GDPR
Last updated: 9 August 2026
Controller and processor
For the conversations flowing through a workspace, the business operating that workspace is the controller and Ritmo acts as the processor. The business decides what to collect from its customers, why, and for how long. We process that data only to provide the service and only on the business's instructions.
For the account data of the businesses themselves — workspace name, email, phone, billing tier — Ritmo is the controller.
Your rights
If the GDPR applies to you, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, subject to legal retention obligations.
- Restriction — limit how we process your data while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Complaint — lodge a complaint with your local supervisory authority.
Exercising a right
Email privacy@uritm.com describing what you need. We respond within 30 days. If you are an end user who messaged a business through Ritmo, we will forward your request to that business, since they control the data — or you can contact them directly, which is usually faster.
For deletion specifically, the step-by-step process is on the data deletion page.
Lawful bases
We rely on the following bases, depending on the processing:
- Performance of a contract — operating the service for account holders.
- Legitimate interests — securing the platform, preventing abuse, and diagnosing faults.
- Consent — where required, for example optional notifications.
- Legal obligation — where we are required to retain or disclose data by law.
Sub-processors
We use Meta Platforms and TikTok for message delivery, Google Firebase for push notifications and file storage, Cloudflare R2 for media storage, and hosting and transactional email providers to run the application. Each processes data solely to provide its service to us.
International transfers
Our infrastructure and sub-processors may process data outside your country of residence. Where data leaves the EEA, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Data processing agreement
Businesses that need a signed Data Processing Agreement can request one at privacy@uritm.com.