1. Our role and the scope of this Policy
Information we control. Risk Vault determines how information is processed when you visit our website, communicate with us, create or administer an account directly with us, or interact with us in another business capacity. This Policy applies to those activities.
Customer-controlled information. Organizations use Risk Vault to manage risks, controls, assets, surveys, reports, workflows, users, and attachments. When we process that content under a customer’s instructions, the customer organization is responsible for deciding why and how it is processed, and Risk Vault acts as its service provider or processor. The customer’s privacy notice and agreement with Risk Vault govern that processing. If your account was provided by your employer or another organization, direct questions about its records to that organization first.
This Policy does not cover third-party websites, identity providers, or integrations that operate under their own privacy policies.
2. Information we collect
The information available to us depends on how you and your organization configure and use the Service.
| Category | Examples | Primary purposes |
|---|---|---|
| Account and professional information | Name, email address, username, telephone number, job title, time zone, employer, business unit, roles, permissions, and account status. | Create and administer accounts; authenticate users; enforce authorization; provide support. |
| Authentication and security information | Password hash, multi-factor authentication configuration, external identity identifiers and claims, login history, IP address, browser/user-agent information, session data, agreement acceptance, and security and audit events. | Authenticate users; prevent fraud and abuse; investigate incidents; maintain auditability. |
| Customer content | Risk, control, asset, incident, survey, compliance, workflow and report data; comments; names and work contact details assigned to records; uploaded documents and attachments; and other content submitted by users. | Provide the customer-directed risk-management Service and its collaboration, reporting, notification and recordkeeping functions. |
| Integration information | Connection settings, encrypted credentials or tokens, identifiers, webhook data, and records exchanged with identity providers, Jira, SCIM, SIEM, MCP clients, or other integrations enabled by an administrator. | Connect and synchronize systems at the customer’s direction; secure and troubleshoot integrations. |
| Device, usage and diagnostic information | IP address, browser and device information, pages or features used, timestamps, request and correlation identifiers, error records, performance data, and security telemetry. | Operate, secure, diagnose and improve the reliability of the Service. |
| Communications | Support requests, administrative messages, feedback, and related correspondence. | Respond to requests; provide support; manage our relationship with you or your organization. |
Sources. We receive information directly from you; from your organization and its administrators; automatically from your browser or device; from identity providers and integrations you or your organization enable; and from service providers that help us operate and secure the Service.
Information about other people. You may enter another person’s business contact details when assigning records, inviting users, or configuring notifications. Only provide information you are authorized to provide.
Free-form and uploaded content. Risk Vault is designed for organizational risk information, not consumer financial accounts, government identification numbers, precise geolocation, medical records, or other unnecessary sensitive personal information. Do not place such information in free-text fields, AI prompts, survey responses, or attachments unless your organization has determined it is necessary and authorized.
3. How we use personal information
- Provide, maintain and support the Service and customer-requested features.
- Create accounts, verify identity, manage roles and permissions, and provide single sign-on or other configured authentication.
- Process customer content, files, reports, workflows, notifications, surveys and integrations according to customer instructions.
- Protect accounts and systems, detect misuse, scan files when configured, enforce our agreements, and investigate security or availability incidents.
- Monitor performance, debug errors, maintain audit trails, and improve accessibility, reliability and usability.
- Respond to support requests and send transactional, security, legal and administrative communications.
- Comply with law, lawful process and contractual requirements, and establish, exercise or defend legal claims.
- Evaluate or complete a financing, acquisition, reorganization, sale or other corporate transaction.
- Create aggregated or de-identified information for lawful operational and analytical purposes. We do not attempt to reidentify information that we maintain as de-identified except to test or validate our de-identification processes as permitted by law.
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in providing and securing a business service, compliance with legal obligations, and consent where required. A customer organization determines the legal basis for customer-controlled information.
6. AI-assisted features
Risk Vault may offer optional features that send selected text, prompts and relevant record context to an AI service configured for the deployment. The current supported configuration uses a separately operated llama.cpp model server; administrators can disable AI features.
AI input and output may contain personal or confidential information if a user includes it. Users should review generated output before relying on or saving it and should not submit information that their organization has not authorized for AI processing.
We do not use customer content, prompts or outputs to train generalized AI models. If Risk Vault introduces a third-party AI provider or materially changes these practices, we will update this Policy and applicable customer documentation before the new processing applies.
7. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, follow customer instructions, maintain security and audit records, comply with legal and contractual obligations, resolve disputes, and enforce agreements.
Customer administrators can configure record-retention requirements. The platform’s default business-record retention setting is seven years, but an organization may select a different period and may place records on legal hold. Report artifacts and short-lived integration or workflow data may have shorter configured periods. Deactivated user records may be preserved where needed to maintain the integrity of audit trails and historical assignments.
Backups are protected and expire according to backup schedules. When information is no longer required, we delete it, anonymize it, or isolate it from ordinary use unless continued retention is required or permitted by law. Browser-local drafts and preferences remain on the device until the feature or user clears them.
8. Security
We use administrative, technical and physical safeguards designed to protect information, including role-based access controls, authentication and multi-factor authentication capabilities, encryption in transit, encrypted storage and key management, audit logging, file validation and optional malware scanning, backup protections, and security monitoring. No method of transmission, storage or processing is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials, using approved devices and promptly reporting suspected unauthorized activity.
9. Your choices and privacy rights
Account information and communications
Depending on your permissions, you may review or update certain account details in the Service. You may opt out of promotional email using the instructions in the message or by contacting us; you will still receive necessary service, security and administrative messages. Contact your organization’s administrator to close an organization-managed account or address customer-controlled records.
U.S. state privacy rights
Subject to the law that applies to you and to available exceptions, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; learn about categories of information collected and disclosed; appeal a denied request; and use an authorized agent. You also may have rights to opt out of sale, targeted advertising, or certain profiling. Risk Vault does not sell personal information, use it for targeted advertising, or use personal information for profiling that produces legal or similarly significant effects.
EEA and UK rights
Risk Vault is a U.S. company with no establishment in the European Economic Area or United Kingdom and does not currently direct the Service to individuals there. If the GDPR or UK GDPR nevertheless applies to particular processing, individuals may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. Withdrawal of consent does not affect processing already performed lawfully.
Submitting a request
Email admin@rkvault.com or use the contact information below. Describe your request and the organization associated with your account. We may ask for information reasonably necessary to verify your identity, residency or authority, and we will use verification information only for that purpose. We will not discriminate against you for exercising an applicable privacy right. If we process the information solely for a customer, we may refer the request to that customer.
10. International data transfers
Risk Vault is headquartered in the United States, and information may be processed in the United States and other countries where we, our customers, or service providers operate. Those countries may have different privacy protections than your home jurisdiction. Where required, we use an approved transfer mechanism or other legally recognized safeguard. Customer deployment and integration choices may also affect processing locations.
11. Children
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children through the Service. If you believe a child has provided personal information contrary to this Policy, contact us so we can investigate and take appropriate action.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, our practices or applicable requirements. We will post the updated Policy and revise the effective date. If changes materially affect how we process personal information, we will provide additional notice through the Service, by email, or through another appropriate method before the change takes effect when required.
13. Contact us
For privacy questions, complaints, or rights requests, contact:
Risk Vault Technologies, Inc.
Attn: Privacy
12359 178th Place Northeast
Redmond, Washington 98052
Email: admin@rkvault.com
Telephone: (216) 414-9840
California residents may also contact the California Privacy Protection Agency for general information about California privacy rights. EEA or UK residents may lodge a complaint with the competent data-protection supervisory authority where applicable.