GDPR compliance

Last updated: June 2026

Riff complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU GDPR. This page summarises our approach.

Lawful bases for processing

Contract. Processing necessary to provide you with the Riff service (matching, messaging, verification).

Legitimate interests. Platform safety, fraud prevention, and service improvement — balanced against your privacy rights.

Consent. Where required (e.g. optional analytics), we ask for explicit, informed consent that can be withdrawn at any time.

Your rights

You have the right to: access your personal data (Article 15), rectify inaccuracies (Article 16), request erasure (Article 17, "right to be forgotten"), restrict processing (Article 18), data portability (Article 20), and object to processing (Article 21).

To exercise any right, email privacy@riff-app.co.uk. We respond within 30 days. If you are unsatisfied with our response, you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Data storage and transfers

Your data is stored on servers in the European Union (Railway, Ireland). Verification data is processed by Veriff (EU data centre, Republic of Ireland). SMS verification is processed by Twilio (US, with EU Standard Contractual Clauses). Payments are processed by Stripe (certified under the EU-US Data Privacy Framework).

Data Protection Officer

For data protection enquiries: privacy@riff-app.co.uk. Riff App Ltd, Woking, England, United Kingdom.

Data deletion

You can delete your account and all associated data from the Settings screen in the app. Alternatively, email privacy@riff-app.co.uk and we will process the deletion within 30 days. Deletion is permanent and irreversible.