you are asking us to delay notifying the user, and the legal basis for that.
We will reject or seek clarification on requests that are overly broad, unclear, or unsupported by valid legal process.
Requests from outside the UK
We are based in the UK and respond to UK legal process. Authorities in other jurisdictions should proceed through a mutual legal assistance treaty, a letter rogatory, or another recognised international cooperation route, so that the request is given effect under UK law.
We will consider a direct request from an overseas authority where a specific legal framework permits it, but we are not obliged to comply with foreign process that has no effect in the UK.
Emergency disclosure
Where we believe in good faith that disclosure is necessary to prevent an imminent risk of death or serious physical harm, we may disclose the minimum information needed without waiting for legal process.
Mark the request “Emergency disclosure request” and set out the nature of the emergency, the risk of harm, the person at risk, and why the information will help prevent it. We assess each on its facts and may decline if the threshold is not met.
Preservation requests
We will preserve data we already hold pending valid legal process, typically for 90 days and extendable once on request. A preservation request does not itself require us to disclose anything, and it does not require us to begin collecting data we do not otherwise hold.
What we may hold
What exists varies by product and is limited by our retention schedules. Depending on the service, it may include registration details, an account's activity metadata, and records of transactions.
Several things are usually not available:
- data already deleted under our retention policy — we cannot recover it;
- content protected by encryption we cannot reverse;
- data held by a client for whom we act as processor. Direct those requests to the client, who is the controller. We will tell you that is the position, and will tell the client.
We do not build capabilities for bulk or indiscriminate access, and we will not create new collection to satisfy a request.
Telling the user
Our policy is to notify a person whose data has been requested, with enough information to seek legal advice, before we disclose it.
We will delay or withhold notice where a court order or statute prohibits it, or where we believe notice would create a risk of serious harm to someone or of destruction of evidence. Where notice is delayed by order, we will normally notify once the restriction expires.
How we handle requests
Each request is logged and reviewed for validity and scope, with legal advice where needed. Valid requests are answered as promptly as we can, usually within 10 working days, and urgent matters faster. Where we disclose, we provide only the data the request covers.
We keep records of the requests we receive and how we responded, and we may publish aggregate figures about their number and type.