Privacy notice
How RIVIAM manages your privacy
Contents
1. Introduction
2. Data protection principles
Part A - Data we process as a processor
3. Our role as a processor
4. What data we process about you
4.1 Special categories of personal data
4.2 Children's and vulnerable adult's data
5. Why we process your data
6. Who we share your data with
7. How we collect your data
8. How long we keep this data
9. Your rights
Part B - Data we process as a controller
10. What data we collect and why
10.1 Office visitors captured on CCTV
10.2 Job applicants
11. Cookies
12. Third parties
12.1 Disclosures to independent controllers
13. International transfers of your personal data
14. How long we keep your data for
15. Automated decision making and profiling
16. Your rights relating to your data
17. Consent
18. Protecting your data
Part C - Contact and complaints
19. Further information
1. Introduction
RIVIAM is committed to protecting the privacy and security of personal data. As a provider of digital solutions to NHS, Local Authorities and health and social care organisations, we take great care to keep your personal data safe and confidential.
This Privacy Notice explains how we handle your personal data. It is published on our website to make it easy to find. It is for members of the public, including patients and service users whose data we process on behalf of our customers, as well as visitors to our website and people who contact us or apply to work with us.
RIVIAM Digital Care Limited is the organisation referred to as ‘RIVIAM’, ‘we’, ‘us’ or ‘our’ in this notice.
RIVIAM Digital Care Limited is registered in England and Wales, Company Number: 04543806.
The rules we must follow depend on the type of personal data involved. Because of this, the notice is divided into two main parts:
- Part A explains the personal data we process as a processor on behalf of our customers – mainly patient and service user data.
- Part B explains the personal data we process as a controller in our own right – for example data about website visitors, people enquiring about our services and business contacts.
This notice does not cover every service we provide. Where the organisation responsible for your care is the controller (Part A), or where one of our own products or services gives you a privacy notice directly, that notice applies instead of this one. For everyone else, such as website visitors, enquirers, potential customers, suppliers and job applicants, this is the primary notice (Part B).
Information about how we handle the personal data of our employees is in a separate internal Staff Privacy Notice, which we give directly to those employees.
We want to be open and honest about how we handle your personal data. Please read this notice carefully, and raise any questions using the contact details in Part C.
We may update this notice at any time. The current version is always available on our website.
2. Data protection principles
Under UK data protection law, the UK GDPR and the Data Protection Act 2018 (called the ‘legislation’ in this notice), all personal data obtained and processed by us must be processed according to a set of core principles. We follow these principles. We will make sure that:
- processing is fair, lawful and transparent
- data is collected for specific, explicit, and legitimate purposes
- data collected is adequate, relevant and limited to what is necessary for the purposes of processing
- data is kept accurate and up to date. Data which is found to be inaccurate will be rectified or erased without delay
- data is not kept for longer than is necessary for its given purpose
- data is processed in a manner that ensures appropriate security of personal data including protection against unauthorised or unlawful processing, accidental loss, destruction or damage by using appropriate technical or organisation measures
Part A – Data we process as a processor
This part covers patient and service user data that we process when we deliver our services to organisations that arrange or provide patient and service user care.
3. Our role as a processor
RIVIAM is a data processor under the UK GDPR and the Data Protection Act 2018. This means we only act on the written instructions of the organisations (the data controllers) that arrange or provide patient and service user care. Those organisations decide how and why your personal data is used, including identifying the lawful basis under Article 6 and, where relevant, the extra condition under Article 9 for processing special category data.
Our responsibilities as a processor include keeping your data secure, only processing it as instructed by the controller, only using sub-processors who have the same obligations we do, and helping the controller meet its own obligations under the legislation.
4. What data we process about you
Personal data is any information about a living person who can be identified from it. It does not include anonymous data. We collect, store and use the following categories of personal data, which are given to us by the organisations that arrange or provide patient and service user care. We hold all such data digitally.
Personal details
- Full name (including previous names) and title
- Home address, telephone numbers and email address
- Date of birth
- Gender
- Racial or ethnic origin
- NHS Number
- The details of your clinician or doctor
- Where you are referred to us by a professional, the professional’s role and the organisation they work for
- Details of your referral or the service you are using, including your health condition, clinical outcomes or immunisation status, and any other accompanying information
Some of our digital products and services are used directly by health and care professionals, for example our referral management services. Where this applies, we also process personal data about those professionals as users of the services. This can include their name, contact details and login information.
4.1 Special categories of personal data
Some types of personal data are especially sensitive and carry extra protections under the UK GDPR. These are known as special category data. When we deliver our services, the data we process on behalf of controllers can include:
- Physical or mental health information
- Racial or ethnic origin
Depending on the service and the controller’s instructions, the data may also include other special category data.
As a processor, we do not decide why this data is processed; the controller decides its lawful basis and the relevant Article 9 condition. We only process special category data when necessary to deliver our digital services for NHS and health and social care organisations, and we apply extra safeguards to protect it, such as controlling who can access it and encrypting it where appropriate. See 'Protecting your data' later in this notice for more on this.
4.2 Children’s and vulnerable adult’s data
When we deliver services to organisations that arrange or provide patient and service user care, we process personal data about children and vulnerable adults, which may include health and other special category data.
We only process this data as a processor, acting on the controller’s written instructions. The controller decides the lawful basis for the processing. Because this information is sensitive and these individuals may be at greater risk, we take appropriate technical and organisational measures to keep it secure, including controlling who can access the data, encrypting it where appropriate, and training our staff to handle it responsibly.
5. Why we process your data
We only process this personal data to deliver our services under our contracts with the relevant controllers. We do not use it for our own purposes. The controller decides the lawful basis on which the data is processed; if you want to know the lawful basis that applies to you, ask the organisation responsible for your care.
6. Who we share your data with
We only share this personal data when necessary to deliver our services and as instructed by the data controller. This may include:
- returning data to, or sharing it with, the controller responsible for your care
- trusted sub-processors who process data on our behalf, giving them only the data they need to do the job
- third parties where we are required to do so by law
We have contracts (known as data processing agreements) in place with all sub-processors, requiring them to process data only on our written instructions and to take appropriate technical and organisational measures to keep it secure.
Any sub-processors we use must follow the same rules.
7. How we collect your data
Personal data usually reaches us from organisations that arrange or provide patient and service user care and that have a contract with RIVIAM. In some cases, for example online referral forms or e-consent, the data is entered directly by patients, service users, their representatives or referring professionals, as part of the service we provide to the controller. In every case, we act only on the controller’s instructions.
8. How long we keep this data
We only keep this data for as long as necessary to deliver our services under our contract with the relevant controller. When the contract ends, data is returned to the controller or securely deleted as agreed, unless the law requires a longer period.
9. Your rights
You have several rights over your personal data under the law (these are set out in full in Part B). Because we only act as a processor for patient and service user data, we are not usually the right organisation to deal with these requests directly. If you contact us to use your rights over this data, we will pass your request to the relevant controller quickly and help them respond. You may also contact the organisation responsible for your care directly.
Part B – Data we process as a controller
This part covers data where RIVIAM decides how and why personal data is processed – for example, data about visitors to our website, people who contact us with an enquiry, our business contacts, and people who apply to work with us. For this data, we are the data controller.
Where we rely on legitimate interests, we have checked that our interests do not override your interests or fundamental rights. You can ask us for more information about this using the contact details in Part C.
10. What data we collect and why
Depending on how you interact with us, we may collect and use the following categories of personal data as a controller:

10.1 Office visitors captured on CCTV
We display notices wherever CCTV is in operation, explaining that images are watched to keep people safe, prevent crime and support the prosecution of offenders. Footage is normally kept for 60 days on a rolling basis, other than where an extract is needed to investigate a specific incident. RIVIAM holds this footage. To ask about footage held about you, or to use your other rights over it, use the contact details in Part C.
10.2 Job applicants
If you apply for a role with us, we collect your name and contact details, your CV, and the information you give us as part of your application. We use this to assess your application and decide whether to take it forward. Our lawful basis for this is our legitimate interests in recruiting for open roles and in choosing the right person for the job, and, where you have asked us to, taking steps prior to entering into a contract of employment with you. Here is what happens to your information after you apply:
- If we do not shortlist your application, we delete your information shortly after we make that decision.
- If you are interviewed but not offered the role, or if we make you an offer that does not go ahead, we keep your information for 6 months from our decision, then delete it securely.
This applies whether you applied directly or through a recruitment agency.
RIVIAM does not use AI to assess or interview candidates.
11. Cookies
You can update your cookie choices in our Cookie Banner. You can also read our full Cookie Notice at any time by selecting 'Cookies' at the bottom of our website.
12. Third parties
We share your personal data with the following third-party service providers, who process it on our behalf under our instruction. We only share the information that is needed for the job.

We have contracts (data processing agreements) in place with all third-party processors, requiring them to process your data only on our written instructions and to take appropriate technical and organisational measures to keep it secure.
12.1 Disclosures to independent controllers
In some circumstances the law requires or allows us to share your personal data with organisations who then use it as independent data controllers in their own right, rather than on our behalf. These include:

Where we share data with independent controllers, those organisations are responsible for their own compliance with data protection law. We will only share data this way where we have a lawful basis to do so.
13. International transfers of your personal data
Your personal data is mainly stored and processed within the United Kingdom and the European Economic Area (EEA). However, there may be times when your data is transferred to, stored, or processed in a country outside the UK or EEA - for example, where we use third-party service providers or cloud-based systems hosted internationally, or where we operate facilities outside these regions.
Whenever we transfer your personal data outside the UK or EEA, we make sure appropriate safeguards are in place to protect your data and that the transfer follows data protection law.
These safeguards may include:
- Transferring data to countries approved by the UK Government or European Commission as providing an adequate level of protection
- Using Standard Contractual Clauses (SCCs) or the International Data Transfer Agreement (IDTA) approved by the Information Commissioner's Office (ICO)
- Relying on binding corporate rules or other legally recognised transfer mechanisms
14. How long we keep your data for
RIVIAM will only keep your personal data for as long as necessary for the purpose it was collected for. However, in many cases we must keep certain data for a set period to meet regulatory or contractual obligations, or to respond to possible claims.
Where the law sets specific retention periods, we will always follow these as a minimum.
15. Automated decision making and profiling
RIVIAM does not make automated decisions about you, without human involvement, where this may have a significant or legal effect on you. We also do not use profiling. This includes as part of the recruitment process.
16. Your rights relating to your data
RIVIAM must uphold individuals’ rights as set out in the UK GDPR and the Data Protection Act 2018, subject to certain exemptions provided for in the law.
- the right to be informed about the data we hold on you and what we do with it
- the right of access to the data we hold on you. More information on this can be found in our separate policy on Subject Access Requests
- the right to have any mistakes in the data we hold on you corrected. This is also known as ‘rectification’
- the right to have data deleted in certain circumstances. This is also known as ‘erasure’
- the right to restrict the processing of the data
- the right to transfer the data we hold on you to another party. This is also known as ‘portability’
- the right to object to us processing your data in certain circumstances, for example where we rely on legitimate interests. Responding to rights’ requests
We will respond to any request to exercise a data subject right within one calendar month of receiving it. To make a request, please email [email protected] with enough information to allow us to find the data you are requesting. We may ask you to prove your identity before we deal with your request.
Where a Data Subject Access Request (DSAR) is complex or involves a large amount of data, we may extend this period by a further two months. If we need to do this, we will tell you within the first month and explain why.
17. Consent
Where you have given consent to our use of your data, you also have the right to withdraw that consent at any time. If you do, we will stop processing your data. We will only ask for your consent to process your personal data in limited circumstances.
18. Protecting your data
RIVIAM uses appropriate technical and organisational measures to protect your personal data and keep it safe and confidential. Measures we take include:
- Access controls – limiting access to personal data to authorised staff only
- Confidentiality duties – staff must follow confidentiality and data protection rules
- Secure IT systems – password protection, multi-factor authentication, and system monitoring
- Encryption – where appropriate, particularly for portable devices and data transfers
- Physical security – secure offices, locked cabinets, and controlled access areas
- Data minimisation – only collecting and retaining data necessary for the purposes described in this notice
- Retention controls – secure deletion or anonymisation in line with retention schedules
- Third-party safeguards – checks and contract protections with data processors
- Staff training – regular data protection and information security training
- Incident management – clear steps for identifying, reporting and managing data breaches
These measures are part of the information security and quality management systems behind our ISO 27001 and ISO 9001 certifications. Certification does not change our legal obligations, and does not remove the need for the safeguards described elsewhere in this notice.
Part C – Contact and complaints
19. Further information
RIVIAM Digital Care Limited is registered in England and Wales, Company Number: 04543806.
Our ICO registration reference is Z8885675.
Our address is 3rd Floor, Westpoint, James Street West, Bath, BA1 2DA, United Kingdom.
If you have a complaint about how we handle your personal data, please contact us first at [email protected]. We will acknowledge your complaint within 30 days and aim to resolve it as quickly as we can.
Where your complaint or enquiry relates to a service we provide for a customer, RIVIAM will usually be acting as a data processor. This means the customer decides how and why your personal data is used. We may need to pass your complaint or enquiry to that customer and will support them where required.
For general data protection questions, or to use your data protection rights where RIVIAM is the controller, please contact [email protected]. We will look at your enquiry and involve our appointed Data Protection Officer (DPO) where appropriate.
We have appointed GRC Solutions as our independent Data Protection Officer (DPO) to check that we follow data protection law. You may contact the DPO directly if you prefer:
- Email: [email protected]
- Phone: +44 (0) 333 900 5555
- Post: GRC Solutions, Unit 3, Clive Court, Bartholomew’s Walk, Cambridgeshire Business Park, Ely, Cambridgeshire, CB7 4EA
If you are still unhappy after we have responded, you can complain to the Information Commissioner’s Office (ICO): ico.org.uk / 0303 123 1113.
This Privacy Notice was last updated in August 2026.