Data Privacy Notice
Our personal data practices for Rivian products, services, applications and websites in the EU and UK
The technology woven into our lives is incredibly personal. When you drive our vehicles, plug into our chargers or use our digital applications and services, you’re trusting us with your information. That’s why we work hard to protect your privacy and put you in the driver’s seat with regard to your personal data. As we move together into an increasingly connected and sustainable automotive future, Rivian is committed to using data responsibly to deliver products and services that keep the world adventurous forever while respecting your privacy and keeping your information safe.
This Data Privacy Notice (“Notice”) is intended to provide a comprehensive description of our online and offline practices regarding the collection, use, disclosure and retention of personal data when you use our mobile applications, browse our websites (the “Site”) such as rivian.com or otherwise interact or communicate with us as an individual (“data subject”) within the European Union (EU) or United Kingdom (UK). The Notice, which provides information about the privacy rights regarding your personal data and how to exercise those rights, includes the following sections:
1. SCOPE OF THIS NOTICE
This Notice uses the Terms “Rivian”, “we”, “us” and “our”, which refer to Rivian Netherlands B.V. or its affiliate in the EU or UK (“Rivian” or “Company”) which offers the relevant product or service you have used, with which you have interacted, with which you have entered into a contract or which has otherwise collected and/or processed your personal data (also referred to as personal information in some jurisdictions). This legal entity is the applicable Data Controller within the meaning of applicable privacy laws and may be found via the link in Section 11 (“Contact Us”).
Rivian maintains separate data privacy notices for different types of data processing. For example, this Notice does not apply to:
Personal data we process under commercial agreements. When we execute commercial agreements, such as for vehicle sales to commercial customers, we may incorporate a commercial data privacy notice into that agreement. In those cases, any processing of personal data we perform for that customer is subject to that notice, rather than this Data Privacy Notice.
Personal data we process as a processor. Our processing of your personal data provided by our commercial customers or partners for our provision of services to them. These parties’ respective privacy notices govern their collection and use of this data and their disclosure of the data to us. Any processing of this data that we conduct on behalf of our customers or partners is governed by the contracts that we have in place with those parties, not this Notice. Any questions or requests relating to this data should be directed to those parties.
Personal data captured during ADAS vehicle public filming. The processing of your personal data (e.g. image, licence plate) that may occur when we capture live public video footage and images using non-customer-owned Rivian vehicles (e.g. Rivian-owned fleet vehicles) for the purpose of improving our Advanced Driver Assistance Systems (“ADAS”) and the vehicles’ safety features. That processing is described in our ADAS Vehicle Public Filming Data Privacy Notice.
Personal data of candidates or job applicants. Our processing of the personal data of job applicants/candidates. That processing is described in our Candidate Data Privacy Notice.
Personal data of our workforce. Our processing of the personal data of our employees, temporary workers, contingent workers or independent contractors in connection with work that they perform in that respective capacity on Rivian’s behalf, including when they drive a vehicle as part of their job duties. That processing is described in the Workforce Data Privacy Notice that we maintain and make available to these workforce members.
Non-personal data. Our processing of data that cannot be linked to an identifiable or identified individual (i.e. non-personal data). Rivian reserves the right to process this data for any legitimate business purpose.
Rivian also maintains other data privacy notices that are specific to a particular Rivian affiliate, product or service. These other notices govern our processing of personal data for those affiliates, products or services, unless the notice is marked as supplemental to this Notice, and can be located on our website or are presented to you when you use a particular product or service. For questions regarding the scope of this Notice, please contact us as set forth in Section 11 (“Contact Us”).
2. PERSONAL DATA WE COLLECT AND HOW WE USE IT
We collect and use personal data depending on how you interact with us, the products or services you use and the choices you make, as well as the type of relationship we have with you (e.g. consumer or customer). Your interactions may include, for example, your use of the Site, sign-ups for communications and marketing messages, calls or messages exchanged with Rivian representatives, and attendance at Rivian events or activities. The personal data we collect and process includes identifying and contact information, customer service information, preferences and device information, which may be collected using automatic information collection technologies. We may collect personal data about you from different sources and in various ways, including:
- Directly from you. Through your relationship with us, such as when you provide data to us directly on the Site, via email or through your online or offline/in-person interactions with us.
- Indirectly from you. From your use of our products, services or Site.
- From third-party sources. From our service providers, relevant parties (e.g. your bank or insurance company) and public sources, including public forums and social media or networking sites.
Below, we describe the personal data we collect, how we use it, and the privacy choices available to you for our products, services and activities currently intended for individuals in the EU and UK.
3. LEGAL GROUNDS FOR PROCESSING YOUR PERSONAL DATA
Rivian uses, retains and otherwise processes personal data that is subject to this Notice for different purposes, dependent on the specific use case, as described in Section 1 (“Scope of this notice”). These purposes include where you have provided consent, where such processing is necessary for the performance of a contract that we have with you, to comply with our legal obligations, or for our legitimate business interests. We process personal data only to the extent that we are legally permitted to do so.
4. OUR DISCLOSURE OF YOUR PERSONAL DATA
We disclose personal data to our affiliates and with the categories of third parties set forth below for legitimate business purposes, which also includes when you direct us to disclose it to others, or as necessary to complete your transactions or provide the products or services you have requested or authorised.
5. DATA RETENTION
Except as otherwise permitted or required by applicable law or regulation, we will retain your personal data only as long as necessary to fulfil the purposes we collected it for, as required to satisfy any legal, accounting or reporting requirements, as necessary to resolve disputes or as otherwise requested by you. In some cases, we may only process the personal data and do not store or retain it.
To determine the appropriate retention period for personal data, we consider our legal obligations, the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means. This duration varies based on data type and use, but we have recorded the durations in our internal records and information management policy and schedule.
Under some circumstances we may anonymise or reasonably de-identify your personal data so that it can no longer be reasonably associated with or used to identify you. We reserve the right to retain and use such information for any legitimate business purpose without further notice to you or your consent, unless required by law.
6. DATA SECURITY
We have in place appropriate security measures intended to prevent your personal data from being accidentally lost or used or accessed in an unauthorised way, including encryption of this information in transit and at rest and implementation of controls designed to limit access to your personal data to those Rivian personnel who have a genuine business need to know it. Those Rivian personnel who process your personal data are required to do so only in an authorised manner and are subject to confidentiality.
Despite our implementation of these measures, posting or transmission of personal data via the internet, by email or by other electronic means is not completely secure and it is possible that third parties may unlawfully intercept or access such data. We cannot guarantee that personal data will be totally secure.
We have procedures in place to deal with any suspected data security breach. We will notify you and/or any applicable regulator of a suspected data security breach where we are legally required to do so in accordance with any legally prescribed timeframes.
7. INTERNATIONAL DATA TRANSFERS
Rivian is based in the United States, and as such your personal data will be processed in the United States. We will transfer your personal data and store it internationally, including to or in countries that do not have data protection laws equivalent to those in the country where you reside or where your personal data is collected, for the purposes described above.
- For transfers from the European Economic Area (“EEA”) Member States or UK to countries for which the European Union (“EU”) Commission or the United Kingdom (“UK”) Information Commissioner’s Office has issued an adequacy decision saying the level of data protection is equivalent to the level within the EU or UK, we can rely on those adequacy decisions; this applies, for example, for data transfers between the UK and EEA Member States.
- For transfers from the EEA or UK to countries without an adequacy decision, Rivian has implemented appropriate safeguards to provide the necessary level of data protection, primarily by entering into appropriate data transfer arrangements based on approved standard contractual clauses.
By using the Site, the App and our products and services, or by otherwise providing us with your personal data, you agree to the collection, transfer, storage and other processing of your personal data to countries outside of your country of residence. Personal data transferred or stored internationally will be subject to the laws of the jurisdiction(s) where it is transferred or stored, and may be accessible to foreign courts, law enforcement and national security authorities in those jurisdiction(s).
8. YOUR PRIVACY CHOICES AND RIGHTS
Your privacy choices
In addition to the privacy choices identified for each product or service in Section 2 (“Personal data we collect and how we use it”), you may have additional privacy choices about your personal data. These choices are determined by applicable law and are described below.
- Email and telephone communications. If you receive an unwanted email from us, you can use the link found at the bottom of the email to stop receiving future emails. Note that you will continue to receive transaction-related emails regarding products or services you have requested. We may also send you certain non-promotional communications regarding us and our services, and you will not be able to opt out of those communications (e.g. communications regarding our services or updates to our Terms or this Notice). We process requests to be placed on do-not-mail, do-not-phone and do-not-contact lists as required by applicable law.
- Text/SMS messages. You may opt out of receiving text messages from us by following the instructions in the text message you have received from us or by contacting us. Note that you may still receive communications from Rivian regarding safety issues, such as vehicle recall notifications, even if you have opted out.
To exercise the above choices, please contact Customer Service at customerservice@rivian.com or by telephone at the number shown in Section 11 (“Contact Us”) below.
9. CHILDREN’S DATA
Rivian’s products and services are not directed at children, and we do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us as set forth in Section 11 (“Contact us”). If we become aware that we have collected the personal data of a child, we will take steps to promptly delete such information.
10. CHANGES TO THIS NOTICE
It is our policy to post any changes we make to this Notice on our Site. If we make material changes to how we treat our users’ personal data, we will notify you by sending an email to the primary email address specified in your account or through a notice on the Site home page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Site and this Notice to check for any changes. Your continued use of our Site or any products, services or solutions following the posting of changes constitutes your acceptance of such changes.
Last updated: 15 January 2024
11. CONTACT US
If you have any questions or concerns about our processing of your personal data or this Notice, please contact us by email at privacy@rivian.com or dpo@rivian.com or by post addressed to Herengracht 433, Unit 2.01 and 2.02, 1017 BR Amsterdam, The Netherlands.
To exercise your privacy rights, please use this web form.
You can identify the applicable Data Controller that processes your personal data on this page.