Legal
Privacy Policy
Last updated: September 2026
This policy explains what personal information Riskly collects, why we collect it, who we share it with, and the choices available under the Privacy Act 2020.
Who we are
Riskly Limited ("we", "us") operates the Riskly risk management platform for New Zealand SMEs. We comply with the Privacy Act 2020. Privacy enquiries: contact@riskly.co.nz.
When you use Riskly for your organisation, your organisation is typically the agency responsible for personal information it enters about workers, reporters, and others. We process that information to provide the Service on your organisation's behalf.
Information we collect
Depending on how you use Riskly, we may collect:
- Account and organisation: name, email, password (stored by our auth provider), organisation name, role, and invitation details. If you enable MFA, we store authenticator factors, recovery codes, and trusted-device records through our auth provider. When SSO is enabled, sign-in may receive identity attributes from your organisation's identity provider
- Business Profile: organisation or enterprise name, industry, employee count, annual turnover band (GST turnover), and risk appetite by category. Industry, headcount, and appetite are used to tailor suggestions. Annual turnover is stored with your organisation record and is not used for those suggestions
- Operational content: Risks & Controls (including documents and processes), Calendar items, actions, Reports, activity log entries, and other records you create or upload
- Sites and locations: site or location names you add for filtering registers
- Organisation chart: position titles and person names (and optional links to user accounts)
- Licences, certificates, and training: holder names, licence or training details, expiry dates, and supporting files
- Health & Safety: hazard and incident details (including location, notes, injury and near-miss outcomes where recorded), Engagement records (including attendees and notes), H&S documents, Governance checklist information, and photos attached to records
- Organisation Reporting (public submissions): reporter name, optional contact details, hazard or incident details, and optional photos submitted via your organisation's public report link or code (without signing in)
- Pro assurance, legislation, and testing (where your plan includes them): Assurance activities, provider reports and engagement documents, findings register entries, remediation and validation notes, validation evidence files, and links to risks, controls, or obligations; Legislation watchlist, Monitoring work queue items, act checks, What You Must Do, obligation review records; Control Testing schedules, results, and evidence files
- Integrations (when enabled): organisation or personal calendar feed tokens and subscription URLs; Slack or Microsoft Teams webhook URLs; provider choice (Slack or Teams); and whether chat notifications are turned on. When chat notifications fire, we send a short summary of the hazard or incident (such as title, site, severity where recorded, and a link back to Riskly) to the webhook you configured
- Billing: Stripe customer and subscription identifiers; card details are handled by Stripe and are not stored by Riskly
- Enquiries and contact: name, email, optional company name, message, and any optional fit-check or intended-use selections you send through our contact form or by email to us
- In-app support: audit logs of actions in the platform, in-app notification records and read state, notification preferences, and reports you submit through Report an issue (including your account email and organisation context attached by the Service)
- Error monitoring: technical diagnostic information when the Service fails or throws an error, such as error type and message, stack trace, browser and device details, page URL, organisation identifier, subscription tier, and user role. We do not send register content, passwords, or payment card details to our error monitoring provider
- SSO setup requests: work email domain, optional identity provider metadata URL, optional notes, and your account and organisation context when you request organisation SSO setup from Settings
- Content complaints: your name, email, optional phone, optional organisation hint, and the details you provide about reported content when you use our Report harmful or illegal content form or email us a complaint
How we use information
We use information to:
- Provide, secure, and improve the Service
- Generate and refresh risk and control suggestions tailored to your profile
- Operate Home, Risks & Controls, Health & Safety, licences, certificates, and training records, Calendar, actions, Reports, global search, and related features
- On Pro plans: track assurance engagements and findings, monitor selected NZ legislation through the Monitoring work queue, support act checks and What You Must Do, and support Control Testing
- Send emails you enable or that are needed to run the Service, including This week's outlook (Monday digest), weekday follow-up reminders, licence and training expiry notices, Health & Safety public-report alerts, scheduled report packs, organisation invites, and trial notices
- Show in-app notifications you enable (for example H&S alerts, follow-up reminders, licence and training expiry, and Pro legislation alerts)
- Notify organisation contacts of public hazard or incident reports (where enabled)
- Deliver optional calendar feed subscriptions and Slack or Microsoft Teams chat notifications you configure under Settings → Integrations
- Process subscriptions, send other transactional emails, and respond to support requests
- Respond to contact and sales enquiries, and follow up where reasonable about Riskly (for example to answer questions, arrange a demo, or check whether you still need help)
- Acknowledge and process content complaints, including under our harmful digital communications obligations
- Respond to organisation SSO setup requests and coordinate configuration with you or your IT team
- Detect, diagnose, and fix errors and reliability problems in the Service
- Meet legal obligations and protect the Service against misuse
Harmful or illegal content
Where Riskly hosts content posted by others (for example Organisation Reporting submissions), we operate a complaints process aligned with New Zealand online content host obligations, including under the Harmful Digital Communications Act 2015. We do not proactively monitor private organisation records for illegal activity.
When you submit a complaint, Riskly collects your contact details and the information you provide about the content so we can acknowledge your report, follow the statutory process, and contact you if we need clarification.
To complain about unlawful or harmful content on the platform, use our Report harmful or illegal content form or email contact@riskly.co.nz with:
- Your name and contact details
- Enough detail to locate the specific content
- Why you consider it unlawful, or which communication principles it breaches and the harm caused
Organisation customers remain responsible for workplace content they and their reporters submit; complaints about a specific employer's records may be referred to that organisation.
Cross-border disclosure
Your organisation data is primarily stored in Australia (Supabase Sydney). Some processors may handle data in other countries (for example payment, email, and error monitoring in the European Union). Where personal information is disclosed overseas, we take steps consistent with the Privacy Act 2020, including using providers with appropriate contractual and security safeguards.
Your rights
Under the Privacy Act 2020, individuals have rights to access and request correction of their personal information. Organisation owners and admins can export organisation data from Settings → Data & privacy, including member details (email, role, profile, and permission settings), Risks & Controls, Health & Safety records (including governance reviews), licences and certificates, Calendar, actions, Reports, activity log, notification preferences, Pro assurance, legislation, and Control Testing data where present, and related metadata (including while an account is locked after subscription end). Uploaded file binaries are not embedded in that download; storage paths are included where available.
You can delete your sign-in account from Settings → Security when you no longer own an organisation. Organisation owners can delete an organisation from Settings → Data & privacy. Members who are not owners can leave an organisation from the same page.
To request access, correction, or deletion we cannot complete in the product, contact contact@riskly.co.nz. If you are an individual whose information was entered by a customer organisation (for example a worker named on a licence or an incident reporter), we may need to refer you to that organisation as the primary agency for your request.
Where we collect personal information about someone other than from that person (indirect collection), we take reasonable steps to ensure appropriate notice is given, including supporting customer organisations that collect such information through Riskly.
Notifiable privacy breaches
If a privacy breach occurs that is likely to cause serious harm, we will notify affected individuals and the Privacy Commissioner as required by law.
Data retention
We retain organisation data while your subscription is active. After a subscription ends, you have 30 days of Basic access, then the account is locked. We keep the data for 90 days from the cancel date to allow export or reactivation, then permanently delete the organisation record and associated stored files, unless a longer retention period is required by law. Organisation owners and account holders can delete sooner using the tools in Settings.
Contact-form messages, content complaints, SSO setup correspondence, and similar support messages may be kept as needed to respond to you, follow up on enquiries, and operate the business.
Contact
Privacy enquiries: contact@riskly.co.nz
Questions? Contact us or email contact@riskly.co.nz.