Legal
Privacy Policy
This policy describes the personal data RiskGear processes, why it is used, who receives it, and the choices available to you.
Effective date: 5 September 2026
1. Scope and roles
This Privacy Policy explains how RiskGear handles personal data when you visit its website, join a waitlist, create or use an account, receive an invitation, contact support, or otherwise use the Service.
RiskGear is the controller for website, waitlist, account, security, support, and service-usage data used for its own purposes. For personal data that a Customer submits inside risk records, incident records, actions, comments, and attachments, the Customer determines why and how it is processed and is normally the controller; RiskGear acts as its processor.
2. Data we collect
- Account and profile data: name, email address, avatar, job title, language, timezone, role, authentication identifiers, and notification preferences.
- Workspace data: organisation name, workspace URL, membership, invitations, plan, billing status, and configuration.
- Customer Data: risk and incident records, people referenced in records, actions, comments, attachments, linked records, audit events, and exported reports.
- Technical and usage data: IP address, browser and device information, timestamps, session and security events, page interactions, diagnostics, and error reports.
- Communications: waitlist submissions, support requests, feedback, and related correspondence.
- Billing data: plan and transaction references received from Paddle. RiskGear does not directly store full payment-card details.
3. How and why we use data
- provide accounts, workspaces, access controls, records, reports, reminders, notifications, and support;
- authenticate users, prevent abuse, investigate incidents, and protect tenant isolation;
- process subscriptions, enforce plan limits, and maintain transaction records;
- monitor reliability, diagnose errors, understand aggregate product usage, and improve the Service;
- send operational messages and, where permitted, product or waitlist updates;
- comply with legal obligations and establish, exercise, or defend legal claims.
4. Legal bases
Where the GDPR or similar law applies, processing is based on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing a B2B service, compliance with legal obligations, and consent where required. You may withdraw consent at any time without affecting earlier lawful processing. Customer is responsible for the legal basis covering personal data it places in Customer Data.
5. Cookies and analytics
RiskGear uses essential cookies or similar storage for authentication, security, language, and theme preferences. Product analytics may be used to understand feature usage and reliability. Sensitive risk and incident content is excluded or masked from analytics and session replay. Where law requires consent for non-essential analytics, those tools will not be activated until consent is obtained.
6. Sharing and service providers
Personal data is shared only where necessary with service providers operating under contractual and confidentiality obligations, including:
- Supabase for database, authentication, storage, and related infrastructure;
- Vercel for application hosting and delivery;
- Resend for transactional and reminder email delivery;
- Telegram for delivery of support requests to RiskGear's private internal support chat;
- Paddle as Merchant of Record for checkout, payment, tax, and billing services;
- Sentry for error monitoring and diagnostics;
- PostHog for privacy-configured product analytics where enabled.
Data may also be disclosed when required by law, to protect rights or security, in connection with a corporate transaction, or with your direction or consent. RiskGear does not sell personal data.
7. International transfers
Providers may process data in countries outside your own. Where required, RiskGear relies on adequacy decisions, the European Commission’s Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, or another lawful transfer mechanism, together with supplementary safeguards appropriate to the transfer.
8. Retention and deletion
Account and workspace data is retained while the Service is active and as needed to provide support, secure the Service, meet legal obligations, and resolve disputes. The current inactivity policy sends notices after 7 and 14 days where applicable and soft-deletes an inactive or unpaid workspace after 30 days; it does not automatically hard-delete compliance records.
Audit logs are retained for the life of the workspace because they support accountability and certification evidence. Billing and transaction records may be retained for statutory periods. Waitlist and marketing data is retained until it is no longer needed or you opt out. Backups and provider logs may remain for a limited period after deletion before rotating out.
9. Security
RiskGear applies reasonable technical and organisational measures such as authenticated sessions, role-based permissions, row-level security, tenant-scoped database constraints, encrypted provider connections, restricted service credentials, audit logs, server-side input validation, and monitoring. No online service can guarantee absolute security. Please report suspected compromise promptly.
10. Your rights and choices
Depending on applicable law, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; and complain to a supervisory authority. You may update many profile settings directly in RiskGear.
For personal data contained in a Customer workspace, contact that Customer first because it controls the record. RiskGear will assist Customers with valid requests. Requests sent directly to RiskGear may require identity verification and may be limited where retention is required by law or legitimate compliance needs.
11. Children
The Service is intended for business users and is not directed to children. RiskGear does not knowingly collect personal data directly from children. Customers must not submit children’s data unless they have a lawful basis and appropriate safeguards.
12. Changes to this policy
This Policy may be updated to reflect changes in the Service, providers, or law. The effective date will be revised and material changes will be communicated through the Service or by email where appropriate.
13. Contact
Privacy questions and rights requests may be sent to hello@tryriskgear.com. Include enough information to identify your account or workspace, but do not send passwords or sensitive record content by email.