Privacy Policy
Last updated: 22 August 2026
1. Controller
The controller responsible for the processing of personal data on this site is Swiss Security Hub AG, Konradshalde 6, 8832 Wilen b. Wollerau, Switzerland. EasyRisk is a product of Swiss Security Hub AG. You can reach us at hello@easyrisk.io.
We have not appointed a data protection officer. We are not required to do so under Art. 37 GDPR, and it is voluntary under Swiss law. Data protection matters are handled at the address above.
2. Representatives in the EEA and the United Kingdom
We are established in Switzerland. Where the GDPR applies to our processing, we have appointed the following representative pursuant to Art. 27 GDPR for the European Economic Area (EEA), including the European Union and the Principality of Liechtenstein, as an additional point of contact for supervisory authorities and data subjects:
VGS Datenschutzpartner GmbH
Am Kaiserkai 69
20457 Hamburg, Germany
info@datenschutzpartner.eu
For matters falling under the UK GDPR, we have appointed the following representative pursuant to Art. 27 UK GDPR as an additional point of contact for the Information Commissioner's Office and for data subjects in the United Kingdom:
Jeremy Suárez
London, United Kingdom
uk-representative@easyrisk.io
Contacting a representative is an option, not a requirement — you can always write to us directly at hello@easyrisk.io.
3. Scope
This policy applies to personal data processed through the EasyRisk.io web application and marketing site. It is drafted to comply with the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revDSG).
4. What we process
- Account data: name, email, hashed password, workspace membership and role.
- Product data you enter: risks, treatment actions, comments, audit trail entries.
- Usage data: server logs (IP, timestamps, request paths) kept for security and abuse prevention.
- Billing data (if you subscribe to a paid plan): your name, email address, billing details and invoice history, handled by our payment processor Stripe. Card numbers are entered on Stripe's systems; we never receive or store them. We keep only the identifiers that link your workspace to its Stripe customer and subscription, plan, billing cycle and renewal date.
5. Legal basis
- Performance of the contract with you (Art. 6 (1) (b) GDPR / Art. 31 (2) (a) revDSG).
- Legitimate interests in operating and securing the service (Art. 6 (1) (f) GDPR).
- Consent, where explicitly requested (e.g. marketing emails).
On the basis of our legitimate interest in helping a new account get started, we send a small number of onboarding emails in the first two weeks: to the person who created a workspace, to a member who was invited into one, and — once, and only while the invitation is still open — to an address a customer invited but that has no account with us. They stop by themselves, and you can end them at any time through the link in each message or under Notifications on your profile page. Doing so leaves service messages such as review reminders unaffected.
6. Hosting and processors
The application and its data are self-hosted: we run the software ourselves on servers hosted by IONOS SE (Germany), so that customer data remains inside the EU/EEA and Switzerland. Requests reach those servers directly — no content delivery network sits in front of the application, and no third party terminates or inspects your traffic to it.
These are the external processors involved, and what each one sees:
- IONOS SE, Germany — the servers the application and its database run on. All customer content passes through this processor; it is inside the EU.
- Stripe Payments Europe Ltd., Dublin, Ireland, together with its affiliates including Stripe, Inc. (USA) — subscription payments for paid plans. Stripe acts as an independent controller for the payment itself and as our processor for subscription management. It sees your billing details; it does not see anything you enter in your risk register.
- Resend — delivery of transactional email (account confirmation, invitations, review reminders, onboarding emails). It sees the recipient address and the content of those messages.
- Cloudflare, Inc., USA — only the DNS records for our domain and the forwarding of email sent to our published addresses onward to our mailbox. Cloudflare is not in the path of your requests to the application, and it sets no cookies on this site.
- Microsoft Ireland Operations Ltd. — the mailbox that receives correspondence sent to our published addresses.
Each external processor is bound by a data processing agreement in line with Art. 28 GDPR.
7. International transfers
Where a sub-processor operates outside the EU/EEA or Switzerland, transfers are covered by EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum and the amendments recognized by the Swiss Federal Data Protection and Information Commissioner, together with supplementary measures — or by the recipient's certification under the EU–U.S. Data Privacy Framework and its UK and Swiss extensions. This applies to Stripe, which processes payment data in the United States as well as the EU, and to Cloudflare for DNS and email forwarding. You can request a copy of the relevant safeguards at hello@easyrisk.io.
8. Retention
We retain account and workspace data for as long as your workspace is active, and delete or anonymize it within 90 days of workspace deletion, subject to legal retention obligations. Audit-log entries are append-only (they cannot be changed or deleted) and retained for the lifetime of the workspace. Invoices and the associated billing records are kept for the statutory accounting retention period of 10 years (Art. 958f of the Swiss Code of Obligations), which takes precedence over an erasure request for that data.
An invitation that is never accepted is deleted 14 days after it expires — four weeks after it was sent — and with it the address it was sent to. An accepted one stays with the workspace: it records who brought that member in.
Server logs rotate automatically and are deleted after at most 90 days.
When a member is deactivated, their access ends immediately and their board memberships are removed. Their profile (name and email address) and the entries they authored — risks, treatment actions, comments and audit-trail entries — stay in the workspace, because a risk register has to remain attributable and the audit trail is append-only. They are removed together with the workspace.
9. Your rights
You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent at any time.
You may also lodge a complaint with a supervisory authority:
- Switzerland — Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
- EEA — the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.
- United Kingdom — Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
To exercise any of these rights, write to hello@easyrisk.io. We reply within one month. On request we provide an export of your workspace data in a structured, commonly used and machine-readable format.
A workspace admin can delete the entire workspace from its settings. Access ends immediately; the data is kept for 90 days so an accidental or unauthorized deletion can still be undone, and is removed after that.
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
10. Cookies and local storage
We do not use cookies. To keep you signed in and to remember interface preferences (such as light or dark mode), we store a small amount of data locally in your browser using local storage. This is strictly necessary for the service to work, stays on your device, and is never used for advertising or cross-site tracking.
11. Analytics
On our public marketing pages (never inside the application) we measure how the pages are used with Umami, an analytics tool we self-host on our own infrastructure. It is cookieless, stores nothing on the device, shares no data with any third party, and does not track you across other sites.
We record page views and, on those same public pages, where visitors click and how far they scroll, so we can tell which content is useful. Alongside each visit we store the browser, operating system, device type, screen size, language, and an approximate location (country and city) derived from the IP address. The IP address itself is never stored. Entries from the same visit share a session identifier, derived from the request rather than kept as such; it is scoped to this site and linked to no account.
You can switch the measurement off for your browser. Doing so stores one value on your device to remember the choice — the only thing the measurement ever stores there, and only if you ask for it.
12. Business use only
EasyRisk is offered exclusively to businesses, self-employed professionals and other organizations acting in a commercial or professional capacity. It is not offered to consumers. Please do not enter personal data into the service that the business relationship does not require, and in particular no special categories of personal data (Art. 9 GDPR) unless we have agreed that in writing.
Where your organization uses EasyRisk to process personal data about its own people or customers, your organization is the controller and we act as its processor under the agreement concluded with it. If you are such a person and want to exercise your rights, please contact the organization that gave you access; we support them in answering you.
13. Contact
Requests concerning this policy or your rights can be sent to hello@easyrisk.io.