Skip to content
RiskAssureTrust operations
PrivacyTerms

Legal

Privacy Policy

Last updated 4 August 2026 · RiskAssure is operated by WISR AI Systems

Who we are

RiskAssure is operated by WISR AI Systems (“we”), a company incorporated in Canada. We are the controller of the personal information described here. For any privacy question, or to exercise the rights below, contact [email protected].

What we collect

When you create an account we collect your first and last name, email address, company name and company domain. If you upload documents to your workspace or Trust Center, we store those documents and the text extracted from them.

If you request access to another company’s Trust Center, that company receives your name, email address and stated company so they can decide whether to grant access.

We record operational events — page views, document downloads, access requests, chat messages — so account owners can see how their Trust Center is being used.

We do not collect payment card details. We do not use advertising cookies or third-party trackers.

Assessment data is not personal information

Our risk assessments are built from publicly available sources about companies — certificate transparency logs, DNS records, published vulnerability databases, breach registries and news coverage. This is information about organisations, not individuals.

Why we use it, and on what basis

We use your account information to operate the service, authenticate you, and send transactional email (address verification, password resets, and notifications when someone requests access to your Trust Center). Where GDPR applies, our basis is performance of a contract; for security logging it is our legitimate interest in keeping the service safe.

We do not sell personal information, and we do not send marketing email without separate consent.

Who else processes your data

We use a small number of sub-processors:

  • Amazon Web Services (Canada, ca-central-1) — hosting, database and document storage
  • Amazon SES — transactional email delivery
  • OpenAI — powers the AI assistant. Content you send to the assistant, including text from documents you select, is transmitted to OpenAI to generate a response
  • Cloudflare — DNS and content delivery

Your data is stored in Canada. Sending content to OpenAI may involve processing in the United States.

How long we keep it

Account information is retained while your account is open and deleted within 30 days of closure. Documents are retained until you delete them. Trust Center visitor records and analytics are retained for 24 months. Security logs are retained for 90 days.

Your rights

You may request access to, correction of, or deletion of your personal information, and may ask us to export it in a portable format. Under GDPR you may also object to or restrict processing. Email [email protected] and we will respond within 30 days.

If you are in Canada and are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. In the EEA or UK, you may complain to your local supervisory authority.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and authenticated. We are not currently SOC 2 or ISO 27001 certified, and we do not claim to be.

Changes

If we make a material change we will update the date at the top of this page and notify account holders by email before it takes effect.

Terms of ServiceBack to RiskAssure

Questions about either document? [email protected]