1. Information We Collect
Vivid Risk collects minimum viable data to provide our assurance services. This includes organizational metadata, technical telemetry for risk assessment, and user identity information provided during registration. We do not "scrape" data outside the scope of defined assessments.
2. How We Use Your Data
Data is used to quantify risk, generate remediation roadmaps, and support audit-readiness. Some features send the content you enter to Google's Gemini models on Vertex AI to produce draft text — the cross-mapper and the AI-assisted narrative sections. Under Google Cloud's Service Specific Terms, section 18 (Training Restriction), Google will not use that content to train or fine-tune any of its models without our prior permission or instruction — and we give neither. Google may retain it briefly for abuse monitoring under their own policy. If you would rather not send content to a third-party model, avoid the features that are labelled as AI-assisted; nothing else on the platform sends your data to them.
3. Data Protection & Storage Location
Your data is encrypted at rest and in transit by Google Cloud, and each tenant's assessment data is isolated from every other tenant's by Firestore security rules. Evidence Vault entries record what you type about a document — title, description, type and source — and, where you attach one, the document itself. Files are held in Google Cloud Storage in europe-west1 (Belgium), encrypted at rest by Google, and are served back to you only through links our server generates on request and which stop working after five minutes. Nothing reads the contents: your files are not scanned, parsed, indexed, or used to train anything, and the relevance check described below sees only the words you typed. Cryptographic hash verification of vault artifacts is not implemented.
On storage location, we would rather be exact than reassuring. Your assessments, vendor records, incidents and audit history are held in Google Cloud Firestore in europe-west1 (Belgium), and our application servers run in the same region. Evidence files you upload are held in Google Cloud Storage in the same region, and our server reads the bucket's own location before every upload rather than taking it from configuration — it refuses to store anything in a location it cannot confirm is in an EU member state. One thing sits outside that, and we would rather name it than let the first sentence stand for the whole picture. Account identity — your email address and sign-in records — is held in Firebase Authentication, which Google does not offer as a region-configurable service: it appears nowhere in Google's own data-residency terms, neither among the services whose location a customer can set nor among those that hold no customer data at rest. So we cannot choose or confirm where it is stored, and there is no EU setting for us to have missed.
AI-assisted features used to sit outside it too, and no longer do. Since 17 September 2026 the text you submit goes to Google's Gemini models on Vertex AI configured to europe-west1, and Google's AI/ML Data Location terms commit it to performing that processing only within the EU multi-region for the models we use. That settles one subprocessor. It does not settle the question, and we are not going to let it read as though it did.
Because of account identity, and because the payment and email subprocessors named in section 4 both process in the United States, please do not rely on this platform to satisfy a data-residency requirement or a GDPR Chapter V transfer obligation, even though the database itself is in the EU. We would rather tell you that than let you assume otherwise. If residency is a condition of your using us, write to support@vividrisk.ai and we will tell you exactly where each of these stands rather than sell you a guarantee we cannot give.
4. Third-Party Sharing
We do not sell your personal or organizational data to anyone. It is shared only with the subprocessors we need to run the service, each under a data processing agreement. Those are, in full: Google Cloud (hosting, database, authentication and the AI-assisted features described in section 2), Stripe (payments) and Resend (transactional email). If we add one, we will update this list.
That is the short form. The full register is at vividrisk.ai/subprocessors — one row per service rather than per company, because the answers differ by service, with what each one receives, where it processes it and the safeguard its transfer rests on. If you are using Vivid Risk on behalf of an organisation and need to tell your own customers who touches their data, that page is the list to hand them.
Because naming a recipient is not the same as saying what reaches it: Stripe receives your email address, our internal account id for you, and the plan tier you chose — plus your practice id if you are a partner upgrading a client. Your card details go to Stripe directly from the checkout page and never touch our systems; whatever else Stripe needs to take a payment, it collects itself under its own privacy policy. Resend receives the address a message is sent to, and where a confirmation email repeats back what you typed into a form — your name, your company, and the framework focus you named — it carries those too. Neither receives your assessment answers, your evidence records, your vendors or your incidents.
Both of them process it in the United States, and we checked that against each company's own data processing agreement rather than assuming it. Stripe's says you transfer personal data to Stripe, LLC in the United States, and that Stripe may then move it "on a global basis" to its affiliates and sub-processors in other jurisdictions. Resend's says its "primary processing operations take place in the United States". Neither agreement offers a European option — the word "residency" does not appear in either document — so this is not a setting we have left unchosen.
Those transfers are lawful, and they rest on the safeguards Chapter V of the GDPR requires rather than on your data staying in Europe. You are entitled to know which, so: Resend relies on the EU Standard Contractual Clauses and on its certification under the EU-U.S. Data Privacy Framework. Stripe relies on its Data Transfers Addendum, which applies the Data Privacy Framework, the EEA Standard Contractual Clauses or the UK addendum as the case requires. Google covers Firebase Authentication under its Cloud Data Processing Addendum, which requires Standard Contractual Clauses or an equivalent for any transfer outside a country the European Commission has found adequate. You can ask us at support@vividrisk.ai for a copy of any of them.
Google Workspace connector, and how we use what it reads
If your administrator connects your Google Workspace, we request exactly one permission — admin.directory.user.readonly — and we ask Google's Directory API for seven fields per account and no others: whether two-step verification is enrolled, whether the account is an administrator, whether it is a delegated administrator, whether it is suspended, whether it is archived, and when it last signed in. We never request or receive a name, an email address, a user id, a phone number, a recovery address or any message, file or calendar content. No Gmail scope and no Drive scope is requested, and none will be added without your administrator granting it explicitly.
What we keep is not a copy of your directory. Each check produces counts — how many accounts have two-step verification, how many are administrators, how many have not signed in — and one sentence describing what was counted. Those numbers are stored against your account and shown to you beside the questions they are evidence for. They do not answer those questions: you do. A count is evidence for your answer, never evidence of it.
Vivid Risk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, and going further than that statement requires: no data obtained through the Google Workspace APIs — raw, aggregated, anonymised or derived — is sent to any AI or machine-learning model, ours or anyone else's. The connector's output is counted and displayed; it reaches no prompt, no model and no training process, and it is not transferred to any third party. The AI-assisted features described in section 2 operate on the assessment answers and documents you enter yourself, and are served by Google Cloud's Vertex AI, whose Service Specific Terms state that Google will not use customer data to train or fine-tune its models without the customer's instruction. We give no such instruction. We use no other AI provider, and no AI gateway, aggregator or model hub.
Disconnecting removes our stored credential. It does not revoke the grant at Google — only your own administrator can do that, from your Google account's permissions page — and we say so in the product rather than implying the access is gone.
Privacy Principle
"Our business model is based on assurance, not data monetization. We succeed when you are secure, not when your data is exposed."
5. Your Rights
If you are in the EU, the EEA or the UK, the GDPR and the UK GDPR give you the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to our processing of it, and to receive it in a portable format. These rights apply regardless of what this platform does or does not automate.
Two things survive a deletion request, because the law requires us to keep them: invoices and payment records, which tax law obliges us to retain for years after you leave, and our security audit log, which is how we can demonstrate who did what on the platform. Neither is used to contact you or to rebuild your account. Everything else goes.
You can delete your account yourself, at any time, from Settings — it removes your assessments, reports, evidence records, vendors, incidents, support history and profile, and signs you out. For anything else — a copy of your data, a correction, or a restriction — email support@vividrisk.ai. We will respond within one month, as Article 12(3) requires. There is no self-service export button yet; we assemble those by hand, and we would rather say so than point you at a screen that does not exist. An export includes the evidence files you uploaded, alongside your records. You also have the right to complain to your supervisory authority — in Ireland, the Data Protection Commission.
Policy Updates
This policy is reviewed annually. Major changes will be notified via the platform dashboard and registered email accounts.