Rivalyne

Privacy Notice

Privacy Notice


Information about the processing of personal data by Rivalyne
Last updated: 29 September 2026


Information about the processing of personal data by Rivalyne
Last updated: 29 September 2026

1 · Controller

The controller responsible for processing personal data is:


Rivalyne GmbH
Am Belvedere 4
1100 Vienna
Austria


Commercial register number: FN 442427 d
Commercial register court: Commercial Court of Vienna
Managing Director: Mag. Gerd Clement
Email: office@rivalyne.com


Privacy contact


For questions about this Privacy Notice or to exercise your data protection rights, please contact:


Mag. Gerd Clement
Rivalyne GmbH
Am Belvedere 4
1100 Vienna, Austria
Email: office@rivalyne.com


Rivalyne processes personal data in connection with visits to this website, enquiries, appointment bookings, the purchase, use and ongoing provision of report products, customer onboarding and recurring report delivery.


This Privacy Notice also covers our English-language website and our business relationships with customers and prospective customers in the United Kingdom and the United States. Our report products are offered for business use.


Business contact details that identify an individual remain personal data, even where that individual acts on behalf of a company.


Definition of report products


“Report products” means all current and future Rivalyne products that follow the same underlying processing model: monitoring, analysing, contextualising and summarising competitive and market information in periodic reports. Product names, the number of products and different packages or service levels do not affect the application of this Privacy Notice.


Products involving fundamentally different processing purposes or materially different processing activities are not covered by this definition. For such products, we will update this Privacy Notice or provide a supplementary notice.

2 · General principles and legal bases

Rivalyne processes personal data only to the extent necessary to provide the website, respond to enquiries, take steps before entering into a contract, perform contracts, comply with legal obligations or pursue legitimate interests.


As Rivalyne is established in Austria, the EU General Data Protection Regulation (“EU GDPR”) applies to processing carried out in the context of that establishment. Applicable UK and US requirements are addressed in sections 20 and 21.


Depending on the activity, processing is based on:


  • Article 6(1)(a) GDPR: consent;

  • Article 6(1)(b) GDPR: performance of a contract with the individual or steps requested by that individual before entering into a contract;

  • Article 6(1)(c) GDPR: compliance with a legal obligation;

  • Article 6(1)(f) GDPR: legitimate interests.


Our legitimate interests include:


  • operating a secure and technically stable website;

  • handling business enquiries;

  • preventing misuse;

  • diagnosing technical problems;

  • conducting relevant business communications with prospective B2B customers;

  • administering customer relationships and delivering services to business customers.


Where a contract is with a company rather than with the individual concerned, processing the personal data of its employees, representatives and report recipients is generally based on our legitimate interests in managing and fulfilling that business relationship, rather than on a contract with those individuals.


References below to contractual necessity should be understood accordingly. Where UK GDPR applies, we rely on the corresponding legal basis under that legislation.


Information needed to process an order, comply with legal requirements or deliver a report must be provided for those purposes. Without it, we may be unable to accept the order or provide the relevant service. Optional information is voluntary.

3 · Hosting through Framer

This website is provided through Framer.


When you access the website, the following technical access data may be processed:


  • IP address;

  • date and time of the request;

  • page accessed;

  • referring URL;

  • browser type and version;

  • operating system;

  • technical status and security information.


Processing supports the availability, stability and security of the website.


Legal basis: Article 6(1)(f) GDPR.


Retention depends on the technical settings of the Framer project, security requirements and applicable legal retention obligations. Technical data is retained only for as long as necessary for those purposes.


Where Framer processes personal data on Rivalyne’s behalf, processing is governed by a data processing agreement under Article 28 GDPR.


Where Framer or related technical services transfer personal data internationally, the safeguards described in section 15 apply.

4 · Cookies and similar technologies

Rivalyne does not use advertising tracking on this website. We do not use Google Ads conversion tracking, Google Analytics, the LinkedIn Insight Tag or other advertising or remarketing pixels.


The website uses Framer’s built-in, cookie-free analytics as described in section 5.


Where strictly necessary cookies or similar technologies are used, they are limited to what is necessary to provide a service you request or maintain its security and functionality.


No cookie consent banner is currently used because the website does not use cookies or similar technologies requiring consent. If this changes, we will update this notice and obtain consent where required before activating the relevant technology.


Applicable rules include section 165(3) of the Austrian Telecommunications Act 2021 and, where applicable, the UK Privacy and Electronic Communications Regulations.


External services you visit through links, including payment and booking services, may use their own cookies or similar technologies. Their applicable notices explain those practices.

5 · Framer Analytics

Rivalyne uses Framer Analytics in the standard form provided by the platform for statistical analysis of website usage.


The analysis is limited to the usage and audience statistics available through that standard service. According to Framer, its built-in analytics service does not use cookies or generate persistent identifiers.


According to Framer, daily unique visitor counts are calculated by hashing the IP address and user-agent information with a secret that changes and is deleted daily. Rivalyne receives anonymised website statistics through the analytics dashboard. Framer states that its built-in analytics does not use cookies or persistent identifiers.


Purposes


Framer Analytics is used to:


  • measure website reach;

  • understand how the website is used;

  • improve content and navigation;

  • diagnose technical problems;

  • assess the effectiveness of the website.


Rivalyne does not use these statistics for personalised advertising.


Legal basis


To the extent personal data is processed, Article 6(1)(f) GDPR applies, based on our legitimate interest in understanding and improving our website. Statistics that are genuinely anonymous are not personal data.


This description concerns Framer’s built-in analytics service. It does not cover separately installed advertising or tracking tools.

6 · Fonts

The website uses a serif font for prominent headings and a sans-serif font for body text, navigation and controls.


Font files may be delivered through external servers, including Google Fonts or Framer’s technical infrastructure. Where this happens, the visitor’s IP address may be transmitted to the relevant technical provider.


The purpose is to display the website consistently.


Legal basis: Article 6(1)(f) GDPR, where delivery is necessary and the applicable balancing of interests permits it. Where an implementation requires consent, consent must be obtained before the relevant processing.


Where font files are delivered by providers outside the European Economic Area, the international transfer safeguards described in section 15 apply.

7 · Contact by email and website enquiries

If you contact Rivalyne at office@rivalyne.com, we process your email address and the information you provide.


If you submit a website enquiry or request a demo report, we also process the information entered in the form, such as your name, company, email address and message.


Processing serves to:


  • handle and respond to your enquiry;

  • provide a requested demo report;

  • take steps before entering into a contract;

  • prepare or perform a contract;

  • document business communications.


Legal bases


  • Article 6(1)(b) GDPR for contractual enquiries where the individual is the prospective contracting party;

  • Article 6(1)(f) GDPR for other business enquiries and communications with company representatives;

  • Article 6(1)(c) GDPR where legal retention obligations apply.


Correspondence is deleted when it is no longer required for its purpose and no legal retention obligation or justified need to retain it remains.


Business and tax records are retained for the applicable statutory periods. Austrian requirements, including section 132 of the Federal Fiscal Code, remain relevant even where the customer is based in the United Kingdom or the United States.

8 · Appointment booking through Microsoft Bookings

Microsoft Bookings is used to arrange the 15-minute introductory call.


The following data may be processed:


  • name;

  • email address;

  • requested appointment;

  • appointment and calendar information;

  • information voluntarily entered in a free-text field;

  • technical access data.


The data is used to:


  • book and manage the appointment;

  • send an appointment confirmation;

  • prepare the conversation;

  • conduct the conversation;

  • enable appropriate personal follow-up.


Legal bases


  • Article 6(1)(b) GDPR for pre-contractual steps requested by an individual who is the prospective contracting party;

  • Article 6(1)(f) GDPR for appointment administration and communication with business representatives.


Microsoft may act as a technical service provider and processor in connection with Microsoft Bookings.


Where Microsoft processes personal data internationally, the safeguards described in section 15 apply.


Appointment and contact data is retained for as long as necessary to manage the appointment, follow up on the conversation and handle any resulting business matters.

9 · Purchases through Stripe

Report products are purchased through dedicated Stripe Payment Links.


The following data may be processed during checkout and payment administration:


  • name;

  • company name;

  • billing address and country;

  • email address;

  • payment information;

  • payment status;

  • subscription information;

  • VAT number or other relevant business tax information, where collected;

  • information confirming the business nature of the purchase, where collected;

  • technical checkout and transaction information.


Stripe is used for:


  • checkout;

  • payment processing;

  • invoicing;

  • subscription management;

  • tax handling;

  • payment confirmation;

  • compliance with commercial record-keeping requirements.


Legal bases


  • Article 6(1)(b) GDPR where processing is necessary for a contract with the individual;

  • Article 6(1)(f) GDPR for administering purchases made on behalf of business customers and preventing misuse;

  • Article 6(1)(c) GDPR for applicable tax, record-keeping and retention obligations.


Stripe is the primary commercial system for payment, invoicing, tax and subscription information.


Where Stripe processes personal data on Rivalyne’s behalf, processing is governed by a data processing agreement under Article 28 GDPR. Stripe may also process certain information as an independent controller for its own legal, regulatory, security and payment-related purposes. Stripe’s own privacy notice applies to those activities.


Where personal data is processed internationally, the safeguards described in section 15 apply.


Payment, invoicing and tax records are retained in accordance with statutory requirements. Other checkout and payment information is deleted when it is no longer required for contract administration, evidential purposes or other applicable legal obligations.

10 · Payment confirmation page and customer setup

After successful payment, the customer is redirected to a confirmation page.


This page serves to:


  • confirm the payment process;

  • explain the next step;

  • inform the customer about the personal onboarding link.


The confirmation page does not contain a public onboarding form.


The following information may be processed to set up the customer operationally:


  • individual or company name;

  • email address;

  • purchased report product;

  • contract start date;

  • Stripe Checkout Session ID;

  • payment status;

  • contact details needed for customer setup.


Operational customer setup uses Rivalyne’s connected SharePoint and Power Automate processes.


Legal bases


  • Article 6(1)(b) GDPR for contracts with individuals;

  • Article 6(1)(f) GDPR for setting up and administering corporate customer relationships;

  • Article 6(1)(c) GDPR where statutory evidential requirements apply.

11 · Onboarding through Tally

Following a successful purchase, an individual onboarding link is sent by email. The onboarding form is provided through Tally.


The following information may be processed:


  • company details;

  • industry context;

  • core competitors;

  • additional competitors to be monitored;

  • names of report recipients;

  • email addresses of report recipients;

  • preferred delivery day;

  • additional contextual information supplied by the customer.


The information is used to:


  • configure the purchased report product;

  • define the relevant competitive environment;

  • prepare the monthly reports;

  • deliver reports to the designated recipients;

  • fulfil the ongoing contract.


Legal bases: Article 6(1)(b) GDPR for contracts with individuals and Article 6(1)(f) GDPR for administering and fulfilling contracts with corporate customers.


Tally is used as a technical service provider to collect and transmit onboarding information.


Where Tally processes personal data on Rivalyne’s behalf, processing is governed by a data processing agreement under Article 28 GDPR.


Where personal data is processed internationally, the safeguards described in section 15 apply.


Onboarding information is retained for the duration of the contractual relationship. After the contract ends, it is deleted when it is no longer needed for contractual obligations, applicable legal requirements or the establishment, exercise or defence of legal claims.

12 · SharePoint and Power Automate

SharePoint and Power Automate are used for operational customer setup, onboarding preparation and handover to report delivery.


The following information may be processed:


  • customer name;

  • company name;

  • contract start date;

  • purchased report product;

  • payment status;

  • industry context;

  • core competitors;

  • additional competitors;

  • names and email addresses of report recipients;

  • delivery day;

  • onboarding status;

  • technical identifiers linking records and processes.


Stripe remains the primary commercial system for payment, invoicing, tax and subscription data. SharePoint receives only the information operationally required for customer administration, onboarding and report delivery.


Legal bases


  • Article 6(1)(b) GDPR for contracts with individuals;

  • Article 6(1)(f) GDPR for administering and fulfilling corporate customer relationships;

  • Article 6(1)(c) GDPR where statutory evidential requirements apply.


Where Microsoft processes personal data on Rivalyne’s behalf through SharePoint and Power Automate, the applicable Microsoft contractual terms and an agreement under Article 28 GDPR govern that processing.


International transfers are subject to the safeguards described in section 15.

13 · Report delivery

The recipient email addresses provided during onboarding are used for recurring delivery of the purchased report.


Processing serves to fulfil the customer relationship.


Legal bases: Article 6(1)(b) GDPR where the recipient is the contracting individual, or Article 6(1)(f) GDPR for delivery to recipients designated by a corporate customer.


Rivalyne processes recipient addresses for:


  • agreed report delivery;

  • necessary delivery-related communications;

  • ongoing contract fulfilment.


Customers must have a lawful basis for providing the email addresses of internal or other recipients to Rivalyne and must inform those individuals where required. This does not replace Rivalyne’s own applicable transparency obligations.


Recipient addresses are retained for the duration of the contractual relationship. After it ends, they are deleted when no longer needed for contractual obligations, applicable legal requirements or justified evidential purposes.


AI-assisted research


Rivalyne uses AI tools to support research into companies, markets and competitive developments. Rivalyne does not upload or otherwise submit personal data to these tools as research inputs. Customer contact details, report recipients’ email addresses, payment information and personal correspondence are not provided to AI tools for this purpose.

14 · B2B prospecting and business communications

Rivalyne processes personal data relating to contacts at prospective business customers.


The information may come from publicly accessible company and professional contact information or from direct business communications.


The following data may be processed:


  • name;

  • role or position;

  • company;

  • business address;

  • business contact details;

  • publicly accessible company information;

  • communication status;

  • responses to business communications.


Rivalyne uses SharePoint, Power Automate, LeadPool and Plumsail for these activities.


Processing serves to:


  • identify potentially relevant business customers;

  • prepare individual business communications;

  • conduct and document B2B communications;

  • handle responses;

  • manage the prospecting process.


Legal basis: Article 6(1)(f) GDPR, subject to an assessment of the interests and rights of the individual concerned.


Our legitimate interest is to communicate with relevant prospective business customers about our services.


A legitimate interest in processing contact information does not, by itself, authorise every marketing channel. We comply with separately applicable rules on electronic communications and obtain consent where required.


You may object to processing for direct marketing at any time by contacting office@rivalyne.com or using an unsubscribe option provided in a message. Following an objection, we will stop using your personal data for that purpose.


A limited suppression record may be retained to ensure that your objection continues to be respected.


Where personal data is obtained from another source, Rivalyne provides the information required by Article 14 GDPR within the applicable period, including information about the source. Where the data is used to contact the individual, this information is provided no later than the first communication, unless a lawful exception applies.


Prospecting data is deleted when it is no longer needed and no legal retention requirement or justified need for a suppression record remains.

15 · Services, recipients and international transfers

Rivalyne uses the following services in its website and business processes:

Service Purpose
Framer Website hosting and delivery
Framer Analytics Statistical audience and usage measurement as described in section 5
Stripe Checkout, payments, invoices, subscriptions and tax information
Microsoft Bookings Appointment booking
Tally Customer onboarding
SharePoint Operational customer setup, administration and handover to delivery
Power Automate Automated business processes
LeadPool Management of prospecting and business contact information
Plumsail Preparation and processing of prospecting letters
Google Fonts or external font infrastructure Delivery of font files where they are not loaded locally

Personal data is made available to service providers only as necessary for the relevant purpose. Where a provider acts as our processor, an agreement under Article 28 GDPR governs its processing.


Data may also be disclosed to professional advisers, public authorities or other recipients where necessary to comply with legal obligations or establish, exercise or defend legal claims.


Rivalyne operates from Austria. Depending on the service used, personal data may also be processed in other countries, including the United States.


Where a transfer is subject to EU GDPR international transfer requirements, it is based on an applicable adequacy decision or appropriate safeguards under Articles 44 onwards GDPR, including the European Commission’s standard contractual clauses where relevant.


Where UK international transfer requirements also apply, transfers are supported by applicable UK adequacy regulations or appropriate UK safeguards, such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, as appropriate.


Additional assessments and protective measures are applied where required. Your use of the website does not, by itself, constitute consent to international transfers.


You may contact office@rivalyne.com for information about the safeguards applicable to your data and to request a copy, subject to necessary protection of confidential information and the rights of others.

16 · Your rights

Subject to the applicable legal conditions, you have the following rights.


Access


You may request confirmation of whether we process your personal data and obtain access to that data and related information.


Rectification


You may request correction of inaccurate data or completion of incomplete data.


Erasure


You may request deletion of your personal data where the legal requirements are met.


Restriction


You may request that processing be restricted in the circumstances provided by law.


Data portability


Where the legal conditions are met, you may receive personal data you provided in a structured, commonly used and machine-readable format and request its transmission to another controller where technically feasible.


Objection


You may object, on grounds relating to your particular situation, to processing based on legitimate interests.


You may object to processing for direct marketing at any time. This includes related profiling to the extent it concerns direct marketing.


Withdrawal of consent


You may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before it was withdrawn.


To exercise your rights, contact:


office@rivalyne.com


We may request proportionate information to verify your identity or an authorised representative’s authority where necessary. We respond within the period required by applicable law.


These rights are subject to statutory conditions and exceptions, including applicable record-retention obligations.

17 · Complaints to a supervisory authority

You have the right to complain to a competent data protection supervisory authority.


For Rivalyne, the relevant Austrian authority is:


Austrian Data Protection Authority
Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna
Austria


Email: dsb@dsb.gv.at


Further information and complaint procedures:
https://dsb.gv.at/ueber-die-datenschutzbehoerde/kontakt


Where UK data protection law applies, you may also complain to the UK Information Commissioner’s Office:


https://ico.org.uk/make-a-complaint/


You are welcome to contact us first so that we can try to resolve your concern. This does not limit your right to contact a competent authority.

18 · Data security

Rivalyne implements appropriate technical and organisational measures to protect personal data against loss, destruction, alteration and unauthorised access.


These include:


  • access controls for the systems used;

  • role-based permissions;

  • secure authentication;

  • encrypted data transmission;

  • access limited to necessary information;

  • processing through service providers subject to appropriate contractual arrangements;

  • regular updates to the systems used.

19 · Changes to this Privacy Notice

We update this Privacy Notice when our processing activities, services, technical processes or applicable legal requirements change.


The current version is published on the website. Its revision date appears at the beginning of this notice.


Where legally required, material changes will also be communicated directly to affected individuals. Changes to this notice do not replace any consent or other legal basis required for new processing activities.

20 · Additional information for the United Kingdom

This section applies where UK data protection law governs the relevant processing.


References to applicable UK data protection law include the UK GDPR and the Data Protection Act 2018, as amended. The Privacy and Electronic Communications Regulations apply where relevant to cookies, similar technologies and electronic marketing.


The processing purposes, categories of data, recipients, retention criteria and rights described in this notice also explain our corresponding UK processing activities.


Business communications


We distinguish between corporate subscribers and individual subscribers under applicable electronic marketing rules. Sole traders and certain partnerships may be treated as individual subscribers, even where communications concern business activities.


We obtain consent where required and provide an effective way to object to direct marketing. Applicable requirements arising from Rivalyne’s establishment in Austria also remain relevant.


International processing


Your personal data may be processed in Austria and through the service providers described in this notice. Where UK international transfer rules apply, the safeguards described in section 15 apply.


Rights and complaints


To exercise your rights, contact office@rivalyne.com.


You may also contact the Information Commissioner’s Office as described in section 17.

21 · Additional information for the United States

This section provides additional information for individuals in the United States.


Rivalyne remains an Austrian company. The EU GDPR continues to apply to processing carried out in the context of our Austrian establishment. Applicable US federal and state requirements may also apply to particular activities.


Information collected and its use


Depending on your interaction with Rivalyne, we may process:


  • identifiers and contact information, such as your name, business email address and business address;

  • professional or employment-related information, such as your company and role;

  • commercial and transaction information, such as purchases, subscription details and payment status;

  • technical website and checkout information;

  • communications, appointment information and onboarding information that you or your company provide.


The sources, purposes, recipients and retention criteria are described in the corresponding sections of this notice.


State privacy rights


Where a US state privacy law applies to Rivalyne and to the relevant processing, you may have additional rights. Depending on that law, these may include rights to access, correct, delete or obtain a portable copy of personal information; opt out of specified uses or disclosures; and appeal a decision concerning a privacy request.


Some laws also permit an authorised agent to submit requests and prohibit unlawful discrimination for exercising privacy rights.


To submit a request or an applicable appeal, email office@rivalyne.com and describe the request. We will verify and handle it in accordance with the applicable law.


This section does not represent that every US state privacy statute applies to Rivalyne or to every business contact. It does not restrict any rights you have under the EU GDPR or another applicable law.


Commercial email


Where the US CAN-SPAM Act applies, our commercial emails identify the sender, use accurate subject lines, include the required business address and provide a method to opt out of further marketing messages.


Opt-out requests are implemented within the applicable legal period. Necessary service communications, such as invoices and delivery messages for an active subscription, may continue where legally permitted.


Processing outside the United States


Personal data may be processed in Austria and other countries as described in section 15.

Legal and technical references

EU General Data Protection Regulation:
https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng


European Commission standard contractual clauses for international transfers:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng


Austrian Telecommunications Act 2021, section 165:
https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20011678&Artikel=&Paragraf=165&Anlage=&Uebergangsrecht=


Austrian Federal Fiscal Code, section 132:
https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10003940&Artikel=&Paragraf=132&Anlage=&Uebergangsrecht=


Austrian Data Protection Authority:
https://dsb.gv.at/ueber-die-datenschutzbehoerde/kontakt


UK Information Commissioner’s Office:
https://ico.org.uk/


California Attorney General — California Consumer Privacy Act:
https://oag.ca.gov/privacy/ccpa


US Federal Trade Commission — CAN-SPAM guidance:
https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business