Privacy Policy
How Nyotta AI collects, uses, stores, and deletes information across our website and products, including the Nyotta Supplier Intelligence application for Microsoft Teams.
Effective July 24, 2026
1. Scope
This policy applies to Rive AI Inc., doing business as Nyotta AI (“Nyotta,” “we,” “us”), and covers our website at nyotta.ai together with the software products and applications we make available to customers, including the Nyotta Supplier Intelligence application for Microsoft Teams (collectively, the “Services”).
2. Controller and processor roles
Most of our customers are businesses. When we handle information that a business customer submits or authorizes us to access through the Services, that customer determines the purposes of the processing and acts as the data controller. Nyotta acts as a processor and handles that information under the customer’s instructions and the terms of the agreement between us. Where a data processing agreement is in place, that agreement governs our handling of customer data and takes precedence over this policy.
When we handle information about visitors to our website, or about individuals who contact us directly, we act as the controller for that information.
3. Information we collect
Account and sign-in information. When you sign in to a Nyotta application using Microsoft Entra ID, we receive your name, email address, and identifiers for your user account and your organization’s tenant. We use this to authenticate you and to associate your activity with your organization’s workspace.
Information you or your organization submit. The Services accept documents and structured data that you or your organization provide, which may include requests for quotation, engineering drawings, specifications, bills of materials, and related commercial information. We process this content to produce the outputs you request.
Usage and log information. We record events such as sign-ins, requests to the Services, feature usage, timestamps, and technical details about the device and browser used to reach us. We use this to operate, secure, troubleshoot, and improve the Services.
Information you send us directly. If you contact us, request a demonstration, or subscribe to updates, we collect the information you choose to provide, such as your name, email address, employer, and the content of your message.
Website analytics. Our website uses third-party analytics and visitor identification tooling that may set cookies or similar identifiers and may record IP address and page activity. This tooling runs on our marketing website and is not part of the Nyotta Supplier Intelligence application for Microsoft Teams.
4. How we use information
- To provide, operate, and maintain the Services
- To authenticate users and administer access
- To generate the outputs a user requests
- To secure the Services, investigate suspected misuse, and maintain audit records
- To diagnose problems and improve performance and reliability
- To communicate with you about the Services, including service and security notices
- To meet legal, regulatory, and contractual obligations
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use customer content to train models that are made available to other customers.
5. How information is stored and secured
Customer data is hosted with established cloud infrastructure providers. The controls we apply include:
- Encryption of data in transit using TLS
- Encryption of data at rest
- Logical separation of each customer’s data from that of other customers
- Role-based access controls, with multi-factor authentication required for administrative access
- Audit logging of access to customer data
- Periodic review of access rights and periodic security testing
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We maintain procedures to investigate and respond to suspected security incidents and to notify affected customers as required by applicable law and by our agreements with them.
6. Retention and deletion
We retain customer content for as long as the customer’s account is active and we are providing the Services to them.
- Deletion on request. A customer may request deletion of their content by writing to privacy@nyotta.ai. We complete deletion from active production systems within 90 days of a verified request.
- Deletion on termination. Following termination of a customer agreement, we delete customer content from active production systems within 90 days, unless the customer asks us to return or retain it, or we are required to keep it by law.
- Backups. Copies of deleted content may persist in encrypted backups for a period after deletion. Backups are cycled so that deleted content is removed within 180 days of its deletion from production systems.
- Logs and business records. We retain usage and audit logs, and business records such as invoices and correspondence, for longer periods where we need them for security, dispute resolution, accounting, or legal compliance.
Where we act as a processor, we follow the customer’s documented instructions on retention and deletion, and the applicable data processing agreement controls.
7. When we disclose information
- Service providers. We use vendors for cloud hosting, infrastructure, and related functions. They are bound by contract to handle information only as needed to provide services to us. A current list of sub-processors is available to customers on request at privacy@nyotta.ai.
- At your direction. Where you or your organization ask us to share information or to connect the Services to another system.
- Legal and safety. Where required by law, legal process, or a governmental request, or where necessary to establish or defend legal claims.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy or a successor policy.
8. International transfers
We operate from the United States, and our infrastructure providers may process information in the United States and in other locations. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on transfer mechanisms recognized under applicable law, such as Standard Contractual Clauses. Customers may request details at privacy@nyotta.ai.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of personal information about you, to object to or restrict certain processing, and to withdraw consent. You may also have the right to appeal a decision or to lodge a complaint with a supervisory authority.
If your information was provided to us by an organization using the Services, please direct your request to that organization, and we will support them in responding. For information we hold as a controller, contact privacy@nyotta.ai. We may need to verify your identity before acting on a request.
10. Children
The Services are business tools intended for use by organizations. They are not directed to children, and we do not knowingly collect personal information from children.
11. Changes to this policy
We may update this policy as the Services change or as legal requirements evolve. The effective date shown at the top of this page reflects the most recent revision. Where a change is material, we will provide notice through the Services or by contacting customers directly.
12. Contact
Privacy questions and requests: privacy@nyotta.ai
Security matters: security@nyotta.ai
General support: support@nyotta.ai
Rive AI Inc., doing business as Nyotta AI