Legal

Privacy Policy

RiskBee is built for MSSPs, vCISOs, and mid-market security teams who handle sensitive vendor data on behalf of their clients. This page explains what we collect, why we collect it, how long we keep it, and the rights you have over it.

What we collect

Account data (name, work email, company), the vendor and assessment records you enter or upload into your workspace, and product telemetry needed to keep the platform reliable and secure. We do not sell personal data, and we do not use client vendor data to train third-party AI models.

Why we collect it

To deliver the RiskBee service to you, meet legal and audit obligations, secure the platform, and improve the product. Our lawful bases under GDPR are contract, legitimate interest, and consent where required.

Where data lives

Application data is stored in an EU or US region depending on your workspace choice, encrypted in transit and at rest. Subprocessors are limited to the infrastructure, email, and analytics providers listed in our processor register, available on request.

Your rights

You can request access, correction, export, or deletion of the personal data we hold about you. MSSP administrators can export or delete client workspace data at any time from settings. Contact privacy@riskbee.co for data-subject requests.

Updates

The definitive, versioned policy lands before general availability. Material changes will be announced by email to workspace owners at least 30 days before they take effect.