Last updated 10 September 2026
Risk Ledger is a global service provider and collects and processes Personal Data relating to individuals in different locations. Risk Ledger strives to manage personal data appropriately and with regard to local differences in applicable regulation. This Privacy Policy applies to Risk Ledger's processing of Personal Data globally.
Risk Ledger commits to processing your personal data fairly, securely and in a way compatible with purposes for which it was collected.
Risk Ledger does not 'sell' personal information, nor do we 'share' personal information for cross-context behavioral advertising.
Unless definitions are provided below, all terms starting with a capital letter shall have the meaning defined in Risk Ledger Terms of Use.
Risk Ledger Ltd. is a Data Controller of Risk Ledger Service Users' Personal Data.
The information below indicates the different purposes for which your Personal Data may be processed as a Risk Ledger Service User, as well as the categories of Personal Data processed, the legal basis on which the processing is based, categories of Personal Data recipients, and information about the period for which we process your Personal Data for the particular processing purpose (the retention period).
In addition to the purposes listed below, Risk Ledger may also process personal data as required by applicable law.
Analytics of user behaviour within the Risk Ledger product.
Manual analysis of customer usage of Risk Ledger product and communication with the customer by Success Managers.
Categories of Personal Data
Legal basis
Processing is necessary for legitimate interests pursued by Risk Ledger (to provide Risk Ledger Services to Customers; to enhance user experience; to improve, develop and administer Risk Ledger products and services)
Categories of Recipients
Retention
Duration of Customer relationship
Analysing registration, usage, access, and other metrics across Risk Ledger systems; identifying and assessing suspicious activity suggesting fraudulent use of the services or account takeover; implementing proactive and reactive security measures.
Categories of Personal Data
Legal basis
Processing is necessary for legitimate interests pursued by Risk Ledger (to provide Risk Ledger Services securely, as contracted between Risk Ledger and its Customers; ensure lawful use and prevent fraudulent activities on the Risk Ledger platform).
Categories of Recipients
Retention
Duration of Customer relationship
Preparation of invoices based on a customer's usage of the Risk Ledger product.
Categories of Personal Data
Legal basis
Processing is necessary for legitimate interests pursued by Risk Ledger (to be able to bill Risk Ledger Services based on usage of Risk Ledger services, as contracted between Risk Ledger and the Customer)
Categories of Recipients
Retention
Duration of Customer relationship plus seven years
Administration of billing and cash collection, including handling requests from customers regarding payments and invoices and any other billing-related requests.
Categories of Personal Data
Legal basis
Processing is necessary for legitimate interests pursued by Risk Ledger (to be able to claim payment of outstanding invoices)
Categories of Recipients
Retention
Duration of Customer relationship plus seven years
Personal data storage for potential questions, disagreements, disputes or claims, and its use to help resolve any question, disagreement, dispute or claim that may arise as required by English law and regulation.
Categories of Personal Data
Legal basis
Processing is necessary for legitimate interests pursued by Risk Ledger (to be able to initiate or respond to questions, disagreements, disputes or claims)
Categories of Recipients
Retention
Up to 6 years following termination of Customer relationship or as advised or directed by legal or regulatory authorities.
Risk Ledger is obliged by the laws of certain countries to:
For this reason, we collect and store the required data for statutory period.
Categories of Personal Data
Legal basis
Categories of Recipients
Retention
If you are a Site Visitor, the Personal Data we process about you are the cookies and similar online identifiers (further on collectively referred to as "cookies").
Please note that the information in this Section only applies to Risk Ledger's usage of cookies on the Site. If you are a Risk Ledger Service User and you access Risk Ledger Services via a browser, Section 1 of this Privacy Policy (Risk Ledger Service User's Personal Data Processing) applies. Risk Ledger's cookie usage as per this Section does not apply to you when you are signed in to your Risk Ledger Service User account and you access the Risk Ledger Services via a browser.
The Data Controller of Site Visitors' cookies is Risk Ledger Ltd. The identity and the contact details of Risk Ledger can be found at the end of this page.
Cookies are alphanumeric identifiers or trackers that are transferred to the device you use to access the Services via your browser. Cookies are widely used to make websites work, or work more efficiently, as well as to provide additional features for a better user experience and to provide information to site owners.
Risk Ledger uses both its own and third-party cookies, including:
Further details about cookies are provided in Section 5 (Other recipients of the shared Personal Data).
At your first visit to the Site, a cookie banner will appear, unless you're visiting the Site from the Americas (if you are visiting the Site from the Americas, please see the section "How do I change my cookie settings?" below). The cookie banner allows you to express your cookie choice for statistical, marketing and personalisation cookies:
The strictly necessary (technical) cookies are automatically deployed to the device upon your first visit to the Site. We do not provide you with options for this cookie type, as disabling these cookies would affect how the Site functions. You may still disable these cookies in your browser settings (see the next paragraph).
We encourage you to check and manage your cookie preferences at any time by clicking on the "Cookies" link at the bottom of the Site. The cookie banner will reappear and you can update your cookie choices from there.
Note: Changes will be applied when you navigate to a different page on the Site or you refresh your browser tab.
Alternatively, most web browsers allow some control of most cookies through the browser settings. The default settings for Internet browsers are usually set to accept cookies, but you can easily change your browser's settings.
For more information, please visit: http://www.aboutcookies.org/
Risk Ledger Ltd. is the Data Controller for requests or complaints regarding the processing of your Personal Data in relation to Risk Ledger's outbound sales development and marketing activities. In the Americas, Risk Ledger Inc. acts as the primary Data Controller.
If we contact you with an email marketing campaign and/or as a part of our outbound sales development activities, it means we have your contact details listed in our database for these purposes. We collect contact details for our database from the following sources:
You can find an "Unsubscribe" link in every email marketing communication sent by Risk Ledger. Using this link is a reliable way to make sure we do not contact you with marketing emails anymore. Please note that it may take us up to 3 working days to process your "Unsubscribe" choice, so you may receive other marketing emails from us in the meantime. Thank you for understanding. You can manage your email preferences more generally by requesting a preference management link at https://www.riskledger.com/manage-your-email-preferences.
If we call you as a part of Risk Ledger's outbound sales development activities, you can inform our outbound sales representative that you do not wish to be contacted in this way anymore at any time. We will make sure not to call you again.
You can contact data@riskledger.com at any time to request us to remove your details from our Lead database.
When we process your data as a Lead—depending on your particular circumstance—we use all or just some of the following Personal Data:
We also use certain data about your company, such as company size and whether you or your company is a Risk Ledger Customer.
The information below indicates the different purposes your Personal Data as a Lead may be processed by Risk Ledger, the legal basis on which we conduct the processing, categories of their recipients, and information about the period for which we process your Personal Data for the particular processing purpose (the retention period).
Legal basis
To the extent that our activities are regulated by UK and EU laws (typically if you are an EEA resident) and if you are a Risk Ledger Customer, we have a legitimate interest to contact you within our email marketing campaigns. We have a strong belief that you want to be informed about news related to our product and services, as you already benefit from them. mails to personal/non-work email addresses rely on your consent, which you can withdraw at any time.
Categories of Recipients
Retention
3 years following the termination of a customer relationship (if you are/were Risk Ledger's customer) or, if sooner, after you unsubscribe to all marketing communications (though we retain communications logs and your unsubscribe request indefinitely).
If we believe that Risk Ledger products and services may suit the needs of your company, our outbound sales representative may email and/or call you to discuss our product with you.
Legal basis
We have a legitimate Interest to contact you within our outbound sales development activities. These activities are a form of direct marketing, where we carefully choose whether we will contact you or not by assessing potential benefits of Risk Ledger products and services for your company. We have a strong belief that your company may benefit from our communication.
Categories of Recipients
Retention
After you unsubscribe to all marketing communications (though we retain communications logs and your unsubscribe request indefinitely).
We perform internal data analysis to have better overall information (aggregate statistics) about our Customers and Leads and a better understanding of the market, to better address their needs.
Legal basis
We have a legitimate interest to perform internal analysis. We have a strong belief that where we are able to better target our communication and suit our product and services to your needs, you will ultimately benefit more from that needs analysis.
Categories of Recipients
Retention
After you unsubscribe to all marketing communications (though we retain communications logs and your unsubscribe request indefinitely).
The information below indicates the purpose for which Risk Ledger may process your Personal Data as a Candidate, as well as the different categories of Personal Data processed, the legal basis for processing, categories of recipients, and information about the period for which we process your Personal Data for the particular processing purpose (the retention period). In addition to the purposes listed below, Risk Ledger may also process personal data as required by applicable law.
Role application information may be provided to us directly from the Candidate or from an agent acting on the Candidate's behalf. The information is processed to assess the Candidate's suitability for defined role requirements and to progress the Candidate through the recruitment or contracting process.
Categories of Personal Data
Legal basis
We conduct this processing on the basis of our legitimate interest in finding and selecting the most suitable candidates to join our team.
Categories of Recipients
Our applicant tracking system provider, background check service providers used in the assessment process, and our business communication/storage providers.
Retention
Only our personnel and our contracted third party service providers may process your Personal Data.
Personal Data may also be disclosed in response to lawful requests made by government agencies or public authorities—including public officers—to meet national security, law enforcement, or any other legal requirements.
Depending on where you are located, we might have to enforce local regulations and requirements in the event we should receive an official request from a competent local authority.
Read more: Third party Data Processors of information we receive as a Data Processor
Amazon Web Services
Purpose: Cloud hosting provider for the Risk Ledger platform
Location: Europe
Google
Purpose: Google Workspace; used for internal business operations, including email
Cloud hosting and inference for the Risk Ledger platform
Location: Europe
Microsoft Ireland Operations Limited
Purpose: Document management
Location: Europe
Intercom Inc.
Purpose: Customer support chat function
Location: Europe
Notion
Purpose: Used for internal business operations, including Service
Location: United States
Planhat AB
Purpose: Customer support
Location: Sweden
Anthropic Ireland, Limited
Purpose: Inference and workflow management
Location: Ireland
Linear Orbit, Inc.
Purpose: Product and project management
Location: United States
Aircall SAS
Purpose: Contact communications
Location: Europe
Gong
Purpose: Service User and Lead communications
Location: United States
Hubspot
Purpose: Lead management
Location: United States
Slack Technologies LLC
Purpose: Internal Business Communication
Location: Europe
Segment.io Inc.
Purpose: Platform & Analytics (Frontend)
Location: United States
LogRocket Inc.
Purpose: Platform & Analytics (Frontend)
Location: United States
Salesforce Inc.
Purpose: Customer support / Contact communications
Location: Europe
Read more: Third Party Cookies
Google Doubleclick
Data processed: Site visitors' device/browser data (cookie metadata)
Purpose: Check for permission to use cookies
Duration (retention): Up to 1 year
Location: United States
Google AdSense
Data processed: Site visitors' device/browser data (cookie metadata)
Purpose: Correlation of website visitors arriving from clicked content
Duration (retention): Up to 1 year
Location: United States
g2crowd.com
Data processed: Site visitors' device/browser data (cookie metadata)
Purpose: Website use analysis
Duration (retention): Up to 180 days
Location: United States
Intercom Inc
Data processed: Site visitors' device/browser data (cookie metadata)
Purpose: Functional support of Intercom chat service via the browser
Duration (retention): Up to 1 year
Location: United States
Cloudflare
Data processed: Site visitors' device/browser data (cookie metadata) — session, bot-detection and load-balancing identifiers
Purpose: Website security (bot/DDoS protection) and load-balancing of site traffic
Duration (retention): Up to 24 hours
Location: United States
YouTube
Data processed: Site visitors' device/browser data (cookie metadata), video-viewing/session data
Purpose: Enable embedded YouTube video playback and personalise/troubleshoot the video service
Duration (retention): Up to 6 months
Location: United States
Google Analytics
Data processed: Site visitors' device/browser data (cookie metadata), pseudonymous website usage/traffic data
Purpose: Website use analysis
Duration (retention): Up to 14 months
Location: United States
Microsoft, Inc.
Data processed: Site visitors' device/browser data (cookie metadata), session interaction data (clicks, scrolls, page views for heatmaps/recordings)
Purpose: Website use analysis (session recording and heatmaps)
Duration (retention): Up to 1 year
Location: United States
Leadfeeder
Data processed: Site visitors' IP address and device/browser data (cookie metadata), matched to company-level (B2B) firmographic data
Purpose: Identification of visiting companies for sales lead generation
Duration (retention): Up to 2 years
Location: European Union (Germany) — Dealfront states data is hosted/processed within the EU
Clay Labs Inc.
Data processed: Site visitors' IP address and device/browser data (cookie metadata), matched to company-level (B2B) firmographic data
Purpose: Site visitor tracking and company identification
Duration (retention): Up to 1 year
Location: United States
Reddit, Inc.
Data processed: Site visitors' device/browser data (cookie metadata), ad-click/conversion identifiers
Purpose: Correlation of website visitors arriving from clicked Reddit ad content
Duration (retention): Up to 2 years
Location: United States
LinkedIn
Data processed: Site visitors' device/browser data (cookie metadata), ad-click/conversion identifiers
Purpose: Correlation of website visitors arriving from clicked LinkedIn ad content
Duration (retention): Up to 1 year
Location: United States (LinkedIn Corporation); EEA/UK visitor data may be processed by LinkedIn Ireland Unlimited Company
Risk Ledger transfers a limited subset of Personal Data to countries located outside of the United Kingdom and the European Economic Area, and Switzerland (collectively, "Europe").
Personal Data can also be processed by mere access by individuals working outside Europe who work for us or for one of our trusted service providers.
We have implemented suitable safeguards designed to transfer Personal Data outside Europe in a secure manner and in compliance with the applicable regulations, most significantly with UK and EU data protection regulations. We also require the importers of the Personal Data to comply with, above all, the security requirements of the UK and EU GDPR. Where there is not an applicable adequacy decision in place (including the EU-US Data Privacy Framework and UK Extension thereto), we execute appropriate contractual arrangements to deal with such transfers, namely the Standard Contractual Clauses adopted by the Commission of the European Union plus the UK Addendum thereto.
Risk Ledger also monitors the legislative developments and guidance in relation to the personal data transfers outside Europe and commits to cooperate with UK and EU data protection authorities.
We retain Personal Data when we have an ongoing legal basis to do so. When we no longer have legal basis to process Personal Data, we will either delete or aggregate it or, if this is not possible (for example, because Personal Data has been stored in backup archives) then we will securely store it and isolate it from any further processing until deletion is possible.
We may retain Personal Data to comply with our legal or regulatory obligations. In any case, upon ceasing or lifting of such obligations, Personal Data shall be removed from our systems and records, as well as that of our contracted suppliers, if any, or otherwise archived or anonymised so that individuals can no longer be identified.
Data retention policy is described above in Sections 1-5 for each use case.
Our Site and Services may include links to and from the websites of our partners, and affiliates. If you follow a link to any of these websites, please note that these companies have their own privacy policies and that Risk Ledger is not responsible or liable for any use of Personal Data by such third parties. We advise that you check their policies before you disclose information on these websites.
We implement precautions—including organisational and technical measures—designed to maintain the security, integrity, and confidentiality of Personal Data, and, in particular, to help prevent them from being modified or damaged and stop any unauthorised party from accessing them. As an example, our employees' accounts are secured by strong passwords with multi-factor authentication, and they are all bound by confidentiality obligations. All our data is encrypted both in transit and at rest.
If you are a Risk Ledger Service User, please see our information security page (https://riskledger.com/security-profile) for more information about how your personal data is protected when you use the Risk Ledger product.
In any case where Risk Ledger processes your Personal Data as a Data Controller, you have the following rights:
For those in the UK, EEA or Switzerland, if you have a dispute with Risk Ledger relating to our data protection practices or are not satisfied with how we've addressed your concerns or questions, you may complain to an independent dispute resolution provider, at no cost to you. You also have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office, whose details are below:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Email and live chat: https://ico.org.uk/global/contact-us/
In the EEA, you can find your local data protection authority at this link: https://www.edpb.europa.eu/about-edpb/our-members_en
If you are a California resident—including a business contact, vendor representative, customer employee, or job applicant—the California Consumer Privacy Act (CCPA), as amended, grants you specific rights regarding your personal information:
Without prejudice to your rights, we invite you to first seek an amicable resolution by contacting Risk Ledger in writing, stating the grounds of your complaint and providing any supporting evidence, using the contact details below.
We may amend the terms of this Privacy Policy from time to time. If you do not agree with the amended version of the Privacy Policy, you should stop using the Services, stop visiting our website, and/or unsubscribe from our marketing. All amended terms automatically become effective on the day when a new Privacy Policy is posted on the Site.
Should we add new consent-based processing of Personal Data, we shall ensure to obtain your consent prior to processing such Personal Data (e.g., via a box to tick).
If you have questions regarding this Privacy Policy or if you want to share your concerns or make a complaint about our processing of your Personal Data, please contact us by email at data@riskledger.com. Please be aware that this email address serves exclusively for matters related to privacy and personal data protection. In such matters we will usually reply to you within 5 working days.
For matters related to security (including with reports of vulnerabilities), please contact us at security@riskledger.com.
You may also contact Risk Ledger Ltd. by mail at our registered office:
Adam House, 7-10 Adam Street, London, WC2N 6AA United Kingdom