Data Processing Addendum
Last updated: August 8, 2026
This Data Processing Addendum ("DPA") forms part of the RivoCRM Terms of Service or other written agreement governing a customer's use of the RivoCRM website, application, and related services (collectively, the "Service").
This DPA is entered into between the customer organization or other business customer using the Service ("Customer," "you," or "your") and RivoCRM ("RivoCRM," "we," "us," or "our").
RivoCRM is currently operated in Canada as an unincorporated business under the name RivoCRM.
This DPA applies where RivoCRM processes Customer Personal Data on behalf of Customer in connection with the Service.
If Customer and RivoCRM have entered into a separately signed data-processing agreement that expressly supersedes this DPA, the separately signed agreement will control to the extent of any conflict.
1. Definitions
For purposes of this DPA:
"Applicable Data Protection Law" means privacy and data-protection laws applicable to the processing of Customer Personal Data under this DPA.
"Controller" means the person or organization that determines the purposes for which and manner in which personal information or personal data is processed, including equivalent concepts such as an "organization" or "business" where applicable.
"Customer Data" has the meaning given in the Terms of Service.
"Customer Personal Data" means personal information or personal data contained in Customer Data that RivoCRM processes on behalf of Customer in providing the Service.
"Data Subject" means an identified or identifiable individual to whom Customer Personal Data relates.
"Personal Data" or "Personal Information" means information relating to an identified or identifiable individual, as defined by Applicable Data Protection Law.
"Process" or "Processing" means any operation performed on Customer Personal Data, including collection, recording, organization, storage, retrieval, use, transmission, disclosure, restriction, deletion, or destruction.
"Processor" means a person or organization that processes Personal Data on behalf of a Controller, including equivalent service-provider concepts under applicable law.
"Security Incident" means a confirmed breach of security safeguards that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by RivoCRM.
"Subprocessor" means a third party engaged by RivoCRM to process Customer Personal Data on behalf of Customer in connection with providing the Service.
2. Roles of the Parties
For Customer Personal Data processed through the Service:
- Customer acts as Controller or in a substantially equivalent role under Applicable Data Protection Law; and
- RivoCRM acts as Processor or service provider on Customer's behalf.
If Customer itself processes Personal Data on behalf of another organization, Customer may be a Processor and RivoCRM may act as Customer's Subprocessor. In that situation, the obligations in this DPA apply to RivoCRM as appropriate to that processing relationship.
Customer determines the purposes for which Customer Personal Data is collected and used.
RivoCRM processes Customer Personal Data only to provide, secure, maintain, support, and improve the Service as permitted by this DPA, the Terms, Customer's use and configuration of the Service, and Applicable Data Protection Law.
RivoCRM's processing of account, billing, website visitor, support, security, and similar information for RivoCRM's own business purposes is governed by the RivoCRM Privacy Policy and is not Customer Personal Data processed solely on Customer's behalf.
3. Details of Processing
The parties acknowledge the following general description of processing.
| Item | Description |
|---|---|
| Subject matter | Providing the RivoCRM CRM, transaction, workflow, communication, collaboration, storage, and related software services |
| Duration | For the duration of Customer's use of the Service, plus applicable deletion, backup, legal, security, and retention periods |
| Nature of processing | Collection, receipt, hosting, storage, organization, structuring, retrieval, consultation, use, transmission, display, backup, modification at Customer's instruction, deletion, and other operations necessary to provide the Service |
| Purpose | To provide functionality selected or configured by Customer, including CRM records, contacts, properties, transactions, tasks, workflows, Autoplans, communications, files, collaboration, integrations, and optional AI-enabled functionality |
| Frequency | Continuous or as initiated by Customer and its authorized users during use of the Service |
| Data subjects | Customer's clients, prospective clients, leads, contacts, buyers, sellers, vendors, collaborators, team members, employees, contractors, and other individuals whose information Customer enters or processes through RivoCRM |
| Types of Personal Data | May include names, email addresses, telephone numbers, mailing and property addresses, contact status, tags, notes, custom fields, property information, transaction information, prices, MLS/listing identifiers, dates, communications, task/activity information, relationship information, files, and other information Customer chooses to enter |
| Special or sensitive information | The Service is not specifically designed as a repository for highly sensitive categories of Personal Data. Customer determines what information it enters and is responsible for ensuring that processing is appropriate and lawful. |
Customer acknowledges that the categories and volume of Customer Personal Data depend substantially on Customer's own use of the Service.
4. Customer Instructions
Customer instructs RivoCRM to process Customer Personal Data as necessary to:
- provide the Service;
- perform actions initiated or configured by Customer or its authorized users;
- host and store Customer Data;
- provide support requested by Customer;
- maintain and secure the Service;
- provide integrations enabled by Customer;
- send communications at Customer's instruction;
- provide optional AI functionality when Customer chooses to use it;
- prevent fraud, abuse, or security threats; and
- comply with other documented instructions agreed between the parties.
The Terms, this DPA, Customer's configuration of the Service, and actions performed through the Service constitute Customer's documented instructions.
RivoCRM will not process Customer Personal Data for materially unrelated purposes except where required by applicable law.
If RivoCRM reasonably believes that a Customer instruction violates Applicable Data Protection Law, we may notify Customer and suspend the affected processing until the parties resolve the issue, unless applicable law prohibits us from doing so.
5. Customer Responsibilities
Customer is responsible for:
- complying with Applicable Data Protection Law;
- determining the lawful purposes for processing Customer Personal Data;
- providing required privacy notices;
- obtaining any required consent or other lawful authority;
- ensuring Customer has the right to provide Customer Personal Data to RivoCRM;
- ensuring Customer's instructions to RivoCRM are lawful;
- maintaining appropriate accuracy of Customer Personal Data;
- determining appropriate retention periods for Customer's business records;
- configuring roles, permissions, and access controls appropriately;
- managing authorized users;
- protecting Customer account credentials;
- responding to Data Subject requests for Customer Personal Data;
- complying with professional, brokerage, recordkeeping, confidentiality, and regulatory obligations applicable to Customer;
- ensuring communications sent through RivoCRM comply with applicable anti-spam and telecommunications law; and
- determining whether the Service is appropriate for the types of information Customer chooses to process.
Customer will not instruct RivoCRM to process Customer Personal Data in a manner that Customer knows violates Applicable Data Protection Law.
6. RivoCRM's Processing Obligations
RivoCRM will:
- process Customer Personal Data only in accordance with documented Customer instructions, this DPA, the Terms, and Applicable Data Protection Law;
- ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
- implement reasonable technical and organizational safeguards appropriate to the nature of the Service and risks associated with the processing;
- take reasonable steps to ensure Subprocessors are subject to data-protection obligations appropriate to the services they provide;
- provide reasonable assistance with Data Subject requests as described below;
- provide reasonable assistance regarding Security Incidents as described below;
- delete or return Customer Personal Data following termination in accordance with Section 13 and the functionality and retention practices of the Service; and
- make information reasonably available to Customer as necessary to demonstrate compliance with RivoCRM's obligations under this DPA.
RivoCRM will not sell Customer Personal Data for monetary consideration.
RivoCRM will not use Customer Personal Data for third-party behavioural advertising.
7. Confidentiality
RivoCRM will restrict access to Customer Personal Data to personnel, contractors, and service providers who require access for legitimate purposes associated with providing, securing, maintaining, or supporting the Service.
Persons authorized by RivoCRM to access Customer Personal Data will be subject to contractual, professional, or other appropriate confidentiality obligations.
RivoCRM may access Customer Personal Data where reasonably necessary for:
- customer support;
- troubleshooting;
- security and abuse investigations;
- maintenance;
- account administration;
- compliance with law; or
- other purposes permitted under the Terms and this DPA.
Administrative access should be limited to authorized personnel and, where appropriate, logged or otherwise subject to internal controls.
8. Security Measures
RivoCRM will implement and maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized access, use, disclosure, alteration, loss, or destruction.
Depending on the applicable system and feature, safeguards may include:
- encryption in transit;
- secure cloud infrastructure;
- password hashing;
- authentication and session controls;
- multi-factor authentication functionality;
- role-based access controls;
- organization and tenant access controls;
- restricted administrative access;
- logging and monitoring;
- bot and abuse protection;
- infrastructure access controls;
- backup and recovery procedures;
- dependency and software maintenance practices; and
- incident-response procedures.
Customer acknowledges that no information system can guarantee absolute security.
Customer is responsible for security matters within Customer's control, including account credentials, authorized users, role assignments, endpoint security, and the information Customer chooses to process through the Service.
9. Subprocessors
Customer provides RivoCRM with general authorization to engage Subprocessors as reasonably necessary to provide the Service.
RivoCRM will take reasonable steps to ensure that Subprocessors that process Customer Personal Data are subject to contractual obligations that provide appropriate protection for that data.
RivoCRM remains responsible for its obligations under this DPA notwithstanding its use of Subprocessors, subject to the limitations of liability in the Terms and applicable law.
Current Core Subprocessors and Service Providers
RivoCRM's production infrastructure may include the following providers:
| Provider | Service / Purpose | Data That May Be Processed |
|---|---|---|
| Vercel | Application hosting, deployment, networking, and delivery | Customer Personal Data and technical information transmitted through or processed by the hosted application as necessary to provide the Service |
| Neon | Hosted PostgreSQL database infrastructure | Customer Personal Data stored in the RivoCRM production database |
| Stripe | Subscription payments, billing, fraud prevention, and related payment services | Primarily account, billing, transaction, and payment-related information; RivoCRM does not intend to store full payment card details |
| Authentication and integrations when enabled and selected | Account identity information and integration data authorized by the applicable user | |
| Cloudflare | Turnstile bot protection and related security functionality when enabled | Technical, browser, device, and verification information necessary to provide the security functionality |
| Resend | Transactional and application email when enabled | Email addresses and message content necessary for delivery of transactional or customer-initiated communications |
| Twilio | SMS and telecommunications when enabled | Phone numbers and message content necessary for SMS features configured by Customer |
| S3-compatible object storage (for example Cloudflare R2) | File and image storage when enabled | Files and images Customer or authorized users upload through the Service |
| OpenAI | Optional AI model functionality when enabled | Prompts, context, and related Customer content Customer or authorized users submit when using AI features |
| Sentry | Error and diagnostic monitoring when enabled | Technical diagnostic information that may include limited contextual data necessary for reliability |
RivoCRM will update its public documentation or Subprocessor information as material production providers are added or replaced.
A further summary appears in Schedule C below.
Changes to Subprocessors
RivoCRM may add, remove, or replace Subprocessors as the Service evolves.
Where required by Applicable Data Protection Law or a separately agreed contractual obligation, RivoCRM will provide reasonable notice of a material new Subprocessor that will process Customer Personal Data.
Customer may object to a new Subprocessor on reasonable and documented data-protection grounds by contacting RivoCRM promptly after receiving notice.
The parties will attempt in good faith to address a valid objection.
If RivoCRM cannot reasonably provide the Service without the Subprocessor and the parties cannot resolve the objection, Customer may discontinue the affected feature or terminate the affected Service in accordance with the Terms.
10. International Processing and Transfers
Customer acknowledges that RivoCRM and its Subprocessors may process Customer Personal Data in Canada, the United States, and other jurisdictions in which RivoCRM's providers operate.
RivoCRM's application infrastructure and database infrastructure may be hosted outside Customer's province, territory, or country.
Customer authorizes such transfers where reasonably necessary to provide the Service, subject to Applicable Data Protection Law.
RivoCRM will use contractual, technical, and organizational measures appropriate to its role and the applicable processing.
Where Applicable Data Protection Law requires a specific transfer mechanism, the parties will cooperate in good faith to implement a legally appropriate mechanism where reasonably required for Customer's use of the Service.
Customer is responsible for determining whether Customer has any sector-specific, brokerage-specific, contractual, or regulatory data-residency requirements before using the Service.
11. Data Subject Requests
If RivoCRM receives a request from a Data Subject relating to Customer Personal Data for which Customer is the Controller, RivoCRM may direct the individual to Customer unless RivoCRM is legally required to respond directly.
Taking into account the nature of the processing and functionality available in the Service, RivoCRM will provide reasonable assistance to Customer with requests to:
- access Personal Data;
- correct Personal Data;
- delete Personal Data;
- export or obtain a copy of Personal Data; or
- exercise other applicable privacy rights.
Where Customer can fulfill a request directly through available Service functionality, Customer should use that functionality before requesting manual assistance from RivoCRM.
RivoCRM may charge reasonable fees for unusually burdensome or repetitive assistance where permitted by law and where the work falls materially outside normal Service functionality, provided any such fees are communicated in advance.
12. Security Incidents
RivoCRM will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data where notification to Customer is required by Applicable Data Protection Law or reasonably necessary for Customer to meet its own legal obligations.
To the extent reasonably available, notice may include:
- the nature of the Security Incident;
- categories of information affected;
- categories or approximate number of affected individuals, where known;
- likely consequences or risks, where reasonably known;
- measures taken or proposed to address the incident; and
- information reasonably necessary for Customer to assess its notification obligations.
RivoCRM may provide information in phases as the investigation develops.
RivoCRM's notification of a Security Incident is not an admission of fault or liability.
Customer is responsible for determining whether Customer must notify affected individuals, regulators, brokerages, insurers, or other parties, except where Applicable Data Protection Law independently requires RivoCRM to provide notification.
RivoCRM will maintain records of privacy/security breaches where required by applicable law.
13. Return, Export, and Deletion of Customer Personal Data
During the term of the Service, Customer may delete or export Customer Data using functionality made available by RivoCRM.
Following termination or closure of Customer's account, RivoCRM will delete or de-identify Customer Personal Data within a reasonable period, subject to:
- applicable backup cycles;
- technical limitations;
- fraud and security requirements;
- legal obligations;
- billing and accounting requirements;
- dispute preservation; and
- other lawful retention requirements.
Customer is responsible for exporting Customer Data it wishes to retain before termination or account closure.
Customer Personal Data may remain in backups or disaster-recovery systems until those systems are overwritten or the applicable retention period expires.
RivoCRM will not intentionally restore deleted Customer Personal Data from backup except where reasonably necessary for disaster recovery, security, legal compliance, or restoration of the Service.
Specific retention periods may be documented separately as RivoCRM's operational procedures mature.
14. Audits and Compliance Information
Upon Customer's reasonable written request, RivoCRM will make available information reasonably necessary to demonstrate compliance with this DPA.
For standard customers, this may include:
- written responses to reasonable security or privacy questionnaires;
- descriptions of applicable safeguards;
- information about relevant Subprocessors; and
- available policies or documentation appropriate to Customer's use of the Service.
Unless required by Applicable Data Protection Law, a competent supervisory authority, or a confirmed Security Incident materially affecting Customer Personal Data, Customer may make such a request no more than once in any twelve-month period.
Customer must protect non-public security and compliance information disclosed by RivoCRM as confidential information.
On-site inspections, penetration testing, access to RivoCRM systems, access to another customer's information, and audits of Subprocessor facilities are not included as standard audit rights.
If Applicable Data Protection Law requires an additional audit that cannot reasonably be satisfied through documentation, the parties will cooperate in good faith to establish a reasonable scope, timing, confidentiality arrangement, and allocation of costs.
Nothing in this section requires RivoCRM to disclose information that would compromise the security of the Service or another customer's confidentiality.
15. Government and Legal Requests
If RivoCRM receives a legally binding request from a government authority for Customer Personal Data, RivoCRM may disclose information to the extent required by law.
Where legally permitted and reasonably practicable, RivoCRM will attempt to notify Customer before disclosing Customer Personal Data in response to such a request.
RivoCRM may challenge or narrow a request where it reasonably determines that doing so is appropriate and lawful, but is not required to initiate legal proceedings on Customer's behalf.
16. Compliance Assistance
Taking into account the nature of processing and information available to RivoCRM, we will provide reasonable assistance to Customer with privacy and security obligations relating to RivoCRM's processing of Customer Personal Data where required by Applicable Data Protection Law.
Such assistance may include information reasonably necessary for:
- privacy assessments;
- security assessments;
- breach investigations;
- Data Subject requests; and
- consultations with privacy regulators.
Customer remains responsible for determining which laws and compliance obligations apply to Customer's business and use of the Service.
17. Highly Sensitive and Regulated Data
RivoCRM is designed as a real estate CRM and transaction-management platform.
Unless RivoCRM expressly states otherwise in writing, the Service is not specifically designed to store or process:
- payment card numbers outside approved payment-provider workflows;
- online banking credentials;
- government authentication credentials;
- passwords belonging to Customer's clients;
- protected health information subject to specialized healthcare regimes;
- biometric templates used for unique identification;
- highly sensitive authentication secrets; or
- other information subject to specialized regulatory requirements that RivoCRM has not agreed to support.
Customer must not use RivoCRM as a general-purpose repository for such information without first confirming that the Service is appropriate for the applicable data and legal requirements.
This section does not prohibit ordinary real estate client information merely because it is personal or confidential.
18. Liability
Each party's liability arising out of or relating to this DPA is subject to the exclusions, limitations, and liability provisions in the RivoCRM Terms of Service or other governing agreement, to the maximum extent permitted by applicable law.
Nothing in this DPA limits liability to the extent such liability cannot lawfully be excluded or limited.
19. Term and Termination
This DPA becomes effective when it applies to Customer's use of the Service and remains in effect for as long as RivoCRM processes Customer Personal Data on Customer's behalf.
Termination of the Terms or Customer's use of the Service does not immediately terminate provisions of this DPA that by their nature must continue while RivoCRM retains Customer Personal Data.
Sections concerning confidentiality, security incidents, deletion, liability, and other provisions that by their nature should survive will continue for the applicable period.
20. Order of Precedence
If there is a conflict concerning processing of Customer Personal Data:
- a separately signed DPA or data-protection agreement between Customer and RivoCRM will control, if it expressly supersedes this DPA;
- this DPA will control over the general Terms of Service with respect to the conflicting data-processing issue; and
- the Terms of Service will otherwise continue to apply.
The Privacy Policy describes RivoCRM's privacy practices but does not reduce contractual obligations expressly provided in this DPA.
21. Changes to This DPA
RivoCRM may update this DPA to reflect changes in the Service, Subprocessors, infrastructure, or applicable legal requirements.
We will update the "Last updated" date when the DPA changes.
For a material change that reduces contractual data-protection commitments applicable to existing customers, RivoCRM may provide additional notice where appropriate or required.
Changes will not retroactively authorize RivoCRM to process Customer Personal Data for materially unrelated purposes.
22. Governing Law
This DPA is governed by the same governing law and dispute provisions that apply under the RivoCRM Terms of Service or other governing agreement between Customer and RivoCRM.
Unless another governing agreement applies, this DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, and the parties submit to the dispute venue of the courts of Ontario, Canada, subject to mandatory law that cannot be contractually excluded.
23. Contact
Privacy and DPA questions may be sent to:
RivoCRM Privacy Officer
RivoCRM
Canada
Email: info@rivocrm.app
Mailing address: Address available on request
Contract and legal inquiries may be sent to:
RivoCRM
Email: info@rivocrm.app
Schedule A — Processing Details
This Schedule forms part of the DPA.
A.1 Subject Matter
RivoCRM processes Customer Personal Data to provide a cloud-based CRM, transaction-management, workflow, communication, collaboration, and related software platform.
A.2 Processing Activities
Processing may include:
- receiving Customer Personal Data;
- hosting and database storage;
- organizing and indexing records;
- displaying information to authorized users;
- searching and retrieving records;
- creating relationships between CRM records;
- storing notes, tasks, comments, and activities;
- storing property and transaction information;
- executing workflows and Autoplans;
- transmitting email or SMS at Customer's instruction;
- storing and serving files;
- providing integrations selected by Customer;
- generating AI-assisted responses or content when Customer invokes an AI feature;
- providing support and troubleshooting;
- creating backups;
- protecting the Service from abuse and security threats; and
- deleting information at Customer's instruction or following termination.
A.3 Categories of Data Subjects
May include:
- prospective buyers;
- buyers;
- prospective sellers;
- sellers;
- leads;
- clients;
- former clients;
- contacts;
- referral partners;
- vendors and service providers;
- real estate professionals;
- organization members;
- assistants;
- employees;
- contractors; and
- other individuals whose information Customer chooses to process.
A.4 Categories of Personal Data
May include:
- name;
- email address;
- telephone number;
- mailing address;
- property address;
- contact stage or status;
- tags;
- notes;
- custom fields;
- property information;
- transaction information;
- listing or MLS identifiers;
- prices and transaction values;
- transaction dates and deadlines;
- communication content;
- communication preferences;
- tasks;
- activities;
- comments;
- files and images;
- relationships between contacts and transactions; and
- other information entered by Customer.
A.5 Duration
Processing continues for the term of Customer's account or subscription and for applicable post-termination deletion, backup, security, legal, and retention periods.
Schedule B — Technical and Organizational Measures
RivoCRM maintains reasonable safeguards appropriate to its size, Service, infrastructure, and processing risks.
Measures may include, as applicable:
B.1 Access Control
- authenticated user accounts;
- role-based access controls;
- organization/tenant separation;
- restricted platform-administrator access;
- least-privilege principles for internal access where practical;
- removal or modification of access when no longer required; and
- optional multi-factor authentication.
B.2 Application and Authentication Security
- password hashing;
- secure session management;
- authentication controls;
- anti-CSRF or equivalent protections where applicable;
- bot/automated-abuse protection;
- rate limiting where appropriate; and
- secure development and dependency maintenance practices.
B.3 Transmission and Infrastructure Security
- encrypted HTTPS/TLS connections;
- managed application hosting;
- managed PostgreSQL database infrastructure;
- restricted production infrastructure access; and
- security capabilities provided by applicable infrastructure vendors.
B.4 Data Resilience
- database/infrastructure backup or recovery capabilities;
- operational monitoring;
- incident-response procedures; and
- restoration procedures appropriate to the Service.
B.5 Organizational Measures
- confidentiality obligations for persons with authorized access;
- limited support access;
- service-provider review;
- documented privacy and security procedures as the business matures;
- breach/incident recordkeeping where required; and
- periodic review of access and infrastructure practices.
The specific implementation of these measures may change as RivoCRM improves its security architecture, provided that RivoCRM does not materially reduce the overall level of protection during an active subscription without appropriate justification.
Schedule C — Subprocessor Register
This Schedule reflects RivoCRM's production service providers as of the "Last updated" date. Whether a provider receives Customer Personal Data depends on feature configuration and Customer's use of the Service.
| Subprocessor | Purpose | Processing location | Status |
|---|---|---|---|
| Vercel | Application hosting, deployment, networking, and delivery | Provider infrastructure (may include the United States and other regions) | Active |
| Neon | Hosted PostgreSQL database | Provider infrastructure (region as configured for the production database) | Active |
| Stripe | Payments and subscription billing | Provider infrastructure | Active when billing is enabled |
| OAuth authentication and integrations | Provider infrastructure | Active when enabled and used | |
| Cloudflare | Turnstile / security functionality | Provider infrastructure | Active when enabled |
| Resend | Transactional and customer email delivery | Provider infrastructure | Active when email features are enabled |
| Twilio | SMS and telecommunications | Provider infrastructure | Active when SMS features are enabled |
| S3-compatible storage (e.g. Cloudflare R2) | File and image storage | Provider infrastructure | Active when file/image uploads are enabled |
| OpenAI | Optional AI functionality | Provider infrastructure | Active when AI features are used |
| Sentry | Error and diagnostic monitoring | Provider infrastructure | Active when monitoring is configured |
RivoCRM may update this register as production providers change. Material changes that affect Customer Personal Data processing will be reflected in this DPA or related public documentation.