Privacy Policy
Effective date: 1 January 2026 · Last updated: 13 June 2026
1. Introduction
RiskLex ("we", "our", "us") is committed to protecting the privacy of individuals who use our AI-powered financial crime intelligence platform. This Privacy Policy explains what personal data we collect, how we use it, and your rights in relation to it. It applies to all users of the Platform, including registered account holders and visitors to our public website.
2. Data We Collect
We collect the following categories of personal data:
- Account data: Name, work email address, job title, organisation name, and region, provided when you register or update your profile.
- Usage data: Pages visited, features used, analysis queries submitted, session duration, and interaction logs collected automatically when you use the Platform.
- Technical data: IP address, browser type and version, device identifiers, operating system, and referral source.
- Payment data: Billing name, payment method type, and transaction records. Full card details are processed directly by our payment provider (Stripe) and are never stored by us.
- Customer Data: Case narratives, scenario descriptions, or other content you submit as inputs to Platform analysis features. This may incidentally contain personal data relating to third parties; you are responsible for ensuring you have a lawful basis to submit such data.
- Communications data: Messages you send us via email or in-platform support channels.
3. How We Use Your Data
We use personal data to:
- Create and manage your account and deliver Platform services.
- Process payments and manage your subscription.
- Send transactional communications such as verification emails, billing notices, and security alerts.
- Provide customer support and respond to enquiries.
- Improve the Platform through aggregate analysis of usage patterns (no individual profiling for marketing).
- Comply with legal and regulatory obligations, including financial crime prevention laws.
- Detect and prevent fraud, abuse, and security incidents.
4. Legal Bases for Processing
We process personal data in accordance with applicable Canadian and US privacy laws, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, and US state privacy laws including the California Consumer Privacy Act (CCPA) where applicable. We rely on the following bases:
- Contract: Processing necessary to provide the Platform services you have subscribed to.
- Legitimate interests: Security monitoring, fraud prevention, and Platform improvement, where these interests are not overridden by your rights.
- Legal obligation: Compliance with applicable laws and regulatory requirements.
- Consent: Where we send optional marketing communications; you may withdraw consent at any time.
5. Data Retention
We retain account data for the duration of your subscription and for up to 3 years after termination for audit and legal compliance purposes. Usage and technical data are retained for up to 12 months. Customer Data submitted to analysis features is retained for as long as your account is active and deleted within 90 days of account closure, unless a longer retention period is required by law.
6. Sharing Your Data
We do not sell your personal data. We may share it with:
- Service providers: Cloud hosting, email delivery, payment processing (Stripe), and analytics tools engaged under data processing agreements.
- AI model providers: Inputs to AI analysis features may be processed by third-party AI providers (e.g. OpenAI) under data processing agreements. We configure these providers to not use your data for model training.
- Legal authorities: Where required by court order, law enforcement request, or applicable regulation.
- Business transfers: In the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.
7. International Transfers
We primarily store and process data within Canada and the United States. Where data is transferred outside these countries (e.g. to third-party cloud or AI providers in other regions), we ensure appropriate safeguards are in place, including contractual protections consistent with PIPEDA and applicable US state privacy laws.
8. Cookies
We use strictly necessary cookies to maintain your authenticated session. We do not use third-party advertising or tracking cookies. You can control cookies through your browser settings; however, disabling session cookies will prevent you from using authenticated Platform features.
9. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where processing is no longer necessary.
- Restriction of processing in certain circumstances.
- Portability of data you have provided to us in a structured, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent where processing is consent-based.
To exercise any of these rights, contact us at privacy@risklexicon.com. We will respond within 30 days.
10. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security assessments. No method of transmission over the internet is completely secure; we cannot guarantee absolute security but we take all reasonable precautions to protect your data.
11. Children's Privacy
The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-platform notice before taking effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
13. Contact & Complaints
For privacy-related questions or to exercise your rights, contact our Data Protection team at privacy@risklexicon.com.
If you are based in Canada, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca. If you are based in the United States, you may contact the Federal Trade Commission (FTC) or your applicable state Attorney General's office.