RivetMoth / Privacy and data handling

Clear boundaries for useful work.

This plain-English guide explains what happens when you share an AI Business Audit and how data boundaries are handled from the first conversation onwards.

At a glance
  • Only customer-provided or explicitly approved sources are in scope.
  • Tool names do not create automatic access.
  • The preview is directional, not evidence or an automated decision.
  • People remain responsible for checking and approving use.
  • Retention arrangements are agreed for each engagement.

What happens when you submit an audit

The public audit form asks for your company name, company context, repetitive work, bottlenecks, tools, data concerns, and estimated impact. When you submit it, those answers are saved so RivetMoth can review the request and understand where work is getting stuck.

The directional first read uses the bottleneck and estimated-impact text you submitted. It is an AI-backed starting point, not verified evidence, a promise of savings, or an automated decision.

Which data sources may be used

For an engagement, we may use only data sources that you provide or explicitly approve for that work. Naming a tool in the audit does not give RivetMoth automatic access, credentials, a connection, or permission to use it.

The source, purpose, scope, and access arrangements should be agreed before any engagement work uses business data. You can start the audit with descriptions rather than sharing sensitive records or credentials.

UK GDPR-aware boundaries

We consider data minimisation, purpose, access, retention, and human oversight as part of responsible work with UK businesses. The audit preview does not decide whether a proposed workflow meets your obligations.

This page is general information, not legal advice, a compliance approval, or a claim of legal certification. You remain responsible for getting the advice and permissions appropriate to your organisation and the data involved.

People remain responsible for approvals

A person should check the relevant context, data, and proposed outcome before an automation is approved or put into use. RivetMoth’s preview is there to help frame a conversation; it does not approve a workflow, reject one, or make decisions about people.

Any implementation should have a clear human owner for checking outputs, handling exceptions, and deciding when an action is safe to take.

Retention and deletion expectations

We aim to keep audit submissions and any engagement information only for as long as it is needed for the purpose agreed with you, subject to operational, contractual, or legal requirements.

Retention and deletion arrangements are agreed per engagement. This page does not promise a fixed deletion date; ask us to confirm the arrangement that applies to your work.

What we ask from customers

Please provide information that is accurate and relevant to the question you want to explore. Do not submit credentials, or personal or sensitive information that is not needed for the initial audit.

You are responsible for making sure you have permission to share the information you provide, identifying constraints we should understand, reviewing proposed outputs, and approving any data source or action before it is used.

What this page is not

It is not legal advice, a certification, a guarantee of an outcome, or permission to connect an external system automatically. It describes the boundaries we intend to discuss; the details for a specific engagement should be agreed with you.

If you want to discuss an audit or its data boundaries, return to the audit form.