Privacy Policy
rial (Rial Ventures Inc.) certifies that photos and videos are real at the moment of capture. This policy explains what we collect and why.
- Effective date:
- August 31, 2026
- Last updated:
- August 31, 2026
Who we are
This policy is issued by Rial Ventures Inc. (“rial”, “we”, “us”). It applies to rial’s website, its app, and the rial capture SDK and links. You can reach us at ulises@rial.io.
1. When this policy applies
rial acts as the data controller for people who use rial’s own app, website, and capture links directly. When you capture through a rial SDK or link embedded in another company’s product, that company is the controller of your personal data and rial acts as its processor, handling data on that company’s instructions. Please direct any requests about that data to that company rather than to rial.
2. Information we collect
Information you provide. Photos and videos you capture, and, for business and operator accounts, contact details such as name and email.
Information collected at the moment of capture. Precise location (GPS) sealed into the capture, only when you grant permission; device and sensor data, including hardware attestation identifiers derived from your device’s secure hardware (Secure Enclave / Trusted Execution Environment), used to prove the capture came from a real device; and capture timestamps.
Information collected automatically. When you use our website or service: IP address, browser and device type, and basic usage and diagnostic data needed to operate and secure the service.
3. How we use information
We use this information to verify that a capture is real and unaltered and to produce a Certificate of Reality; to provide, maintain, and secure the service; to prevent fraud and abuse; to communicate with you about the service; and to comply with legal obligations. We do not sell your personal information and we do not use it for cross-context behavioral advertising.
4. AI and model use
rial does not use your captured photos or videos to train or improve artificial intelligence or machine-learning models by default. We use captured content only to verify the capture and provide the service. We may use it to train or improve models only where you give explicit consent, or where a business client instructs us to do so under its agreement with us and has obtained the necessary permissions from you.
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract; our legitimate interests in providing, securing, and improving the service, preventing fraud, and verifying authenticity; your consent (for example, camera and precise-location permissions, which you can withdraw); and compliance with legal obligations.
6. How we share information
We share personal data with:
- Infrastructure subprocessors that run the service on our behalf — Amazon Web Services (hosting, storage, and compute) and Amazon SES (transactional email) — under data-protection terms.
- The business client that is the controller, where rial acts as a processor.
- Our professional advisers.
- Authorities where required by law or valid legal process.
- Parties to a corporate transaction such as a merger or acquisition.
We do not sell personal information.
7. Cookies and tracking
rial’s website uses only strictly necessary cookies required to operate and secure the site. We do not use third-party advertising cookies, cross-site tracking, or session-replay technologies.
8. International data transfers
rial operates in the United States and Latin America, and personal data is processed and stored in the United States (Amazon Web Services, US region). Where we transfer personal data from the EEA, the UK, or other regions with cross-border transfer rules, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable).
9. Data retention
We keep capture evidence for as long as needed to provide the service and as required by our agreements with business clients and our internal Data Management Policy. Operational and security logs are kept for a limited period. We retain records of privacy requests for 24 months. When an account is closed, we delete or de-identify associated personal data within 30 to 90 days where technically feasible, except where we must retain it to comply with law or resolve disputes; residual copies may persist in backups for a limited time.
10. Security
We protect personal data with technical and organizational measures, including encryption in transit and at rest, access on a need-to-know basis, and monitoring. rial’s captures are additionally bound to device secure hardware. No method of transmission or storage is completely secure, and you are responsible for keeping your account credentials safe.
11. Your rights and choices
Depending on where you live — including under the GDPR/UK GDPR and the CCPA/CPRA — you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email ulises@rial.io; we acknowledge requests within 10 business days and respond within 30 days (up to 45 in California). We will not discriminate against you for exercising your rights. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection supervisory authority.
12. Business customers and their end users
When rial provides its SDK or capture links to a business client, that client is responsible for providing privacy notices to and obtaining any necessary permissions from its own end users, and for identifying the legal basis for processing their data.
13. Marketing communications
If we send promotional emails, you can opt out at any time using the unsubscribe link; we will still send necessary transactional or service messages.
14. Children
rial is not directed to children. We do not knowingly collect personal data from children under 13 (or under 16 in the EEA where required). If you believe a child has provided us personal data, contact ulises@rial.io and we will delete it.
15. Changes to this policy
We may update this policy from time to time and will post the new effective date here; for material changes we will provide reasonable notice.
16. Contact us
Rial Ventures Inc., a United States C-corporation. Privacy questions and requests: ulises@rial.io. Security incidents: ulises@rial.io.