Legal

Data Processing Addendum

Last updated: August 8, 2026

This Data Processing Addendum ("DPA") forms part of the RivoCRM Terms of Service or other written agreement governing a customer's use of the RivoCRM website, application, and related services (collectively, the "Service").

This DPA is entered into between the customer organization or other business customer using the Service ("Customer," "you," or "your") and RivoCRM ("RivoCRM," "we," "us," or "our").

RivoCRM is currently operated in Canada as an unincorporated business under the name RivoCRM.

This DPA applies where RivoCRM processes Customer Personal Data on behalf of Customer in connection with the Service.

If Customer and RivoCRM have entered into a separately signed data-processing agreement that expressly supersedes this DPA, the separately signed agreement will control to the extent of any conflict.

1. Definitions

For purposes of this DPA:

"Applicable Data Protection Law" means privacy and data-protection laws applicable to the processing of Customer Personal Data under this DPA.

"Controller" means the person or organization that determines the purposes for which and manner in which personal information or personal data is processed, including equivalent concepts such as an "organization" or "business" where applicable.

"Customer Data" has the meaning given in the Terms of Service.

"Customer Personal Data" means personal information or personal data contained in Customer Data that RivoCRM processes on behalf of Customer in providing the Service.

"Data Subject" means an identified or identifiable individual to whom Customer Personal Data relates.

"Personal Data" or "Personal Information" means information relating to an identified or identifiable individual, as defined by Applicable Data Protection Law.

"Process" or "Processing" means any operation performed on Customer Personal Data, including collection, recording, organization, storage, retrieval, use, transmission, disclosure, restriction, deletion, or destruction.

"Processor" means a person or organization that processes Personal Data on behalf of a Controller, including equivalent service-provider concepts under applicable law.

"Security Incident" means a confirmed breach of security safeguards that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by RivoCRM.

"Subprocessor" means a third party engaged by RivoCRM to process Customer Personal Data on behalf of Customer in connection with providing the Service.

2. Roles of the Parties

For Customer Personal Data processed through the Service:

  • Customer acts as Controller or in a substantially equivalent role under Applicable Data Protection Law; and
  • RivoCRM acts as Processor or service provider on Customer's behalf.

If Customer itself processes Personal Data on behalf of another organization, Customer may be a Processor and RivoCRM may act as Customer's Subprocessor. In that situation, the obligations in this DPA apply to RivoCRM as appropriate to that processing relationship.

Customer determines the purposes for which Customer Personal Data is collected and used.

RivoCRM processes Customer Personal Data only to provide, secure, maintain, support, and improve the Service as permitted by this DPA, the Terms, Customer's use and configuration of the Service, and Applicable Data Protection Law.

RivoCRM's processing of account, billing, website visitor, support, security, and similar information for RivoCRM's own business purposes is governed by the RivoCRM Privacy Policy and is not Customer Personal Data processed solely on Customer's behalf.

3. Details of Processing

The parties acknowledge the following general description of processing.

ItemDescription
Subject matterProviding the RivoCRM CRM, transaction, workflow, communication, collaboration, storage, and related software services
DurationFor the duration of Customer's use of the Service, plus applicable deletion, backup, legal, security, and retention periods
Nature of processingCollection, receipt, hosting, storage, organization, structuring, retrieval, consultation, use, transmission, display, backup, modification at Customer's instruction, deletion, and other operations necessary to provide the Service
PurposeTo provide functionality selected or configured by Customer, including CRM records, contacts, properties, transactions, tasks, workflows, Autoplans, communications, files, collaboration, integrations, and optional AI-enabled functionality
FrequencyContinuous or as initiated by Customer and its authorized users during use of the Service
Data subjectsCustomer's clients, prospective clients, leads, contacts, buyers, sellers, vendors, collaborators, team members, employees, contractors, and other individuals whose information Customer enters or processes through RivoCRM
Types of Personal DataMay include names, email addresses, telephone numbers, mailing and property addresses, contact status, tags, notes, custom fields, property information, transaction information, prices, MLS/listing identifiers, dates, communications, task/activity information, relationship information, files, and other information Customer chooses to enter
Special or sensitive informationThe Service is not specifically designed as a repository for highly sensitive categories of Personal Data. Customer determines what information it enters and is responsible for ensuring that processing is appropriate and lawful.

Customer acknowledges that the categories and volume of Customer Personal Data depend substantially on Customer's own use of the Service.

4. Customer Instructions

Customer instructs RivoCRM to process Customer Personal Data as necessary to:

  • provide the Service;
  • perform actions initiated or configured by Customer or its authorized users;
  • host and store Customer Data;
  • provide support requested by Customer;
  • maintain and secure the Service;
  • provide integrations enabled by Customer;
  • send communications at Customer's instruction;
  • provide optional AI functionality when Customer chooses to use it;
  • prevent fraud, abuse, or security threats; and
  • comply with other documented instructions agreed between the parties.

The Terms, this DPA, Customer's configuration of the Service, and actions performed through the Service constitute Customer's documented instructions.

RivoCRM will not process Customer Personal Data for materially unrelated purposes except where required by applicable law.

If RivoCRM reasonably believes that a Customer instruction violates Applicable Data Protection Law, we may notify Customer and suspend the affected processing until the parties resolve the issue, unless applicable law prohibits us from doing so.

5. Customer Responsibilities

Customer is responsible for:

  • complying with Applicable Data Protection Law;
  • determining the lawful purposes for processing Customer Personal Data;
  • providing required privacy notices;
  • obtaining any required consent or other lawful authority;
  • ensuring Customer has the right to provide Customer Personal Data to RivoCRM;
  • ensuring Customer's instructions to RivoCRM are lawful;
  • maintaining appropriate accuracy of Customer Personal Data;
  • determining appropriate retention periods for Customer's business records;
  • configuring roles, permissions, and access controls appropriately;
  • managing authorized users;
  • protecting Customer account credentials;
  • responding to Data Subject requests for Customer Personal Data;
  • complying with professional, brokerage, recordkeeping, confidentiality, and regulatory obligations applicable to Customer;
  • ensuring communications sent through RivoCRM comply with applicable anti-spam and telecommunications law; and
  • determining whether the Service is appropriate for the types of information Customer chooses to process.

Customer will not instruct RivoCRM to process Customer Personal Data in a manner that Customer knows violates Applicable Data Protection Law.

6. RivoCRM's Processing Obligations

RivoCRM will:

  • process Customer Personal Data only in accordance with documented Customer instructions, this DPA, the Terms, and Applicable Data Protection Law;
  • ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
  • implement reasonable technical and organizational safeguards appropriate to the nature of the Service and risks associated with the processing;
  • take reasonable steps to ensure Subprocessors are subject to data-protection obligations appropriate to the services they provide;
  • provide reasonable assistance with Data Subject requests as described below;
  • provide reasonable assistance regarding Security Incidents as described below;
  • delete or return Customer Personal Data following termination in accordance with Section 13 and the functionality and retention practices of the Service; and
  • make information reasonably available to Customer as necessary to demonstrate compliance with RivoCRM's obligations under this DPA.

RivoCRM will not sell Customer Personal Data for monetary consideration.

RivoCRM will not use Customer Personal Data for third-party behavioural advertising.

7. Confidentiality

RivoCRM will restrict access to Customer Personal Data to personnel, contractors, and service providers who require access for legitimate purposes associated with providing, securing, maintaining, or supporting the Service.

Persons authorized by RivoCRM to access Customer Personal Data will be subject to contractual, professional, or other appropriate confidentiality obligations.

RivoCRM may access Customer Personal Data where reasonably necessary for:

  • customer support;
  • troubleshooting;
  • security and abuse investigations;
  • maintenance;
  • account administration;
  • compliance with law; or
  • other purposes permitted under the Terms and this DPA.

Administrative access should be limited to authorized personnel and, where appropriate, logged or otherwise subject to internal controls.

8. Security Measures

RivoCRM will implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized access, use, disclosure, alteration, loss, or destruction.

Depending on the applicable system and feature, safeguards may include:

  • encryption in transit;
  • secure cloud infrastructure;
  • password hashing;
  • authentication and session controls;
  • multi-factor authentication functionality;
  • role-based access controls;
  • organization and tenant access controls;
  • restricted administrative access;
  • logging and monitoring;
  • bot and abuse protection;
  • infrastructure access controls;
  • backup and recovery procedures;
  • dependency and software maintenance practices; and
  • incident-response procedures.

Customer acknowledges that no information system can guarantee absolute security.

Customer is responsible for security matters within Customer's control, including account credentials, authorized users, role assignments, endpoint security, and the information Customer chooses to process through the Service.

9. Subprocessors

Customer provides RivoCRM with general authorization to engage Subprocessors as reasonably necessary to provide the Service.

RivoCRM will take reasonable steps to ensure that Subprocessors that process Customer Personal Data are subject to contractual obligations that provide appropriate protection for that data.

RivoCRM remains responsible for its obligations under this DPA notwithstanding its use of Subprocessors, subject to the limitations of liability in the Terms and applicable law.

Current Core Subprocessors and Service Providers

RivoCRM's production infrastructure may include the following providers:

ProviderService / PurposeData That May Be Processed
VercelApplication hosting, deployment, networking, and deliveryCustomer Personal Data and technical information transmitted through or processed by the hosted application as necessary to provide the Service
NeonHosted PostgreSQL database infrastructureCustomer Personal Data stored in the RivoCRM production database
StripeSubscription payments, billing, fraud prevention, and related payment servicesPrimarily account, billing, transaction, and payment-related information; RivoCRM does not intend to store full payment card details
GoogleAuthentication and integrations when enabled and selectedAccount identity information and integration data authorized by the applicable user
CloudflareTurnstile bot protection and related security functionality when enabledTechnical, browser, device, and verification information necessary to provide the security functionality
ResendTransactional and application email when enabledEmail addresses and message content necessary for delivery of transactional or customer-initiated communications
TwilioSMS and telecommunications when enabledPhone numbers and message content necessary for SMS features configured by Customer
S3-compatible object storage (for example Cloudflare R2)File and image storage when enabledFiles and images Customer or authorized users upload through the Service
OpenAIOptional AI model functionality when enabledPrompts, context, and related Customer content Customer or authorized users submit when using AI features
SentryError and diagnostic monitoring when enabledTechnical diagnostic information that may include limited contextual data necessary for reliability

RivoCRM will update its public documentation or Subprocessor information as material production providers are added or replaced.

A further summary appears in Schedule C below.

Changes to Subprocessors

RivoCRM may add, remove, or replace Subprocessors as the Service evolves.

Where required by Applicable Data Protection Law or a separately agreed contractual obligation, RivoCRM will provide reasonable notice of a material new Subprocessor that will process Customer Personal Data.

Customer may object to a new Subprocessor on reasonable and documented data-protection grounds by contacting RivoCRM promptly after receiving notice.

The parties will attempt in good faith to address a valid objection.

If RivoCRM cannot reasonably provide the Service without the Subprocessor and the parties cannot resolve the objection, Customer may discontinue the affected feature or terminate the affected Service in accordance with the Terms.

10. International Processing and Transfers

Customer acknowledges that RivoCRM and its Subprocessors may process Customer Personal Data in Canada, the United States, and other jurisdictions in which RivoCRM's providers operate.

RivoCRM's application infrastructure and database infrastructure may be hosted outside Customer's province, territory, or country.

Customer authorizes such transfers where reasonably necessary to provide the Service, subject to Applicable Data Protection Law.

RivoCRM will use contractual, technical, and organizational measures appropriate to its role and the applicable processing.

Where Applicable Data Protection Law requires a specific transfer mechanism, the parties will cooperate in good faith to implement a legally appropriate mechanism where reasonably required for Customer's use of the Service.

Customer is responsible for determining whether Customer has any sector-specific, brokerage-specific, contractual, or regulatory data-residency requirements before using the Service.

11. Data Subject Requests

If RivoCRM receives a request from a Data Subject relating to Customer Personal Data for which Customer is the Controller, RivoCRM may direct the individual to Customer unless RivoCRM is legally required to respond directly.

Taking into account the nature of the processing and functionality available in the Service, RivoCRM will provide reasonable assistance to Customer with requests to:

  • access Personal Data;
  • correct Personal Data;
  • delete Personal Data;
  • export or obtain a copy of Personal Data; or
  • exercise other applicable privacy rights.

Where Customer can fulfill a request directly through available Service functionality, Customer should use that functionality before requesting manual assistance from RivoCRM.

RivoCRM may charge reasonable fees for unusually burdensome or repetitive assistance where permitted by law and where the work falls materially outside normal Service functionality, provided any such fees are communicated in advance.

12. Security Incidents

RivoCRM will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data where notification to Customer is required by Applicable Data Protection Law or reasonably necessary for Customer to meet its own legal obligations.

To the extent reasonably available, notice may include:

  • the nature of the Security Incident;
  • categories of information affected;
  • categories or approximate number of affected individuals, where known;
  • likely consequences or risks, where reasonably known;
  • measures taken or proposed to address the incident; and
  • information reasonably necessary for Customer to assess its notification obligations.

RivoCRM may provide information in phases as the investigation develops.

RivoCRM's notification of a Security Incident is not an admission of fault or liability.

Customer is responsible for determining whether Customer must notify affected individuals, regulators, brokerages, insurers, or other parties, except where Applicable Data Protection Law independently requires RivoCRM to provide notification.

RivoCRM will maintain records of privacy/security breaches where required by applicable law.

13. Return, Export, and Deletion of Customer Personal Data

During the term of the Service, Customer may delete or export Customer Data using functionality made available by RivoCRM.

Following termination or closure of Customer's account, RivoCRM will delete or de-identify Customer Personal Data within a reasonable period, subject to:

  • applicable backup cycles;
  • technical limitations;
  • fraud and security requirements;
  • legal obligations;
  • billing and accounting requirements;
  • dispute preservation; and
  • other lawful retention requirements.

Customer is responsible for exporting Customer Data it wishes to retain before termination or account closure.

Customer Personal Data may remain in backups or disaster-recovery systems until those systems are overwritten or the applicable retention period expires.

RivoCRM will not intentionally restore deleted Customer Personal Data from backup except where reasonably necessary for disaster recovery, security, legal compliance, or restoration of the Service.

Specific retention periods may be documented separately as RivoCRM's operational procedures mature.

14. Audits and Compliance Information

Upon Customer's reasonable written request, RivoCRM will make available information reasonably necessary to demonstrate compliance with this DPA.

For standard customers, this may include:

  • written responses to reasonable security or privacy questionnaires;
  • descriptions of applicable safeguards;
  • information about relevant Subprocessors; and
  • available policies or documentation appropriate to Customer's use of the Service.

Unless required by Applicable Data Protection Law, a competent supervisory authority, or a confirmed Security Incident materially affecting Customer Personal Data, Customer may make such a request no more than once in any twelve-month period.

Customer must protect non-public security and compliance information disclosed by RivoCRM as confidential information.

On-site inspections, penetration testing, access to RivoCRM systems, access to another customer's information, and audits of Subprocessor facilities are not included as standard audit rights.

If Applicable Data Protection Law requires an additional audit that cannot reasonably be satisfied through documentation, the parties will cooperate in good faith to establish a reasonable scope, timing, confidentiality arrangement, and allocation of costs.

Nothing in this section requires RivoCRM to disclose information that would compromise the security of the Service or another customer's confidentiality.

15. Government and Legal Requests

If RivoCRM receives a legally binding request from a government authority for Customer Personal Data, RivoCRM may disclose information to the extent required by law.

Where legally permitted and reasonably practicable, RivoCRM will attempt to notify Customer before disclosing Customer Personal Data in response to such a request.

RivoCRM may challenge or narrow a request where it reasonably determines that doing so is appropriate and lawful, but is not required to initiate legal proceedings on Customer's behalf.

16. Compliance Assistance

Taking into account the nature of processing and information available to RivoCRM, we will provide reasonable assistance to Customer with privacy and security obligations relating to RivoCRM's processing of Customer Personal Data where required by Applicable Data Protection Law.

Such assistance may include information reasonably necessary for:

  • privacy assessments;
  • security assessments;
  • breach investigations;
  • Data Subject requests; and
  • consultations with privacy regulators.

Customer remains responsible for determining which laws and compliance obligations apply to Customer's business and use of the Service.

17. Highly Sensitive and Regulated Data

RivoCRM is designed as a real estate CRM and transaction-management platform.

Unless RivoCRM expressly states otherwise in writing, the Service is not specifically designed to store or process:

  • payment card numbers outside approved payment-provider workflows;
  • online banking credentials;
  • government authentication credentials;
  • passwords belonging to Customer's clients;
  • protected health information subject to specialized healthcare regimes;
  • biometric templates used for unique identification;
  • highly sensitive authentication secrets; or
  • other information subject to specialized regulatory requirements that RivoCRM has not agreed to support.

Customer must not use RivoCRM as a general-purpose repository for such information without first confirming that the Service is appropriate for the applicable data and legal requirements.

This section does not prohibit ordinary real estate client information merely because it is personal or confidential.

18. Liability

Each party's liability arising out of or relating to this DPA is subject to the exclusions, limitations, and liability provisions in the RivoCRM Terms of Service or other governing agreement, to the maximum extent permitted by applicable law.

Nothing in this DPA limits liability to the extent such liability cannot lawfully be excluded or limited.

19. Term and Termination

This DPA becomes effective when it applies to Customer's use of the Service and remains in effect for as long as RivoCRM processes Customer Personal Data on Customer's behalf.

Termination of the Terms or Customer's use of the Service does not immediately terminate provisions of this DPA that by their nature must continue while RivoCRM retains Customer Personal Data.

Sections concerning confidentiality, security incidents, deletion, liability, and other provisions that by their nature should survive will continue for the applicable period.

20. Order of Precedence

If there is a conflict concerning processing of Customer Personal Data:

  1. a separately signed DPA or data-protection agreement between Customer and RivoCRM will control, if it expressly supersedes this DPA;
  2. this DPA will control over the general Terms of Service with respect to the conflicting data-processing issue; and
  3. the Terms of Service will otherwise continue to apply.

The Privacy Policy describes RivoCRM's privacy practices but does not reduce contractual obligations expressly provided in this DPA.

21. Changes to This DPA

RivoCRM may update this DPA to reflect changes in the Service, Subprocessors, infrastructure, or applicable legal requirements.

We will update the "Last updated" date when the DPA changes.

For a material change that reduces contractual data-protection commitments applicable to existing customers, RivoCRM may provide additional notice where appropriate or required.

Changes will not retroactively authorize RivoCRM to process Customer Personal Data for materially unrelated purposes.

22. Governing Law

This DPA is governed by the same governing law and dispute provisions that apply under the RivoCRM Terms of Service or other governing agreement between Customer and RivoCRM.

Unless another governing agreement applies, this DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, and the parties submit to the dispute venue of the courts of Ontario, Canada, subject to mandatory law that cannot be contractually excluded.

23. Contact

Privacy and DPA questions may be sent to:

RivoCRM Privacy Officer

RivoCRM
Canada
Email: info@rivocrm.app
Mailing address: Address available on request

Contract and legal inquiries may be sent to:

RivoCRM
Email: info@rivocrm.app


Schedule A — Processing Details

This Schedule forms part of the DPA.

A.1 Subject Matter

RivoCRM processes Customer Personal Data to provide a cloud-based CRM, transaction-management, workflow, communication, collaboration, and related software platform.

A.2 Processing Activities

Processing may include:

  • receiving Customer Personal Data;
  • hosting and database storage;
  • organizing and indexing records;
  • displaying information to authorized users;
  • searching and retrieving records;
  • creating relationships between CRM records;
  • storing notes, tasks, comments, and activities;
  • storing property and transaction information;
  • executing workflows and Autoplans;
  • transmitting email or SMS at Customer's instruction;
  • storing and serving files;
  • providing integrations selected by Customer;
  • generating AI-assisted responses or content when Customer invokes an AI feature;
  • providing support and troubleshooting;
  • creating backups;
  • protecting the Service from abuse and security threats; and
  • deleting information at Customer's instruction or following termination.

A.3 Categories of Data Subjects

May include:

  • prospective buyers;
  • buyers;
  • prospective sellers;
  • sellers;
  • leads;
  • clients;
  • former clients;
  • contacts;
  • referral partners;
  • vendors and service providers;
  • real estate professionals;
  • organization members;
  • assistants;
  • employees;
  • contractors; and
  • other individuals whose information Customer chooses to process.

A.4 Categories of Personal Data

May include:

  • name;
  • email address;
  • telephone number;
  • mailing address;
  • property address;
  • contact stage or status;
  • tags;
  • notes;
  • custom fields;
  • property information;
  • transaction information;
  • listing or MLS identifiers;
  • prices and transaction values;
  • transaction dates and deadlines;
  • communication content;
  • communication preferences;
  • tasks;
  • activities;
  • comments;
  • files and images;
  • relationships between contacts and transactions; and
  • other information entered by Customer.

A.5 Duration

Processing continues for the term of Customer's account or subscription and for applicable post-termination deletion, backup, security, legal, and retention periods.


Schedule B — Technical and Organizational Measures

RivoCRM maintains reasonable safeguards appropriate to its size, Service, infrastructure, and processing risks.

Measures may include, as applicable:

B.1 Access Control

  • authenticated user accounts;
  • role-based access controls;
  • organization/tenant separation;
  • restricted platform-administrator access;
  • least-privilege principles for internal access where practical;
  • removal or modification of access when no longer required; and
  • optional multi-factor authentication.

B.2 Application and Authentication Security

  • password hashing;
  • secure session management;
  • authentication controls;
  • anti-CSRF or equivalent protections where applicable;
  • bot/automated-abuse protection;
  • rate limiting where appropriate; and
  • secure development and dependency maintenance practices.

B.3 Transmission and Infrastructure Security

  • encrypted HTTPS/TLS connections;
  • managed application hosting;
  • managed PostgreSQL database infrastructure;
  • restricted production infrastructure access; and
  • security capabilities provided by applicable infrastructure vendors.

B.4 Data Resilience

  • database/infrastructure backup or recovery capabilities;
  • operational monitoring;
  • incident-response procedures; and
  • restoration procedures appropriate to the Service.

B.5 Organizational Measures

  • confidentiality obligations for persons with authorized access;
  • limited support access;
  • service-provider review;
  • documented privacy and security procedures as the business matures;
  • breach/incident recordkeeping where required; and
  • periodic review of access and infrastructure practices.

The specific implementation of these measures may change as RivoCRM improves its security architecture, provided that RivoCRM does not materially reduce the overall level of protection during an active subscription without appropriate justification.


Schedule C — Subprocessor Register

This Schedule reflects RivoCRM's production service providers as of the "Last updated" date. Whether a provider receives Customer Personal Data depends on feature configuration and Customer's use of the Service.

SubprocessorPurposeProcessing locationStatus
VercelApplication hosting, deployment, networking, and deliveryProvider infrastructure (may include the United States and other regions)Active
NeonHosted PostgreSQL databaseProvider infrastructure (region as configured for the production database)Active
StripePayments and subscription billingProvider infrastructureActive when billing is enabled
GoogleOAuth authentication and integrationsProvider infrastructureActive when enabled and used
CloudflareTurnstile / security functionalityProvider infrastructureActive when enabled
ResendTransactional and customer email deliveryProvider infrastructureActive when email features are enabled
TwilioSMS and telecommunicationsProvider infrastructureActive when SMS features are enabled
S3-compatible storage (e.g. Cloudflare R2)File and image storageProvider infrastructureActive when file/image uploads are enabled
OpenAIOptional AI functionalityProvider infrastructureActive when AI features are used
SentryError and diagnostic monitoringProvider infrastructureActive when monitoring is configured

RivoCRM may update this register as production providers change. Material changes that affect Customer Personal Data processing will be reflected in this DPA or related public documentation.