Home
RiskOnyx

Legal

Privacy Policy

RiskOnyx respects the privacy of its users, visitors, customers, partners, and affiliates. This page explains how personal data may be collected, used, stored, shared, and protected when you use the website, the platform, or interact with RiskOnyx.

Who we are

RiskOnyx is the controller of the personal data described in this Privacy Policy for the purposes set out below, except where RiskOnyx processes data on behalf of a customer as a processor under a separate agreement.

The controller details should be completed with the final legal entity name, registered address, and contact email before publication.

Scope of this Privacy Policy

This Privacy Policy applies to personal data processed in connection with:

website visits and resource-page access

contact forms, demo requests, and other enquiries

trial registration, subscription purchase, account creation, and account administration

affiliate or partner applications

customer support, onboarding, and specialist-support interactions

use of the RiskOnyx platform where RiskOnyx acts as controller

Where RiskOnyx processes personal data on behalf of a customer in connection with customer-controlled content, records, or platform use, RiskOnyx will generally act as processor and the relevant Data Processing Agreement will apply.

Categories of personal data we may collect

Depending on how you interact with RiskOnyx, we may collect:

identification and contact data, such as name, work email, company, job title, phone number, and country

account and subscription data, such as login credentials, workspace details, billing status, and user role

enquiry and communications data, such as messages, meeting requests, and support correspondence

affiliate or partner application data, such as business description, website, professional credentials, and referral profile

payment and transaction data provided through payment providers

technical and usage data, such as IP address, device information, browser type, session data, log data, and basic analytics data

customer-provided content and records to the extent they contain personal data

How we use personal data

We may use personal data to:

provide, operate, secure, and improve the website and platform

create and manage user accounts, subscriptions, and trials

process payments and manage billing

respond to enquiries, demo requests, and support requests

review affiliate or partner applications

provide onboarding, customer support, and service communications

monitor performance, security, misuse, and service integrity

comply with legal obligations and defend legal claims

send marketing or service-related communications where permitted by law or based on valid consent

Legal bases for processing

Where the GDPR or similar laws apply, RiskOnyx may rely on one or more of the following legal bases:

performance of a contract, where processing is necessary to provide the requested service, trial, subscription, or support

legitimate interests, such as operating and improving the service, protecting security, preventing misuse, managing ordinary business communications, and evaluating partner applications

compliance with legal obligations, including tax, accounting, fraud-prevention, and regulatory obligations

consent, where consent is required, for example for certain marketing communications or non-essential cookies

Controller and processor roles

RiskOnyx may act either as controller or processor depending on the context.

RiskOnyx generally acts as controller for website traffic, direct enquiries, marketing communications, billing, account management, affiliate applications, and its own business records.

RiskOnyx generally acts as processor where a customer uses the platform to upload, manage, or structure personal data that the customer controls for its own compliance or governance purposes. In those cases, the customer remains responsible for its instructions and its own legal basis for processing, and the Data Processing Agreement governs the processing relationship.

Sharing of personal data

RiskOnyx does not sell personal data. RiskOnyx may share personal data with:

hosting and cloud infrastructure providers

analytics, communications, CRM, customer-support, and scheduling providers

payment processors and related financial service providers

professional advisers, auditors, insurers, and legal counsel

affiliates or specialist partners only where necessary for a specific requested interaction and subject to suitable controls

courts, regulators, law-enforcement bodies, or public authorities where required by law or necessary to protect rights and legitimate interests

International transfers

Some service providers may process personal data outside the European Economic Area or the United Kingdom. Where that happens, RiskOnyx will rely on an appropriate transfer mechanism under applicable law, such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.

Where relevant, transfers to participating U.S. organisations may rely on the EU-U.S. Data Privacy Framework or the UK extension where applicable, and other transfers may rely on Standard Contractual Clauses. The European Commission explains that personal data may flow to third countries through adequacy decisions and other safeguards such as SCCs.

Retention

RiskOnyx retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the service, comply with legal obligations, resolve disputes, maintain records, and enforce agreements.

Retention periods should be aligned in practice to billing records, support logs, account-closure logic, security needs, and any customer contract terms. Deleted or deactivated accounts may be followed by a limited retention period where reasonably necessary for legal, accounting, security, or fraud-prevention purposes.

Security

RiskOnyx uses technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, disclosure, or misuse. These measures may include access controls, authentication measures, logging, vendor controls, backup processes, and infrastructure security measures.

No system can guarantee absolute security. Users are responsible for maintaining the confidentiality of their credentials and for using the platform in a secure and responsible manner.

Your rights

Where applicable, individuals may have the right to:

be informed about how their personal data is processed

request access to their personal data

request correction of inaccurate or incomplete data

request deletion of personal data in certain circumstances

request restriction of processing in certain circumstances

object to processing based on legitimate interests

request data portability where applicable

withdraw consent where processing is based on consent

lodge a complaint with a competent supervisory authority

The European Commission summarises these GDPR rights, including access, rectification, erasure, restriction, objection, and portability.

Requests may be sent to the privacy contact details provided on the website. RiskOnyx may ask for reasonable proof of identity before acting on a request.

Cookies and analytics

The RiskOnyx website may use cookies and similar technologies for essential site functionality, security, performance, analytics, and user experience. Non-essential cookies or tracking technologies should only be used where appropriate notice and, where legally required, valid consent have been obtained. Cookie details should be reflected in a separate cookie notice or cookie management layer if implemented.

Marketing communications

RiskOnyx may send service messages that are necessary for account, billing, security, or operational reasons. These are not the same as marketing messages. Where RiskOnyx sends newsletters, product updates, or other promotional communications, it will do so in accordance with applicable law and, where required, on the basis of valid consent. Individuals may opt out of marketing communications at any time using the unsubscribe mechanism or by contacting RiskOnyx.

Children's data

RiskOnyx is not directed to children and is not intended for users under 18 years of age. RiskOnyx does not knowingly collect personal data from children in connection with the website or service.

Changes to this Privacy Policy

RiskOnyx may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, or operational practices. The latest version should always be made available on the website with its effective date.

Contact

Privacy-related questions, requests, or complaints should be directed to:

ASMAK AI SOLUTIONS S.L. Calle Ali Bei 25 Atico, 1 08010 Barcelona Spain Email: info@riskonyx.es

If a dedicated privacy email address or Data Protection Officer is later adopted, this section should be updated accordingly.

Official source note

This draft reflects general GDPR concepts, controller and processor distinctions, data subject rights, and international-transfer mechanisms described by the European Commission and the EDPB. It should still be reviewed and tailored against the final RiskOnyx sub-processor list, cookie setup, hosting geography, and Data Processing Agreement.