Effective date: August 8, 2026
This Privacy Policy explains how DSPLife Collaborative Group ("RisqRadar", "we", "us") processes personal data in connection with the RisqRadar service and website. When we process personal data contained in Customer Data on behalf of a customer, the customer is the controller and we act as processor; that processing is governed by our Data Processing Addendum.
We use personal data to provide, secure, and support the service; to authenticate users; to send service-related communications (such as invitations, reminders, and notifications you or your organization enable); to monitor and improve reliability and performance; to prevent fraud and abuse; and to comply with legal obligations.
Where the GDPR or UK GDPR applies to processing for which we are the controller (for example, account and website data), we rely on legitimate interests (operating and securing the service), performance of a contract, consent (where required), and legal obligation. Where we process Customer Data as a processor, we act on the customer's documented instructions.
We do not sell personal data. We share personal data with service providers ("subprocessors") that help us deliver the service, subject to appropriate confidentiality and data-protection obligations. Our current subprocessors are listed on our Subprocessors page. We may also disclose data where required by law or to protect rights, safety, and security.
Some features use AI models provided by our AI subprocessor to assist with drafting, summarization, and analysis. Content submitted for these features is processed to return a result and is not used to train foundation models. You control whether to use AI-assisted features for a given task.
We retain account and Customer Data for as long as your organization maintains an account, and thereafter for a limited period to allow export, meet legal obligations, and resolve disputes, after which it is deleted or anonymized. Log data is retained for a limited period for security and diagnostics.
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, encryption of sensitive stored credentials, tenant isolation, role-based access controls, and audit logging. No method of transmission or storage is completely secure, but we work to protect data commensurate with its sensitivity.
We and our subprocessors may process data in the United States and other countries. Where we transfer personal data subject to the GDPR or UK GDPR internationally, we rely on appropriate safeguards such as the Standard Contractual Clauses.
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. If we process your personal data as a processor on behalf of a customer, please direct your request to that customer, and we will assist them in responding. For data we control, contact us at privacy@risqradar.com. Residents of certain US states have rights under applicable state privacy laws, including the right not to be discriminated against for exercising them; we do not sell personal data or use it for cross-context behavioral advertising.
We use strictly necessary cookies for authentication and to keep you signed in. We do not use advertising cookies. Because these cookies are essential to the service, they cannot be disabled while using the authenticated application.
The service is intended for use by organizations and is not directed to children. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be indicated by an updated effective date and, where appropriate, additional notice.
For privacy questions or requests, contact privacy@risqradar.com or use our contact page.