
Privacy Policy
RiskRight Privacy Policy
Last updated: 17 May 2026
RiskRight helps companies monitor supply-chain risks and manage follow-up actions. This policy explains how RiskRight collects, uses, stores and discloses personal information when you use riskright.ai and related RiskRight services.
1. Information We Collect
We collect information that you or your organisation provides, including name, email address, company or workspace name, role, department, login details, action recipients, comments, action status and completion dates.
We also collect company setup information used to build a supply-chain profile, such as locations, materials, suppliers, product categories, markets and planning notes. Some of this may not identify a person, but it can include business contact details or comments about identifiable users.
We may collect technical information such as device type, browser, IP address, app usage events, authentication logs and error information to keep the service reliable and secure.
2. How We Use Information
We use personal information to create accounts, manage company workspaces, generate and refresh risk dashboards, send alerts and weekly digests, track delegated actions, provide support, improve RiskRight and protect the service from misuse.
Where Pro billing is enabled, billing information is used to manage subscriptions, seat counts, invoices and payment-related support.
3. AI And Risk Monitoring
RiskRight may use AI and search services to help identify supply-chain risk signals and draft planning actions. Users should review outputs before relying on them for commercial decisions.
RiskRight does not use personal information to make solely automated decisions that are intended to significantly affect an individual's rights or interests. If this changes, we will update this policy before using personal information in that way.
4. Disclosure To Service Providers
We may disclose personal information to service providers that help operate RiskRight, including hosting, database, authentication, email delivery, analytics, payment processing, support, AI and web-search services.
Current or planned providers may include Supabase, Vercel, Resend, Stripe, Anthropic and search-data providers. We do not sell personal information.
5. Overseas Processing
RiskRight may use cloud providers and service providers that process or store information outside Australia, including in the United States, Europe, Asia-Pacific regions or other countries where those providers operate.
We take reasonable steps to use reputable providers and configure access controls appropriate to the information being handled.
6. Security And Retention
We use reasonable technical and organisational measures to protect personal information, including managed authentication, access controls and encrypted cloud infrastructure where supported by our providers.
We keep personal information for as long as needed to provide RiskRight, meet legal and billing obligations, resolve disputes, maintain audit records and improve service reliability. Organisations may request deletion or export of workspace data, subject to legal and operational limits.
7. Access And Correction
You may access or correct account details in RiskRight where the app provides those controls. You may also ask us to access, correct or delete personal information by contacting us.
We may need to verify your identity and authority to act for the relevant workspace before making changes.
8. Cookies And Local Storage
RiskRight may use cookies, browser storage and similar technologies to keep you signed in, remember workspace settings, store app preferences and support installable web-app functionality.
9. Complaints
If you have a privacy question or complaint, contact us first so we can investigate and respond. We aim to respond within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
10. Contact
Email: privacy@riskright.ai
Website: riskright.ai
11. Changes To This Policy
We may update this policy as RiskRight changes. The latest version will be available on riskright.ai and will show the date it was last updated.