Privacy Policy

How RisqRadar handles personal data.

Effective date: September 28, 2026

1. Scope

This Privacy Policy explains how DSPLife Collaborative Group ("RisqRadar", "we", "us") processes personal data in connection with the RisqRadar service and website. When we process personal data contained in Customer Data on behalf of a customer, the customer is the controller and we act as processor; that processing is governed by our Data Processing Addendum.

2. Information we collect

  • Account information — name, work email, organization, and role, provided when an account is created or a user is invited.
  • Customer Data — the risk, compliance, vendor, asset, and related records your organization enters into the service. This may include personal data your organization chooses to store.
  • Usage and log data — technical information such as IP address, device and browser type, pages viewed, and timestamps, used for security, diagnostics, and improving the service.
  • Cookies — strictly necessary cookies for authentication and session management. See the Cookies section below.

Most of this comes from you or your organization directly. Some does not: where your organization connects the service to its own systems — for example a directory, an email platform, a device-management console, or a security tool — the service receives information about people in that organization who have never used RisqRadar themselves. That can include names, work email addresses, group memberships, sign-in and device activity, and records of AI assistant usage. Your organization chooses which connections to make and remains the controller of that data; we process it on their instructions, and the obligation to inform those individuals rests with them.

3. How we use information

We use personal data to provide, secure, and support the service; to authenticate users; to send service-related communications (such as invitations, reminders, and notifications you or your organization enable); to monitor and improve reliability and performance; to prevent fraud and abuse; and to comply with legal obligations.

4. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies to processing for which we are the controller (for example, account and website data), we rely on legitimate interests (operating and securing the service), performance of a contract, consent (where required), and legal obligation. Where we process Customer Data as a processor, we act on the customer's documented instructions.

5. Sharing and subprocessors

We do not sell personal data. We share personal data with service providers ("subprocessors") that help us deliver the service, subject to appropriate confidentiality and data-protection obligations. Our current subprocessors are listed on our Subprocessors page. We may also disclose data where required by law or to protect rights, safety, and security.

6. AI-assisted features

Some features use AI models provided by our AI subprocessor to assist with drafting, summarization, and analysis. Content submitted for these features is processed to return a result and is not used to train foundation models. You control whether to use AI-assisted features for a given task.

7. Automated decision-making

We do not make decisions about individuals that produce legal effects, or similarly significant effects, solely by automated means. RisqRadar scores risks, controls, vendors and systems, and its AI-assisted features draft and summarize text — all of it is decision support presented to a person, who decides. Where a score or a generated suggestion concerns an individual, it is reviewable by your organization and can be corrected or overridden by them.

8. Data retention

We retain account and Customer Data for as long as your organization maintains an account, and thereafter for a limited period to allow export, meet legal obligations, and resolve disputes, after which it is deleted or anonymized. Log data is retained for a limited period for security and diagnostics.

9. Security

We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, encryption of sensitive stored credentials, tenant isolation, role-based access controls, and audit logging. No method of transmission or storage is completely secure, but we work to protect data commensurate with its sensitivity.

10. International transfers

We and our subprocessors may process data in the United States and other countries. Where we transfer personal data subject to the GDPR or UK GDPR internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies. You can obtain a copy of the safeguards we rely on for a particular transfer by writing to privacy@risqradar.com.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. If we process your personal data as a processor on behalf of a customer, please direct your request to that customer, and we will assist them in responding. For data we control, contact us at privacy@risqradar.com. Residents of certain US states have rights under applicable state privacy laws, including the right not to be discriminated against for exercising them; we do not sell personal data or use it for cross-context behavioral advertising.

Where we rely on your consent for a particular processing activity, you can withdraw that consent at any time by contacting privacy@risqradar.com. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect processing we carry out on a different legal basis.

If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to lodge a complaint with a data protection supervisory authority — normally the authority in the country where you live, where you work, or where you believe the issue arose. You are entitled to complain to a supervisory authority whether or not you raise the matter with us first, though we would like the chance to resolve it.

12. Cookies

We use strictly necessary cookies for authentication and to keep you signed in. We do not use advertising cookies. Because these cookies are essential to the service, they cannot be disabled while using the authenticated application.

13. Children

The service is intended for use by organizations and is not directed to children. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be indicated by an updated effective date and, where appropriate, additional notice.

15. Contact

For privacy questions or requests, contact privacy@risqradar.com or use our contact page.