Riff Financial Ltd Last updated – July 23, 2026

Privacy Notice

This Privacy Notice explains how Riff Financial Ltd (“we”, “us”, “our”) collects, uses, and shares personal information when you use our services, including our website at riffagent.ai. Questions can be sent to help@riff-fin.com.

01 What information do we collect?

Personal information you disclose to us

In short: we collect personal information that you voluntarily provide to us.

We collect personal information you provide when you register on the Services, express interest in our products, participate in activities on the Services, or otherwise contact us. Depending on your interactions, this may include:

  • Names
  • Email addresses
  • Usernames
  • Passwords

Sensitive information. We do not process sensitive information.

All personal information you provide must be true, complete, and accurate – please let us know of any changes.

Information automatically collected

In short: some information – such as your IP address and device characteristics – is collected automatically when you use our Services.

This information doesn’t reveal your specific identity but may include device and usage data: IP address, browser and device characteristics, operating system, language preference, referring URLs, and general information about how and when you use the Services. It’s used primarily to keep the Services secure and operational, and for internal analytics.

We also collect information through cookies and similar technologies – see our Cookie Notice: link not yet added.

This includes:

  • Log and usage data – diagnostic, usage and performance data our servers record automatically, including timestamps, pages viewed, searches, and error reports.
  • Device data – information about the computer, phone or tablet used to access the Services, such as IP address, hardware model, operating system, and ISP/carrier.
  • Location data – general or precise location, typically derived from IP address. You can opt out via your device’s location settings, though some features may stop working.

02 How do we process your information?

In short: to provide, improve and administer the Services, communicate with you, prevent fraud, comply with law – and, with your consent, for other purposes.
  • Account creation & authentication – to let you create and log in to your account and keep it in working order.
  • Administrative communication – details about our products, changes to terms and policies, and similar information.
  • Order fulfilment – processing orders, payments, returns and exchanges made through the Services.
  • Protecting vital interests – when necessary to prevent harm to an individual.

03 What legal bases do we rely on?

In short: we only process personal information when we have a valid legal basis under applicable law.

Under GDPR and UK GDPR, we rely on:

  • Consent – which you can withdraw at any time.
  • Performance of a contract – to fulfil our obligations to you or at your request before entering into a contract.
  • Legal obligations – e.g. cooperating with law enforcement or regulators, or defending legal rights.
  • Vital interests – to protect you or a third party from harm.

We are generally the “data controller” of the personal information described in this notice. Where we act as a “data processor” on behalf of a customer, this notice does not apply – refer to that customer’s own privacy policy.

04 When and with whom do we share information?

In short: only in specific situations, and with specific categories of third parties.

We share data with vendors, consultants and service providers who perform work on our behalf and require access to do so. Contracts are in place to ensure they only use the data as instructed, don’t share it further, and retain it only as long as we require.

Categories of third parties we may share with:

  • Ad networks
  • Affiliate marketing programs

We may also share information for business transfers – e.g. in connection with a merger, acquisition, financing, or sale of company assets.

05 Cookies and other tracking technologies

In short: we may use cookies and similar technologies to collect and store information.

Cookies and technologies such as web beacons and pixels help maintain security, prevent crashes, fix bugs, remember preferences, and support core functionality. We also allow third parties to use tracking technologies on our Services for analytics and advertising purposes.

Full detail is set out in our Cookie Notice: link not yet added.

06 Do we offer AI-based products?

In short: yes – we offer features powered by artificial intelligence and machine learning.

We provide these AI Products through third-party AI Service Providers, including Anthropic. Your input, output, and related personal information are shared with and processed by these providers to enable your use of the AI Products. You must not use AI Products in a way that violates any AI Service Provider’s terms or policies.

Our AI Products are used for:

  • AI automation
  • AI deployment
  • AI insights

All personal information processed via AI Products is handled per this Privacy Notice and our agreements with third parties. To opt out, contact us using the details in Section 13.

07 How long do we keep your information?

In short: only as long as necessary for the purposes set out in this notice, unless a longer period is legally required.

No purpose in this notice requires us to keep personal information for longer than 24 months past termination of your account. Once there is no ongoing legitimate need, we delete or anonymise the data, or – where that isn’t possible (e.g. backup archives) – securely isolate it until deletion is possible.

08 How do we keep your information safe?

In short: through a system of organisational and technical security measures.

Despite reasonable safeguards, no transmission over the internet or storage system can be guaranteed 100% secure. Transmission of information to and from the Services is at your own risk; please only access the Services within a secure environment.

09 Do we collect information from minors?

In short: we do not knowingly collect data from, or market to, children under 18.

By using the Services you represent that you are at least 18, or the parent/guardian of a minor consenting to their use. If we learn we’ve collected data from someone under 18, we will deactivate the account and delete the data. Flag this to us at help@riff-fin.com.

10 What are your privacy rights?

In short: in the EEA, UK and Switzerland, you have enhanced rights over your personal information.

These may include the right to access and obtain a copy of your data, request correction or erasure, restrict processing, request portability, and object to automated decision-making. Requests can be made using the contact details in Section 13.

UK complaints

If you’re in the UK and unhappy with how we’ve handled your information, you can complain to us directly – this is in addition to your rights under UK GDPR and the Data Protection Act 2018.

We’ll acknowledge your complaint within 30 days, investigate without undue delay, and keep you informed of progress and outcome. If unresolved, you can escalate to the Information Commissioner’s Office:

Website: ico.org.uk/make-a-complaint

Helpline: 0303 123 1113

Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

EEA residents may contact their Member State data protection authority. Swiss residents may contact the Federal Data Protection and Information Commissioner.

Withdrawing consent

Where we rely on your consent, you may withdraw it at any time via the contact details in Section 13. This won’t affect the lawfulness of processing prior to withdrawal.

Marketing opt-out

Unsubscribe via the link in any marketing email, or by contacting us – you’ll still receive necessary service-related messages.

Account information

Log in to your account settings to review or update your details. On request to terminate your account, we deactivate/delete it from active databases, retaining only what’s needed to prevent fraud, resolve disputes, or meet legal obligations.

11 Controls for Do-Not-Track features

No uniform standard for Do-Not-Track (DNT) signals currently exists, so we do not respond to DNT browser signals. If a standard is adopted that we must follow, we’ll update this notice accordingly.

12 Do we make updates to this notice?

In short: yes, as necessary to stay compliant with relevant laws.

Updates are marked with a revised date at the top of this notice. Material changes may be communicated via a prominent notice or direct notification.

13 How can you contact us?

Riff Financial Ltd

Arquen House, Spicer Street

St. Albans, AL3 4PQ, United Kingdom

Email: help@riff-fin.com

UK residents: we are the data controller of your personal information. Our appointed UK representative is Oliver Butcher, reachable at oliver.butcher@riff-fin.com or by post to the address above.

14 Review, update, or delete your data

Depending on applicable law, you may have the right to access, correct, or delete the personal information we hold, and to withdraw consent to processing. To exercise these rights, submit a data subject access request.