Legal

Data Processing Agreement

Last updated: July 2026
Processor: RiskBee Pty Ltd ("RiskBee", "we", "us")
Governing law: New South Wales, Australia

How this takes effect: This DPA is incorporated by reference into the RiskBee Terms of Service and applies automatically from the moment you create a workspace. No signature or countersignature is required. If your procurement process needs an executed copy, email privacy@riskbee.co.

Disclaimer: This document is maintained by RiskBee to answer common data protection questions. It is not legal advice and it is not an independent certification or audit report. You should have a qualified commercial lawyer review it against your own obligations.

1. Definitions and roles

"Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data" and "Processing" have the meanings given in the EU General Data Protection Regulation (GDPR). "Applicable Data Protection Law" means the GDPR, the UK GDPR, the Australian Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs), and any other privacy law applicable to a party's processing under this DPA.

You are the Controller. RiskBee is the Processor. RiskBee processes Personal Data only on your documented instructions, which consist of this DPA, the Terms of Service, and your use of the platform's features.

MSSP and vCISO workspaces. Where you operate managed client workspaces, you may act as Controller in your own right or as Processor on behalf of your client. In the latter case RiskBee acts as your Sub-processor, this DPA applies on equivalent terms down the chain, and you warrant that you hold the authority and consents required to instruct us in relation to your client's data.

2. Subject matter, duration, nature and purpose

Subject matter: provision of the RiskBee third-party risk management platform.

Duration: for as long as you hold an active RiskBee workspace, plus the retention period described in section 10.

Nature and purpose: hosting, storage, retrieval, analysis and transmission of vendor risk records, evidence documents, contracts, assessment responses and related notifications, including AI-assisted classification, extraction, scoring and summarisation of the material you submit.

3. Categories of data subjects and personal data

Data subjects: your staff and administrators; staff of the client organisations you manage; named contacts at the vendors you assess; individuals identified through customer-authorised identity provider discovery scans; and any individuals named in documents you upload.

Personal data: name, work email address, job title or role, avatar image, workspace role and permissions, authentication metadata, product usage and audit events, email delivery status, and the contents of uploaded documents, which may incidentally contain names, signatures and contact details.

Special categories: RiskBee is not designed for and must not be used to process special category data, unredacted health records, cardholder data or classified government data. Section 2 of the Terms of Service sets out the threshold at which a negotiated Master Services Agreement is required instead of this DPA.

4. RiskBee's obligations as Processor

  • Process Personal Data only on your documented instructions, including in relation to transfers, unless required otherwise by law, in which case we will inform you unless that law prohibits it.
  • Ensure personnel authorised to process Personal Data are bound by confidentiality obligations and access data on a least-privilege basis.
  • Implement the technical and organisational measures set out in Annex II.
  • Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations for security, breach notification and data protection impact assessments.
  • Inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
  • Not use your Personal Data, uploaded documents or assessment responses to train third-party AI models, and not sell Personal Data.

5. Sub-processing

You grant RiskBee general authorisation to engage the Sub-processors listed on our subprocessor register, which forms Annex III of this DPA and is maintained as a living page.

We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance. Before adding or replacing a Sub-processor we will update the register and give at least 30 days' notice by email to workspace owners. You may object in writing within that period on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected subscription without penalty for the remainder of its term.

6. International transfers

Personal Data may be processed in Australia, the European Union, the United Kingdom and the United States, depending on your workspace configuration and the Sub-processors engaged.

Where Personal Data subject to the GDPR is transferred outside the EEA to a country without an adequacy decision, the European Commission Standard Contractual Clauses (Module Two, Controller to Processor, or Module Three, Processor to Processor, as applicable) are incorporated into this DPA by reference and prevail in the event of conflict. Annex I and Annex II of this DPA populate the corresponding SCC annexes. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies. For Australian data, RiskBee takes reasonable steps under APP 8 to ensure overseas recipients handle Personal Data consistently with the Australian Privacy Principles.

7. Security measures

RiskBee maintains the technical and organisational measures described in Annex II below, and will not materially decrease the overall security of the service during the term.

8. Personal data breach

RiskBee will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of records affected where known, the likely consequences, and the measures taken or proposed. We will provide reasonable assistance with your own regulatory and data subject notifications. Notifications are sent to the workspace owner's email address and, where supplied, your designated security contact. Report a suspected issue to security@riskbee.co.

9. Assistance with data subject rights

The platform allows administrators to access, correct, export and delete workspace records directly. Where a data subject contacts RiskBee instead of you, we will refer them to you and will not respond substantively without your instruction, except as required by law. Requests can be sent to privacy@riskbee.co.

10. Retention, return and deletion

On termination or cancellation your workspace enters a read-and-export retention window, during which you may export your data from the platform. After that window RiskBee deletes or irreversibly anonymises the Personal Data, except where retention is required by law, in which case the data remains subject to the confidentiality and security terms of this DPA. Backups are removed on our standard rolling backup cycle. Written confirmation of deletion is available on request.

11. Audits and demonstration of compliance

RiskBee will make available the information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires, our security measures documentation, and available assurance reports from our infrastructure providers. You may request an audit no more than once in any twelve-month period, on reasonable notice, subject to confidentiality, conducted remotely and at your cost, and scoped so as not to compromise the confidentiality of other customers. On-site audits apply only where a supervisory authority requires them.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in section 7 of the Terms of Service. Where this DPA conflicts with the Terms of Service in relation to the processing of Personal Data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.

Annex I - Parties and processing details

Data exporter: the Customer identified in the RiskBee workspace account, acting as Controller, or as Processor for its managed clients.

Data importer: RiskBee Pty Ltd, New South Wales, Australia, acting as Processor. Contact: privacy@riskbee.co.

Frequency of transfer: continuous, for the duration of the subscription.

Categories of data and data subjects: as set out in section 3.

Competent supervisory authority (for SCC purposes): the supervisory authority of the EEA member state in which the data exporter is established, or the authority identified under Clause 13 of the SCCs.

Annex II - Technical and organisational measures

  • Encryption: all data encrypted in transit with TLS and at rest at the storage layer.
  • Tenant isolation: row-level security policies enforce workspace boundaries at the database level, so records are only readable by members of the owning organisation.
  • Access control: role-based permissions within each workspace, least-privilege internal access, multi-factor authentication on administrative access, and access review on staff changes.
  • Authentication: email and password with strength enforcement, plus optional single sign-on with Microsoft Entra ID and Google Workspace.
  • Logging: append-only audit records for security-relevant and state-changing events, scoped per workspace.
  • Secrets management: credentials and API keys held in managed secret storage, never in application source code, and rotated on suspected exposure.
  • Secure development: automated dependency scanning, automated security review of changes, and remediation of critical findings before release.
  • Resilience: managed automated backups of the production database with point-in-time recovery available from the infrastructure provider.
  • Egress controls: server-side request filtering on document and trust centre fetching to prevent access to internal networks.
  • Sub-processor governance: published register, contractual data protection terms, and advance change notice as described in section 5.

Annex III - Sub-processors

The current list is maintained, and available on request, at riskbee.co/subprocessors.