Privacy Policy

Last Updated: August 20, 2026

1. Introduction

RiskApplication Limited ("we", "our", or "us") operates RiskApp, a cloud-based risk assessment management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Contact Information:
RiskApplication Limited
15 Kindale Road
Wirral, CH43 3AU
United Kingdom
Registered in England & Wales. Company No: 17150687
Email: info@riskapp.co.uk

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide to us, including:

  • Account Information: Name, email address, company name, phone number, and password
  • Profile Information: Job title, department, and other profile details
  • Risk Assessment Data: Assessment records, observations, photos, signatures, and related documentation
  • Payment Information: Billing address and payment details (processed securely by Stripe)
  • Communication Data: Messages, support requests, and feedback you send to us

2.2 Automatically Collected Information

When you access our service, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, features used, time spent, click patterns
  • Location Data: Approximate location based on IP address (precise location only with your permission for mobile apps)
  • Cookies and Similar Technologies: Session tokens, preferences, and analytics data

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve RiskApp functionality
  • Account Management: To create and manage your account, process subscriptions, and handle billing
  • Communication: To send service updates, security alerts, and support messages
  • Analytics: To understand usage patterns and improve our service
  • Security: To detect, prevent, and address fraud, security issues, and technical problems
  • Compliance: To comply with legal obligations and enforce our Terms and Conditions
  • Marketing: To send promotional content (only with your consent, and you may opt out anytime)

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We share data with third-party service providers who perform services on our behalf:

  • Stripe: Payment processing and subscription management
  • Amazon Web Services (AWS): Cloud hosting and storage
  • Email Service Providers: Transactional and marketing emails
  • Analytics Providers: Usage analytics and performance monitoring

4.2 Team Members

Within your organization, data you create (such as risk assessments) may be accessible to other team members according to your team's permissions and access controls.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Legal processes (subpoenas, court orders)
  • Governmental requests
  • Protection of our rights, property, or safety
  • Investigation of fraud or security issues

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

5. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Specifically:

  • Active Accounts: Data is retained while your account is active
  • Closed Accounts: Account data may be retained for up to 90 days after closure for recovery purposes, except for permanent inactivity deletion described below
  • Risk Assessment Records: May be retained longer for compliance and audit purposes
  • Financial Records: Retained for 7 years in compliance with UK tax law
  • Marketing Data: Retained until you unsubscribe or request deletion

Inactivity deletion

Policy publication date: To be announced before enforcement. Effective date: To be announced before enforcement. We will announce this change in the Service at least 30 days before it takes effect.

Free or expired teams may be permanently deleted after three calendar months without authenticated usage and at least 30 days of emailed warnings to the owner and administrators, with further reminders at 14, seven and one day remaining. Existing teams start a new observation period no earlier than the policy effective date. Authenticated team usage cancels the countdown; active paid access, trials and payment recovery are protected.

Inactivity deletion removes live team resources and uploaded media with no additional recovery period, including the team's risk assessment records unless an applicable hold prevents deletion. Users with other team or client associations retain their other access. A minimal operational receipt records completion; recipient details are retained for retrying the final notification and removed after successful sending.

Live deletion does not mean immediate erasure from backups, external support systems or Stripe accounting records. These remain subject to their applicable retention arrangements and obligations. See the inactivity terms and inactivity guide.

6. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Role-based access with multi-factor authentication available
  • Regular Audits: Security assessments and penetration testing
  • Secure Infrastructure: AWS infrastructure with regular security updates
  • Data Backup: Regular automated backups with secure storage

However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights (GDPR & UK GDPR)

Under data protection law, you have rights including:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (right to be forgotten)
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing of your data
  • Right to Withdraw Consent: Withdraw consent for data processing
  • Right to Lodge a Complaint: File a complaint with the UK Information Commissioner's Office (ICO)

To exercise these rights, please contact us at info@riskapp.co.uk

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Required for basic functionality (login sessions, security)
  • Analytics Cookies: Help us understand how you use our service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling certain cookies may affect service functionality.

9. International Data Transfers

Your information may be transferred to and processed in countries outside the UK/EEA where our service providers operate. We ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Service providers certified under privacy frameworks
  • Adequate protection measures as required by UK GDPR

10. Children's Privacy

RiskApp is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will take steps to delete that information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date
  • Sending you an email notification (for material changes)

Your continued use of RiskApp after changes become effective constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

RiskApplication Limited

15 Kindale Road

Wirral, CH43 3AU

United Kingdom

Registered in England & Wales. Company No: 17150687

Email: info@riskapp.co.uk

This privacy policy was created to comply with UK GDPR, Data Protection Act 2018, and best practices for SaaS applications. For questions about data protection, you may also contact the UK Information Commissioner's Office (ICO) at ico.org.uk