Privacy Policy
This notice explains how Riskonami processes personal data. Version
2026-08-12. This is a product draft pending counsel
review.
1. Controller
Musmato BV (Netherlands) is the controller for Riskonami account and platform data. Contact us via the contact page.2. What we collect
- Account: email (from Google/Microsoft sign-in), name, role, organisation links, billing references, and consent records (Terms/Privacy version accepted).
- Assessment content: session data, uploads, worksheets, reports, and related logs you create while using the product.
- Technical / ops: authentication events, system logs, support requests, and usage metrics needed to run and secure the service.
- Payments: handled by Stripe; we store entitlement and provisioning metadata, not full card numbers.
3. Why we process data
- Provide and secure the service (contract / legitimate interests).
- Create and manage your account when you sign in (contract).
- Record Terms and Privacy acceptance (legal obligation / contract).
- Process purchases and entitlements (contract).
- Improve reliability and detect abuse (legitimate interests).
- Comply with law and respond to support requests.
4. AI enrichment subprocessors
If you consent to AI enrichment inside an assessment, bounded prompts and relevant assessment context are sent to our model provider (currently OpenAI) to generate proposals. Those calls are transient for inference; Riskonami keeps the system of record in EU-hosted storage. You can skip enrichment on free/manual paths where the product allows.5. Where data is hosted
Application data and files are hosted on Google Cloud in the EU (typicallyeurope-west4). Authentication uses Google and/or Microsoft identity providers.6. Retention
Product policy targets (may be automated):| Context | Target retention after last activity |
|---|---|
| Forever-free / unpaid inactive sessions | 90 days, then purge |
| Paid entitlements / paid customers | 12 months after last activity / entitlement end unless a contract says otherwise |