Privacy Policy
Last updated: July 31, 2026
1. Introduction
Rivvi AI Inc. ("Rivvi," "we," "us," or "our") operates a HIPAA-grade conversational AI platform that healthcare organizations use to communicate with patients and website visitors across voice, text, and web channels — including automated voice agents, SMS, an embeddable web-chat widget, an in-application AI assistant, and integrations with third-party systems of record. This Privacy Policy explains what information we collect, how we use and disclose it, and how we protect it.
This Privacy Policy applies to:
- Healthcare organizations and their authorized personnel who use our platform ("Users")
- Patients and other individuals whose information Users process through our platform ("Patients")
- Visitors who interact with the embeddable web-chat widget on a User's website ("Web Chat Visitors")
- Individuals who sign up for, or start a trial of, our platform ("Signup and Trial Users")
- Visitors to our own websites and acquisition surfaces (rivvi.ai, try.rivvi.ai, chat.rivvi.ai)
- Referral partners and individuals who apply to our referral program
- Individuals who sign a Business Associate Agreement on behalf of a User ("BAA Signers")
This policy does not replace, and is subordinate to, any Business Associate Agreement (BAA) between Rivvi and a User with respect to Protected Health Information. Where a conflict exists as to PHI, the BAA controls.
2. Definitions
- "Users": Healthcare organizations, providers, health systems, and their authorized staff who have accounts on the Rivvi platform.
- "Patients": Individuals whose information is processed through our platform on behalf of Users.
- "Web Chat Visitors": Individuals who interact with the embeddable Rivvi web-chat widget installed on a User's website.
- "Patient Data": Information relating to Patients that is collected, stored, or processed through our platform.
- "PHI": Protected Health Information as defined under HIPAA.
- "Platform" / "Services": The Rivvi software, applications, APIs, voice and text agents, web-chat widget, in-application AI assistant, integrations, and related services.
- "Subprocessor": A third party we engage to process information in order to provide the Services.
3. Our Role in Data Processing
Rivvi's legal role depends on the data and the context.
3.1 HIPAA Business Associate
When processing PHI on behalf of a User that is a Covered Entity (or another Business Associate), Rivvi acts as a Business Associate under HIPAA. We process PHI only as permitted by our BAA with the User and applicable law, and we require our Subprocessors that may handle PHI to be bound by equivalent obligations.
3.2 Data Processor for Patient Data
For Patient Data generally, we act as a data processor (or "service provider" under U.S. state privacy laws) on behalf of our Users, who are the data controllers. We process Patient Data according to the User's instructions and the functionality they configure, and not for our own independent purposes except as described in this policy (for example, service operation, security, and the creation of de-identified/aggregated data).
3.3 Controller for Our Own Data
For information we collect for our own purposes — Signup and Trial User data, account and billing data, marketing-site visitor data, referral-program data, and the operational metadata we generate to run and secure the Platform — Rivvi acts as a controller.
3.4 Web-Chat Widget
The embeddable web-chat widget is a marketing and contact-capture surface that runs on Rivvi's infrastructure and is installed on a User's website. It does not solicit PHI — a persistent notice instructs Visitors not to share medical or sensitive health information, which keeps the widget outside the scope of the BAA. For the contact details and consent a Visitor submits through the widget, Rivvi and the User act as joint or independent controllers depending on the User's configured destination for that data (retained with Rivvi, synced to the User's CRM, or sent to a webhook the User specifies).
4. Information We Collect
4.1 User Account Information
From healthcare organizations and their staff, we collect:
- Organization name, legal business name, website, and business address
- User names, email addresses, and phone numbers
- Account credentials and authentication data (managed via AWS Cognito)
- Roles, permissions, and team membership
- Billing and payment information (see Section 4.6)
- Usage logs, audit logs, and platform interaction data
4.2 Patient Data Processed on Behalf of Users
Through our platform, Users may process:
- Contact Information: Names, phone numbers, addresses, email addresses, dates of birth
- Voice Data: Recordings of patient calls, call audio, and derived voice/emotional analysis
- Communication Data: Call transcripts, text (SMS) messages, web-chat transcripts, and email communications
- Health Information: Where a User configures it, information such as medication lists, adherence data, appointment information, and health conditions
- Campaign Data: Responses to outreach, survey answers, and engagement metrics
- Uploaded Data: Information from Excel/CSV uploads or API transfers
- Behavioral Data: Opt-in/opt-out preferences, communication preferences, and response patterns
- Consent Records: Consent type, date, time, method, and status
4.3 Web Chat Visitor Information
When a Visitor interacts with the web-chat widget on a User's website, we may collect:
- Contact details the Visitor chooses to submit: name, phone number, and/or email address
- Consent selections: a marketing-contact opt-in and, where enabled, a separate phone/SMS (TCPA) opt-in
- The conversation transcript between the Visitor and the AI assistant
- Technical context captured automatically to operate and secure the widget: IP address, page URL and title, referrer, and browser user-agent
The widget is a no-PHI, marketing-purpose surface. Visitors are asked not to submit health information, and the widget is not intended for medical advice or emergencies.
4.4 Signup and Trial User Information
When you sign up for or start a trial of the Platform, we collect: first and last name, username, email address, organization name and website, business type, the signer's phone number (and optionally an organization business phone), provider-count and location-count bands, a password, and marketing attribution data (UTM parameters, referrer, and landing page). At checkout we also collect Terms-of-Service acceptance (with a version stamp), a "handles PHI" indicator, and — where PHI will be processed — BAA signer name, email, and title, the covered-entity legal name, and address.
4.5 Referral Program Information
From referral partners and applicants we collect name, email, phone number, and application details. Users may also generate organization-to-organization referral codes.
4.6 Payment Information
Subscription billing is handled by Stripe. We send Stripe your name, email, and organization metadata; Stripe collects and tokenizes your card or bank (ACH) details through its hosted checkout. Rivvi does not receive or store full payment card numbers. We store subscription state, plan, trial status, and entitlement/usage data.
4.7 Automatically Collected Information
We automatically collect IP addresses and device/browser information, platform usage statistics and performance data, error logs and diagnostic information, and product-analytics events (see Section 13).
5. Artificial Intelligence and Automated Processing
The Platform uses artificial intelligence and large language models to operate voice agents, the web-chat assistant, and the in-application AI assistant, and to generate analytics, summaries, and research.
5.1 HIPAA-Eligible AI Processing
Our in-application AI assistant and related AI features run on Amazon Web Services (AWS) Bedrock, using HIPAA-eligible foundation models covered under our AWS Business Associate Agreement. Where AI features process PHI, that processing stays within the AWS security boundary. We restrict AI processing of PHI to models confirmed as eligible under the AWS BAA.
5.2 AI Memory
To provide continuity, the assistant maintains a scoped, organization-isolated memory. Writes to this memory are screened to keep PHI out of it, and memory is partitioned by organization and, where applicable, by user.
5.3 Voice and Emotional Analysis
Where a User enables it, call recordings may be processed to derive voice/emotional analysis (voice biomarkers). This may involve sending call audio to a specialized Subprocessor for analysis (see Section 6). Results are stored within our AWS environment.
5.4 No Sale; No Model Training on Your Data for Third Parties
We do not sell personal information, and we do not permit our AI Subprocessors to use PHI or Patient Data to train their general-purpose models. We may use de-identified and aggregated data to improve the Platform as described in Section 6.6.
5.5 Automated Communications
The Platform initiates automated voice calls and text messages on a User's behalf, based on the User's configuration and the consent the User is responsible for obtaining (see Section 8).
6. Data Sharing, Disclosure, and Subprocessors
6.1 We Do Not Sell Personal Information
We do not sell, rent, or trade personal information or Patient Data.
6.2 Sharing at User Direction
We share Patient Data and Web Chat Visitor lead data only as directed by the User through the Platform's functionality — for example, syncing a captured lead to the User's connected CRM or a webhook the User specifies.
6.3 Customer-Connected Integrations
Users may connect third-party systems using their own credentials. When connected, data flows between Rivvi and those systems at the User's direction. These may include CRMs (e.g., HubSpot, Salesforce, Zoho, Nutshell, Veeva), Microsoft 365 / Teams / Power BI / SharePoint / OneDrive / Excel, Google Workspace, business-intelligence tools, advertising platforms, telephony providers, scheduling tools (e.g., Cal.com, Calendly), and healthcare referral networks (e.g., LeadingReach). The data exchanged is governed by the connected provider's own terms and privacy policy in addition to this policy.
6.4 Subprocessors
We engage the following categories of Subprocessors to provide the Services. Subprocessors that may handle PHI are bound by written agreements consistent with HIPAA.
Infrastructure and AI (may process PHI):
- Amazon Web Services — cloud hosting, storage (S3), databases (RDS, DynamoDB), authentication (Cognito), compute, encryption, eventing, and Bedrock for AI/LLM processing. Covered by a BAA.
Voice and telephony (may process PHI):
- Retell — voice-agent calls, recordings, transcripts, and call analysis
- ElevenLabs — voice-agent speech
- LiveKit — real-time transport for the web-chat widget and voice sessions
- Twilio — phone numbers, SMS delivery, and voice trunking
- Valence AI — voice/emotional analysis of call recordings, where enabled by the User
Billing, communications, and operations:
- Stripe — subscription billing and payment processing
- DocuSeal — Business Associate Agreement e-signature (self-hosted within our AWS environment)
- PostHog — product analytics (metadata only; configured not to capture PHI)
- Google Analytics — marketing-site analytics
- Cloudflare Turnstile and Google reCAPTCHA — abuse/bot prevention on forms
- Google Places — business-information lookup used to research a User's organization
- Sanity — marketing-site content management
We maintain a current list of Subprocessors and will provide it, and reasonable advance notice of material changes, to Users under an active BAA on request. All Subprocessors are bound by confidentiality obligations and may use information only to provide services to us.
6.5 Legal Requirements
We may disclose information where required by a court order or subpoena, a lawful law-enforcement request, applicable law or regulation, or to protect rights, property, or safety.
6.6 Aggregated and De-Identified Data
We may create aggregated and de-identified datasets (de-identified consistent with HIPAA where derived from PHI) to operate, secure, and improve the Platform, conduct research, and develop new features and benchmarks. Such data cannot reasonably be used to identify any individual.
6.7 Business Transfers
In a merger, acquisition, financing, or sale of assets, information may be transferred to the successor entity, subject to this policy and any applicable BAA. We will notify Users of any such change affecting their data.
7. Data Security
7.1 Security Measures
We implement administrative, physical, and technical safeguards, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256)
- Multi-factor authentication for User accounts
- Role-based access controls and multi-tenant isolation scoped by organization
- Segregation of PHI processing within our AWS environment
- Regular security audits and penetration testing
- Security monitoring, logging, and incident response
- HIPAA-aligned physical and technical safeguards
7.2 Breach Notification
In the event of a breach affecting PHI, we will notify affected Users without unreasonable delay and consistent with the timelines in the applicable BAA and the HIPAA Breach Notification Rule, and we will assist Users with their notification obligations.
8. TCPA and Communications Compliance
The Platform provides features to help Users comply with the Telephone Consumer Protection Act (TCPA) and related laws, including consent tracking and documentation, calling-window (time-of-day) enforcement, opt-out management and suppression, call-frequency controls, and Do-Not-Call handling.
For the web-chat widget, phone/SMS (TCPA) consent is presented as a separate, unchecked opt-in, distinct from any general marketing opt-in, and includes the disclosures required for prior express written consent (that the person authorizes automated calls/texts, that consent is not a condition of purchase, and how to opt out).
Users remain responsible for ensuring that their use of the Platform — including the consent basis for any outreach — complies with the TCPA and all applicable laws.
9. Data Retention
9.1 Retention Periods
- Patient call recordings, transcripts, and analytics: 6 years, unless otherwise specified by the User
- Voice/emotional analysis data: retained with the associated interaction
- Web-chat transcripts and captured lead data: retained per the User's configuration and applicable law
- Consent records: at least 4 years to support TCPA compliance
- Opt-out / suppression records: retained as long as necessary to honor the opt-out
- BAA and legal-acceptance records (including Terms version accepted): at least 6 years
- User account, billing, and audit data: for the duration of the account plus a retention period required by law or contract (generally 6 years)
- Marketing-site and analytics data: retained for a limited period consistent with its purpose
9.2 Deletion Requests
Users may request deletion of Patient Data through their account or by contacting support. We will comply unless retention is required by law or contractual obligation. Deletion from connected third-party systems is governed by those systems.
10. Individual Rights
10.1 HIPAA Rights
Patients have rights under HIPAA to access their health information, request amendments, request restrictions, request confidential communications, and receive an accounting of disclosures. Because Rivvi acts as a Business Associate, Patients should direct these requests to their healthcare provider (our User), who may instruct us to assist.
10.2 State Privacy Rights
Depending on your residence, you may have rights under U.S. state privacy laws (for example, the California Consumer Privacy Act as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, and other states) to access, correct, delete, or receive a portable copy of personal information, and to opt out of certain processing. Where we act as a controller (Section 3.3), you may exercise these rights by contacting us at legal@rivvi.ai. Where we act as a processor/service provider on behalf of a User, we will refer your request to the relevant User or assist them in responding. We do not sell personal information or use it for cross-context behavioral advertising.
10.3 Notice at Collection
Where we or a User collect personal information directly from you — for example, through the web-chat widget or a signup form — a link to the applicable privacy policy is presented at or before the point of collection, together with the categories collected and the purposes of use.
11. International Data Transfers
The Platform is operated from the United States, and information is processed in the United States. If we transfer personal data from other jurisdictions, we rely on appropriate safeguards such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where applicable. (We no longer rely on the EU-U.S. Privacy Shield, which was invalidated in 2020.)
12. Children's Privacy
The Platform is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through our own surfaces. Patient Data processed on behalf of Users may relate to minors as part of the User's healthcare operations, governed by the User's instructions and the BAA. If we learn we have inadvertently collected a child's personal information outside that context, we will delete it.
13. Cookies and Tracking
13.1 Essential Cookies
We use cookies and similar technologies to maintain sessions, secure the Platform, and remember preferences.
13.2 Analytics and Attribution
We use PostHog for product analytics. It is configured to identify only known users, and session replay, autocapture, heatmaps, and dead-click capture are disabled; it is configured not to capture PHI or prompt content. To connect a single experience across our subdomains (rivvi.ai, try.rivvi.ai, chat.rivvi.ai), PostHog uses a cross-subdomain identifier stored on the .rivvi.ai domain. We also capture marketing-attribution parameters (UTMs, referrer, landing page), and use Google Analytics on our marketing site. Server-side analytics record operational metadata (such as AI cost and latency) keyed to a user and organization, and do not include PHI or message content.
13.3 Your Choices
You can control cookies through your browser settings and can opt out of non-essential analytics where offered. Server-side event logging necessary to operate and secure the Platform may continue regardless of cookie settings.
14. Changes to This Policy
We may update this Privacy Policy periodically. We will notify Users of material changes via email or platform notification and update the "Last updated" date above. Continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
15. Contact Information
For questions about this Privacy Policy or our privacy practices, contact us at:
Rivvi AI Inc. Email: support@rivvi.ai (general) · legal@rivvi.ai (privacy and legal) · hipaa@rivvi.ai (HIPAA and PHI)
Acknowledgment
By using the Rivvi platform, Users acknowledge that they have read and understood this Privacy Policy and agree to the collection, use, and disclosure of information as described herein.