Riff Apps

Privacy policy

What personal data Riff Apps collects, why we hold it, who we share it with and the rights you have over it.

Last updated 13 September 2026


Who we are

This site is operated by Riff Apps (“Riff Apps”, “we”, “us”, “our”), registered in England and Wales, company number [company number], registered office [registered office address]. We can be reached at Contact@Riff-Apps.com.

This policy explains what we do with personal data when you visit riff-apps.com, contact us, or work with us as a client. Our own products — such as Riff and TeachWise AI — have their own privacy notices covering the data they process, and those notices apply when you use them.

We are the controller for the data described in this policy. When we build or run software for a client, that client is normally the controller and we act as their processor under a written data processing agreement.

What we collect

When you visit this site

This site does not run advertising or analytics trackers. Our hosting provider processes technical information as a normal part of serving the site — including your IP address, the pages requested, the time of the request, and your browser type — in server logs used for security and reliability.

Fonts, images, scripts and stylesheets are served from our own domain, so simply loading a page does not share your details with a third-party content network.

When you contact us

Our enquiry form opens a message in your own email application. Nothing reaches us until you choose to send it. When you do, we receive your name, email address, any organisation you give, the topic you selected and the content of your message.

When you become a client

We hold business contact details for the people we work with, records of the work, correspondence, and the billing information needed to invoice and be paid.

What we do not collect

We do not buy personal data from data brokers, we do not build advertising profiles, and we do not ask for special category data (such as health or biometric data) in the course of a business enquiry.

Why we use it, and our lawful basis

PurposeDataLawful basis
Replying to your enquiryName, email, organisation, messageLegitimate interests — responding to someone who has asked us to
Delivering a projectContact details, project records, correspondencePerformance of a contract
Invoicing and accountsBilling details, transaction recordsLegal obligation — tax and company law
Keeping the site secure and availableServer log dataLegitimate interests — protecting our service
Occasional updates about our workName, emailConsent — withdrawable at any time

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not. You can object at any time using the details below.

AI and your data

We use AI tools in our own work — for drafting, code assistance and analysis. Two rules apply without exception:

  • We do not put client confidential information or end-user personal data into a general-purpose AI tool that is outside an agreed processing arrangement.
  • We do not permit client or end-user content to be used to train third-party models, and we choose providers whose commercial terms reflect that.

Where a product we build uses AI to process personal data, that use is documented in the product's own privacy notice, along with what the model does, what it does not decide on its own, and how a person can challenge an output. Our AI transparency statement sets out the approach in full.

Who we share it with

We do not sell personal data. We share it only with service providers who help us operate, each under a contract that limits them to our instructions:

ProviderPurposeWhere processed
Vercel Inc.Website hosting and deliveryEU / US
Email providerReceiving and storing correspondenceUK / EU
Accounting softwareInvoicing and statutory recordsUK / EU

We will also disclose data where we are legally required to — see our law enforcement guidelines — or where necessary to establish or defend legal claims. If our business is ever sold or restructured, data may transfer with it, and you will be told before that changes how your data is used.

International transfers

Some providers process data outside the UK. Where that happens we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with an assessment of the protections in the destination country.

You can ask us for details of the safeguard applied to any particular transfer.

How long we keep it

RecordKept for
Enquiries that do not become projects12 months from last contact
Client project records and correspondence6 years after the engagement ends
Invoices and accounting records6 years, as required by UK tax law
Server access logsUp to 30 days
Mailing list detailsUntil you unsubscribe

When a retention period ends, records are deleted or anonymised.

How we protect it

Data is encrypted in transit and at rest. Access is restricted to the people who need it, on named accounts protected by multi-factor authentication, and reviewed when someone joins or leaves a project. Dependencies are scanned automatically and patched to a defined schedule by severity.

We maintain an incident response plan. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.

Your rights

You have the right to access your data, have it corrected, have it deleted, restrict or object to how we use it, receive it in a portable format, and withdraw consent where consent is what we relied on.

To exercise any of these, email Contact@Riff-Apps.com. We will respond within one month and will not charge you. We may ask for enough information to be confident we are dealing with the right person. Our GDPR statement explains each right in more detail.

If we are processing your data on behalf of a client — for example, as users of an application we built for them — please direct your request to that organisation. We will pass on anything that reaches us and support them in responding.

Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from children through it. Products we build that are intended for younger users apply age assurance and additional protections appropriate to their audience, described in their own notices.

Complaints and changes

If you are unhappy with how we have handled your data, tell us first at Contact@Riff-Apps.com and we will try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.

We review this policy at least annually. If we make a material change we will update the date at the top of this page and, where the change affects you significantly, tell you directly.