How we handle your data.
Written in plain English, structured for UK GDPR and EU GDPR compliance. Last reviewed by us, not generated by a wizard.
Who we are
Rivo Tools is operated by Yeema Holdings LTD (company number 15809333), a company registered in England and Wales. Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom.
We are the data controller for personal data we collect about you when you use Rivo Tools. That means we are responsible for deciding how and why your data is used. You can reach us about anything in this notice at tyrese@yeema.co.
We are not affiliated with Cfx.re, FiveM, Rockstar Games, or Take-Two Interactive. Trademarks and game content remain the property of their respective owners.
The short version
We try not to collect more than we need to run the service. Concretely:
- Sign-in uses a third-party identity service connected to your community account. We never receive that account's password.
- Files you upload are kept in encrypted object storage, processed by our worker, and deleted automatically.
- Payments are handled by a regulated payment processor. We never see your full card number.
- AI tools send the prompt or source image you provide to the selected third-party AI provider to generate an image or 3D model.
- We use cookieless and storage-minimal analytics to understand usage.
- You can ask us to delete everything we hold about you at any time.
What data we collect
We collect a small set of categories:
We do not ask for, and do not knowingly collect, special category data (health, political views, ethnicity, etc.) or government IDs.
Why and how we use it
Under the UK GDPR and EU GDPR, we must have a lawful basis for every use of your personal data. Here's what we do and why:
We do not sell your personal data. We do not run advertising on Rivo Tools, and we do not share your data with advertising networks.
Two things happen automatically on our side: free-tool access pauses while your connected account is not a member of our community server (and restores itself when you rejoin), and clear patterns of free-tier abuse (such as repeated leave/rejoin cycling) can automatically suspend an account. Both are reversible, and you can always ask a human to review an automated action by contacting us. Beyond that, we do not make automated decisions that produce legal or similarly significant effects about you (no automated profiling for hiring, credit, eligibility, etc.).
How long we keep it
The shortest period we can get away with. Where retention is open-ended, you can ask us to delete it earlier (see Your rights).
Service providers
We use a small number of carefully chosen processors to run the service. We describe them by function rather than brand. Each processes data only for the stated purpose and under appropriate contractual terms.
Sign-in, connected-account authentication, and session management.
UK, EEA, and other safeguarded processing regions
Accounts, jobs, subscriptions, realtime application data, and service operation.
UK, EEA, and other safeguarded processing regions
Uploaded files, generated outputs, short-lived download links, and edge delivery.
Global infrastructure with contractual transfer safeguards
Image and 3D generation. Only the prompt or source file needed for the generation you request is sent for processing.
International processing with contractual transfer safeguards
Card payments, subscriptions, receipts, refunds, and fraud prevention. Full card details do not reach our servers.
International processing with regulated and contractual safeguards
Aggregate usage analytics, product improvement, error reporting, and performance monitoring. We do not use these services for advertising.
Primarily UK/EEA, with safeguards where international processing occurs
If the categories or purposes of our processors change, we will update this section. Material changes will be announced in our changelog and, where required, by email.
International transfers
Some of our processors are based outside the UK and the EEA, most commonly in the United States. Where personal data is transferred outside the UK or the EEA, we rely on one or more of the following:
- The European Commission's Standard Contractual Clauses (SCCs).
- The UK International Data Transfer Addendum (IDTA) to the SCCs.
- The EU-US Data Privacy Framework where the receiving organisation is certified, and the UK Extension where applicable.
You can ask us for a copy of the safeguards in place for any specific transfer by emailing tyrese@yeema.co.
Your rights
Under the UK GDPR and EU GDPR, you have the following rights over personal data we hold about you:
- Access. Ask for a copy of the personal data we hold about you.
- Rectification. Ask us to correct data that is inaccurate or incomplete.
- Erasure. Ask us to delete your personal data. We will, unless we are required to keep it (for example, for tax records).
- Restriction. Ask us to limit how we use your data while a dispute is resolved.
- Portability. Ask for a machine-readable export of data you have provided to us.
- Objection. Object to processing we do on the basis of legitimate interests.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Complain. Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or with your local EU supervisory authority. We would appreciate the chance to address your concern first, but it is your right to skip that step.
To exercise any of these rights, email tyrese@yeema.co from the address linked to your account. We will respond within 30 days. We may need to verify your identity before disclosing personal data.
Security
We take security seriously and apply commercially reasonable measures to protect your data:
- TLS for all traffic to and from the site and the worker pool.
- Encryption at rest for uploaded files and database storage.
- Least-privilege access controls for staff and worker tokens.
- Short-lived presigned URLs for downloads.
- Automatic deletion of inputs and outputs on the schedule above.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where required, you.
Children
Rivo Tools is intended for people aged 13 or over, in line with the minimum age for our connected account service. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided data to us, email tyrese@yeema.co and we will delete it.
In some EU jurisdictions, the age of consent for processing under the GDPR is higher than 13. If you live somewhere with a higher age of consent and you are under that age, please have a parent or guardian get in touch.
Changes to this notice
We may update this notice from time to time as the service evolves or the law changes. The date at the top reflects the most recent version. Material changes will be highlighted in our changelog and, where appropriate, notified by email.
Contact and complaints
Privacy questions, data subject requests, or complaints: tyrese@yeema.co.
Post: Yeema Holdings LTD, 128 City Road, London, EC1V 2NX, United Kingdom.
You can also complain to the UK Information Commissioner's Office at ico.org.uk or, if you are based in the EU, to your local supervisory authority.