Privacy Policy

Understand how Recivo collects, uses, and protects your personal data. Review our privacy practices and your rights regarding your information.

Last updated: August 2025

General Information

This privacy policy ("Policy") applies to Recivo known called as Recivo and was last updated in August 2025. We may change or update this policy at any time, and the same will be updated here. If you are a Recivo user or customer, we shall notify the changes or updates either by sending an e-mail or other means to keep such notices credible. We sincerely believe that you should know how your personal data is collected from you, the purposes for which such data is used, and that you should have the ability to make informed decisions about what, you want to share with us. Therefore we have tried to maintain this Policy in the most simple and straightforward manner as possible. This Policy describes in detail all the information we collect, why and how we use it and what choices you have. To determine the contours of this Information: While we would strongly advise you to read this Policy in full, the following summary will give you a snapshot of the salient points covered herein.

This Policy details the critical aspects governing your personal data relationship with Yikes Technology Pvt. Ltd. and its subsidiaries (collectively Recivo).

Your personal data relationship with Recivo varies based on the capacity in which you interact with us/avail of our products and solutions ("Services"). You could be a Visitor on our Website (referred to as "Website") or any pages thereof ("Visitor"), (ii) a person/entity availing of our services ("Customer"), or (iii) an employee/agent/representative/appointee of a customer who uses the said Services ("User").

Based on whether you are a Visitor, Customer or User, the type of data we collect and the purposes for which we use it will differ and this Policy details such variations.

This Policy is a part of and should be read in conjunction with our Terms of Use available at https://www.recivo.ai/terms-of-use.

This Policy will apply to data collected by Recivo on behalf of its Customers (in addition to its own data collection). For any privacy queries or concerns with this Policy, please contact our Grievance Officer (refer Section 12). If you do not agree with the Policy, we would advise you to not use the Website or the Recivo App/services(s)/platform(s)("App").


Information We Collect and How We Use It

What Data We May Collect Visitor Customer User
What Data We May Collect 1. How you behave on the Website (what pages you land on, how much time you spend etc).
2. Information we use to access the Website, like your device (model, operating system, etc).
3. Cookies and Web Beacons data.
4. Name and e-mail.
1. The name and e-mail of your representative who signs up for a Service on your behalf.
2. Billing information including Payment Mode information to help facilitate payments and to detect fraud and facilitate payments for our Services.
1. Your name, e-mail.
2. How you behave in the relevant product environment and its features.
3. What device you use to access the technology and its data (model, operating system, etc).
4. Cookies and Web Beacon data.
How and Why We Use It We use this information to analyse and identify your behaviour and to enhance the experience you have with the Website. If you submit your details and give us your consent, we may send you newsletters and e-mails to market any products and services we may provide. We collect this data in order to help facilitate the provision of our Services. We also use this data to enable you to make payments for our Services. We use a third-party service provider to manage payment processing. This service provider is not permitted to store, retain, or use information you provide to them for the sole purpose of payment processing on our behalf. In the event you report an issue with a Service, we may also send you newsletters and e-mails to market other products and services we may provide. We collect this data in order to facilitate provision of our Services. We will occasionally send you e-mails regarding changes or updates to the Service that you are using. In the event you report an issue with a Service, we may also sometimes record your device (for a limited time period) to help us better understand how to address the issue. If you give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.

Your Rights & Preferences as a Data Subject

Subject to the GDPR and applicable laws/ limitations, the rights afforded to you as a data subject are:

RIGHT TO BE INFORMED: You have a right to be informed about the manner in which any of your personal data is collected or used which we endeavored to do by way of this Policy.

RIGHT OF ACCESS: You have a right to access the personal data you have provided by requesting us to provide you with the same.

RIGHT TO RECTIFICATION: You have a right to request us to correct or supplement your personal data if it is inaccurate or incomplete.

RIGHT TO ERASURE: You have a right to request us to delete your personal data.

RIGHT TO REJECT: You have a right to request us to temporarily or permanently stop processing all or some of your personal data.

RIGHT TO OBJECT: You have a right, at any time, to object to our processing of your personal data under certain circumstances. You have an absolute right to object to us processing your personal data for the purposes of direct marketing.

RIGHT TO DATA PORTABILITY: You have a right to request us to provide you with a copy of data in electronic format and you can transmit that data for use in another service if the processing is based on consent or required for a contract.

RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING: You have a right not to be subject to a decision based solely on automated decision-making, including profiling.

In case you want to exercise the rights set out above you can contact our DATA PROTECTION OFFICER whose details are set out below. The data provided by you as a Visitor or when you sign up as a Customer / User or register for our Services will be processed by us for the purposes of rendering Services to you or otherwise unless you separately withdraw consent for the same. You specifically consent to the processing by us of your personal data as set out herein. You can at any time seek your consent for using the App by sending us an email containing your request. Additionally, we may process your data to serve legitimate interests. Accordingly, the grounds on which we may engage in processing are as follows:

Nature of Data Grounds
Visitor Data • Consent
• Performance of a Contract
• Legitimate Interest
Account Registration Data • Compliance with applicable laws
• Legitimate Interest
Service Usage Data • Performance of a Contract
• Legitimate Interest
Data for Marketing our Services • Consent
• Legitimate Interest

Your Rights Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011

Right to be informed and give consent: Before Recivo collects any of your personal data, we will clearly explain what information we need, why we need it, and how we will use it. We will only collect your personal data with your explicit consent.

The right to access your data: You have the right to request access to the personal information Recivo holds about you. This includes the ability to review and verify its accuracy and completeness.

The right to correct mistakes: If you find any incorrect information in your data held by Recivo, you have the right to request corrections. We will take reasonable steps to update your information promptly upon verification and receipt of your request.

The right to withdraw consent: You can withdraw your consent for Recivo to process your sensitive personal data at any time. Once you withdraw your consent, we will stop using your data for the purpose originally agreed upon, unless there's a legal reason for continued processing (like a court order).

To exercise these rights, please contact our Grievance Officer (details in Section 12).


Tools Used by Our Customers

Our customers may use various third-party technologies and integrate with our App. If you do, you agree and acknowledge that it is your sole obligation to inform your stakeholders about any data you collect by using such technologies and the policies by which such data may be used.

Transfer of Information: In order for us to facilitate our operations, we may transfer and store the data we collect and process in accordance with this Policy in locations outside of India where we or our third-party service providers operate. Further, in the ordinary course of business, we may employ other companies and people to assist in providing certain components of our Services in compliance with this Privacy Policy. To do so, we may need to share your personal data with them. Where transfers are effected out of situations deemed adequate by the European Commission, we shall enter into appropriate Data Protection Agreements with such providers. In all such cases, we will contractually require our sub-processors to ensure appropriate confidentiality and security of the data they process on our behalf. Some of the third parties that we work with for supporting our processing activities and whom we may sub-contract for processing activities include: data analysts, marketing assistants, processing credit / payment processors etc.

Compelled Disclosure: In addition to the purposes set out in the Policy, we may disclose or are obligated to disclose your personal data (a) if it is required by applicable law or regulation, (b) to respond to a governmental request, (c) to enforce our applicable policies, (d) to protect our operations or those of any of our affiliates, (e) to protect the rights, privacy, property or safety of Recivo or others, or (f) to allow us to pursue available remedies or limit the damages that we may sustain. We may need to disclose your data to third parties if such disclosure is required in connection with legal proceedings brought against our legal rights.


Data Protection

We implement industry standard technical and organizational measures by using a variety of security technologies and procedures to help protect your personal data from unauthorized access, use, or disclosure. The technical and physical safeguards we implement include, but are not limited to, storage of your personal information on secure computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. Recivo is certified to ISO 27001 standards and operates and maintains an Information Security Management System (ISMS). Our commitment to ISO 27001 ensures that we follow rigorous security practices and continuously work to minimize the risk of data breaches and unauthorized access to your personal data. In accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we adhere to the following reasonable security practices and procedures to protect your personal data:

Security Control Description
Access Control We ensure that access to personal data is granted to authorized personnel on a need-to-know basis, using role-based access controls and authentication methods.
Data Encryption Sensitive personal data is encrypted both in transit and at rest using strong encryption methods such as AES-256.
Network Security We employ secure network architecture, including firewalls and intrusion detection systems, to safeguard our infrastructure.
Regular Audits We conduct regular security audits and assessments to identify potential vulnerabilities and ensure compliance with our security policies.
Incident Management We have established protocols for managing and responding to security incidents, including data breaches, to mitigate any potential impact on your personal data.
Employee Training We educate and train our employees to ensure they are aware of and comply with our security policies and procedures.
Third-Party Management We ensure that any third-party service providers who handle personal data on our behalf adhere to equivalent security standards set by us.
Physical and Environmental Security We have implemented robust physical security controls to protect our data centres and other facilities from unauthorised access, damage, and interference.
Business Continuity Management We have developed and tested business continuity plans to ensure the availability of critical business functions and systems in the event of a disruption.
Risk Assessment and Treatment We conduct regular risk assessments to identify potential security threats and vulnerabilities, and implement appropriate risk treatment plans to mitigate identified risks.
Audit and Compliance We perform regular internal and external audits to ensure compliance with ISO 27001 standards and continuously improve our ISMS.

EMAIL: hello@recivo.ai