Our approachPortfolioAbout
Let's talk
Let's talk
Legal

Privacy Policy

Last updated: [DATE]

This policy explains what personal information [COMPANY LEGAL NAME] (“Riverlight”, “we”, “us”) collects, why we collect it, and the choices you have. It applies to this website and to the enquiries and correspondence that reach us through it.

1. Who we are

[COMPANY LEGAL NAME] is registered in [COUNTRY] under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS]. Under UK and EU data protection law we are the controller of the personal information described here.

Questions about this policy, or about how we handle your information, can be sent to [PRIVACY EMAIL].

2. Information we collect

Information you give us
  • Your name, email address, organisation and the content of your message when you use our contact form.
  • Anything you choose to send us by email, or share with us in a call or meeting that we record in our records.
  • Information you provide if you ask to receive updates from us.
Information we collect automatically
  • Your IP address, browser and device type, operating system and screen size.
  • The pages you view, the page that referred you, and the dates and times of your visit.
  • An approximate location derived from your IP address, no more precise than city level.

This information is collected through [ANALYTICS PROVIDER] and through server logs kept by [HOSTING PROVIDER]. We do not ask for special category data, and we ask that you do not send it to us through this site.

3. How we use your information

  • To reply to your enquiry and continue the conversation that follows it.
  • To assess a potential investment, partnership or working relationship.
  • To operate, secure and improve this website, and to understand which pages people find useful.
  • To send updates where you have asked to receive them.
  • To keep records we are required to keep, and to establish, exercise or defend legal claims.

We do not use your information to make decisions about you by automated means alone.

4. Our legal bases (UK and EU)

Where UK or EU GDPR applies, we rely on one of the following bases each time we use your information.

  • Legitimate interests — responding to enquiries, running and protecting our website, and pursuing opportunities relevant to our business. We balance these against your interests and rights.
  • Consent — non-essential cookies and analytics, and any marketing updates you sign up for. You may withdraw consent at any time.
  • Contract — steps taken at your request before entering into an agreement, and performance of that agreement.
  • Legal obligation — tax, accounting, anti-money-laundering and similar record keeping.

5. Cookies and similar technologies

Essential cookies keep the site working and cannot be switched off. Analytics cookies help us understand how the site is used, and are set only where you have agreed to them or where local law allows them without consent.

You can clear or block cookies through your browser settings. Doing so may affect how parts of the site behave. Full details of the cookies we set are listed in [COOKIE POLICY LINK].

6. How we share information

We share personal information only where there is a reason to, and only with:

  • Service providers who work on our behalf — [HOSTING PROVIDER], [ANALYTICS PROVIDER], [EMAIL PROVIDER] and [CRM PROVIDER] — each bound to use the information only as we instruct.
  • Professional advisers such as lawyers, accountants and auditors, where they need it to advise us.
  • A buyer or investor, and their advisers, if we sell or reorganise part of our business.
  • Regulators, courts or law enforcement where we are required to disclose it.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

7. International transfers

Some of our providers are based outside the UK and the European Economic Area, including in the United States. Where information moves outside those areas we rely on an adequacy decision covering the destination country, or on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses together with any additional safeguards the transfer requires.

You can ask us for a copy of the safeguards that apply by writing to [PRIVACY EMAIL].

8. How long we keep information

  • Enquiries and correspondence — [RETENTION PERIOD] from our last exchange with you.
  • Analytics data — [ANALYTICS RETENTION PERIOD], in aggregated or pseudonymised form wherever possible.
  • Records we are required to keep by law — for the period the relevant law sets.

When a retention period ends we delete the information or anonymise it so it can no longer be linked to you.

9. How we protect information

We use encryption in transit, access controls that limit who inside our business can see personal information, and providers who maintain their own recognised security standards. No system is completely secure, but we review these measures regularly and will tell you and the relevant regulator about a breach where the law requires it.

10. Your rights in the UK and EU

If UK or EU data protection law applies to you, you have the right to:

  • Ask for a copy of the personal information we hold about you.
  • Have inaccurate information corrected, or incomplete information completed.
  • Ask us to delete information, or to restrict how we use it.
  • Receive information you gave us in a portable, machine-readable form.
  • Object to use based on legitimate interests, including any direct marketing.
  • Withdraw consent at any time, without affecting anything done before you withdrew it.

Write to [PRIVACY EMAIL] to exercise any of these. We answer within one month. If you are not satisfied you can complain to [SUPERVISORY AUTHORITY] — in the UK, the Information Commissioner’s Office at ico.org.uk.

11. Your rights in the United States

If you live in California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have the right to know what personal information we have collected about you and why, to receive a copy of it, to have it corrected, and to have it deleted.

Categories we collect
  • Identifiers — name, email address, IP address.
  • Commercial and professional information — your organisation, role and the substance of your enquiry.
  • Internet activity — pages viewed and how you reached them.
  • Approximate geolocation, no more precise than city level.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. We will not discriminate against you for exercising any of these rights.

To make a request, write to [PRIVACY EMAIL]. We will verify your identity before we act, usually by matching details you give us against what we already hold. An authorised agent may make a request on your behalf with written permission. If we decline a request you may appeal by writing to [APPEALS EMAIL].

12. Children

This site is meant for adults and is not directed at children. We do not knowingly collect personal information from anyone under [AGE]. If you believe a child has given us their information, write to [PRIVACY EMAIL] and we will delete it.

13. Other websites

Our site links to companies we work with and to other organisations. Their privacy practices are their own, and this policy does not cover them. It is worth reading the policy on any site you follow a link to.

14. Changes to this policy

We update this policy when the way we handle information changes. The date at the top shows when it was last revised. Where a change materially affects you we will say so on this page, and contact you directly if the law requires it.

15. Contact us

[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
[PRIVACY EMAIL]

Our representative for the purposes of [UK / EU GDPR ARTICLE 27] is [REPRESENTATIVE NAME AND ADDRESS].

Simple. Profitable. Repeatable.
explore
Our ApproachPortfolioAbout
© 2026 Riverlight. All rights reserved.
Privacy Policy