1. Introduction
This Privacy Policy explains how the operator of r1sk.co.uk, trading as R1SK ("we", "us", or "our"), collects, uses, discloses, and safeguards personal data when you use our digital risk assessment and risk management solution (the "Service"). Company name, company number, and registered office will be added to this policy when a limited company is incorporated.
This policy is intended to meet the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Our Terms of Service govern use of the Service. If you do not agree with this policy, you should not use the Service.
2. Who We Are
Depending on the data involved, we act as a controller or as a processor:
- Controller: we determine the purposes and means of processing for website visitors, cookie choices, contact-form enquiries, and account-holder data we need to run accounts and billing (for example name, email, job title, company name, authentication data, and Stripe customer and subscription identifiers).
- Processor: we process risk assessment content, organisation structure, signatures, share-link activity, and other workplace data customers put in the Service, on the customer's documented instructions (including how they configure and use the Service). The customer is the controller of that data. Employees, contractors, and signers should contact their employer or the customer organisation first about those records.
Where we act as processor, we process that Customer Content only to provide the Service for the life of the customer account (unless the customer deletes it sooner), only on the customer's instructions, and we will assist the customer with UK GDPR requests and notify them of a personal-data breach affecting that data without undue delay.
Paid workspaces include a standing R1SK Support membership (support@r1sk.co.uk) so we can provide the Service, including support and operational maintenance. That membership is visible in User Management, does not consume a licensed seat, cannot be changed or removed by the customer, and access is logged. Accepting the Terms is the documented instruction for this access. Security event logs (including support access, sign-in, export, and deletion) are retained for 12 months.
Privacy requests can be sent using the details in section 14. We have not appointed a statutory Data Protection Officer.
3. Information We Collect
3.1 Personal data
We may collect the following types of personal data:
- Account Information: Name, email address, phone number, job title, and company name
- Authentication Data: Login credentials (passwords stored in hashed form) and authentication tokens
- Customer Content: Information customers provide when creating and managing risk assessments, including assessment details, risk ratings, control measures, organisation structure, names of employees, contractors, or other people they record, and electronic signatures or acknowledgements
- Usage Data: Information about how you use our Service, including pages visited, features used, and time spent on the platform
- Technical Data: IP address, browser type and version, device information, operating system, and unique device identifiers
- Communication Data: Records of correspondence when you contact us for support or enquiries
- Payment Information: Billing name, email, company name, and address if you provide it. We store Stripe customer and subscription identifiers, plan, billing interval, and subscription status. Full payment card numbers, CVC, and payment-method details are collected and stored by Stripe; we do not store them
3.2 Special category data
We do not require special category data (such as health information) to use the Service. If a customer includes that kind of data in an assessment or other User Content, the customer is the controller and must have a lawful basis for doing so. We process it only as their processor.
3.3 How we collect information
We collect information through:
- Direct interactions when you register, start checkout, create assessments, invite signers, or contact us
- Automated technologies such as cookies, server logs, and analytics tools (analytics only with consent — see section 10)
- Third-party sources such as Stripe (payments) and authentication infrastructure
4. Legal Basis for Processing
Where we act as controller, we process personal data on these UK GDPR bases:
- Contract: to create and manage your account, provide the Service, process payments, and send service-related messages
- Legitimate interests: to keep the Service secure, prevent fraud and abuse, understand how the product is used at a high level, and improve reliability (balanced against your rights)
- Legal obligation: to keep tax and accounting records and to respond to lawful requests
- Consent: for non-essential cookies (analytics and functional workspace memory) and for any marketing emails. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal
Where we act as processor, the customer's lawful basis applies to Customer Content. We process that data only to provide the Service to that customer.
We do not make solely automated decisions that produce legal or similarly significant effects about you.
5. How We Use Your Information
We use personal data for the following purposes:
- To provide, maintain, and operate the Service
- To process transactions and manage your account
- To host and process risk assessments and related documentation on the customer's instructions
- To send service-related communications, including updates and security alerts
- To respond to enquiries and provide customer support
- To detect, prevent, and address technical issues and security threats
- To comply with legal obligations and enforce our Terms of Service
- To analyse usage patterns, with analytics cookies only where you have consented
- To send marketing communications only with your consent, which you can withdraw at any time
We do not use customer risk assessment content to train third-party machine-learning models.
6. Data Sharing and Disclosure
We may share personal data with:
- Stripe: we use Stripe to take subscription payments. Stripe collects payment information directly (including card details) and may also collect device and cookie data on Checkout for fraud prevention, authentication, and related purposes. Stripe processes that data as our processor and, for some of those purposes, as an independent controller. See Stripe's Privacy Policy.
- Supabase: hosting, database, and authentication for the Service
- Microsoft: transactional email (account, signing, and support messages) sent via Microsoft Graph
- Vercel: website and application hosting. Vercel Analytics and Speed Insights run only if you accept analytics cookies
- Business transfers: in connection with any merger, acquisition, or sale of assets, data may transfer to the acquiring entity
- Legal requirements: when required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users or others
Except where a provider acts as an independent controller (as Stripe does for some payment purposes), these providers are permitted to process personal data only for the purposes we specify. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Multi-tenant architecture to isolate customer data
- Access controls and authentication mechanisms
- Incident response procedures
No method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain personal data only for as long as necessary for the purposes in this policy, unless a longer period is required or permitted by law:
- Account data: while the account is active and for a reasonable period afterwards to close the account and meet legal obligations
- Customer Content (assessments and related records): for the life of the customer account, unless the customer deletes it sooner, including while a workspace is paused or locked for non-payment. The customer is responsible for any health and safety record-keeping periods that apply to them, and should export records they need before the account ends
- Billing and transaction records: up to 7 years as required for UK tax and accounting. Stripe customer and subscription identifiers are kept while the Stripe customer record exists and as needed for those records
- Contact enquiries: for a reasonable period to handle the enquiry and keep a support record
- Marketing data: until you withdraw consent or opt out
- Cookie consent: the consent cookie is stored for 1 year (see section 10)
When we no longer need personal data, we securely delete or anonymise it.
9. Your Rights Under UK GDPR
Where we are the controller, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you
- Right to Rectification: You can request correction of inaccurate or incomplete data
- Right to Erasure: You can request deletion of your personal data in certain circumstances
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Data Portability: You can request a copy of your data in a structured, machine-readable format
- Right to Object: You can object to processing based on legitimate interests or for direct marketing
- Automated decision-making: You have rights in respect of solely automated decisions with legal or similarly significant effects. We do not carry out that type of processing
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, please contact us using the details in section 14. We will respond within one month, which we may extend in complex cases as UK GDPR allows.
If you are an employee, contractor, or signer whose data appears in a customer's assessments, please contact that organisation first. We will support the customer in meeting their obligations as controller.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concern first.
11. International Data Transfers
Some of our providers may process personal data outside the UK, including Stripe and others that may process data in the United States. When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the UK government
- Adequacy decisions recognising the recipient country's data protection laws
- Other appropriate safeguards as required by UK GDPR
12. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy contact:
R1SK Privacy Contact
Please use our contact form and include "Privacy Related Enquiry" in your message, or email support@r1sk.co.uk.
We aim to respond to privacy-related requests within one month.