Platform Privacy Notice
Last updated: May 2026
This notice describes how Risk Quilt Ltd (company number 17049484) ("RiskQuilt", "we", "us", "our") handles personal data and Customer Data in connection with the RiskQuilt platform.
This notice covers the platform itself — the application you sign in to and use. It does not cover the marketing website at www.riskquilt.com, which is covered by a separate Website Privacy Policy.
Who this notice is for
"You" in this notice means the individual using the RiskQuilt platform — typically an employee, contractor, or other personnel of an organisation that subscribes to RiskQuilt.
If you are signing up on behalf of an organisation, your organisation is the "Customer" — this is a contractual relationship governed by our Terms of Service. Where this notice refers to "your organisation" or "the Customer", we mean that contracting entity.
Two roles we play with your data
We play two distinct roles depending on the type of data:
For Customer Data — the risks, controls, actions, events, and other content your organisation creates inside the platform — we act as a data processor. Your organisation is the data controller and decides how that data is used. We process Customer Data only on your organisation's documented instructions, to provide and support the platform, and to comply with applicable law.
For platform-account data — your name, email address, sign-in events, account preferences, and similar — we act as a data controller. We use this data to operate the platform, secure your account, communicate with you about the service, and meet our legal obligations.
This split affects how you exercise your data protection rights — see Your rights below.
What data we collect
Account data
- Your name and email address
- Identity provider information (issuer, subject identifier, email claim) supplied by your organisation's identity provider
- Authentication events (sign-in success and failure, including source IP address and timestamp)
- Account preferences and settings
Customer Data
- Risks, controls, actions, events, obligations, and related content your organisation creates in the platform
- Categorisation, scoring, and assessment data
- Evidence files uploaded by users
- Audit trail entries recording changes to the above
Sign in with Google
If you use the "Sign in with Google" option to authenticate, we receive from Google:
- Your Google account email address
- Your name (as it appears on your Google account)
- Your Google account profile picture URL (if present; not stored)
- A unique identifier for your Google account (the OpenID Connect "subject" claim)
We use this data only to identify you within the platform and match you to your existing platform account. We do not use it for advertising, profiling, or any purpose other than authentication. We do not request access to your Google data beyond these basic sign-in fields, and we never request access to your Gmail, Calendar, Drive, or other Google services.
You can revoke RiskQuilt's access to your Google account at any time by visiting https://myaccount.google.com/permissions. Revoking access prevents future sign-in via Google but does not delete your platform account or platform data — see How long we keep your data below for how to delete your account.
Communications
- Support requests you send us
- Service announcements and security notifications we send you
What we do not collect
- We do not store passwords. Authentication is handled by your identity provider (your organisation's IdP, or Google for Sign in with Google users) or via single-use magic links.
- We do not place advertising cookies, analytics cookies, or any third-party tracking cookies on the platform. The platform uses only essential session cookies.
How we use your data
We use account data and Customer Data to:
- Provide and operate the platform
- Authenticate you and secure your account
- Maintain audit trails (a core platform feature your organisation relies on)
- Investigate and respond to security incidents
- Provide customer support when requested
- Send service announcements, security notifications, and account-related communications
- Comply with legal obligations
- Generate anonymised, aggregated statistics about platform usage (further restricted by our Terms of Service, which prohibit any use of free-text or narrative content for this purpose)
We do not:
- Use your data for advertising
- Sell your data to third parties
- Train AI or machine learning models on Customer Data (our Terms of Service contain a contractual prohibition on this)
- Use Customer Data outside your tenant for any purpose other than the anonymised statistics use described above
Legal basis for processing (UK GDPR / EU GDPR)
Where we act as controller (account data), our legal bases are:
- Contract — to provide the platform you've signed up for
- Legitimate interests — to secure the platform, prevent abuse, and operate it efficiently
- Legal obligation — to meet record-keeping, tax, and other statutory requirements
Where we act as processor (Customer Data), the legal basis is your organisation's responsibility as controller. We process on their documented instructions.
Where your data is stored and processed
Customer Data and platform account data are stored and processed in the United Kingdom on Google Cloud infrastructure (europe-west2 region).
Backup and disaster recovery copies are stored in the same region and do not leave the United Kingdom.
Some sub-processors (see below) may transfer limited data outside the UK or EEA. Where this happens, we rely on UK International Data Transfer Agreements, EU Standard Contractual Clauses, or adequacy decisions, depending on the destination.
Sub-processors
We use the following sub-processors to deliver the platform. Each is bound by data protection obligations equivalent to those we owe you and your organisation.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google LLC (Google Cloud) | Cloud infrastructure — application hosting, database, object storage, secrets management, telemetry | United Kingdom (europe-west2) |
| Google LLC (Sign in with Google) | Authentication for users who choose the "Sign in with Google" option | United States (transfer governed by SCCs / IDTA) |
| Cloudflare Inc | DNS, web application firewall, content delivery network | Global edge network |
| Auth0 Inc (Okta) | Identity provider for the RiskQuilt-operated demo environment | United Kingdom / European Union |
| Twilio SendGrid (Twilio Inc) | Outbound transactional email — magic links, notifications, service announcements | United States (transfer governed by SCCs / IDTA) |
| Stripe Inc | Card payment processing for self-serve subscriptions | United States (transfer governed by SCCs / IDTA) |
We may add or change sub-processors. Where a change is material, we will update this notice and notify your organisation's primary contact at least 30 days in advance.
Your rights
Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
- Access — to see what personal data we hold about you
- Rectification — to correct inaccurate personal data
- Erasure — to have your personal data deleted
- Restriction — to limit how we process your personal data
- Portability — to receive your personal data in a structured, machine-readable format
- Objection — to object to processing based on legitimate interests
- Withdrawal of consent — where processing relies on consent
You also have the right to complain to a data protection supervisory authority — the Information Commissioner's Office (ico.org.uk) in the UK, or your local supervisory authority in the EEA.
Where to direct your request
For Customer Data (the content your organisation has put into the platform): contact your organisation's administrator or data protection contact. They are the data controller and decide how to respond. We will assist them where the request relates to Customer Data we hold on their behalf.
For your platform account data (your name, email, sign-in events, account communications): contact us directly at privacy@riskquilt.com.
For Sign in with Google: you can revoke RiskQuilt's access to your Google account at any time at https://myaccount.google.com/permissions. To delete your RiskQuilt platform account or its associated data, contact us or your organisation's administrator as described above.
We will respond to your request within one month. We may extend this by up to two further months for complex requests, and will let you know if we need to.
How long we keep your data
| Data category | Retention |
|---|---|
| Account data | For the lifetime of your account; deleted within 90 days after off-boarding |
| Audit trail | For the lifetime of your organisation's account; deleted within 90 days after off-boarding |
| Sign-in event logs | 3 months |
| Application logs | 3 months |
| Service-related communications you receive from us | 3 months |
| Customer Data | For the lifetime of your organisation's account. On off-boarding: a 30-day data export window, after which Customer Data is deleted within 90 days |
| Backups | Daily snapshots: 7 days. Monthly snapshots: 3 months. Backups age out naturally per this schedule and are not selectively pruned on off-boarding. |
| Anonymised usage statistics | Indefinite (does not contain personal data) |
| Billing metadata | Indefinite, where required to meet legal record-keeping obligations |
How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data we process. These include:
- Logical tenant isolation enforced at the database level (PostgreSQL row-level security with a two-role separation between schema management and application access)
- Role-based access control with least privilege within the platform
- Encryption in transit (TLS 1.2 or higher for all connections) and at rest (AES-256 for application data and backups)
- Externalised authentication — we do not store user passwords; authentication is via OpenID Connect or single-use magic links sent to verified email addresses
- Backup and disaster recovery processes
- Vulnerability management, dependency scanning, and security patching
- Controlled change management and migration procedures
- Incident identification and response procedures
- Audit logging of administrative operations
- Penetration testing prior to platform launch
We do not guarantee uninterrupted service or absence of security incidents. Our obligation is to apply reasonable and appropriate measures and to respond promptly when incidents occur.
Incident notification
If a personal data breach occurs that affects Customer Data, we will notify your organisation's primary contact without undue delay. Where you are an end user and the incident affects your own account data, we will notify you directly where required by law.
Children
The RiskQuilt platform is a business-to-business product intended for adult workplace use. We do not knowingly collect personal data from children under 16.
Changes to this notice
We may update this notice from time to time. The "Last updated" date at the top tells you when. Material changes affecting sub-processors or the categories of data we process will be notified to your organisation's primary contact at least 30 days in advance.
Contact
For privacy queries, data subject access requests relating to your platform account, or general questions about this notice:
privacy@riskquilt.com
Risk Quilt Ltd
(Company number 17049484)
United Kingdom
For Customer Data requests (risks, controls, evidence, and other content held within your organisation's tenant), contact your organisation's administrator first — they are the data controller for that data.
For the contractual relationship between RiskQuilt and your organisation, see our Terms of Service.