Home Features Salesforce Pricing Try Demo
Legal

Data Processing Agreement

Last updated: February 24, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between RiskDetect ("Processor") and the organization using the RiskDetect service ("Controller") for the processing of personal data.

1. Definitions

2. Scope of Processing

What RiskDetect Processes

Data TypePurposeRetention
Call transcript textRisk scoring, signal detection, sentiment analysisUntil account deletion or data deletion request
Email/message contentRisk scoring, signal detectionUntil account deletion or data deletion request
Contact email/phoneCustomer identification, journey trackingUntil account deletion or data deletion request
Organization name, admin emailAccount management, authenticationUntil account deletion

RiskDetect processes Customer Data solely to provide the risk analysis service as described in our documentation. We do not:

3. Sub-processors

RiskDetect uses the following sub-processors:

Sub-processorPurposeData ProcessedLocation
OpenAI (GPT-4o-mini)AI risk analysisText content (transcripts, emails)United States
Neon (PostgreSQL)Database storageAll Customer DataUnited States (AWS)
VercelApplication hostingAPI requests (in transit)United States (AWS)

OpenAI Data Usage

RiskDetect uses the OpenAI API (not ChatGPT). Per OpenAI's API data usage policy: API inputs and outputs are not used to train OpenAI models. Data is retained by OpenAI for up to 30 days for abuse monitoring, then deleted. See OpenAI API Data Usage Policies.

4. Security Measures

RiskDetect implements the following technical and organizational measures:

5. Data Subject Rights

The Controller may exercise the following rights on behalf of data subjects at any time:

All deletion requests are processed immediately and permanently. RiskDetect does not retain backups of deleted data beyond standard database backup windows (up to 7 days via Neon's point-in-time recovery).

6. Breach Notification

In the event of a confirmed data breach affecting Customer Data, RiskDetect will:

  1. Notify the Controller within 72 hours of becoming aware of the breach
  2. Provide details of the nature of the breach, data affected, and remediation steps
  3. Cooperate with the Controller's investigation and notification obligations

7. Data Return and Deletion

Upon termination of the service agreement:

8. Audit Rights

The Controller may request information about RiskDetect's data processing practices. RiskDetect will respond to reasonable audit requests within 10 business days. For security assessments, we support:

9. Contact

For DPA-related inquiries: morgan@riskdetect.app