Back to RiskIQ AI

Privacy Notice

Last updated: 1 September 2026

1. Who we are

This Privacy Notice is provided by Deepesh Verma and Company, the operator of the RiskIQ AI platform ("RiskIQ AI", "we", "us"). Deepesh Verma and Company is the data controller for the personal data described in this notice.

2. Personal data we collect

  • Account data: name, email address and login credentials.
  • Support and sales data: messages you send us, including contact-sales enquiries.
  • Usage and telemetry data: pages visited, features used, audit events, IP address, device and browser identifiers.
  • Customer content: borrower, financial and document data (including bank statements) that your organisation uploads for assessment.

3. How we use personal data

  • Creating and managing your account (contract performance).
  • Providing the RiskIQ AI assessment service (contract performance).
  • Security, fraud prevention and audit logging (legitimate interests).
  • Product improvement and analytics (legitimate interests).
  • Customer support and sales follow-up (legitimate interests / consent).
  • Meeting legal and regulatory obligations (legal obligation).

4. Who we share personal data with

  • Service providers and subprocessors (hosting, analytics and support tooling).
  • Paddle, our Merchant of Record, for sale of the product, subscription management, payments, tax compliance and invoicing.
  • Professional advisers (legal and accounting) where needed.
  • Authorities where required by law.

5. Retention

We keep personal data only for as long as needed for the purposes above, including legal and accounting requirements. When no longer needed, data is deleted or anonymised.

6. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. To exercise these rights, contact us using the details on this site. If you are in the UK or EEA, you may also complain to your supervisory authority; we respond to requests within one month.

7. Security

We apply appropriate technical and organisational measures, including encryption in transit, access controls and role-based permissions, to protect personal data.

8. Cookies

We use essential cookies required for authentication and security. We do not use marketing cookies. You can control cookies through your browser settings; disabling essential cookies may prevent sign-in.