Privacy Policy

Last updated: 28 August 2026

1. Introduction

Welcome to RiskRegisterPro ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our risk management platform.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly to us, including:

  • Account information (name, email address, organization details)
  • Profile information and preferences
  • Risk data, controls, mitigations, and related information you enter into the platform
  • Communications with us (support requests, feedback)
  • Payment and billing information

2.2 Automatically Collected Information

When you use our services, we automatically collect:

  • Usage data (features accessed, actions taken, timestamps)
  • Device information (IP address, browser type, operating system)
  • Log data (access times, pages viewed, errors)
  • Cookies and similar tracking technologies

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send technical notices, security alerts, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our terms

4. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • With your consent: When you authorize us to share information
  • Service providers: Third-party vendors who perform services on our behalf (hosting, payment processing, analytics)
  • Legal requirements: When required by law or to protect rights and safety
  • Business transfers: In connection with a merger, acquisition, or sale of assets
  • Within your organization: With other users in your organization based on permissions you set

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection practices
  • Incident response procedures

6. Data Retention

We retain your information for as long as your account is active or as needed to provide services. We will retain and use your information to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we will delete or anonymize your personal information within a reasonable timeframe.

7. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your information
  • Restriction: Request restriction of processing
  • Withdrawal of consent: Withdraw consent where processing is based on consent

To exercise these rights, please contact us at info@infracto.co.uk

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable data protection laws.

9. Cookies and Tracking

We use cookies and similar tracking technologies to collect and track information about your use of our services. You can control cookies through your browser settings. However, disabling cookies may affect the functionality of our services.

10. Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Email: info@infracto.co.uk