Security & Incident Response
Last updated: 7 October 2026
How PayRivo protects information and responds to suspected incidents.
1. Our approach
We use role-based access, authenticated accounts, secure service providers and proportionate technical and organisational controls designed to protect confidentiality, integrity and availability.
2. Your role
Keep login details private, use unique passwords, limit manager access to people who need it and notify us immediately at support@payrivo.co.uk if you suspect unauthorised access or a security incident.
3. Incidents
We record, contain and assess suspected incidents, preserve relevant evidence, take corrective action and communicate with affected customers as appropriate. Where we act as processor, we notify the customer controller without undue delay so it can assess its legal notification obligations.
4. Service continuity
We maintain and improve procedures intended to restore service safely following an incident. No system is completely risk-free, so customers should also keep appropriate records and approval controls.
These documents provide general information about PayRivo’s service and data handling. They are not legal advice. They should be reviewed by a qualified UK solicitor before reliance for a regulated activity, bespoke enterprise agreement or a material change in service.