Privacy Policy
Last updated: January 1, 2026
1. Introduction
This Privacy Policy describes how River AI GmbH ("River", "we", "us") processes personal data in connection with the provision and operation of the River software-as-a-service platform, including any related applications, features and services (collectively, the "Service").
River is committed to protecting personal data and complying with applicable data protection laws and regulations, including:
- Regulation (EU) 2016/679 (the General Data Protection Regulation – "GDPR"); and
- the UK General Data Protection Regulation (the "UK GDPR"), together with any applicable implementing or supplementary legislation.
This Privacy Policy is intended for business customers, their authorised users and other individuals whose personal data may be processed by River in the context of providing the Service.
The Service is offered exclusively on a business-to-business (B2B) basis and is not intended for use by consumers within the meaning of applicable consumer protection laws.
Where River processes personal data on behalf of its customers, such processing is carried out in River's capacity as a data processor and is governed by the applicable Data Processing Agreement (DPA).
Where River processes personal data for its own business purposes, River acts as an independent data controller, as further described in this Privacy Policy.
This Privacy Policy explains the categories of personal data processed, the purposes and legal bases for processing, the applicable safeguards, and the rights of individuals under applicable data protection law.
2. Who We Are
2.1 River's Role Under Data Protection Law
Depending on the context of the processing activity, River AI GmbH acts either as a data processor or, in limited circumstances, as an independent data controller, in accordance with applicable data protection law.
2.2 Data Processor (Primary Role)
For personal data processed within the Service on behalf of customers, including personal data uploaded, submitted or otherwise made available by customers or their authorised users, River acts as a data processor within the meaning of the GDPR and the UK GDPR.
In this capacity:
- River processes personal data solely on documented instructions of the customer;
- the customer organisation acts as the data controller and determines the purposes and lawful bases of processing;
- River does not independently determine the purposes or means of processing such data.
The processing of such personal data is governed by the applicable Data Processing Agreement (DPA) entered into between River and the customer.
2.3 Data Controller (Limited Role)
River acts as an independent data controller only with respect to limited processing activities relating to its own business operations, including:
- customer account administration and user management;
- billing, invoicing and payment processing;
- contractual, legal and compliance records;
- security monitoring, audit logs and fraud prevention;
- communications with customers and prospective customers.
In these cases, River determines the purposes and means of processing and processes personal data in accordance with this Privacy Policy.
2.4 No Joint Controller Relationship
River does not act as a joint controller with its customers in relation to personal data processed within the Service, unless expressly agreed otherwise in writing.
Patients, end users or other third parties whose data may be processed through the Service are data subjects of the customer, not of River.
2.5 Company Details and Contact Information
River AI GmbH
Badenerstrasse 549
8048 Zürich
Switzerland
Email (legal & data protection inquiries): sandro@get-river.ai
This contact information is provided for privacy, data protection and legal matters only.
For technical or customer support inquiries, customers should use the designated support channels made available through the Service.
3. Scope of This Privacy Policy
This Privacy Policy applies to the processing of personal data by River only to the extent River acts as a data controller, including personal data processed in connection with:
- visits to our website or online presence operated by River;
- the creation, administration and management of customer accounts;
- communications with customers, prospective customers and business partners;
- billing, invoicing, contractual and compliance-related activities;
- security, monitoring, audit and fraud-prevention activities relating to River's own operations.
3.1 Customer Data Processed Within the Service
Personal data processed within the Service on behalf of customers, including personal data uploaded, submitted or otherwise made available by customers or their authorised users ("Customer Data"), is processed by River solely in its capacity as a data processor.
Such processing is not governed by this Privacy Policy.
Instead, Customer Data is governed by:
- the applicable Data Processing Agreement (DPA) entered into between River and the customer; and
- the customer's own privacy notices and data protection documentation, which are provided by the customer to data subjects.
River does not provide privacy notices directly to patients, end users or other data subjects whose personal data is processed within the Service on behalf of customers.
3.2 Responsibility of Customers
Customers remain solely responsible for:
- informing data subjects about the processing of their personal data;
- identifying and documenting the applicable lawful bases for processing;
- responding to data subject requests and regulatory inquiries;
- ensuring compliance with all applicable data protection laws in their capacity as data controllers.
River's obligations in relation to Customer Data are limited to those expressly set out in the applicable DPA and mandatory data protection law.
4. Roles and Responsibilities
4.1 Customer Data – Processor Role
Where River processes personal data uploaded, submitted, stored or otherwise managed by customers within the Service ("Customer Data"), the following allocation of roles applies:
- the customer organisation acts as the data controller and determines the purposes and lawful bases of processing;
- River acts solely as a data processor, within the meaning of the GDPR and the UK GDPR;
- River processes Customer Data only on documented instructions of the customer, as necessary to provide the Service and as set out in the applicable Data Processing Agreement (DPA).
In this context, River does not:
- determine or influence the purposes or means of processing Customer Data;
- provide privacy notices, transparency information or disclosures directly to patients, end users or other data subjects;
- make independent decisions regarding the collection, use, retention or disclosure of Customer Data.
All obligations relating to transparency, lawful basis, consent (where applicable), and data subject rights rest exclusively with the customer in its capacity as data controller.
4.2 River Business Data – Controller Role
River acts as an independent data controller with respect to personal data processed for its own legitimate business purposes, including personal data relating to:
- customer account administrators and authorised business contacts;
- billing, invoicing, payment processing and financial administration;
- contractual, legal and compliance documentation;
- security monitoring, audit trails, access logs and fraud prevention;
- communications with customers, prospective customers and business partners.
For such processing activities, River determines the purposes and means of processing and processes personal data in accordance with this Privacy Policy and applicable data protection law.
4.3 No Joint Controller Relationship
Except where expressly agreed in writing, River does not act as a joint controller with its customers in relation to any personal data processed within the Service.
Patients, end users and other third parties whose personal data may be processed through the Service are data subjects of the customer, not of River, and any rights or claims relating to such data must be addressed to the relevant customer organisation.
4.4 Allocation of Compliance Responsibilities
The Customer acknowledges and agrees that:
- it remains solely responsible for compliance with applicable data protection laws in its capacity as data controller;
- River's responsibilities in relation to Customer Data are limited to those expressly set out in the DPA and mandatory provisions of data protection law;
- nothing in this Privacy Policy shall be construed as shifting or reducing the Customer's obligations as data controller.
5. Categories of Personal Data
Depending on the context of the interaction with River and the use of the Service, River may process the following categories of personal data.
The specific categories processed will depend on whether River acts as a data controller or a data processor, as described in this Privacy Policy.
5.1 Customer Account and Business Data (Controller Role)
Where River acts as a data controller, River may process personal data relating to customer account administration and business relationships, including:
- name, business email address and business telephone number;
- job title, role or function within the customer organisation;
- company name and organisational details;
- billing, invoicing and payment-related information;
- contractual communications and correspondence.
Such data is processed solely for the purposes of account management, contractual performance, billing and compliance.
5.2 Service Usage and Technical Data (Controller Role – Limited)
River may process certain technical and usage-related data in connection with the operation, security and maintenance of the Service, including:
- user identifiers and authentication-related data;
- IP addresses, device identifiers and browser information;
- timestamps, access logs and usage activity;
- security, audit and monitoring logs.
This data is processed for legitimate purposes such as service functionality, security, fraud prevention, system integrity and troubleshooting.
5.3 Customer Content (Processor Role)
Where River acts as a data processor, River may process personal data contained in content uploaded, submitted or otherwise made available by customers or their authorised users through the Service ("Customer Content"), including:
- contact and identification data relating to individuals;
- communications, messages and correspondence;
- appointment-related, scheduling or operational information;
- notes, records or other information entered by authorised users;
- any other personal data determined and controlled by the customer.
River does not determine the categories of personal data included in Customer Content and processes such data solely on the instructions of the customer, in accordance with the applicable Data Processing Agreement.
5.4 Special Category Data
Customer Content may include special category personal data, such as health-related data, only where the customer chooses to upload or process such data within the Service.
River does not require the processing of special category data by design and does not process such data for its own independent purposes.
Further details regarding the processing of special category data are set out in Section 6 of this Privacy Policy.
5.5 Data Minimisation
River processes personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed, in accordance with the principle of data minimisation under applicable data protection law.
6. Special Category (Health) Data
6.1 Processing of Special Category Data
The Service may technically process special category personal data, including health-related data within the meaning of Article 9 GDPR, solely if and to the extent such data is uploaded, submitted or otherwise made available by customers or their authorised users in the course of using the Service.
The Service is not designed to require the processing of special category data, and the inclusion of such data is neither mandated nor encouraged by River.
6.2 River's Role and Limitations
In relation to special category personal data, River:
- acts solely as a data processor on behalf of the customer;
- does not independently determine the purposes or means of processing;
- does not access, analyse, reuse or otherwise process such data for its own independent purposes;
- does not use special category data for profiling, analytics, training, automated decision-making or any secondary use.
Any processing of special category data by River is strictly limited to what is technically necessary to provide the Service in accordance with the customer's documented instructions and the applicable Data Processing Agreement.
6.3 Customer Responsibility and Lawful Basis
Customers acknowledge and agree that they are solely responsible, in their capacity as data controllers, for:
- determining whether special category data is processed within the Service;
- ensuring a valid lawful basis under Article 6 GDPR and, where applicable, a valid condition under Article 9 GDPR;
- providing all required information and transparency to data subjects;
- implementing appropriate safeguards in accordance with applicable data protection law.
River does not verify, assess or monitor the customer's compliance with Article 9 GDPR requirements.
6.4 Risk Allocation
To the maximum extent permitted by applicable law, River shall not be responsible for any claims, regulatory actions or liabilities arising from the customer's decision to process special category personal data within the Service, except where such liability cannot be excluded under mandatory data protection law.
7. Purposes of Processing
River processes personal data only for specific, explicit and legitimate purposes, in accordance with applicable data protection law and the principle of purpose limitation.
The purposes of processing depend on whether River acts as a data controller or a data processor, as described in this Privacy Policy.
7.1 Purposes Where River Acts as a Data Controller
Where River acts as a data controller, personal data is processed for the following purposes:
- provision, operation and maintenance of the Service, including user authentication, access management and system functionality;
- customer account administration, relationship management and customer support communications;
- billing, invoicing, payment processing and contract management;
- security, monitoring, audit logging and fraud prevention, including the detection and prevention of unauthorised access or misuse;
- compliance with applicable legal and regulatory obligations, including record-keeping and responding to lawful requests from authorities;
- service improvement and development, including performance analysis, troubleshooting and optimisation, using aggregated or anonymised data where reasonably possible.
7.2 Purposes Where River Acts as a Data Processor
Where River processes personal data on behalf of customers within the Service, River processes such data solely for the purpose of providing the Service and strictly in accordance with the customer's documented instructions and the applicable Data Processing Agreement.
River does not determine the purposes for which Customer Data is processed.
7.3 No Medical or Clinical Purposes
River does not process personal data for the purpose of:
- providing medical advice, diagnosis or treatment recommendations;
- delivering clinical decision support;
- performing automated medical or clinical decision-making;
- profiling individuals for medical or health-related purposes.
Any medical, clinical or professional decisions made using information processed through the Service are taken solely by the customer and its authorised users and remain outside the scope of River's processing purposes.
7.4 Purpose Limitation
River does not further process personal data in a manner that is incompatible with the purposes set out in this Section.
Any material change to the purposes of processing will be reflected in an updated version of this Privacy Policy and, where required, communicated to customers in advance.
8. Legal Bases for Processing
River processes personal data only where a valid legal basis applies, in accordance with Article 6 GDPR and, where applicable, the UK GDPR.
The applicable legal basis depends on the context of the processing and whether River acts as a data controller or a data processor.
8.1 Legal Bases Where River Acts as a Data Controller
Where River acts as a data controller, personal data is processed on one or more of the following legal bases:
(a) Performance of a Contract — Article 6(1)(b) GDPR
Processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract, including:
- creation and administration of customer accounts;
- provision and operation of the Service;
- customer communications relating to the contractual relationship.
(b) Compliance with Legal Obligations — Article 6(1)(c) GDPR
Processing is necessary to comply with legal or regulatory obligations to which River is subject, including:
- accounting and tax obligations;
- record-keeping and audit requirements;
- responding to lawful requests from public authorities or regulators.
(c) Legitimate Interests — Article 6(1)(f) GDPR
Processing is necessary for the purposes of River's legitimate interests, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
River's legitimate interests include, in particular:
- ensuring the security, integrity and availability of the Service;
- preventing fraud, misuse and unauthorised access;
- maintaining and improving the Service, including performance monitoring and troubleshooting;
- managing business operations and protecting River's legal rights.
Where processing is based on legitimate interests, River has conducted a balancing assessment to ensure that such processing does not disproportionately impact data subjects.
8.2 Legal Bases Where River Acts as a Data Processor
Where River processes personal data on behalf of customers within the Service, River acts solely as a data processor.
In such cases:
- the customer organisation determines the applicable legal bases for processing;
- River does not independently assess or determine the lawful basis;
- River processes personal data strictly in accordance with the customer's documented instructions and the applicable Data Processing Agreement.
8.3 No Reliance on Consent by River
River does not generally rely on consent as a legal basis for processing personal data in its role as a data controller, except where expressly required by applicable law.
Where consent is required in relation to Customer Data, responsibility for obtaining and managing such consent rests exclusively with the customer.
8.4 UK GDPR Alignment
Where the UK GDPR applies, references in this Privacy Policy to the GDPR and its legal bases shall be construed as references to the corresponding provisions of the UK GDPR.
9. Data Sharing and Sub-Processors
9.1 Use of Sub-Processors and Service Providers
River may share personal data with trusted third-party service providers acting as sub-processors or independent processors, where necessary to provide, operate, secure and support the Service.
Such service providers may include, without limitation, providers of:
- cloud hosting, infrastructure and storage services;
- authentication, identity and access management;
- analytics, monitoring and logging services;
- customer support, communications and incident response services.
River does not sell personal data and does not disclose personal data to third parties for their own independent marketing purposes.
9.2 Data Protection Safeguards
River ensures that all sub-processors engaged to process personal data on its behalf are subject to appropriate contractual safeguards, including data protection obligations that are substantially equivalent to those set out in the applicable Data Processing Agreement and required by Article 28 GDPR and the UK GDPR.
River remains responsible for the performance of its sub-processors in accordance with applicable data protection law.
9.3 Sub-Processor List and Updates
River maintains a current and dynamic list of sub-processors, which may be updated from time to time to reflect changes in service providers, technical requirements or business needs.
Where required by applicable data protection law or the DPA, River will inform customers of material changes to its sub-processors and provide an opportunity to raise objections on reasonable data protection grounds, in accordance with the procedures set out in the DPA.
9.4 Disclosure Required by Law
River may disclose personal data where required to do so by applicable law, regulation, court order or other valid legal process.
Where legally permitted, River will notify the affected customer of such disclosure.
10. International Data Transfers
10.1 Data Hosting and Primary Processing Locations
River's primary infrastructure and the majority of its sub-processors are configured to process and store personal data within the European Union and the United Kingdom.
River does not intentionally transfer personal data outside the EU or the UK as part of the normal operation of the Service.
10.2 Limited Transfers Outside the EU/UK
In limited circumstances, personal data may be accessed or processed from locations outside the EU or the UK, for example in connection with:
- technical support or incident response activities;
- system maintenance or security-related investigations;
- the use of globally distributed service providers.
Such transfers, where they occur, are limited in scope and duration and are subject to appropriate safeguards in accordance with applicable data protection law.
10.3 Transfer Safeguards
Where personal data is transferred outside the EU or the UK, River ensures that one or more of the following safeguards apply, as appropriate:
- adequacy decisions adopted by the European Commission or the UK Government;
- Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK Information Commissioner;
- additional technical and organisational measures designed to ensure an essentially equivalent level of protection.
10.4 Ongoing Assessment
River regularly assesses the legal and technical framework governing international data transfers and implements additional measures where necessary to address identified risks.
Further details regarding international data transfers may be set out in the applicable Data Processing Agreement.
11. Data Retention
11.1 General Retention Principles
River retains personal data only for as long as necessary to fulfil the purposes for which it was collected and processed, in accordance with the principle of storage limitation under applicable data protection law.
Retention periods vary depending on:
- the nature of the personal data;
- the purpose of processing; and
- whether River acts as a data controller or a data processor.
11.2 Retention Where River Acts as a Data Controller
Where River acts as a data controller, personal data is retained for the duration of the contractual relationship with the customer and thereafter only for as long as necessary to:
- comply with applicable legal, regulatory or accounting obligations;
- maintain records for audit and compliance purposes;
- resolve disputes, enforce agreements or protect legal rights.
Once the applicable retention period expires, such personal data is securely deleted or anonymised.
11.3 Retention of Customer Content (Processor Role)
Where River processes personal data on behalf of customers within the Service ("Customer Content"), River acts solely as a data processor.
Customer Content is retained only for the duration of the applicable subscription or contractual relationship, unless otherwise instructed by the customer or required by applicable law.
Upon termination or expiration of the Service, Customer Content is deleted or returned to the customer in accordance with the applicable Data Processing Agreement (DPA), subject to any legally required retention obligations.
11.4 Backups and Residual Copies
Customer Content may be retained for a limited period in backup systems or logs following deletion or termination, solely for security, integrity and disaster recovery purposes.
Such data is protected by appropriate technical and organisational measures and is deleted in accordance with River's backup retention schedules.
11.5 Customer Responsibility
Customers remain responsible for defining and implementing appropriate data retention and deletion policies for personal data they control and process within the Service.
River does not independently assess the appropriateness of the customer's retention periods for Customer Content.
12. Security Measures
12.1 General Security Approach
River implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR and applicable data protection law.
Such measures are implemented taking into account:
- the state of the art;
- the nature, scope, context and purposes of processing;
- the risks to the rights and freedoms of natural persons.
12.2 Technical Security Measures
River's technical security measures include, where appropriate:
- encryption of personal data in transit and at rest;
- secure communication protocols (e.g. HTTPS/TLS);
- role-based access controls and authentication mechanisms;
- logical separation of environments;
- logging, monitoring and audit trails to detect and investigate security events;
- secure hosting environments provided by reputable infrastructure providers.
12.3 Organisational Security Measures
River's organisational measures include, where appropriate:
- access restrictions based on the principle of least privilege;
- internal policies and procedures governing data access and security;
- security awareness and confidentiality obligations for personnel with access to personal data;
- incident detection and response procedures.
12.4 Incident and Breach Management
River maintains procedures to identify, assess and respond to personal data breaches.
Where River acts as a data processor, it will notify the relevant customer without undue delay upon becoming aware of a personal data breach, in accordance with the applicable Data Processing Agreement and applicable law.
12.5 Limitations
While River takes reasonable and appropriate measures to protect personal data, no system or security measure can guarantee absolute security.
The Customer acknowledges that residual risks may remain and agrees that security obligations are assessed in light of applicable legal standards, not absolute risk elimination.
12.6 Customer Responsibilities
Customers remain responsible for:
- implementing appropriate security measures on their own systems and devices;
- managing access rights of their authorised users;
- ensuring that credentials are kept secure and not shared;
- configuring the Service in a manner consistent with their internal security requirements.
River is not responsible for security incidents arising from the Customer's failure to implement appropriate internal safeguards.
13. Data Subject Rights
13.1 Rights Where River Acts as a Data Controller
Where River acts as a data controller, individuals may exercise the rights available to them under the GDPR and the UK GDPR, subject to applicable conditions and limitations, including the right to:
- access their personal data;
- rectification of inaccurate or incomplete personal data;
- erasure of personal data ("right to be forgotten");
- restriction of processing;
- objection to processing;
- data portability, where applicable.
Requests relating to such rights may be submitted using the contact details set out in Section 17 (Contact).
River will respond to such requests within the timeframes required by applicable data protection law.
13.2 Rights Where River Acts as a Data Processor
Where River processes personal data on behalf of customers within the Service, River acts solely as a data processor.
In such cases:
- the customer organisation, as data controller, is responsible for responding to data subject requests;
- data subjects should direct their requests directly to the relevant customer organisation;
- River does not independently assess or respond to such requests unless instructed by the customer.
13.3 Assistance to Customers
Where required under applicable data protection law and the applicable Data Processing Agreement (DPA), River will provide reasonable assistance to customers to enable them to fulfil their obligations in responding to data subject requests.
Such assistance may include:
- providing relevant technical information;
- enabling access, correction or deletion of Customer Data within the Service;
- implementing restrictions or exports, where technically feasible.
River's assistance does not shift or reduce the customer's responsibility as data controller.
13.4 Limitations and Verification
River may request additional information to verify the identity of a data subject before responding to a request, where permitted by law.
Certain rights may be subject to limitations or exemptions under applicable data protection law.
13.5 Complaints
Where River acts as a data controller, individuals also have the right to lodge a complaint with a competent supervisory authority, in particular in the EU Member State or the UK where they have their habitual residence, place of work or where the alleged infringement occurred.
14. Children's Data
The Service is designed and intended exclusively for use by business customers in the field of medical aesthetics and plastic surgery and is not intended for use by individuals under the age of eighteen (18).
River does not knowingly collect or process personal data of minors, including any individual under the age of 18.
The Service must not be used to process personal data relating to minors.
Customers are strictly prohibited from uploading, submitting or otherwise processing personal data of individuals under the age of 18 within the Service.
If River becomes aware that personal data relating to a minor has been processed through the Service, River may take reasonable steps to restrict, delete or anonymise such data, in accordance with applicable law and, where relevant, the applicable Data Processing Agreement.
Customers remain solely responsible for ensuring that:
- the Service is used only in relation to adult individuals (18+); and
- all personal data processed within the Service complies with applicable age-related, medical and data protection requirements.
15. Automated Decision-Making
River does not carry out automated decision-making, including profiling, that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 GDPR and the UK GDPR.
In particular:
- the Service does not make automated decisions relating to medical diagnosis, treatment, eligibility, suitability, prioritisation or outcomes;
- the Service does not replace or override professional, clinical or medical judgment;
- any automation within the Service is limited to technical, administrative or workflow-related functions (such as message routing, task organisation or operational support) and does not result in legally or clinically binding decisions.
Any decisions, assessments or actions taken in relation to patients or prospective patients are made solely by the customer and its authorised users, in accordance with their professional judgment and applicable legal and medical obligations.
Where the Service includes configurable or assistive features (including rule-based or AI-assisted functionality), such features are intended solely to support internal workflows and do not constitute automated decision-making within the meaning of Article 22 GDPR.
16. Changes to This Privacy Policy
River may update or amend this Privacy Policy from time to time to reflect:
- changes to the Service or its functionality;
- changes in applicable laws or regulatory guidance;
- operational, security or business developments.
Where changes are material, River will provide reasonable notice of such changes through the Service, by email or by other appropriate means.
The updated version of this Privacy Policy will become effective as of the date indicated at the top of the document, unless stated otherwise.
Customers and authorised users are encouraged to review this Privacy Policy periodically to remain informed about how personal data is processed.
17. Contact
For any questions, requests or concerns relating to privacy, data protection or this Privacy Policy, individuals and customers may contact River using the details below:
River AI GmbH
Badenerstrasse 549
8048 Zürich
Switzerland
Email (privacy & data protection inquiries): sandro@get-river.ai
This contact information is provided exclusively for privacy, data protection and legal inquiries.
For technical support or customer service matters, customers should use the support channels made available through the Service.
