Privacy Policy
Last updated: 8 March 2026
RiskSight ("we", "us", "our") is operated by RiskSight Pty Ltd (ABN pending), based in Adelaide, South Australia. We are committed to protecting the privacy of your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information we collect
Account information
When you sign up for RiskSight, we collect your name, email address, organisation name, and role. If you subscribe to a paid plan, our payment processor (Stripe) collects your payment details. We do not store credit card numbers on our servers.
Usage data
We collect information about how you use the platform, including pages visited, features used, and actions taken. This helps us improve the product and provide support.
Risk and safety data
You may enter risk registers, incident reports, bowtie analyses, assessment data, and other operational risk information into the platform. This data belongs to you. We process it only to provide the service.
Website analytics
Our marketing website may use analytics tools to understand visitor behaviour. We use privacy-friendly analytics where possible and do not sell or share this data with advertisers.
2. How we use your information
We use your information to:
- Provide and maintain the RiskSight platform
- Process payments and manage subscriptions
- Send service-related communications (account alerts, product updates)
- Provide customer support
- Improve the platform based on usage patterns
- Power AI features (risk scoring, gap analysis) using your risk data within the platform only
- Comply with legal obligations
3. AI and your data
RiskSight includes AI-powered features that analyse your risk data to suggest scores, detect similar risks, and identify control gaps. Your data is processed by our AI systems solely to provide these features to you. We do not use your data to train general-purpose AI models. Your risk data is not shared with other customers or third parties.
4. How we share your information
We do not sell your personal information. We may share information with:
- Service providers who help us operate the platform (hosting, payment processing, email delivery), under strict data processing agreements
- Legal authorities if required by law, regulation, or legal process
- Business transfers in connection with a merger, acquisition, or sale of assets, with prior notice
5. Data storage and security
Your data is hosted on secure cloud infrastructure. We use encryption in transit (TLS) and at rest. Access to production systems is restricted and logged. We conduct regular security reviews.
While we take reasonable steps to protect your data, no system is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
6. Data retention
We retain your account and risk data for as long as your account is active. If you cancel your subscription, we retain your data for 90 days to allow for reactivation. After that, your data is permanently deleted. You can request earlier deletion by contacting us.
7. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your data
- Complain to the OAIC if you believe we have breached your privacy
To exercise these rights, contact us at hello@risksight.com.au.
8. Cookies
Our website uses essential cookies to maintain your session and preferences. We may use analytics cookies to understand website usage. You can control cookie settings in your browser.
9. International data transfers
Some of our service providers may process data outside Australia. Where this occurs, we ensure appropriate safeguards are in place consistent with the APPs. Details of our hosting locations are available on request.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or in-app notification. The "last updated" date at the top reflects the most recent revision.
11. Contact us
If you have questions about this privacy policy or how we handle your data:
RiskSight
Email: hello@risksight.com.au
Adelaide, South Australia
You can also contact the Office of the Australian Information Commissioner at oaic.gov.au or call 1300 363 992.