This English version is provided for information only. The German version at Datenschutzerklärung is the legally binding text.
This privacy policy applies both to the marketing website rivly.de and to the application at app.rivly.de (registration, onboarding, running measurements, customer account). There is no separate privacy policy for the application; app.rivly.de/datenschutz redirects to this policy.
1. Controller
The controller responsible for data processing on rivly.de and app.rivly.de is:
Vladyslav Mazur
Mazur Software- und E-Commerce-Dienstleistungen
Kleingesee-Brunnenstr. 17
91327 Gößweinstein
E-mail: kontakt@rivly.de
No data protection officer has been appointed, as the statutory requirements for such an appointment are not met for a sole proprietorship.
2. Your rights
You have the following rights at any time:
- access to the data stored about you (Art. 15 GDPR, General Data Protection Regulation),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure of your data (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing (Art. 21 GDPR).
An informal message to kontakt@rivly.de is sufficient to exercise these rights.
You also have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA, Bavarian State Office for Data Protection Supervision), Promenade 18, 91522 Ansbach.
3. Server log files
When this website is accessed, the hosting provider (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany) automatically records information in so-called server log files. The IP address is stored in truncated form. The following are recorded:
- truncated IP address,
- date and time of access,
- page accessed,
- volume of data transferred,
- browser type and operating system.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website). The log files are deleted after 7 days at the latest. A data processing agreement (DPA) under Art. 28 GDPR is in place with Hetzner.
4. Cookies and consent management (cookie consent tool)
This website uses cookies. In addition to technically necessary cookies (see below), the analytics tool Google Analytics 4 is used optionally (see section 5). Cookies that are not necessary are not loaded before consent to them has been given.
a) Cookie consent tool. To obtain, manage and document your consent, we use the open source tool vanilla-cookieconsent (orestbida). The tool is self-hosted entirely on our own server; no request is made to a third-party provider and no data is transmitted to third parties in the process.
On your first visit to the website you are shown a cookie banner in which you can choose between the categories “Technically necessary” (always active, cannot be deactivated) and “Statistics” (deactivated by default, active only with your active consent). Your choice is stored in the cookie cc_cookie (first-party cookie, storage period 182 days).
| Cookie | Purpose | Provider | Storage period |
|---|---|---|---|
cc_cookie | Stores your cookie choice (proof of consent) | Rivly (first-party, self-hosted) | 182 days |
The legal basis for setting the consent cookie itself is § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act; technically required to implement the choice you have made) together with Art. 6(1)(f) GDPR (legitimate interest in documenting consent that has been validly given or refused, Art. 7(1) GDPR).
b) Withdrawal and changing your choice. You may withdraw your consent or change your choice at any time with effect for the future. To do so, use the “Cookie settings” link in the footer of this website. Withdrawal is as easy as giving consent (Art. 7(3) GDPR). You can additionally delete statistics cookies that have already been set at any time via your browser settings.
5. Audience measurement with Google Analytics 4
If you expressly give your consent via the cookie banner (see section 4), we use Google Analytics 4 (measurement ID G-788CT2YRR0) for the statistical analysis of how this website is used.
a) Provider. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Its parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
b) No loading without consent. Google Analytics is technically loaded only after you have actively consented to the “Statistics” category. Without your consent, no Google script is loaded and no connection to Google servers is established.
c) Google Consent Mode v2. We use Google Consent Mode v2. As long as no consent has been given, all consent signals are set to “denied” by default. After you give consent, only the signal analytics_storage is set to “granted”; the signals ad_storage, ad_user_data and ad_personalization remain permanently set to “denied”. We use Google Analytics solely for audience and usage analysis; there is no link to Google Ads, no advertising personalisation and no use of Google Signals.
d) Data processed and cookies. With your consent, Google Analytics sets cookies on your device in order to recognise returning visits and to compile usage statistics (e.g. pages viewed, time spent, approximate location, device and browser type). Your IP address is not permanently stored or logged by Google Analytics 4; it is processed only briefly when the technical connection is established.
| Cookie | Purpose | Provider | Storage period |
|---|---|---|---|
_ga | Distinguishes website visitors | 2 years | |
_ga_<container-id> | Stores the session state for the respective property | 2 years |
The event data collected by Google Analytics is deleted automatically once the retention period configured in the Google Analytics settings (currently 14 months) has expired.
e) Legal basis. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (access to information on your device). You may withdraw your consent at any time with effect for the future (see section 4 b).
f) Transfer to third countries. Google Ireland Limited also processes data with the involvement of its parent company Google LLC in the USA. To that extent, personal data is transferred to a third country. This transfer is safeguarded by the certification of Google LLC under the EU-US Data Privacy Framework (DPF) and, in addition, by the EU standard contractual clauses (SCC) under Art. 46(2)(c) GDPR. A data processing agreement under Art. 28 GDPR (Google Ads Data Processing Terms) is in place with Google.
g) Further information. Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://policies.google.com/privacy.
6. Fonts (web fonts)
The font used on this website (Instrument Sans) is served locally from our server in Germany. It is not embedded via Google Fonts or any other third-party CDN. No data is transmitted to third parties when the fonts are loaded.
7. Forwarding to the application (app.rivly.de)
When you submit the domain form on this website, the domain you entered (parameter d), the page on rivly.de you are coming from (parameter ref), the selected plan where applicable (parameter plan) and any campaign parameters present in the address (utm_source, utm_medium, utm_campaign, utm_content) are transmitted to app.rivly.de by HTTP GET, and you are forwarded there. If a Google click identifier is present in the address of this page (gclid, gbraid or wbraid), it is transmitted as well. If you have previously consented to the “Statistics” category (see sections 4 and 5), the Google Analytics 4 client identifier (parameter cid, from the _ga cookie) and a session identifier (parameter sid) are transmitted in addition. This information is not stored on rivly.de itself; no cookie is set and no browser storage is used for this purpose.
Further processing in the application, in particular registration, onboarding and running measurements, is governed by section 9 of this privacy policy below.
8. Free tools (rivly.de/tools/)
Under rivly.de/tools/ we offer free tools relating to search engine and AI visibility. Using them does not require a customer account. You enter a domain, a search term or a brand name, and the result is shown to you on the same page. The tools themselves do not set any cookies of their own (see letter f). The domain, search term or brand name you enter can in individual cases be personal data, for example if it is the name of a sole proprietorship that is also the name of a natural person; the tools are designed for entering company and brand names, not the names of individual people.
a) Domain check (AI crawler check and llms.txt generator). If you enter a domain, our server retrieves publicly accessible files and pages of that domain from our hosting provider Hetzner in Germany (see section 3): the robots.txt, the llms.txt and the llms-full.txt, the sitemap, the start page and up to ten further pages. We identify these requests under our own, recognisable program name (user agent RivlyCheck/1.0 (+https://rivly.de/tools/)) and retrieve only publicly accessible addresses, not areas protected by a login. Publicly accessible content of the checked domain, for instance a company or brand name from a legal notice, may contain personal data of the person responsible for that domain if it is a sole proprietorship; we do not separately analyse or store such content beyond the check result and the summary under letter c. The legal basis is Art. 6(1)(b) GDPR (performing the check you requested) and Art. 6(1)(f) GDPR (legitimate interest in a functional, abuse-free service).
b) Further tools. When further tools are added, we extend this policy with their data flows before the tools go live.
c) Usage log. For each use of a tool we store the tool used, the domain, search term or brand name you entered, the time, and a short summary of the result. We do not store an IP address in this log. As described at the start of this section, the domain, search term or brand name you enter can in individual cases be personal data. The purpose of this storage is to operate the tools, to prevent abusive use, and to evaluate which tools are used and how often, so that we can improve our offering. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a functional, abuse-free service that we can improve). If an account is later registered for the same domain, we link the two internally to see which tools lead to registrations. We do not use this log for advertising purposes and we do not use the information stored in it to contact you without your consent. Entries are deleted automatically after 12 months.
d) IP address and rate limiting. To limit the number of requests per visitor and to prevent abuse, we process your IP address only briefly. It is held in a cache for rate limiting for no more than 24 hours and then deleted; we do not carry it over into the usage log under letter c. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in an abuse-free operation of the tools).
e) Caching of results. We cache the result of the domain check under letter a per domain for up to one hour, so that checking the same domain again within that hour does not cause the checked website to be retrieved again. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in resource-efficient operation and in not unnecessarily burdening checked websites).
f) Cookies and audience measurement. As described at the start of this section, the tools themselves do not set any cookies of their own. The cookie consent tool under section 4 and, where you give your consent, Google Analytics 4 under section 5 also apply on the pages of the tools under rivly.de/tools/.
9. Processing in the application (app.rivly.de)
This section applies to the use of the software-as-a-service application Rivly at app.rivly.de. Users of the application are exclusively businesses within the meaning of § 14 BGB (German Civil Code) acting on behalf of their company (see Terms § 1(2)). Account data, projects and measurement results are kept until you permanently delete your customer account; they are not deleted merely because time has passed. Shorter retention periods for individual data are stated separately where they apply (letters e, g, h, k and m).
a) Registration and customer account. On registration we collect your name, business e-mail address and a password, which is stored exclusively in hashed (non-reversible) form. The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement, see Terms § 3).
If the information described in section 7 was transmitted to app.rivly.de when you visited rivly.de (domain, referring page, plan, campaign parameters, a Google click identifier and, where you consented to the “Statistics” category, the Google Analytics 4 client and session identifiers), we store this information with your registration as a record of the channel through which it came about. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in being able to trace the channel through which registrations come about).
b) Onboarding and account master data. During onboarding we process the customer’s own domain, brand or company name and the domains and names of the competitors selected by the customer for comparison (see Terms § 8(1)). This information relates to companies and brands, not to natural persons. In addition, we process the customer’s billing and contact details (company name, billing address, contact person) for the performance of the contract. The legal basis is Art. 6(1)(b) GDPR.
Recognition at set-up. So that we can propose a profile, competitors and search terms, our program RivlyBot (user agent Mozilla/5.0 (compatible; RivlyBot/1.0; +https://rivly.de/wie-wir-messen)) retrieves publicly reachable pages of your domain at set-up: home page, robots.txt, sitemap, legal notice, contact, locations, about page and up to two town pages. For the competitor proposal, RivlyBot retrieves once the home page of up to 20 companies that Google, Google Maps or AI answers show for your search terms, to check that the website is reachable and belongs to that company; for companies named only by a language model, we request just the robots.txt. If you add a competitor yourself, RivlyBot reads its home page and legal notice to propose the company name. For the evaluation of the Meta Ad Library, RivlyBot reads the home page of your brand and of each competitor to find the Facebook presence linked there, once after it is created and then monthly as long as none has been found. Before the first request, RivlyBot reads the robots.txt of the domain and follows the rules that apply to RivlyBot or to all programs; we do not retrieve a blocked website and base the proposal on other sources. We store the details recognised about the company (such as company name, offers, places, the company’s phone number and Facebook page), short supporting excerpts and the addresses of the pages read, not the page text. These requests concern company websites; where the company name of a sole proprietorship contains the owner’s name, we use it only as the company name. We do not record names of owners or representatives from the legal notice as a separate item. For the recognition we transmit titles, headings and short text excerpts of the pages read, together with the company name, legal form and place from the legal notice, via OpenRouter, Inc. (see section 11) to a language model; names of representatives, phone numbers and email addresses from the legal notice are not passed on. The legal basis is Art. 6(1)(b) GDPR (setting up the project you commissioned) and, insofar as third-party websites are concerned, Art. 6(1)(f) GDPR (legitimate interest in an accurate competitor comparison).
Information for operators of websites we read (Art. 14 GDPR). If RivlyBot reads your website because a Rivly customer tracks you as a competitor or because Google, Google Maps or AI answers show you as a competitor, we process public details of your company as described in the previous paragraph, not the page text. Recipients are the customer to whom we show you as a competitor, our host Hetzner in Germany and, for the recognition, OpenRouter, Inc. (USA). We keep the details until the customer deletes their customer account and delete them earlier if you object. You can exclude RivlyBot via robots.txt, object to the processing and request access, rectification or erasure, informally to kontakt@rivly.de; you also have the right to lodge a complaint with a supervisory authority (section 2). We do not inform operators individually because that would reveal the customer who tracks them as a competitor (Art. 14(5)(b) GDPR); this policy and the page “How we measure” are the public information provided for that purpose.
c) Measurements (competitive intelligence). To provide the analysis owed under the contract (see Terms § 2), Rivly regularly queries publicly accessible commercial data from third parties: advertisements from the official Meta Ad Library API, answers given by AI-based language models (large language models) to product- and brand-related prompts, results from search engine interfaces and public press and media sources. These queries relate exclusively to the companies, brands and products of the customer and of the competitors named by the customer; no targeted processing of personal data of natural persons takes place; for Google business profiles and reviews, letter m applies, and for the website check and the AI live check the two following paragraphs apply. Where publicly accessible advertisements or press articles incidentally contain the names of company representatives, these are not separately analysed or stored. The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and, insofar as individual queries go beyond the narrower purpose of the contract and serve to improve the quality of the analysis, Art. 6(1)(f) GDPR (legitimate interest in reliable competitive intelligence).
Website check. For the website check we retrieve, at your request, the website you have entered in the project as your domain (see Terms § 2(6)(d) and § 8(4)). The retrieval is carried out from our servers in Germany (see section 3 and letter f). Our program identifies itself under recognisable names: when reading pages as RivlyBot (user agent Mozilla/5.0 (compatible; RivlyBot/1.0; +https://rivly.de/wie-wir-messen)), and when reading the start page, robots.txt, llms.txt and sitemap as RivlyCheck (user agent RivlyCheck/1.0 (+https://rivly.de/tools/)). Only publicly accessible pages of this domain are retrieved, never areas protected by a login. RivlyBot observes the robots.txt of the domain, including a waiting time specified there, and requests at most two pages at the same time. The retrieval takes place when the project is set up, after that weekly in a short version and once a month within the page quota of your plan (see Terms § 2(7)). At your request we also check individual pages of your domain immediately; nothing is stored in the process.
In addition, we check whether search and AI crawlers can read your pages. To do this, we retrieve the start page and a few further pages from the sitemap once with an ordinary browser identifier and once with the identifiers of well-known AI crawlers as their providers publish them (for example GPTBot, ClaudeBot and PerplexityBot), and compare the responses. This shows us whether a firewall or a host blocks these crawlers. The requests are staggered (at most two at the same time, at least one second apart) so that they do not trigger a block themselves.
Per page, only technical characteristics are stored: address, response status, redirect target, information on indexability (robots directives, canonical address), title, main heading, meta description, language, word count, Schema.org types, a checksum of the content, size and response time of the page, and the times of retrieval, plus the result of the other checks (for example whether robots.txt, llms.txt and a sitemap exist, which shop or website system was detected and which crawlers have access). The text of the pages themselves is not stored.
To measure loading speed and to detect the technology in use, we transmit the domain and the addresses of the start page and of further important pages (within the page quota of your plan, once a month) to DataForSEO OÜ (see section 11). DataForSEO retrieves these pages itself, measures them with the Lighthouse tool in mobile view and returns scores (performance, accessibility, search engine optimisation, best practices) as well as loading time measurements to us; DataForSEO also names the technologies detected on the domain (for example the shop or content management system). Of these responses we store only the scores, the measurements, the identifiers of the three checks with the greatest savings potential and the names of the detected technologies; the full Lighthouse report is not stored.
The website check concerns company websites. Publicly retrievable content, such as titles or headings, can in individual cases contain personal data in the case of sole traders; no targeted analysis beyond the characteristics named takes place. The legal basis is Art. 6(1)(b) GDPR (providing the website check you have commissioned) and, insofar as the retrieved pages contain personal data of third parties, Art. 6(1)(f) GDPR (legitimate interest in a reliable technical check). The retention rule in the introduction to this section applies.
AI live check. With the AI live check you put individual questions to AI-based systems and view their answers (see Terms § 2(6)(c) and § 8(5)). You can ask questions in the application or via the MCP access. You word the question freely (up to 400 characters); please do not enter personal data, trade secrets or other confidential information in it. We transmit the text of the question via the LLM Scraper service to DataForSEO OÜ (see section 11). It is supplemented by the place the question refers to (for projects with a location, the main place of the project), for a follow-up question by up to three of your previous questions from the last six hours so that the follow-up question remains understandable, and by the language and country of the project. DataForSEO puts the question to the services ChatGPT (OpenAI) and Gemini (Google) and returns their answers to us. The text of the question thus reaches DataForSEO and the providers of these two services; your name, your e-mail address and your account data are not transmitted.
We also transmit the text of the answer, but not your question, to OpenRouter, Inc. (see section 11) so that a language model identifies the brands and companies named in it; we then check ourselves whether and at what position your brand and your competitors are named. We store questions and answers in the history of the project, together with the information on which user of the account asked, in our database on servers in Germany (see letter f); the retention rule in the introduction to this section applies. A repetition of the same question for the same place within 24 hours is answered from the cache without being forwarded again. The legal basis is Art. 6(1)(b) GDPR (carrying out the question you initiated).
d) Billing. Payments for paid subscriptions are processed by the payment service provider Stripe (see Terms § 5). For this purpose we transmit the data required for invoicing (company name, billing address, e-mail address, preferred language for invoices and receipts, subscription and payment data) to Stripe; the actual payment instrument data (e.g. card details) is processed exclusively by Stripe and does not pass through our systems. Invoices and payment receipts for your subscription are sent directly by Stripe to the e-mail address you have provided; these messages do not pass through our e-mail service provider Postmark and are not covered by the archive described in letter e). The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (retention obligations under commercial and tax law).
e) Sending and archiving of e-mails. We use the e-mail service provider Postmark to send the e-mails of the application: for messages about your contract and your account (for example confirming your e-mail address, resetting your password, notices after a change of password or e-mail address, team invitations, the booking confirmation under Terms § 4(5), confirmations of plan changes and cancellations, the data export, and the reminder and confirmation of an account deletion), for messages about the results of your measurement, in particular the weekly report, and, where the conditions stated there are met, for the e-mails about the trial period and our plans under letter i). Invoices and payment receipts for your subscription are not among these; as described in letter d), Stripe sends those directly. The e-mail address and the content of the respective message are processed for the e-mails sent via Postmark. The legal basis is Art. 6(1)(b) GDPR (performance of the contract), insofar as the individual e-mail is directly owed under the contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in reliable communication and in providing the analysis owed under the contract); the e-mails under letter i) are governed by the legal basis stated there. Independently of the archive described below, Postmark also stores the content and delivery data of each e-mail in its own systems; according to Postmark’s own information, this retention period is 45 days after sending by default.
Postmark also automatically notifies us when an e-mail cannot be delivered, is reported as spam, or a recipient unsubscribes from an e-mail. We process these notifications in order to stop sending further non-essential e-mails, in particular the weekly report and the e-mails under letter i), to the address concerned; messages about your contract and your account are not affected by this. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in permissible and reliable communication).
In addition, every e-mail we send via the application is kept as a copy in our own e-mail archive. The archive is stored in the same database as the customer account data on the servers of our hosting provider in Germany (see letter f). This covers all e-mails of the application, for example messages confirming the e-mail address and resetting the password, team invitations, the booking confirmation, the data export, the weekly report and, where applicable, the e-mails about the trial period and our plans under letter i), as well as internal notifications that we send to ourselves about events in a customer account (e.g. about a support request under letter j). We store the HTML and plain-text versions of the e-mail, its headers (in particular sender, recipient, subject, date, message ID and unsubscribe information) and the message source. The purpose is to be able to trace and prove which e-mail we sent to whom, when and with what content, to answer your questions about individual e-mails and to check the presentation and content of our e-mails and correct errors (quality assurance).
Security-relevant links that trigger an action on behalf of the recipient (for example resetting the password, confirming the e-mail address, accepting an invitation, downloading a data export or unsubscribing) are removed before storage. Only our administrators can view the archive. The archived content is not passed on to third parties; its only recipient is our hosting provider Hetzner, which processes it as our processor (see section 11).
Archived content assigned to a customer account is kept until the customer account is permanently deleted and is deleted together with it; e-mails addressed to a user are also deleted as soon as that user’s access is deleted. Archived content not assigned to a customer account (for example internal reports to our own address) is deleted automatically 180 days after sending. The sending log, in which we record for each e-mail only the recipient address, subject, type of e-mail, delivery status and timestamps, is kept until the customer account and the users assigned to it are deleted; it is not deleted merely because time has passed.
The legal basis for the archive and the sending log is Art. 6(1)(f) GDPR (legitimate interest in traceable and reliable communication, in answering enquiries and in the quality assurance of our e-mails).
You may object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR); an informal message to kontakt@rivly.de is sufficient. We will then no longer process the data concerned for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
f) Hosting of the application. The application app.rivly.de is hosted, like the marketing website, by Hetzner Online GmbH in Germany (see section 3). The statements made there regarding server log files apply accordingly. We make backups of the data stored on these servers, which also remain in Germany.
g) Draft before registration. If you enter a domain in the domain form without completing registration, we store this domain, the public profile of the website derived from it (in particular the company or brand name from its legal notice, location, industry, market, suggested competitors and example questions, and whether the domain is reachable) and a randomly generated identifier of your session, by which the draft is associated solely with your browser. The purpose is to prepare the analysis, to allow an interrupted process to be resumed without re-entering the data, and to evaluate which companies and industries are interested in our offering, in order to align our offering and advertising accordingly; we do not contact the company behind the domain. If the domain entered belongs to a company other than yours, the paragraph “Recognition at set-up” under letter b applies accordingly to that company’s details (Art. 6(1)(f) GDPR). The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request) and Art. 6(1)(f) GDPR (legitimate interest in being able to resume a process that has been started and in aligning our offering). An IP address is not stored with this draft; to limit abusive bulk requests, only the number of requests originating from an IP address is counted in a volatile cache. The draft is not deleted merely because time has passed: we keep it as long as it is needed for these purposes and delete it at your request to kontakt@rivly.de or if you object to the processing. Apart from the random identifier of your session, it contains no information about you. If you register, it is assigned to your account; from that point on the statements under letter b apply.
Under the identifier of the draft we additionally record the following steps: entering the domain, together with the page of rivly.de you came from, a campaign source where present (parameter utm_source) and a plan you may have chosen; the successful or failed completion of the check of your domain (whether a brand was recognised and how many competitors were suggested); viewing the registration page; a failed registration attempt (in this case we store only the type of error as an internal error code, for example an e-mail address already in use, not the values you entered); and the completion of registration and its method (e-mail or Google account). The domain itself is not stored in these entries. The purpose is to understand at which point visitors do not continue with the process, in order to improve onboarding; the same legal basis applies as in the preceding paragraph of this letter. If you register, we assign these entries to your account; from that point on letter l) applies. Without a registration they remain assigned to the draft. If the draft is deleted at your request, the entries remain stored without the domain; since the identifier was generated at random and is linked to your browser only for the duration of your session, they can no longer be attributed to a person afterwards.
h) Logging of the interface for AI assistants (MCP). If you connect an AI assistant to your account using an access key generated by you, we log every call to this interface with its time, the function called, the result, the duration, the name and version of the connected program (or, failing that, its identifier, the user agent) and the full IP address from which the call originates. The content of requests and responses is not stored; only a checksum of the call parameters is formed. The purpose is to detect and prevent abusive use of a key: only the full IP address makes it recognisable that a key is being used from a foreign system; we provide it to the account holder on request. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security of the account and of the systems). The IP address is removed from the log automatically 90 days after the call; the other information in the log and revoked keys are kept until the project or the customer account is deleted.
You may object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR); an informal message to kontakt@rivly.de is sufficient. Because this logging serves the security of your account and of our systems, we will then examine whether compelling legitimate grounds for the processing continue to exist which override your interests, rights and freedoms; otherwise we will no longer process the data concerned for this purpose.
i) E-mails about the trial period and our plans (direct marketing). When you register, we give you a separate notice that we also use your e-mail address to inform you about our own, similar services of Rivly: with companion e-mails during the trial period about your first measurement results, where applicable with a reminder to start your first measurement, and occasionally with information about Rivly’s plans and features. We send these e-mails only to the person who registered the account, not to invited team members. The legal basis is § 7(3) UWG (German Act Against Unfair Competition); under data protection law we base this processing on Art. 6(1)(f) GDPR, our legitimate interest being direct marketing for our own services.
In addition, when you register you may separately and voluntarily consent to receiving the e-mails named in the preceding paragraph, independently of accepting the Terms (§ 7(2) no. 2 UWG). This consent only takes effect once you have verified your e-mail address via the confirmation link; we store the time and the version of the consent text for this purpose. The notice under the first paragraph and this consent exist independently of one another.
You receive the message before the end of the trial period and the message after its end in any case as information about your contract, regardless of the above. We only include the reference to our plans contained in them if the notice under the first paragraph applies, or you have given consent under the second paragraph, and you have not objected to the use of your e-mail address for these purposes.
Right to object to direct marketing. You may object to the use of your e-mail address for these purposes, or withdraw consent you have given, at any time, at no cost other than standard transmission charges: via the unsubscribe link in any of these e-mails, in the settings under Notifications, or informally to kontakt@rivly.de. After your objection or withdrawal we will no longer use your address for these purposes (Art. 21(2) and (3) GDPR). We store your objection with its date so that it is always honoured. You can unsubscribe from the weekly report, the notices about your measurements and the e-mails under this letter separately. You will continue to receive messages about your contract and your account, for example about the end of the trial period.
j) Support requests in the customer account. Via the support form in the application, you can send us a request as a logged-in customer with a topic and a message. We store this information, together with a ticket number and technical context data of the request (the page and address accessed, where applicable the brand, measurement week and date of the content shown, language, browser identifier), assigned to your account. To process your request, we also forward it as an internal notification to our own address, kontakt@rivly.de; if we reply to that internal message, the reply goes directly to your e-mail address. If you request an individual offer or apply for the deletion of your customer account in the application, we also receive an internal notification about it at kontakt@rivly.de. The legal basis is Art. 6(1)(b) GDPR (performance of ancillary contractual duties, in particular support). This information is deleted as soon as it is no longer required to handle your request, at the latest when your customer account is deleted.
k) Server-side events to Google Analytics 4 (registration and first measurement). If a Google Analytics 4 client identifier reached us with a registration as described in section 7 and in letter a) of this section, our server transmits two events to Google Analytics 4 via the Google Measurement Protocol: the event sign_up at registration and the event first_measurement once the first measurement is complete. Only the client identifier, the session identifier, the name and time of the event, the chosen plan where applicable and, for the sign_up event, the registration method (e-mail or Google account) are transmitted in each case; your e-mail address, your name, the domain checked and your account number are not transmitted. The purpose is to measure the channel, for example a search query or an advertisement, through which a registration came about. The legal basis is your consent to the “Statistics” category on rivly.de (Art. 6(1)(a) GDPR, see sections 4 and 5); without that consent we do not receive a client identifier and no transmission takes place. The recipient is Google Ireland Limited; the statements on the transfer to third countries in section 5, letter f), apply accordingly. The transmitted event data is subject to the same retention period as the other event data of Google Analytics 4 (see section 5, letter d).
l) Usage log of the application. To improve onboarding and the product and to support our customers, we log the use of the application by registered users. On our server we record which areas of the application a user opens (the name of the area, not further parameters of the address), the steps of setting up a project (viewing and completing the two confirmation steps, a renewed check of the domain, and in doing so only whether brand, industry or market were changed and how many suggested competitors, questions and search terms were kept, removed, added or edited, the completion of the setup, and the first visit to the overview after the first measurement), and certain key actions from a fixed list: changing the status of a recommendation, changes to competitors, questions or search terms, creating an access key (see letter h), requesting a data export, starting or cancelling the checkout, opening and creating a page brief in the roadmap, checking a page (only whether the check was carried out, refused or limited by the quota) and, in the AI live check, opening the area, asking a question (only whether the answer was fetched anew, served from the cache or limited by the quota, not the text of the question) and adding a question to the measurement plan. Some actions are captured by a small script in your browser and transmitted to our own server by a POST request: opening a recommendation, opening the AI answers to a question, switching between tabs, viewing the plans, opening the support form, opening a field of the market map and copying a page brief. They are limited to names from this fixed list, and this is not a third-party script. We do not set any additional cookie for this purpose; we use only the application’s existing session cookie.
We do not store an IP address or your browser identifier (user agent) for this purpose; only the device class derived from it (mobile or desktop) is recorded. Content of pages, for instance the text of an AI answer you open, is not stored, only the fact that such content was opened. No transfer to third parties takes place; the data remains in our own database on our servers in Germany.
Accounts we use internally (for example our own account, partner and test accounts, administrator accounts, and sessions in which an administrator is logged in as a user for support purposes) are flagged separately and excluded from our internal evaluations.
The purpose of this processing is to understand where users encounter difficulties or do not continue with a process and which functions are used, in order to improve onboarding and the product and to support customers more specifically; we also evaluate this information in aggregated form for an internal weekly report. Within our company, this information can be viewed per account. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving our offering and in supporting our customers).
We keep the entries until you permanently delete your customer account. When the account is deleted, we remove from the entries every reference to your account, to you as a user and to your former session; the remaining information (for example the area opened, the time and the device class) can then no longer be attributed to a person and serves statistical purposes only.
You may object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR); an informal message to kontakt@rivly.de is sufficient. We will then no longer process the data concerned for this purpose unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms.
m) Google business profiles and reviews. For customers with locations, we evaluate the public Google business profiles of their locations and of the competitors they track: name, address, telephone number, categories, opening hours, average rating and number of reviews, and the individual public reviews (stars, date, text, language, and whether and when the owner replied, and for the customer’s own locations also the text of that reply). We obtain the data via DataForSEO OÜ (see section 11). We do not store the name, profile picture, profile link or any other information about the authors; before storage we replace personal names in texts with a placeholder. Review texts can nevertheless allow conclusions about the person who wrote them and are therefore personal data. The purpose is to evaluate how customers write about our customer’s business and its market; the legal basis is Art. 6(1)(f) GDPR. We delete the texts of reviews and replies 24 months after the review date or as soon as the review can no longer be retrieved on Google; we keep stars, dates and evaluations until the customer account is deleted. Because we do not know the authors, we do not inform them individually (Art. 11 and Art. 14(5)(b) GDPR). You may object to the processing of your review at any time (Art. 21(1) GDPR); to do so, send the link or the text of the review to kontakt@rivly.de.
10. Contact
If you contact us by e-mail (kontakt@rivly.de), the information you provide is processed in order to handle your enquiry and any follow-up questions. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into a contract or contract initiation) or Art. 6(1)(f) GDPR (legitimate interest in responding). The data is deleted as soon as it is no longer required for handling the enquiry and no statutory retention periods prevent deletion. Support requests submitted via the form in the application are additionally governed by section 9, letter j).
11. Processors and other service providers
For the operation of rivly.de (including the free tools under section 8) and app.rivly.de we use the following processors and service providers. A data processing agreement under Art. 28 GDPR is in place with all processors where required by law.
| Service provider | Purpose | Registered office | Status |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (marketing website and application) | Germany (EU) | DPA under Art. 28 GDPR |
| Google Ireland Limited | Audience measurement (Google Analytics 4), only with your consent (see section 5) | Ireland (EU), intra-group processing also in the USA (Google LLC) | DPA via the Google Ads Data Processing Terms under Art. 28 GDPR; third-country transfer safeguarded by the EU-US Data Privacy Framework (DPF, Google LLC certified) and the EU standard contractual clauses (SCC) |
| Stripe Payments Europe, Ltd. | Payment processing (subscriptions), including sending invoices and payment receipts | Ireland (EU), intra-group processing also in the USA | DPA included in the Stripe Services Agreement; third-country transfer safeguarded by the EU standard contractual clauses (SCC) |
| Postmark (AC PM LLC) | Sending the e-mails of the application (see section 9, letters e and i) | USA | DPA (Data Processing Addendum) included in the terms of use; third-country transfer safeguarded by the EU-US Data Privacy Framework (DPF, AC PM LLC certified) and additionally by the EU standard contractual clauses (SCC) |
| OpenRouter, Inc. | Gateway to large language models for AI-based measurements (forwarding of product- and brand-related queries to language models) and for identifying the brands named in AI live check answers (transmission of the answer text, not of the question) and for recognising profile and competitors at set-up (excerpts of public websites, see section 9 letter b) | USA | Processing exclusively of public, company- and brand-related query data; third-country transfer via the EU standard contractual clauses (SCC) insofar as personal data is affected |
| SerpApi, LLC | Retrieval of search engine results for competitive intelligence | USA | Processing exclusively of public search result data; third-country transfer via the EU standard contractual clauses (SCC) insofar as personal data is affected |
| Metapi.io | Retrieval of advertisements from the public Meta Ad Library (EU transparency data under the Digital Services Act) | USA | Processing exclusively of public, commercial advertising data (companies/brands); third-country transfer via the EU standard contractual clauses (SCC) insofar as personal data is affected |
| DataForSEO OÜ | Retrieval of search results, advertising transparency data, news, AI answers, and Google business profiles and reviews; in the website check, Lighthouse measurement and technology detection for the customer’s domain; forwarding of AI live check questions to ChatGPT and Gemini | Estonia (EU), sub-processors also in the USA and the United Kingdom | DPA included in the terms of use; third-country transfer via the EU standard contractual clauses (SCC) or an adequacy decision |
The data processed via OpenRouter, SerpApi and Metapi.io is publicly accessible commercial competitive data (advertisements, search results, AI answers about brands and products); to our knowledge, no targeted processing of personal data takes place. Insofar as personal data is nevertheless contained in publicly accessible content in individual cases, we base the transfer to the USA on the standard contractual clauses of the European Commission or, where the respective provider is certified, on the EU-US Data Privacy Framework.
The questions of the AI live check (section 9, letter c) reach the providers of the services ChatGPT (OpenAI) and Gemini (Google) via DataForSEO, who process the question to generate the answer. The forwarding is carried out by our service provider DataForSEO; we do not transmit the questions to these providers ourselves.
The self-hosted cookie consent tool (see section 4) is not a processor within the meaning of Art. 28 GDPR, as it is software we operate ourselves without any transmission to a third-party provider.
12. Transfers to third countries
Insofar as processors established in the USA are used within the application app.rivly.de (Postmark, OpenRouter, SerpApi, Metapi.io), in the case of intra-group processing by Stripe, where DataForSEO OÜ (Estonia) uses sub-processors in the USA and the United Kingdom, and where the providers of the services ChatGPT and Gemini, to which DataForSEO forwards the questions of the AI live check, process these questions in the USA, personal data is transferred to a third country outside the EU/EEA. Where applicable, these transfers are safeguarded by the EU-US Data Privacy Framework (adequacy decision of the European Commission), by the adequacy decision of the European Commission for the United Kingdom and, additionally or alternatively, by the EU standard contractual clauses (SCC) under Art. 46(2)(c) GDPR.
For the marketing website rivly.de, a transfer to a third country takes place only if you consent to the use of Google Analytics 4 (see section 5); this transfer is safeguarded by the EU-US Data Privacy Framework and the EU standard contractual clauses. Without your consent, no personal data is transferred to a third country on rivly.de; hosting, the cookie consent tool and the font are operated entirely in Germany or self-hosted (see sections 3, 4 and 6).
13. Version of this policy
Version dated 3 October 2026. We reserve the right to amend this privacy policy so that it always meets current legal requirements or to reflect changes to our services.