Privacy Policy.
This is a draft pending legal review. The content reflects RiskBridge's actual operational and security commitments but is not yet a final or legally-binding document.
Who we are
RiskBridge is a GRC vendor selection and lifecycle management platform operated by Effective Risk Management Pty Ltd, an Australian-incorporated company headquartered in Melbourne. Legal review required Australian Business Number and registered address to be inserted by counsel.
This Privacy Policy describes how we collect, use, share and protect personal information across the RiskBridge platform and associated websites. It applies to customer users, prospective customers, website visitors, and security researchers who interact with us.
For the purposes of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), Effective Risk Management Pty Ltd is the entity responsible for personal information collected through RiskBridge. For the purposes of the EU GDPR, we act as a processor in respect of platform data, and as a controller in respect of information collected directly from website visitors.
Personal information we collect
Account and identity information
When a user is provisioned into a RiskBridge tenant, we collect: name, work email address, role, organisation name, country, and authentication identifiers (managed via SSO — Okta, Microsoft Entra ID, Google Workspace, or equivalent).
Platform usage information
We collect information about how users interact with the platform — assessments completed, scores recorded, evidence uploaded, comments and decisions logged. This information is purpose-limited to product operation, security, and customer support.
Website visitor and contact form information
When you submit the contact form, we collect: name, work email, role, organisation, country, sector, journey stage, and the content of your message. We use this solely to prepare and conduct the conversation you have requested.
We do not collect sensitive information (as defined under the Privacy Act 1988) unless explicitly required for a specific purpose, with consent. Legal review required
How we use personal information
We use personal information for the following purposes only:
- Platform operation. To deliver RiskBridge to the customer organisation, including vendor selection workflows, implementation tracking, program management, reporting, and audit logging.
- Customer support. To respond to support requests and communicate with users about service-impacting events.
- Security. To detect, investigate and respond to security incidents, fraud, and unauthorised access attempts.
- Aggregate benchmarking. Where customers explicitly opt in, fully-anonymised statistics are produced. Individual customer data is never identifiable in benchmarking output.
- Sales and prospect engagement. Where you have submitted a contact form, we use the information solely to prepare for and conduct the conversation you requested.
- Legal and regulatory compliance. Where required by law, regulator request, or court order.
Sharing and disclosure
We share personal information only in the following limited circumstances:
- With sub-processors who provide infrastructure, security, and operational services, under written Data Processing Agreements. See Section 06.
- Within the customer's tenant — subject to role-based access controls administered by the customer.
- With professional advisors (legal, audit, accountancy) under confidentiality obligations, where reasonably necessary.
- Where required by law — in response to lawful regulator requests, court orders, or legal process. Legal review required
- In connection with a business transaction — if Effective Risk Management Pty Ltd is involved in a merger, acquisition, or asset sale, subject to equivalent protection commitments. Legal review required
Data residency and storage
Customer data is stored in Google Cloud Platform Australia, primary region Sydney (australia-southeast1) and disaster recovery in Melbourne (australia-southeast2).
Data residency is a contract-level commitment. Customer data — primary, backup, analytics, and logs — does not leave the Australian region.
Backups are retained for 35 days on a rolling basis with point-in-time recovery. Recovery objectives: RTO 4 hours, RPO 15 minutes. Data in transit is encrypted using TLS 1.3 only. Data at rest is encrypted using AES-256.
Sub-processors
Our primary infrastructure sub-processor is Google Cloud Platform — primary cloud infrastructure. Australian regions only. Data Processing Agreement in place.
Additional sub-processors are disclosed in our trust pack under non-disclosure agreement on request from active customers and verified prospects in evaluation. The complete list is updated whenever a sub-processor is added, removed, or changes region.
Every sub-processor undergoes security review before onboarding and has a signed Data Processing Agreement. Legal review required
Security
We maintain a security program designed to protect personal information against unauthorised access, use, modification, disclosure, loss and destruction. Key controls include:
- Authentication. SSO via SAML 2.0 and OIDC; MFA enforceable at tenant level; password policy defaults exceeding NIST SP 800-63B.
- Encryption. AES-256 at rest, TLS 1.3 in transit.
- Access control. Granular role-based access; least-privilege by default; every permission change audit-logged.
- Audit logging. Every user action logged to a write-once audit store; retained for seven years; tamper-evident and cryptographically signed.
- Personnel. Police checks, reference verification, and confidentiality undertakings for all personnel with production access; quarterly access reviews.
- Incident response. Aligned to NIST SP 800-61; 72-hour maximum notification for any incident affecting customer data.
Our full compliance program is detailed on the Trust & Security page.
Retention and deletion
Customer data on the platform
While a customer tenant is active, customer data is retained for the duration of the engagement.
On contract termination
On termination, we provide a full export in standard formats (JSON, CSV, XLSX, PDF) within 30 days. Customer data is then deleted from production systems within 60 days.
Audit logs
Audit logs are retained for seven years by default to support compliance and security investigation obligations.
Contact form information
Information submitted via the contact form is retained for the duration of the prospect engagement. Legal review required
Your rights
Depending on the jurisdiction in which you reside, you may have the following rights:
- Right to access — request a copy of the personal information we hold about you.
- Right to rectification — request correction of inaccurate or incomplete personal information.
- Right to erasure — request deletion of your personal information, subject to legal and contractual retention obligations.
- Right to restrict processing — request that we limit how we use your personal information.
- Right to data portability — receive your personal information in a structured, machine-readable format.
- Right to object — object to certain processing activities, including direct marketing.
- Right to lodge a complaint — with the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.
To exercise any of these rights, contact us at contact@effectiverm.com with the subject line "Privacy". We will respond within 30 days.
International transfers
Customer data is held in Australia as a contract-level commitment. We do not transfer customer data outside Australia in the ordinary course of operations.
Where international transfer is necessary, we rely on appropriate safeguards including Standard Contractual Clauses and adequacy decisions where applicable. Legal review required
Cookies and tracking
Our website uses minimal first-party cookies necessary for site operation and security. We do not deploy third-party advertising trackers, behavioural analytics pixels, retargeting cookies, or session-replay tools.
Children
RiskBridge is a business-to-business enterprise platform. The platform and this website are not directed to children under 16, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to active customers in writing at least 30 days in advance, and posted to this page with an updated date.
Contact
For privacy questions, requests, or complaints:
- Email: contact@effectiverm.com — subject line "Privacy"
- Postal: Effective Risk Management Pty Ltd, Melbourne, Australia. Legal review required
- Response timeframe: Within one Australian business day for acknowledgement; within 30 days for substantive response.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Questions about how we handle your data?
A practitioner will respond within one Australian business day.
