Legal
Privacy Policy
Version 0.1-draft · Last updated 6 July 2026
This Privacy Policy explains how PE Risk Profiler (“we”, “us”, “our”) collects, uses, and discloses personal data when you use the Service. It applies to visitors and account holders wherever they are located, with additional sections below for users in the UK/EEA and users in the United States.
1. Who we are
PE Risk Profiler is operated by [Legal entity name to be confirmed]. For data protection purposes, we act as the controller of the personal data described in this policy, except for third-party personal data entered by users into free-text assessment fields, which is addressed separately in Section 4.
2. What we collect
- Account data: the email address you sign up with, and your password (stored as a salted hash by our authentication provider — we never see or store your password in plain text).
- Assessment data: your answers to the guided questionnaire, including any free-text answers, the resulting risk assessment (risk level, narrative, dimension scores, triggered concerns), and any supplementary answers you provide for re-assessment.
- Feedback data: ratings and comments you submit through the in-app feedback form.
- Referral data:your referral code and, if you signed up via someone else's referral link, a record of that relationship.
- Usage and log data: basic technical logs (e.g. timestamps, error logs) generated by our hosting and infrastructure providers in the ordinary course of running the Service.
We do not ask for your name, job title, or company name at signup, and we do not currently collect payment information (the Service is free during early access).
3. How we use it
- To create and maintain your account and authenticate you.
- To run your assessment answers through our AI evaluation service and generate your risk profile.
- To save your progress so you can resume an in-progress assessment.
- To send transactional emails (e.g. confirming your email address).
- To operate the referral program, if you choose to use it.
- To improve the Service, using feedback you choose to submit.
- To maintain the security and integrity of the Service.
4. Third-party personal data in free-text answers
Important — read before entering free text
Please describe roles and activities in general terms(e.g. “a local sales agent”) rather than naming individuals. You are responsible for any personal data about others that you choose to submit.
5. Who we share it with (sub-processors)
We use a small number of third-party service providers (“sub-processors”) to operate the Service. This disclosure applies regardless of whether we hold a formal Data Processing Agreement with you — we do not act as a processor of your business' data for you (see Section 6), but we are still required to disclose who processes personal data on our behalf.
Anthropic — AI evaluation (required disclosure)
- Supabase — database, authentication, and file storage. Our project is hosted in the EU West region.
- Vercel — application hosting and content delivery.
- Resend — transactional email delivery (sent from the perisk.tax domain).
We do not sell personal data, and we do not share personal data with third parties for their own marketing purposes.
6. Why we don't have a Data Processing Agreement (DPA) with you
We only collect an email address directly from you at signup — we are not processing your business' customer or employee data on your behalf as a processor, so a DPA between us in that sense is not required at this stage. However, as explained in Section 4, your free-text answers can contain personal data about third parties, and Section 5 discloses where that data goes. If our processing role changes as the Service develops, we will update this policy and put appropriate agreements in place.
7. Data retention
We retain account and assessment data for as long as your account is active, plus a reasonable period afterwards to comply with legal obligations, resolve disputes, and enforce our agreements. You can request deletion of your account and associated data at any time — see Section 10.
8. Security
We use industry-standard measures to protect personal data, including encryption in transit, access controls, and row-level security policies restricting each user to their own assessment data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Cookies
We use essential cookies required to keep you signed in. See our Cookie Policy for details.
10. Your rights and how to exercise them
Regardless of where you are located, you can ask us to access, correct, or delete your personal data, or ask questions about how it is used, by contacting [privacy contact email to be confirmed — suggested: privacy@perisk.tax]. The sections below describe additional, legally-specific rights that may apply to you.
UK and EEA users
If you are located in the UK or the European Economic Area, we process your personal data under the UK GDPR (and, where applicable, the EU GDPR) on the following legal bases: performance of a contract (to provide the Service you signed up for), legitimate interests (to operate, secure, and improve the Service), and consent (for optional features such as the referral program). You have the right to access, rectify, erase, or restrict processing of your personal data, to data portability, and to object to processing based on legitimate interests. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local EEA data protection authority.
United States users
If you are a resident of a US state with a comprehensive privacy law (such as California), the following applies. In the preceding 12 months we have collected the categories of personal information described in Section 2 for the business purposes described in Section 3. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. You may have the right to know what personal information we hold about you, to request its deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. To make a request, contact us using the details in Section 10; we may need to verify your identity before completing certain requests. [State-specific detail to be reviewed by counsel before this section is relied on for any specific state beyond a general good-faith disclosure.]
11. Children's privacy
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18.
12. Changes to this policy
We may update this policy from time to time. Each version is labelled with a version number and a “last updated” date at the top of this page. For material changes, we will seek renewed acceptance before you can continue using the Service.
13. Contact
Questions about this policy, or requests relating to your personal data, can be sent to [privacy contact email to be confirmed — suggested: privacy@perisk.tax].
A note on where this document stands
This page has been drafted to satisfy the requirements identified in our internal legal scoping document — most importantly, the Anthropic sub-processor disclosure in Section 5, which is a hard requirement regardless of DPA status. It covers UK/EEA and US users because that is the current expected beta cohort. It has not yet been reviewed by a lawyer. Bracketed placeholders (legal entity name, transfer mechanism, contact emails) need confirming, and the US-state section in particular is a general good-faith disclosure rather than a jurisdiction-by-jurisdiction legal analysis — it should be reviewed by counsel before being relied on, especially if the beta cohort expands beyond a small number of US states.