Legal
Privacy Policy
Last updated: August 2026
This policy explains what personal information Riskly collects, why we collect it, who we share it with, and the choices available under the Privacy Act 2020.
Who we are
Riskly Limited ("we", "us") operates the Riskly risk management platform for New Zealand SMEs. We comply with the Privacy Act 2020. Privacy enquiries: contact@riskly.co.nz.
When you use Riskly for your organisation, your organisation is typically the agency responsible for personal information it enters about workers, reporters, and others. We process that information to provide the Service on your organisation's behalf.
Information we collect
Depending on how you use Riskly, we may collect:
- Account and organisation: name, email, password (stored by our auth provider), organisation name, role, and invitation details
- Business profile: industry, size, activities, risk appetite, and related profile fields used to tailor suggestions
- Operational content: risks, controls, actions, calendar items, reports, obligations, and documents you create or upload
- Organisation chart: position titles and person names (and optional links to user accounts)
- Licences and certificates: holder names, licence details, expiry dates, and supporting files
- Health & safety: hazard and incident details (including location, notes, injury/near-miss outcomes where recorded), meeting attendees and notes, H&S documents, governance checklist information, and photos attached to records
- Organisation Reporting (public submissions): reporter name, optional contact details, hazard/incident details, and optional photos submitted via your organisation's public report link or code (without signing in)
- Billing: Stripe customer and subscription identifiers; card details are handled by Stripe and are not stored by Riskly
- Usage and support: audit logs of actions in the platform, notification preferences, and messages you send via our contact form
How we use information
We use information to:
- Provide, secure, and improve the Service
- Generate and refresh risk and control suggestions tailored to your profile
- Operate H&S, licences, calendar, actions, reports, and related features
- On Pro plans: monitor selected NZ legislation, send digests/alerts you enable, and support control testing
- Notify organisation contacts of public hazard/incident reports (where enabled)
- Process subscriptions, send transactional emails, and respond to support requests
- Meet legal obligations and protect the Service against misuse
Automated personalisation
Some features can use automated processing (including optional OpenAI models when configured) to personalise risk and control suggestions and to analyse process document text you upload. Business profile and related content may be sent to that provider for those features. If automated personalisation is unavailable, Riskly falls back to rule-based suggestions where possible. We do not use your organisation content to train our own models for unrelated customers, and we instruct providers not to use your data to train their models where that option is available.
Cross-border disclosure
Your organisation data is primarily stored in Australia (Supabase Sydney). Some processors may handle data in other countries (for example payment, email, or optional AI processing). Where personal information is disclosed overseas, we take steps consistent with the Privacy Act 2020, including using providers with appropriate contractual and security safeguards.
Your rights
Under the Privacy Act 2020, individuals have rights to access and request correction of their personal information. Organisation owners and admins can export organisation data from Settings, including member details (email, role, profile, and permission settings), registers, H&S records, licences, and related metadata (including while an account is locked after subscription end). Uploaded file binaries are not embedded in that download; storage paths are included where available.
To request access, correction, or deletion, contact contact@riskly.co.nz. If you are an individual whose information was entered by a customer organisation (for example a worker named on a licence or an incident reporter), we may need to refer you to that organisation as the primary agency for your request.
From 1 May 2026, where we collect personal information about someone other than from that person (indirect collection), we will take reasonable steps to ensure appropriate notice is given, including supporting customer organisations that collect such information through Riskly.
Notifiable privacy breaches
If a privacy breach occurs that is likely to cause serious harm, we will notify affected individuals and the Privacy Commissioner as required by law.
Data retention
We retain organisation data while your subscription is active. After a subscription ends, you have 30 days of Basic access, then the account is locked. We keep the data for 90 days from the cancel date to allow export or reactivation, then permanently delete the organisation record and associated stored files, unless a longer retention period is required by law or you ask us to delete sooner.
Contact-form messages and similar support correspondence may be kept as needed to respond to you and operate the business.
Contact
Privacy enquiries: contact@riskly.co.nz
Questions? Contact us or email contact@riskly.co.nz.