EU / GDPR

Privacy Policy

This Privacy Policy describes how Rivaler ApS (“Rivaler”, “we”, “us”) processes personal data in connection with the Rivaler.io service (the “Service”).

Last updated: 19 January 2026

1. Controller Information

1.1 Data Controller

Rivaler ApS
Denmark

1.2 Contact Details

Email: [email protected]
Phone: +45 31 48 10 31

1.3 Processor Role

Where Rivaler processes personal data on behalf of customers, such processing is governed by Rivaler’s Data Processing Agreement (DPA).

2. Purpose of Processing

2.1 Service Purpose

Rivaler provides a software-as-a-service platform for internal business intelligence and market analysis.

2.2 Processing Purposes

Personal data is processed solely for the purpose of:

  • Providing and operating the Service
  • Enabling analysis of brands’ and competitors’ publicly available marketing activity
  • Managing user accounts and subscriptions
  • Ensuring security and operational integrity

2.3 Excluded Use

The Service is not intended for:

  • Analysis of individuals
  • Profiling or tracking of natural persons
  • Marketing activation or advertising delivery

3. Categories of Personal Data

3.1 User and Account Data

When users create and use an account, Rivaler processes:

  • Name
  • Business email address

This data is required to provide access to the Service and manage the customer relationship.

3.2 Publicly Available Personal Data in Marketing Material

The Service may incidentally process personal data contained in publicly available marketing material, including:

  • Names, images, or likenesses of individuals (e.g. influencers, spokespersons, or public figures) appearing in advertisements, newsletters, or marketing campaigns

Such data:

  • Is publicly disclosed by the original publisher
  • Appears in a professional and commercial context
  • Is processed only as part of contextual analysis of brand and campaign activity
  • Is not enriched, combined with other datasets, or used for profiling
  • Is not used to make decisions about individual persons

Rivaler’s analyses relate to brands and campaigns, not individuals.

4. Personal Data Not Processed

Rivaler does not process:

  • Special categories of personal data under GDPR Article 9
  • Personal data relating to private individuals’ behavior
  • IP addresses, cookies, device identifiers, or tracking technologies
  • Data from private communications
  • Data behind login walls, paywalls, or access restrictions

5. Legal Basis for Processing

5.1 Performance of a Contract

Processing of account-related data is based on GDPR Article 6(1)(b) and is necessary to provide the Service.

5.2 Legitimate Interest

Incidental processing of publicly available personal data in marketing material is based on GDPR Article 6(1)(f).

Rivaler’s legitimate interest consists of enabling internal business intelligence and market analysis.

Given the public and professional context of the data and the limited scope of processing, this processing is assessed as low risk and does not override the rights or freedoms of data subjects.

6. Use of Personal Data

6.1 Permitted Use

Personal data is used only to:

  • Operate and maintain the Service
  • Provide analytical insights related to marketing activity
  • Manage user access and subscriptions
  • Ensure platform security

6.2 Prohibited Use

Personal data is not used for:

  • Profiling or scoring individuals
  • Automated decision-making affecting individuals
  • Tracking or monitoring online behavior

7. Sharing and Disclosure

7.1 No Sale of Personal Data

Rivaler does not sell or rent personal data.

7.2 Authorized Disclosure

Personal data may be disclosed only to:

  • Authorized employees of Rivaler
  • Service providers acting as data processors (e.g. cloud infrastructure providers, payment providers such as Stripe, Inc., for payment status only)

All processors are subject to appropriate contractual data protection obligations.

8. International Transfers

8.1 Processing Location

Personal data is primarily processed within the EU/EEA.

8.2 Transfers Outside the EU/EEA

Where personal data is transferred outside the EU/EEA, Rivaler ensures appropriate safeguards in accordance with GDPR Chapter V, including Standard Contractual Clauses where applicable.

9. Data Retention

9.1 Retention Periods

Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy.

Account-related data is retained for the duration of the customer relationship and a limited period thereafter for legal or administrative purposes.

Publicly available personal data contained in marketing material is retained only as long as relevant for analytical purposes.

10. Data Subject Rights

10.1 Rights

Where applicable, data subjects have the right to:

  • Request access to their personal data
  • Request rectification or erasure
  • Object to processing based on legitimate interest
  • Request restriction of processing

10.2 Exercising Rights

Requests may be submitted to [email protected].

Where personal data forms part of publicly available marketing material, certain rights may be limited where erasure would undermine the integrity of analytical records or where continued processing is justified by legitimate interest.

11. Security Measures

Rivaler implements appropriate technical and organizational measures to protect personal data, including:

  • Access controls
  • Encryption in transit
  • Role-based access for internal personnel

Security measures are proportionate to the limited scope and low-risk nature of the processing.

12. Changes to This Privacy Policy

Rivaler may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by other appropriate means. Continued use of the Service constitutes acceptance of the updated Privacy Policy.

13. Contact

Questions regarding this Privacy Policy or Rivaler’s data processing practices may be directed to:

Rivaler ApS
Email: [email protected]
Phone: +45 31 48 10 31