Background Shape

Rivulo Data Processing Addendum

Updated: August 27, 2026

This Data Processing Addendum ("DPA") forms part of the Master Services Agreement ("MSA") between Rivulo Ltd (company number 16569958, registered office 63 Craddocks Avenue, Ashtead, KT21 1PE, United Kingdom) ("Rivulo", "Processor") and the Customer ("Controller"). It governs the Processing by Rivulo of Personal Data on the Controller's behalf in connection with the Services.

By signing the MSA, the Controller accepts this DPA. No separate signature is required, but a signed copy is available on request by emailing legal@rivulo.ai.

Where there is a conflict between this DPA and the MSA, this DPA prevails in respect of the Processing of Personal Data.

1. Definitions

Terms defined in the MSA have the same meaning here, including Automation, Process, Platform, Service Schedule and Services. In addition:

"Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and, where applicable to the Processing, the EU GDPR, in each case as amended or replaced from time to time.

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Special Category Data", and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.

"Customer Personal Data" means Personal Data that Rivulo Processes on behalf of the Controller in connection with the Services, whether provided by the Controller, retrieved from the Controller's or a third party's systems on the Controller's behalf, or generated or derived by Rivulo in the course of operating the Automations.

"International Transfer" means a transfer of Personal Data from the United Kingdom (or, where relevant, the European Economic Area) to a third country not covered by an adequacy decision.

"Restricted Transfer Mechanism" means the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or any successor mechanism approved under Applicable Data Protection Law.

"Subprocessor" means a third party engaged by Rivulo to Process Customer Personal Data.

2. Roles and scope

2.1 Roles

In relation to Customer Personal Data, the Controller is the Controller and Rivulo is the Processor. Each party will comply with its obligations under Applicable Data Protection Law.

2.2 Scope

This DPA applies to the Processing of Customer Personal Data by Rivulo during the term of the MSA.

2.3 Details of Processing

The details of the Processing (subject matter, duration, nature and purpose, categories of Data Subjects, and types of Personal Data) are set out in Schedule 1.

3. The Controller's responsibilities

The Controller:

  • warrants that it has a valid lawful basis under Applicable Data Protection Law for the Processing carried out by Rivulo under the MSA and the Service Schedules;

  • is responsible for providing all required privacy notices to Data Subjects and, where required, obtaining consent;

  • determines the business processes to be automated, and is responsible for ensuring that the scope of the system access and credentials it grants to Rivulo is appropriate to those processes;

  • is responsible for the security of the credentials it issues to Rivulo, and for revoking them when a Service Schedule ends; and

  • is responsible for the security of Personal Data in transit to and from the Platform on the Controller's side.

4. Rivulo's obligations

4.1 Instructions

Rivulo will Process Customer Personal Data only:

  • (a) on the documented instructions of the Controller (the MSA, this DPA, each signed Service Schedule, and any subsequent written instructions are each "documented instructions"); or

  • (b) where required by law, in which case Rivulo will notify the Controller before Processing unless the law prohibits such notification.

Rivulo will Process Customer Personal Data only to the extent necessary to deliver the business processes described in the Service Schedules.

If Rivulo considers that an instruction infringes Applicable Data Protection Law, it will inform the Controller.

4.2 Confidentiality

Rivulo will ensure that personnel authorised to Process Customer Personal Data are bound by appropriate obligations of confidentiality.

4.3 Security

Rivulo will implement appropriate technical and organisational measures to protect Customer Personal Data, as set out in Schedule 2. Rivulo may update these measures from time to time, provided the overall level of protection is not materially reduced.

4.4 Access to the Controller's systems and data

Automations authenticate to the Controller's systems, and to third-party systems used by the Controller, using credentials the Controller provides. Access is limited to the scope those credentials permit, which the Controller controls.

Rivulo personnel do not log in to the Controller's systems directly.

Rivulo personnel may access Customer Personal Data where necessary to design, build, test, monitor and support the Automations. Such access is role-based, granted on a least-privilege basis, logged, and limited to what the relevant Service Schedule requires.

4.5 Assistance with Data Subject Rights

Taking into account the nature of the Processing, Rivulo will assist the Controller by appropriate technical and organisational measures to enable the Controller to respond to Data Subject requests for access, rectification, erasure, restriction, portability, and objection. Where a Data Subject contacts Rivulo directly in respect of Customer Personal Data, Rivulo will redirect the Data Subject to the Controller and notify the Controller without undue delay.

On the Controller's written request, Rivulo will provide a copy of Customer Personal Data held in the Platform in respect of the Controller's Processes, in a commonly used format, within a reasonable period.

4.6 Assistance with obligations

Taking into account the nature of the Processing and the information available to Rivulo, Rivulo will assist the Controller with:

  • notification of Personal Data Breaches;

  • data protection impact assessments;

  • prior consultation with Supervisory Authorities; and

  • ensuring compliance with the security obligations in Articles 32 to 36 of the UK GDPR.

The Controller acknowledges that any such assistance that requires Rivulo to incur material cost or effort beyond its standard controls may be subject to reasonable additional charges, agreed in advance.

4.7 Return or deletion

On termination of the MSA or of the relevant Service Schedule, Rivulo will, at the Controller's choice, delete or return all Customer Personal Data to the Controller and delete existing copies, except to the extent retention is required by law.

This applies to all Customer Personal Data, including Personal Data generated, derived or extracted by Rivulo in the course of operating the Controller's Processes, and not only Personal Data the Controller submitted.

Unless the Controller requests return in writing within 30 days of termination, Rivulo will delete Customer Personal Data in accordance with its standard retention schedule. The Controller's account and its contents are decommissioned after that period.

4.8 Records and audit

Rivulo will make available to the Controller information necessary to demonstrate compliance with this DPA, which will typically take the form of current certifications (for example, ISO 27001 when achieved), audit reports, or security questionnaire responses. Where the information reasonably made available is insufficient, the Controller may, on at least 30 days' prior written notice and no more than once in any 12-month period (except where a Personal Data Breach has occurred or a Supervisory Authority requires), conduct an audit at its own cost, subject to reasonable confidentiality and security conditions.

5. Personal Data Breaches

Rivulo will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent then known:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;

  • the likely consequences of the breach;

  • the measures taken or proposed to address the breach and mitigate its effects; and

  • a contact point for further information.

Rivulo will cooperate with the Controller and provide reasonable assistance to enable the Controller to meet its own notification obligations.

6. Subprocessors

6.1 General authorisation

The Controller provides general written authorisation for Rivulo to engage Subprocessors, subject to the remainder of this Section 6.

6.2 Current Subprocessors

The Subprocessors currently engaged by Rivulo are listed in Schedule 3.

6.3 Change notification

Rivulo will give the Controller at least 30 days' prior notice before engaging a new Subprocessor that will Process Customer Personal Data, by email to the Controller's named contact under the relevant Service Schedule.

6.4 Objection

The Controller may object, within the 30-day notice period, to the proposed engagement of a new Subprocessor on reasonable data-protection grounds. If the parties cannot agree a resolution within a further 30 days, the Controller may terminate the affected Service Schedule and receive a pro-rata refund of any Fees paid in advance for the unused portion of the month.

6.5 Flow-down and liability

Rivulo will impose on each Subprocessor data-protection obligations substantially equivalent to those in this DPA, and remains liable to the Controller for the acts and omissions of its Subprocessors in connection with Customer Personal Data.

Rivulo will not engage a Subprocessor to Process Customer Personal Data unless an appropriate Restricted Transfer Mechanism is in place where one is required.

7. International transfers

7.1 Controller authorisation

The Controller authorises Rivulo and its Subprocessors to make International Transfers of Customer Personal Data where necessary to provide the Services, subject to this Section 7.

7.2 Safeguards

Where Rivulo or a Subprocessor makes an International Transfer, Rivulo will put in place, or rely on, an appropriate Restricted Transfer Mechanism, together with any supplementary measures required by Applicable Data Protection Law.

7.3 Controller-to-Processor clauses

Where required, the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses, as applicable) is incorporated by reference into this DPA between the Controller and Rivulo as exporter and importer respectively, and the parties will be deemed to have completed the relevant schedules using the information in this DPA (including Schedules 1, 2, and 3).

8. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the MSA.

9. General

9.1 Term

This DPA takes effect on the date the MSA is signed and continues for the duration of the MSA. Provisions that by their nature should survive termination will continue to apply after termination.

9.2 Order of precedence

In the event of conflict between this DPA and the MSA, this DPA prevails in respect of Personal Data Processing. In the event of conflict between this DPA and a Service Schedule, this DPA prevails in respect of Personal Data Processing. In the event of conflict between this DPA and any Restricted Transfer Mechanism, the Restricted Transfer Mechanism prevails.

9.3 Changes

Rivulo may update this DPA from time to time to reflect changes in law, Subprocessors, or security measures, provided that no change will materially reduce the protections afforded to Customer Personal Data. Material changes will be notified in accordance with the MSA.

9.4 Governing law

This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales, except where Applicable Data Protection Law requires otherwise.

Schedule 1 — Details of Processing

Subject matter of the Processing Provision of the Rivulo managed automation service as described in the MSA and the Service Schedules.

Duration of the Processing For the duration of the MSA and the Service Schedules made under it, plus any period required for deletion or return under Section 4.7.

Nature and purpose of the Processing Rivulo designs, builds, operates and maintains Automations that carry out the business processes described in the Service Schedules, on the Controller's behalf. This includes executing those Automations (which may involve API integrations, browser automation, and LLM inference); retrieving and submitting data in the Controller's systems and in third-party systems used by the Controller; storing process definitions, configurations, run records and outputs in the Platform; providing support; and securing and monitoring the Platform.

Categories of Data Subjects (as determined by the business processes the Controller asks Rivulo to automate)

  • The Controller's employees, contractors, and agents;

  • The Controller's customers, prospects, or other end users whose data is Processed in the course of the Controller's business processes;

  • Account holders and contacts at third-party systems used in those processes;

  • Any other categories of Data Subjects introduced by the business processes described in a Service Schedule.

Types of Personal Data

Personal Data provided by the Controller:

  • Contact data (name, email, phone number, job title);

  • Account and authentication data;

  • Credentials and OAuth tokens for the Controller's own and third-party systems;

  • Any Personal Data contained in files, records, or inputs the Controller provides for a Process.

Personal Data generated, derived or extracted by Rivulo in the course of operating the Controller's Processes:

  • Records retrieved from the Controller's systems or from third-party systems on the Controller's behalf;

  • Run records, outputs, logs and screenshots created when an Automation executes;

  • Process knowledge and configurations held in the Platform;

  • Any Personal Data contained in LLM prompts and outputs generated in the course of a Process.

All of the above is Processed on the Controller's documented instructions under Section 4.1.

Special Category Data and criminal-offence data

Special Category Data may appear incidentally in material Processed on the Controller's behalf, for example where a Data Subject volunteers information about their health in correspondence handled by a Process. Where this occurs, Rivulo applies the same protections as to other Customer Personal Data, and the Controller remains responsible for ensuring it has an appropriate condition under Article 9 of the UK GDPR.

Rivulo will not operate a Process designed to Process Special Category Data or criminal-offence data unless the parties have agreed it in advance in writing and it is recorded in the relevant Service Schedule.

Schedule 2 — Technical and organisational measures

Rivulo implements the following technical and organisational measures, which are maintained as part of its information security management system (aligned to ISO 27001:2022):

Access control

  • Role-based access control (least privilege) for production systems;

  • Multi-factor authentication for all personnel with access to production systems;

  • Formal joiner/mover/leaver procedures with access reviews at least quarterly;

  • Administrative access to Customer Personal Data logged;

  • Credentials issued by the Controller held in secrets management and used only within the scope of access the Controller has granted;

  • Personnel access to Customer Personal Data limited to the engagements the individual works on.

Encryption

  • Personal Data encrypted in transit using TLS 1.2 or higher;

  • Personal Data encrypted at rest on production infrastructure and in backups;

  • Full-disk encryption on all company-managed devices.

System security

  • Hardened production environments on DigitalOcean and Vercel;

  • Automatic security patching for supported infrastructure components;

  • Separation of production, staging, and development environments;

  • Secrets management for credentials and API keys.

Application security

  • Secure software development lifecycle with independent QA testing or code review before merge to production;

  • Automated vulnerability scanning of code and dependencies;

  • Penetration testing for major releases or at least annually;

  • OWASP-aligned coding practices.

Operations and monitoring

  • Centralised logging and monitoring via Datadog;

  • Intrusion and anomaly detection on production infrastructure;

  • Documented incident response plan with defined roles and escalation paths;

  • Business continuity and disaster recovery plan, tested at least annually.

Backups and resilience

  • Automated encrypted backups with documented retention and restoration procedures;

  • Regular backup restoration testing.

Vendor management

  • Tiered vendor risk assessment before engagement;

  • Written data processing agreements with all Subprocessors Processing Personal Data;

  • At least annual review of Subprocessor security posture.

People

  • Confidentiality obligations for all personnel;

  • Annual security and privacy awareness training;

  • Background checks where legally permitted;

  • Formal off-boarding procedures including revocation of access within 24 hours.

Physical security

  • Rivulo has no physical premises; all processing takes place on managed cloud infrastructure or personal devices under Rivulo's Acceptable Use and Workstation Security Policy.

Governance

  • Designated Security and Privacy Owner;

  • Documented policies reviewed at least annually;

  • Quarterly management review of security and privacy posture;

  • Register of Processing Activities maintained and reviewed quarterly.

Schedule 3 — Subprocessors

Rivulo engages the Subprocessors listed below to Process Customer Personal Data. The list is current as of the "Updated" date at the top of this DPA and is maintained as part of Rivulo's Tool and Vendor Register.

Infrastructure

Subprocessor Service provided Location of Processing Transfer mechanism DigitalOcean, LLC Application hosting United States UK International Data Transfer Agreement / UK Addendum Vercel, Inc. Web application delivery United States UK International Data Transfer Agreement / UK Addendum

Workflow execution

Subprocessor Service provided Location of Processing Transfer mechanism Pipedream, Inc. API integration execution United States UK International Data Transfer Agreement / UK Addendum Browser Use, Inc. Browser automation execution United States EU Standard Contractual Clauses (Modules Two and Three), as amended by the UK Addendum (ICO Version B1.0)

LLM providers

Subprocessor Service provided Location of Processing Transfer mechanism Notes Anthropic, PBC LLM inference United States UK International Data Transfer Agreement / UK Addendum Zero Data Retention enabled OpenAI, LLC LLM inference United States UK International Data Transfer Agreement / UK Addendum No training on API inputs under standard terms Google LLC (Gemini) LLM inference United States UK International Data Transfer Agreement / UK Addendum No training on API inputs under paid-tier terms Mistral AI LLM inference France / EEA Adequacy (UK-EEA)

Business support

Subprocessor Service provided Location of Processing Transfer mechanism Stripe Payments UK Ltd Payment processing United States / Ireland UK International Data Transfer Agreement / UK Addendum Google LLC (Workspace) Email, documents, calendar United States UK International Data Transfer Agreement / UK Addendum Slack Technologies, LLC Internal messaging United States UK International Data Transfer Agreement / UK Addendum Notion Labs, Inc. Internal documentation and workspace United States UK International Data Transfer Agreement / UK Addendum Datadog, Inc. Logging and monitoring United States UK International Data Transfer Agreement / UK Addendum Attio Ltd Customer relationship management United Kingdom / United States UK International Data Transfer Agreement / UK Addendum for US processing

Contact

Questions about this DPA: privacy@rivulo.ai Formal DPA requests (signed copy, amendments, notices): legal@rivulo.ai Security incident reporting: security@rivulo.ai

Hand over your first workflow this week

Hand Rivulo your most tedious workflow or your team’s most-asked question. Either way, it starts by understanding how your business works, and then it takes care of the rest.

Hand over your first workflow this week

Hand Rivulo your most tedious workflow or your team’s most-asked question. Either way, it starts by understanding how your business works, and then it takes care of the rest.

Hand over your first workflow this week

Hand Rivulo your most tedious workflow or your team’s most-asked question. Either way, it starts by understanding how your business works, and then it takes care of the rest.

Hand over your first workflow this week

Hand Rivulo your most tedious workflow or your team’s most-asked question. Either way, it starts by understanding how your business works, and then it takes care of the rest.