
Privacy Notice
- Introduction
This Privacy Notice (together with any documents referred to in it) explains how RIVA Partnership Ltd (“RIVA”, “we”, “us” or “our”) collects, uses, stores and shares personal data and your rights in relation to that data. It applies to personal data we collect when you use our website, engage our services, contact us, or when we contact you as a prospective client, supplier or partner. RIVA is committed to the protection and promotion of individuals’ privacy.Where applicable, this Privacy Notice should be read in conjunction with our: (i) website terms of use which can be accessed here https://rivapartnership.co.uk/terms-of-use/; and (ii) our Cookie Policy which can be accessed here https://rivapartnership.co.uk/cookie-policy-uk/. - What is personal data ?
In simple terms, personal data is any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.Personal data is defined by the UK GDPR and the Data Protection Act 2018 (collectively ‘Data Protection Laws’) as “any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier”.For the purposes of Data Protection Laws we are the ‘data controller’ of your personal data. - Who we are and our contact details
We are RIVA Partnership Ltd registered with company number 08308143 whose registered offices are at Hone’s Business Park, 1 Waverley Lane, Farnham, Surrey GU9 8BB. Our VAT number is 158835176.
Our website is located at https://rivapartnership.co.uk/
For enquiries about this notice or your rights, contact our Data Protection Officer:- By email at privacy@rivapartnership.co.uk;
- By telephone on 01252 977017; or
- By post to our registered office above.
- Scope of this notice
This notice applies to personal data we process about:- existing clients and their staff;
- prospective clients and their staff (including contacts made at events or via public sources);
- suppliers, their staff and subcontractors;
- users of our website and services;
- a person or business who through research and other data sources in the public domain, we consider that you may be interested in our services; and
- other business contacts we interact with for commercial purposes.
- Information we collect
We collect and process the following categories of personal data:
A. Information you provide directly:- identity and business details: name, job title, employer, business address;
- contact details: business email, work telephone;
- service-related information: contract and procurement details, project documents;
- recruitment data: CVs, interview notes, employment references, right to work evidence;
- meeting and event registrations and communications.
B. Information we collect automatically:
- technical and usage data when you visit our website: IP address, browser and device information, referral pages, pages viewed and time spent; and
- cookies and analytics data (please see our Cookie Policy https://rivapartnership.co.uk/cookie-policy-uk/).
C. Information from third parties:
- data from public sources and purchased/commercial contact lists;
- data provided by partner organisations, service providers and subcontractors;
- information from background checks where required (e.g., DBS numbers for contractor staff where lawfully permitted).
We do not collect special category personal data unless explicitly required and lawful (for example, DBS details where necessary for safeguarding).
- How and why we use your personal data (purposes & legal bases)
We process personal data for the following purposes and for the stated lawful bases:- To perform contracts and provide services (Lawful basis: performance of a contract): delivering procurement consultancy, tender management, training and related services.
- To manage commercial relationships (Legitimate interests): client and supplier relationship management, invoicing, billing and contract administration.
- For compliance and legal obligations (Legal obligation): safeguarding checks, tax, statutory reporting and regulatory compliance.
- For recruitment and HR administration (Performance of contract / Legal obligation): processing applications and managing employment records.
- For marketing and business development (Legitimate interests or Consent): sending relevant service updates, training and invitations to events. We will rely on consent where required by law for direct marketing; you may unsubscribe at any time.
- For website administration, security and analytics (Legitimate interests): detecting and preventing fraud, improving website performance and user experience.
We will not process personal data for purposes incompatible with the purposes stated above without notifying you.
- Cookies and tracking technologies
We use cookies and similar technologies on our websites. Non-essential cookies require consent. Please see our Cookie Policy [insert link] for detailed information and how to manage preferences. - Data sharing and third parties
We may share personal data with:- clients, suppliers and subcontractors where necessary to deliver services;
- service providers such as IT hosts, CRM providers, analytics and email platforms;
- professional advisers, insurers and auditors where appropriate;
- regulators, law enforcement or authorized third parties when required by law; and
- current or potential providers of finance;
- potential purchasers or successors in the event of a business sale or reorganisation.
- Data security
We implement technical and organisational measures to protect personal data, including access controls, encryption (where appropriate), secure backups, staff training and supplier due diligence. While we take reasonable steps to protect data, no system can be guaranteed entirely secure. - Data retention
We retain personal data for as long as necessary for the purposes set out in this notice and to meet insurance, legal, tax and regulatory requirements. Typical retention periods:- contractual and financial records — minimum 6 years after end of contract;
- recruitment records — up to 6 months after application;
- client contact details — retained while the business relationship exists and for a reasonable period afterwards.
In some circumstances you can ask us to delete your data: see your legal rights in paragraph 10 below for further information.
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
- Your rights
Subject to legal limits, you have the right to:- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure in certain circumstances;
- request restriction of processing;
- object to processing (including direct marketing);
- request portability of data you have provided where applicable; and
- withdraw consent (where processing is based on consent).
To exercise your rights, please contact us at privacy@rivapartnership.co.uk. We will respond within statutory timeframes. For legitimate requests the time limit is one month although this can be extended in some cases. We will advise you if this is the case and keep you updated.).
Whilst there is not normally a fee associated with getting access to your personal data (or to exercise any other right) we may charge a fee if your request is clearly unfounded, repetitive or excessive.
We may need specific information from you to help us confirm your identity and verify your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
You also have the right to lodge a complaint with the Information Commissioner’s Office (www.ico.org.uk).
- Marketing and opting out
We send marketing communications only where we have a legitimate interest to do so or your consent. You can opt out at any time by contacting privacy@rivapartnership.co.uk. - Children and safeguarding
Our services are primarily provided to organisations. Where we process data relating to children (e.g., in safeguarding contexts), we will only do so where necessary, lawfully and with appropriate safeguards. Contractor staff working with schools will be subject to DBS and other safeguarding checks as required. - Links to other websites
Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit. - Transfers outside of the UK
Whilst we do not currently transfer personal data outside of the UK, if we do so in the future we will ensure a similar degree of protection is afforded to it by ensuring appropriate safeguards are implemented, for example data is transferred to countries deemed to provide an adequate level of protection. - Contact and complaints
For all enquiries relating to your data you should contact us:- By email to the Data Protection Officer: privacy@rivapartnership.co.uk
- By post : RIVA Partnership, Hone’s Business Park, 1 Waverley Lane, Farnham, Surrey GU9 8BB
If you have concerns about our handling of your data please contact us in the first instance so that we can try and make things right. You also have the right to complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk.
- Changes to this notice
We may update this notice periodically. We will publish changes on our website and update the “Last updated” date.
Last Updated
28th November 2025