Legal
Política de privacidad
RiskOnyx respects the privacy of its users, visitors, customers, partners, and affiliates. This page explains how personal data may be collected, used, stored, shared, and protected when you use the website, the platform, or interact with RiskOnyx.
Who we are
RiskOnyx is the controller of the personal data described in this Privacy Policy for the
purposes set out below, except where RiskOnyx processes data on behalf of a customer as a
processor under a separate agreement.
The controller details should be completed with the final legal entity name, registered
address, and contact email before publication.
Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with:
website visits and resource-page access
contact forms, demo requests, and other enquiries
trial registration, subscription purchase, account creation, and account administration
affiliate or partner applications
customer support, onboarding, and specialist-support interactions
use of the RiskOnyx platform where RiskOnyx acts as controller
Where RiskOnyx processes personal data on behalf of a customer in connection with
customer-controlled content, records, or platform use, RiskOnyx will generally act as
processor and the relevant Data Processing Agreement will apply.
Categories of personal data we may collect
Depending on how you interact with RiskOnyx, we may collect:
identification and contact data, such as name, work email, company, job title, phone number,
and country
account and subscription data, such as login credentials, workspace details, billing status,
and user role
enquiry and communications data, such as messages, meeting requests, and support
correspondence
affiliate or partner application data, such as business description, website, professional
credentials, and referral profile
payment and transaction data provided through payment providers
technical and usage data, such as IP address, device information, browser type, session
data, log data, and basic analytics data
customer-provided content and records to the extent they contain personal data
How we use personal data
We may use personal data to:
provide, operate, secure, and improve the website and platform
create and manage user accounts, subscriptions, and trials
process payments and manage billing
respond to enquiries, demo requests, and support requests
review affiliate or partner applications
provide onboarding, customer support, and service communications
monitor performance, security, misuse, and service integrity
comply with legal obligations and defend legal claims
send marketing or service-related communications where permitted by law or based on valid
consent
Legal bases for processing
Where the GDPR or similar laws apply, RiskOnyx may rely on one or more of the following
legal bases:
performance of a contract, where processing is necessary to provide the requested service,
trial, subscription, or support
legitimate interests, such as operating and improving the service, protecting security,
preventing misuse, managing ordinary business communications, and evaluating partner
applications
compliance with legal obligations, including tax, accounting, fraud-prevention, and
regulatory obligations
consent, where consent is required, for example for certain marketing communications or
non-essential cookies
Controller and processor roles
RiskOnyx may act either as controller or processor depending on the context.
RiskOnyx generally acts as controller for website traffic, direct enquiries, marketing
communications, billing, account management, affiliate applications, and its own business
records.
RiskOnyx generally acts as processor where a customer uses the platform to upload, manage,
or structure personal data that the customer controls for its own compliance or governance
purposes. In those cases, the customer remains responsible for its instructions and its own
legal basis for processing, and the Data Processing Agreement governs the processing
relationship.
Sharing of personal data
RiskOnyx does not sell personal data. RiskOnyx may share personal data with:
hosting and cloud infrastructure providers
analytics, communications, CRM, customer-support, and scheduling providers
payment processors and related financial service providers
professional advisers, auditors, insurers, and legal counsel
affiliates or specialist partners only where necessary for a specific requested interaction
and subject to suitable controls
courts, regulators, law-enforcement bodies, or public authorities where required by law or
necessary to protect rights and legitimate interests
International transfers
Some service providers may process personal data outside the European Economic Area or the
United Kingdom. Where that happens, RiskOnyx will rely on an appropriate transfer mechanism
under applicable law, such as an adequacy decision, Standard Contractual Clauses, or another
lawful safeguard.
Where relevant, transfers to participating U.S. organisations may rely on the EU-U.S. Data
Privacy Framework or the UK extension where applicable, and other transfers may rely on
Standard Contractual Clauses. The European Commission explains that personal data may flow
to third countries through adequacy decisions and other safeguards such as SCCs.
Retention
RiskOnyx retains personal data only for as long as reasonably necessary for the purposes
described in this Privacy Policy, including to provide the service, comply with legal
obligations, resolve disputes, maintain records, and enforce agreements.
Retention periods should be aligned in practice to billing records, support logs,
account-closure logic, security needs, and any customer contract terms. Deleted or
deactivated accounts may be followed by a limited retention period where reasonably
necessary for legal, accounting, security, or fraud-prevention purposes.
Security
RiskOnyx uses technical and organisational measures intended to protect personal data
against unauthorised access, loss, alteration, disclosure, or misuse. These measures may
include access controls, authentication measures, logging, vendor controls, backup
processes, and infrastructure security measures.
No system can guarantee absolute security. Users are responsible for maintaining the
confidentiality of their credentials and for using the platform in a secure and responsible
manner.
Your rights
Where applicable, individuals may have the right to:
be informed about how their personal data is processed
request access to their personal data
request correction of inaccurate or incomplete data
request deletion of personal data in certain circumstances
request restriction of processing in certain circumstances
object to processing based on legitimate interests
request data portability where applicable
withdraw consent where processing is based on consent
lodge a complaint with a competent supervisory authority
The European Commission summarises these GDPR rights, including access, rectification,
erasure, restriction, objection, and portability.
Requests may be sent to the privacy contact details provided on the website. RiskOnyx may
ask for reasonable proof of identity before acting on a request.
Cookies and analytics
The RiskOnyx website may use cookies and similar technologies for essential site functionality, security, performance, analytics, and user experience. Non-essential cookies or tracking technologies should only be used where appropriate notice and, where legally required, valid consent have been obtained. Cookie details should be reflected in a separate cookie notice or cookie management layer if implemented.
Marketing communications
RiskOnyx may send service messages that are necessary for account, billing, security, or operational reasons. These are not the same as marketing messages. Where RiskOnyx sends newsletters, product updates, or other promotional communications, it will do so in accordance with applicable law and, where required, on the basis of valid consent. Individuals may opt out of marketing communications at any time using the unsubscribe mechanism or by contacting RiskOnyx.
Children's data
RiskOnyx is not directed to children and is not intended for users under 18 years of age. RiskOnyx does not knowingly collect personal data from children in connection with the website or service.
Changes to this Privacy Policy
RiskOnyx may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, or operational practices. The latest version should always be made available on the website with its effective date.
Contact
Privacy-related questions, requests, or complaints should be directed to:
ASMAK AI SOLUTIONS S.L. Calle Ali Bei 25 Atico, 1 08010 Barcelona Spain Email:
info@riskonyx.es
If a dedicated privacy email address or Data Protection Officer is later adopted, this
section should be updated accordingly.
Official source note
This draft reflects general GDPR concepts, controller and processor distinctions, data
subject rights, and international-transfer mechanisms described by the European Commission
and the EDPB. It should still be reviewed and tailored against the final RiskOnyx
sub-processor list, cookie setup, hosting geography, and Data Processing Agreement.