Legal

Privacy policy

Rivea is built for work that is confidential by nature, so it would be strange to be vague here. This page sets out what personal information rivea.io collects, why, who else touches it, and what you can ask us to do about it.

Effective 10 September 2026 · Rivea Inc.

The short version

  • The case-study form asks for your name, work email, firm and role. It does not subscribe you to marketing communications.
  • Opening the booking page loads Calendly and third-party advertising and analytics technologies, before you make a booking.
  • Our own pages use cookieless Cloudflare Web Analytics. The embedded scheduler uses its own cookies and browser storage.
  • We do not sell personal information for money, and search information you share with us is not used to train third-party models.

Who we are

Rivea Inc. (“Rivea”, “we”, “us”) builds a research agent for healthcare executive search. Our address is 69 Charlton St, New York, NY 10014, United States, and you can reach us at hello@rivea.io.

For the purposes of the UK and EU General Data Protection Regulation, Rivea Inc. is the controller of the personal information described in this policy. This policy covers the rivea.io website. It does not cover the Rivea product itself, which is governed by the agreement we sign with a customer firm.

What we collect, and when

When you ask for a case study

The case-study form asks for your name, your work email, your firm and your role. We also record the time of the request. The form includes a hidden anti-spam field. Web3Forms processes submissions and technical information, such as IP addresses, for delivery and spam prevention.

When you book a demo

The “Book a demo” link opens our booking page, which loads Calendly's embedded scheduler automatically. Whatever you enter there — name, email address, and any notes you add — is collected by Calendly and passed to us as a booking. The scheduler also processes browser and device information before you enter any details, as described below.

When you email us

We receive your email address and whatever you choose to write, and we keep the thread so we can pick the conversation back up.

If you opt in to marketing communications

We do not currently send marketing email or maintain a marketing list. If we offer marketing communications in the future and you opt in, we will use your name, email address and opt-in preferences to send the updates you choose. Requesting a case study or booking a demo does not subscribe you. If a future booking flow offers marketing updates, it will require a separate opt-in. You will be able to unsubscribe at any time using the link in an email or by writing to hello@rivea.io.

When you simply read the site

Cloudflare, which hosts and serves rivea.io, processes your IP address, your browser's user-agent string and the pages you request in order to deliver the site and protect it from abuse. We also use Cloudflare Web Analytics, which reports aggregate page views and referrers. It sets no cookies and does not build a profile of you.

Please do not send candidate records, client names or other search material through this website. We do not ask for it, we do not want it in a web form, and there is a better place for it once we are talking. Nothing on this site asks for health information or any other special-category data.

Why we use it, and our legal basis

Where the EU or UK GDPR applies, our legal bases for Rivea's handling of enquiries and operation of the site are listed below. Calendly's own advertising and analytics processing is described separately; opening the booking page is not an opt-in to Rivea marketing email.

Sending you the case study you asked for
Our legitimate interest in responding to an inbound business enquiry with the information you requested. Art. 6(1)(f).
Answering your email and arranging a demo
Our legitimate interest in answering inbound business enquiries and arranging conversations requested by the people who contact us. Art. 6(1)(f).
Following up on your enquiry
Our legitimate interest in continuing the conversation you started. Art. 6(1)(f). This stays within your enquiry and does not subscribe you to marketing communications. Tell us to stop and we will.
Marketing communications, if you opt in
If we offer these communications, we will rely on your consent, which you can withdraw at any time. Art. 6(1)(a).
Keeping the site up, fast and free of abuse
Our legitimate interest in running a secure website. Art. 6(1)(f).
Meeting a legal or regulatory obligation
Compliance with a legal obligation. Art. 6(1)(c).

We do not make automated decisions about you that produce legal or similarly significant effects.

What we do not do

  • We do not sell personal information for money. The scheduler's advertising and analytics technologies are described below.
  • Requesting a case study or booking a demo does not add you to a marketing list. We may follow up about your enquiry; you can ask us to stop. Any future marketing communications will require a separate opt-in.
  • We do not add our own advertising pixels to the site. Calendly loads advertising and analytics technologies inside its embed on our booking page.
  • We do not use search information you share with us — briefs, criteria, candidate names — to train third-party models.

Who else handles it

The marketing site uses these service providers:

Cloudflare
Hosts and serves rivea.io, protects it from abuse, and provides the cookieless Web Analytics described above. United States.
Web3Forms
Delivers case-study requests to our inbox. Your browser posts the form directly to api.web3forms.com, which relays it to us by email. Submissions are processed by this third-party form provider and may also be stored on its systems. Web3Forms describes using infrastructure and spam-prevention providers to process submissions and technical information. It is operated by Web3Creative in India and uses infrastructure in several countries. See its privacy policy and data processing terms.
Calendly
Runs the embedded demo scheduler and holds booking records as our processor. United States. Calendly also processes data for its own purposes, as explained in its privacy notice. See the next section for what the embed loads.
Our email provider
Runs the mailbox behind hello@rivea.io, where case-study requests and your messages to us arrive and are stored.

Beyond that, we may disclose personal information to our professional advisers where they need it to advise us, or where the law, a court or a regulator requires it. We do not provide enquiry emails or form submissions to other companies for their marketing. The scheduler's collection of browser information for its own purposes is described next.

Calendly, and what the booking page loads

Calendly loads automatically when you visit /book/. Our page loads its widget from assets.calendly.com, which embeds a calendly.com frame. In a fresh-browser check on 10 September 2026, that frame loaded Google Analytics, the Google tag, Meta (Facebook) Pixel, Segment, Braze and Sprig scripts before a cookie choice. It also loaded Stripe, Google reCAPTCHA, Google sign-in, OneTrust cookie controls and Airbrake configuration.

These services receive browser connections, including your IP address and browser information. Calendly and Stripe set cookies; the Calendly frame also stored anonymous analytics identifiers in local storage. Meta Pixel is advertising technology; Google Analytics and Segment are analytics technologies. Loading a script does not by itself establish which events it sends. The technologies and their behaviour can vary with your browser, region and cookie choices.

We choose to embed Calendly on rivea.io; Calendly determines the technologies bundled inside its frame. Both run in your browser while you are on our booking page. Calendly's privacy notice describes its own uses of information, including advertising, and says some cookies may amount to a “sale” or “share” under state privacy laws.

The scheduler provides “Cookie settings” and a way to decline optional cookies. Some requests and storage occurred before a choice in our check, so these controls should not be understood as preventing all initial connections. To arrange a demo without loading the scheduler, email hello@rivea.io instead of visiting the booking page.

Cookies and fonts

Our own site code does not set visitor cookies or use local or session storage to track you. Cloudflare Web Analytics is cookieless. This does not mean every page is cookie-free: visiting the booking page loads the third-party cookies and storage described above. Cloudflare may also use cookies for security checks. Browser settings can restrict cookies and storage, though doing so may affect the scheduler.

The site's typefaces, DM Sans and DM Mono, are served from rivea.io itself through Cloudflare Fonts rather than fetched from Google's font servers in our production configuration. This concerns font delivery; the booking embed separately connects to Google services.

How long we keep it

This table covers information from the marketing site and the enquiries it generates. It does not cover the Rivea product or customer accounts. Retention depends on the type of record and where it is held. The website does not automatically delete enquiry emails or control every provider's storage and backups.

Marketing-site retention by category
Information Retention
Website analytics and ordinary server logs Cloudflare currently makes Web Analytics available for the previous six months, according to its documentation. That is an access window, not a promise that all underlying logs are deleted then. Cloudflare manages ordinary delivery logs under its own retention schedules; the website keeps no separate visitor-log database.
Case-study requests, demo enquiries and emails Kept to handle your enquiry and related follow-up, including booking notifications in our inbox. We aim to remove inactive correspondence during mailbox housekeeping; ongoing conversations, pending requests and a need to preserve a record of an enquiry affect what is kept. Deletion is not automated on a fixed deadline.
Submissions processed by Web3Forms Web3Forms may retain submissions separately from the emails in our inbox. Its published storage descriptions differ, and we have not confirmed the retention setting for our form. We therefore cannot give a verified provider deletion period here. Its privacy policy and data processing terms describe its processing and deletion arrangements.
Booking records in Calendly Held by Calendly as our processor under its retention and deletion procedures, described in its data processing terms. The website does not store a separate booking database. You can ask us to request deletion of booking details held for us; Calendly handles requests under its procedures and applicable requirements.
Future marketing contacts, if you opt in If we offer marketing email and you opt in, we would keep contact details for the updates you choose. Opting out ends that use; a limited record of your preference may be kept to avoid contacting you again. Inactivity would be a reason to review whether to keep a contact. There is no marketing list today.
Security and abuse logs Cloudflare manages routine security logs under its own retention schedules. If we keep records relating to a specific incident, their retention depends on investigation, remediation and any related legal preservation needs.
Backup copies, where we keep them Copies may remain after deletion from active systems until the relevant backup cycle expires or overwrites them. Timing depends on the system and provider; we have not established a single backup deletion deadline for the site.

Legal obligations or the need to resolve a dispute may require particular records to be kept longer. To ask for deletion, email hello@rivea.io. We review what we hold and what can be removed, and explain any reason for retaining information. Requests remain subject to applicable law.

International transfers

Rivea is based in New York. This website uses providers based in the United States and India, with international infrastructure. Information you send us is received in the United States and may also be processed in other countries where those providers operate. Data protection laws there may differ from those where you live. You can contact hello@rivea.io with questions about where your information is handled.

Your rights in the EEA, UK and Switzerland

Where applicable, data protection law in the EEA, UK or Switzerland gives you rights to ask us to:

  • confirm what we hold about you, and give you a copy;
  • correct anything that is wrong or incomplete;
  • delete it;
  • restrict what we do with it while a question is resolved;
  • hand it to you, or to someone else, in a portable machine-readable form;
  • consider your objection to processing based on legitimate interests;
  • stop using it for direct marketing, if you have opted in to any future marketing communications.

Where we rely on your consent you can withdraw it at any time, which does not affect anything we did before you withdrew it.

Email hello@rivea.io with “Privacy request” in the subject line. We handle requests in line with the deadlines and conditions of applicable law, including any permitted extensions. Requests are ordinarily free, and we may need to ask for information to confirm you are who you say you are. You can also complain to your local supervisory authority, or to the Information Commissioner's Office in the United Kingdom.

California visitors and choices for everyone

For visitors in California, the website information described above falls into these categories:

  • Identifiers — your name and work email address, and the IP address our host processes to serve the site, plus browser identifiers used by the embedded scheduler and its providers.
  • Professional or employment-related information — your firm and your role.
  • Internet or network activity — the pages you requested and your browser's user-agent string, including interactions with the embedded scheduler.
  • Communications — your enquiry, booking details and messages you choose to send us.

Enquiry information comes from people who contact us through the form, email or Calendly. Technical information comes from your browser through our host and, on the booking page, through Calendly and the services it loads. We use information for the purposes set out above and disclose it to the providers described above to run the site and respond to you. We do not ask for sensitive personal information or use website information to infer characteristics about you.

Rivea does not sell personal information for money. California law also uses “sharing” to mean disclosure for cross-context behavioural advertising. Our booking page embeds Calendly, which loads third-party advertising and analytics technologies as described above. Calendly says some of its cookies may constitute a “sale” or “share” under state privacy laws. We therefore do not make a blanket claim that no such sharing occurs through the scheduler. Use its cookie controls to express your preferences, or contact us by email to arrange a demo without loading it.

As our practice for everyone, regardless of where you live, you can ask to access or receive a copy of your information, correct it, or delete it. You may ask someone to contact us on your behalf. We may ask for enough information to confirm your identity and their permission to act for you. We will not treat you differently for asking. Email hello@rivea.io with “Privacy request” in the subject line.

Children

This site is aimed at people doing executive search for a living. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us something, contact us so we can investigate and address deletion where appropriate.

Security

The site supports HTTPS, and the case-study form submits over an encrypted connection to Web3Forms. The website application does not maintain its own database of case-study requests or bookings. Enquiries are held in our mailbox and may also be stored by the providers described above.

No method of transmission or storage is completely secure, and we will not pretend otherwise. If you are assessing us as a vendor rather than reading as a visitor, write to us and we will answer specific questions directly rather than gesture at a badge.

Changes to this policy

When this policy changes we update the effective date at the top of the page. For material changes, we may also provide a notice on the site or contact you where appropriate, and will provide any additional notice required by applicable law.

Governing law

This policy is governed by the laws of the State of New York, without regard to its conflict-of-laws rules. That does not remove any right you have under the data protection law of your own country — including the GDPR and the CCPA — that cannot be waived by agreement.

How to contact us

For anything in this policy, including a request about your own information, email hello@rivea.io and put “Privacy request” in the subject line to help us identify it.

Rivea Inc.
69 Charlton St
New York, NY 10014
United States