Privacy notice

What RiskWoven collects, and why.

This describes riskwoven.com as it is actually built, not as a template imagines it. Every category below corresponds to something the software really stores, and the retention periods are the ones in the code.

Last updated 30 September 2026.

1. Who is responsible

RiskWoven is operated by RiskWoven Inc., a corporation incorporated under the Canada Business Corporations Act, based in Aurora, Ontario, Canada.

RiskWoven Inc. has a Privacy Officer who is accountable for this notice and for how personal information is handled. Write to the Privacy Officer at hello@riskwoven.com.

RiskWoven is offered to organisations in Canada and the United States. It is not marketed to people in the European Union or the United Kingdom, and no representative is designated there.

RiskWoven is a controller for the account, contact and telemetry information described below. For the content you put into your workspace, RiskWoven acts on your instructions.

2. What is collected, and when

Nothing here is collected speculatively. Each category exists because a specific part of the product needs it.

CategoryWhat it isWhy it exists
Contact details Name, email address, phone number, organisation, role, country, and the version and time of the consent you gave. Collected by the contact form before a document is released, and by the account form on first sign-in. The email address is confirmed by a link before anything is generated.
Support messages What you write on the contact page, in the feedback form, or to the help assistant, with the name and email address you give and the page you were on. So a person can answer you. Contact messages, feedback and any conversation you choose to hand off are stored and emailed to the person who replies. Questions to the help assistant are sent to Anthropic's API to produce the answer; the assistant sees only what you type in that conversation and none of your account or workspace.
Sign-in identity The email address confirmed by the sign-in method you choose (Google, LinkedIn, or a one-time code sent to your email), and the time of your last sign-in. Sign-in is handled by Cloudflare Access. If you choose Google or LinkedIn, that provider shares your name, email address and profile picture with Cloudflare Access so it can confirm who you are. RiskWoven receives only a signed token naming your email address. It never receives or stores your password, and it does not ask Google or LinkedIn for your mail, contacts, files or any other data.
Workspace content The answers you give in an intake, the documents generated from them, uploaded evidence, vendor and asset records, questionnaires, and review requests. This is the product. It is stored against your organisation and is not readable by other customers.
Usage telemetry Which pages and features were used and when, tied to two opaque first-party identifiers and, when you are signed in, to a random key issued for your account. The two identifiers exist only if you accept analytics cookies (section 3). Actions the server carries out for you, such as generating a document or completing a purchase, are counted either way, without them. To see which parts of the product are used and where people abandon it. The event rows themselves carry no email address; a separate table holds the key alongside your address so that support and administration can resolve it, which means the separation is organisational and not one-way. Rate-limit counters hold IP addresses.
Security and audit records Rate-limit counters, audit events naming the address that performed an administrative action, agent run records, and delivery records for emails sent to you. So that a question about what the system did on a given day has an answer. Some of this is what makes the product's own assurance claims checkable.
Payment records Stored by RiskWoven: the Stripe event identifier, the email address on the purchase, what was bought, the amount, and the resulting entitlement. Held in RiskWoven's Stripe account: the name, business name, billing address and any tax ID you enter at checkout, and the receipt and invoice issued for the purchase. To grant what you paid for, to issue a receipt and invoice, and to reconcile it later. The billing address sets which sales tax applies. Card details never reach RiskWoven. Payment happens on Stripe's own hosted pages.
Information from Google or LinkedIn sign-in. It is used only to sign you in and to identify your account. It is not sold, not used for advertising, not used to train AI models, and not shared except with the processors in section 4 as needed to run the service. It is deleted with your account. RiskWoven's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What is not collected. No cross-site tracking identifiers, with one exception. If you reach riskwoven.com by clicking one of our Google ads, Google adds a click identifier to the link. We keep it with your free scan record for 90 days, but only if you accept analytics cookies. If you decline, or your browser sends Global Privacy Control or Do Not Track, it is removed from the address bar and neither kept nor sent. If you accepted, and you verify your email or buy within the 90 days, we send Google that identifier, the date and time, the type of action and, for a purchase, the amount, so we can see which ads work. We never send Google your name, email address or answers. Once received, Google holds that information under its own privacy policy. One third-party analytics script, loaded only with your consent: Cloudflare Web Analytics (section 3). No social media pixels. No profiling of individuals, and no automated decision producing a legal effect about a person: the product's outputs are about organisations and their controls, and every generated document is a draft awaiting a human decision.

3. Cookies

All of these are first-party. There are no advertising cookies. They fall into two groups.

Strictly necessary. Set without asking, because the site cannot sign you in, protect its forms, remember what you already told it, or remember your cookie choice without them.

NamePurposeLifetime
rw_lead_sessionRemembers the contact details you already gave, so the form does not ask twice. Not readable by JavaScript.30 days
CF_AuthorizationSet by Cloudflare Access when you sign in. It is how the site knows who you are.Set by Cloudflare Access
rw_elevationMarks a recently completed second-factor check for administrative access. Owner only.Short-lived, minutes
Cloudflare TurnstileThe anti-abuse check on the sign-up form, the contact and feedback forms, and the first message to the help assistant. Cloudflare states that Turnstile's signals are used solely to tell people from bots, and that it cannot identify individuals from them.Set by Cloudflare
rw_consentRemembers whether you accepted or declined analytics cookies, so you are asked once and not on every page. It holds the word granted or denied and nothing else.180 days

Analytics, only with your consent. Set only after you press Accept on the cookie banner. Until then, and if you press Decline, neither exists. If your browser sends Global Privacy Control or Do Not Track, they are never set and the banner is not shown, even if you accepted earlier.

NamePurposeLifetime
rw_anon, rw_sessTwo opaque identifiers that let a sequence of actions be counted as one visit. They carry no information about you. The visit identifier is also kept in your browser's session storage, which is cleared when the tab closes.rw_anon: 180 days
rw_sess: 30 minutes of inactivity

The same Accept also loads Cloudflare Web Analytics, a script from Cloudflare that counts page views and how long pages take to load. It sets no cookie. Cloudflare states that it does not use cookies or local storage for these measurements and does not fingerprint individuals by IP address, browser or any other data. It is not loaded before you accept, and never if your browser sends Global Privacy Control or Do Not Track.

The same Accept covers the Google Ads click identifier described in section 2, which the free scan keeps in session storage, never in a cookie.

You can change your choice at any time: . Declining removes both analytics cookies and any kept click identifier at once, and Cloudflare Web Analytics is not loaded again from the next page you open. Refusing does not change how the site works for you.

4. Who else sees it

Four processors, each doing one job, and no others. Google Ads is not one of them: it receives only the ad click identifier described in section 2, and only when you arrived through one of our ads. Nothing is sold.

Cloudflare

Hosting, the database, file storage, sign-in and the anti-abuse check, and, only if you accept analytics cookies, counting page views through Cloudflare Web Analytics. Effectively all stored data sits on Cloudflare infrastructure.

Privacy policy · Turnstile policy

Anthropic

The model that drafts documents and answers the help assistant. Your intake answers, the text being worked on, and what you type to the assistant are sent to Anthropic's API. Anthropic states that by default it does not train its models on inputs or outputs from its commercial API, and that it deletes API inputs and outputs within 30 days.

Model training statement · Retention statement · Commercial terms

Resend

Sends the confirmation and notification emails. Receives the recipient address and the message.

Privacy policy

Stripe

Takes payment on its own pages, holds the billing details you enter there, sends your receipt and invoice, and tells RiskWoven what was bought and by which email address. Card details are held by Stripe, never by RiskWoven.

Privacy policy

Where the data physically sits. RiskWoven's database (Cloudflare D1) and file storage (Cloudflare R2) are both placed in Cloudflare's Eastern North America (ENAM) location, and the database keeps no read copies in other regions. That location is not limited to Canada, so treat stored data as possibly held in the United States. Anthropic, Stripe and Resend may also process data in the United States. Information processed outside Canada is subject to the laws of the country where it is held, including lawful access by that country's authorities.

5. How long it is kept

RecordKept for
Raw usage events180 days, then deleted. Aggregated daily counts, which name nobody, are kept longer.
The contact-form session30 days from issue
Audit recordsAt least one year
Account and contact detailsDeleted within 90 days of the account being closed. A deletion request is completed within 30 days.
Workspace content and documentsUntil you delete them, or the account is closed. You can delete a document from the workspace yourself.
Payment recordsSix years from the end of the tax year they relate to, as the Canada Revenue Agency requires

6. What you can ask for

Write to the Privacy Officer at hello@riskwoven.com and RiskWoven will act on any of the following.

RiskWoven replies within 30 days. If a request needs longer, you will be told why, and how much longer, within those 30 days.

7. Children

RiskWoven is sold to organisations and is not directed at children. Accounts are not knowingly created for anyone under 18.

8. Changes

The date at the top of this page changes when this notice does. A change that materially affects what is collected or who receives it will be notified to account holders by email before it takes effect.