Privacy
Privacy Notice
This notice explains how Riera Studio handles personal data when people visit the website, create an account, use a company workspace, purchase a subscription, contact support or exercise data protection rights.
Riera Studio acts as controller for account, billing, security, support and product administration data. For personal data a customer enters into its private workspace, the customer is normally the controller and Riera Studio acts as processor under the Data Processing Addendum.
1. Who is responsible
The controller for Riera Studio account administration, service delivery, billing, security, support and website operations is the legal operator identified at the end of this notice.
Riera Studio does not currently publish an EU representative. EU/EEA onboarding that legally requires an Article 27 representative must not be completed until representative details are added here.
2. Personal data we handle
Account and identity data: name, email address, authentication identifiers, company membership, role, account status and language preference.
Company and workspace data: business details, team members, clients, contacts, venues, events, inventory, quotes, invoices, payments, documents, notes, imports and exports entered by authorised workspace users.
Billing data: plan, subscription state, Stripe customer and subscription references, payment status, billing contact and transaction records. Full card details are handled by Stripe and are not stored by Riera Studio.
Support and rights data: messages, complaint details, verification information, correspondence, request status and outcome.
Security and technical data: session identifiers, login events, IP and request metadata available in provider logs, device/browser information, audit events, error information and abuse-prevention signals.
Optional analytics data: page path, product identifier and anonymous usage events only after analytics consent. Form contents, document contents and customer records are not intentionally sent to analytics providers.
3. Purposes and legal bases
Contract and pre-contract steps: create accounts, provide the workspace, generate requested documents, process subscriptions, provide support and manage cancellation or closure.
Legal obligations: maintain records required for tax, accounting, fraud prevention, regulatory requests and data protection rights or complaints.
Legitimate interests: secure the service, prevent abuse, diagnose faults, maintain audit trails, improve reliability, administer business relationships and establish or defend legal claims. These interests are assessed against the rights of affected people.
Consent: optional analytics or any future non-essential storage. Consent can be refused or withdrawn without losing essential service access.
Riera Studio does not sell personal data and does not use workspace data for third-party advertising.
4. Customer workspace data and instructions
A business customer decides why and how it uses personal data about its clients, suppliers, crew and contacts. That customer must provide its own privacy information and have a lawful basis for entering the data into Riera Studio.
Riera Studio processes workspace data only to provide, secure, support and maintain the service, as documented in the Terms and Data Processing Addendum, unless law requires otherwise.
Authorised platform personnel may access workspace data only where necessary for support, security, incident investigation, legal compliance or service administration, subject to confidentiality and access controls.
5. Recipients and subprocessors
Personal data may be processed by infrastructure, database, authentication, payment, analytics and email providers used to operate Riera Studio. The current provider list and purpose of each provider is maintained on the Subprocessors page.
Data may also be disclosed to professional advisers, insurers, regulators, courts, law enforcement or prospective business transferees where there is a lawful and proportionate reason.
Workspace owners and authorised members can access data according to their role. Customers are responsible for managing their own membership and permissions.
6. International transfers
Providers may process data outside the United Kingdom or European Economic Area. Where a restricted transfer occurs, Riera Studio relies on an applicable adequacy decision, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, or another lawful safeguard supplied by the provider.
Transfer arrangements are reviewed as part of provider management. Customers can request relevant transfer information through the data rights channel, subject to confidentiality and security limits.
7. Retention
Account and workspace data is kept while the account or customer contract remains active and for a limited closure period needed to complete export, deletion, dispute handling and recovery processes.
Customer workspace data is deleted or returned following verified closure instructions, subject to backups and legal holds. Deleted backup data is placed beyond normal use and expires through the documented backup cycle.
Billing, tax and accounting evidence may be retained for the legally required period. Security logs are retained only for a proportionate period based on risk. Rights and complaint records are retained to demonstrate compliance and manage legal claims.
Where exact retention depends on a legal or operational category, Riera Studio applies the documented retention schedule and deletes or anonymises data when the purpose ends.
8. Your rights
Depending on the circumstances and applicable law, individuals may request access, correction, erasure, restriction, portability or objection, and may withdraw consent at any time. Rights are not absolute and lawful exemptions may apply.
Requests can be submitted through the Data Rights page or by email. Identity and authority may be verified before disclosure or deletion. Riera Studio normally responds within one month under UK GDPR, subject to any lawful extension.
Where Riera Studio acts only as processor, the request may be referred to the relevant customer controller and Riera Studio will provide reasonable assistance.
9. Complaints
A data protection complaint can be submitted through the dedicated Privacy Complaint page. Receipt is acknowledged electronically and the complaint is investigated without undue delay. UK complaints are acknowledged within 30 days in line with the Data (Use and Access) Act requirements.
Individuals may also complain to the UK Information Commissioner’s Office or, where EU GDPR applies, to a competent EEA supervisory authority. Riera Studio asks that the internal complaint route is used first where practical so the issue can be investigated promptly.
10. Security and breaches
Riera Studio uses authentication, server-side permission checks, company-scoped access controls, row-level security, private storage controls, encrypted provider connections, audit logging and restricted secret handling appropriate to the service.
No system is completely secure. Suspected incidents are assessed, contained and documented. Notifiable UK personal data breaches are reported to the ICO without undue delay and, where required, within 72 hours of awareness. Affected people are informed when the legal risk threshold is met.
11. Children and special-category data
Riera Studio is a business service and is not directed at children. Account holders must be at least 18 and authorised to act for a business.
Customers should not intentionally store special-category or criminal-offence data unless they have confirmed a lawful basis, appropriate safeguards and a genuine operational need. The standard service is not designed for medical records or similarly high-risk datasets.
12. Changes to this notice
Material changes are published with a new version and effective date. Where a change materially affects existing account use, reasonable notice is provided through the service or registered contact email.
Legal operator and contact
Riera Studio is operated by Sergi Riera Félix, trading as SRF Systems, a sole trader in the United Kingdom.
Service address: United Kingdom. The full geographic address for formal service is stated on contractual order documents and is available from the contact email.
Email: RieraStudio@srfsystems.uk
