RIVEN
Sign inCreate account
Gaming ServersConsultancyLicensingContact

Legal information

Privacy policy

What data we process, why, for how long, who it is shared with, and how to exercise your rights.

1. Data controller

  • Controller: Riven Software
  • Data protection contact: privacidad@riven-software.com

2. What data we process

We process only what is needed to provide the service:

  • Account data: name, email address and password, stored hashed with a key derivation function, never in plain text.
  • Order data: services purchased, chosen configuration, amount, date and order status.
  • Service technical data: identifiers of the servers provisioned for you and their expiry date.
  • Billing and payment data: handled entirely by Stripe. We never store or see your card number.

3. Purposes and legal basis

We do not send marketing communications without your prior consent, and if we ever do you will be able to withdraw it at any time in one click.

  • Providing the contracted service and managing your account: performance of a contract (art. 6(1)(b) GDPR).
  • Charging for services and keeping accounts: contract performance and legal obligations (art. 6(1)(b) and 6(1)(c) GDPR).
  • Handling support enquiries: contract performance or legitimate interest in replying to you (art. 6(1)(f) GDPR).
  • Service security and fraud prevention: legitimate interest (art. 6(1)(f) GDPR).

4. Retention

Account data is kept while the account remains active. Order and billing data is kept for the periods required by commercial and tax law (generally six years), even if you close your account.

After those periods, data is deleted or anonymised.

5. Who it is shared with

We do not sell or transfer your data. Only the providers needed to deliver the service have access, each under a data processing agreement:

  • Stripe Payments Europe, Ltd.: payment processing.
  • Cloudflare, Inc.: content delivery and protection of the website against attacks.
  • Public authorities where we are legally required to provide it.

6. International transfers

Some of the providers above may process data outside the European Economic Área. Where that happens, the transfer relies on the standard contractual clauses approved by the European Commission or on an adequacy decisión.

7. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to privacidad@riven-software.com from the address linked to your account, or otherwise proving your identity.

If you believe your request was not handled properly, you may complain to the Spanish Data Protection Agency (www.aepd.es).

8. Security

The site is served entirely over HTTPS, passwords are stored hashed, and access to production systems is restricted to staff who need it. No system is infallible, but we handle any security incident with the diligence and notification deadlines the GDPR requires.

9. Minors

The services are intended for adults. We do not knowingly collect data from minors; if we find an account belonging to a minor without guardian authorisation, we will delete it.

Join our Discord