RISOS Data Processing Addendum
Effective and last updated: September 14, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between a business customer (“Customer”) and RISOS, the operator of the RISOS service (“RISOS”), to the extent RISOS processes Customer Personal Data on Customer’s behalf.
1. Definitions
“Applicable Data Protection Law” means privacy and data-protection law applicable to the processing covered by this DPA. “Customer Personal Data” means personal data processed by RISOS on behalf of Customer through the services. “Subprocessor” means a third party engaged by RISOS to process Customer Personal Data on Customer’s behalf. “Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, excluding unsuccessful attempts that do not compromise Customer Personal Data.
Controller, processor, data subject, personal data, processing, and supervisory authority have the meanings given by applicable law.
2. Roles and scope
As between the parties, Customer acts as controller or as a processor with authority to appoint RISOS, and RISOS acts as processor or subprocessor for Customer Personal Data, except for processing RISOS independently determines for its own purposes as described in the Privacy Policy, such as account security, abuse prevention, legal compliance, and service administration.
3. Processing instructions
RISOS will process Customer Personal Data to provide, secure, maintain, support, and administer the services; according to Customer’s documented instructions expressed in the agreement, product configuration, API/MCP requests, and lawful written instructions; and as otherwise required by applicable law. If RISOS reasonably believes an instruction conflicts with Applicable Data Protection Law or a binding source-platform restriction, RISOS may inform Customer and suspend or limit the affected processing while the issue is resolved.
4. Customer responsibilities
Customer is responsible for the lawfulness of its instructions, the notices and legal bases required for Customer Personal Data, appropriate user access, and ensuring that it does not submit data categories the service is not designed to process. Unless a feature expressly states otherwise, RISOS is not designed for payment-card data, regulated health records, children’s data, biometric templates, or other specially regulated information.
5. Confidentiality
RISOS will limit access to Customer Personal Data to personnel and service providers who need access for authorized purposes and who are subject to appropriate confidentiality obligations or equivalent duties.
6. Security
RISOS will maintain technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the service and available controls. Verified controls are summarized in Annex 2. This DPA does not promise absolute security or an unverified certification.
7. Subprocessors
Customer generally authorizes RISOS to use the subprocessors listed on the Subprocessor List. RISOS will require subprocessors to protect Customer Personal Data consistently with the processing they perform and applicable law. The public list is updated when RISOS materially changes subprocessors. Unless a separate written agreement grants a specific advance-notice or objection period, this DPA does not invent one.
8. Data-subject requests
Taking into account the nature of the processing, RISOS will provide reasonable assistance through available product controls and support channels to help Customer respond to valid data-subject requests. If RISOS receives a request concerning Customer-controlled data for which Customer is responsible, RISOS may direct the requester to Customer unless law requires RISOS to act directly.
9. Government and third-party requests
Where legally permitted and reasonably practicable, RISOS will notify Customer of a legally binding request from a public authority seeking Customer Personal Data when Customer is entitled to notice. RISOS may review requests for legal sufficiency and will disclose only information required by law.
10. Security Incidents
RISOS will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data when notification is required by Applicable Data Protection Law or a governing written agreement. Information may be provided in phases as details become available. This DPA does not create an arbitrary fixed-hour notification promise.
11. Assistance with compliance
Taking into account the nature of processing and information available to RISOS, RISOS will provide reasonable assistance with Customer obligations relating to security, breach response, data-protection impact assessments, and prior consultation where applicable law requires such assistance.
12. Deletion and return
During use of the service, Customer can use available export and deletion controls described on the Data & Account Rights page. After termination, RISOS will delete, return, or de-identify Customer Personal Data according to the verified product retention and deletion process, except where retention is required or permitted for security, fraud prevention, dispute resolution, legal obligations, backups, or source-platform compliance.
13. Audits and information
RISOS will make available information reasonably necessary to demonstrate compliance with applicable processor obligations, subject to confidentiality, security, proportionality, and protection of other customers and systems. Any broader audit right must be agreed in writing and scoped so it does not compromise service security or third-party confidentiality.
14. International transfers
Where Customer Personal Data is transferred from a jurisdiction that requires a lawful transfer mechanism, the parties will use an applicable approved mechanism. If EU Standard Contractual Clauses, a UK transfer mechanism, or another official transfer instrument is required, the mandatory official text and appropriate module must control; this public DPA does not paraphrase or replace mandatory clauses.
15. U.S. state privacy terms
Where RISOS acts as a service provider, processor, or contractor under an applicable U.S. state privacy law, RISOS will process Customer Personal Data for the specified business purposes and Customer instructions, subject to restrictions that law requires for that role. This provision does not claim that every state privacy law applies to every Customer or processing activity.
16. Order of precedence
If this DPA conflicts with the governing agreement specifically concerning processing of Customer Personal Data, this DPA controls to the extent of that conflict. Mandatory transfer clauses control where they require a different result. Provider-specific source restrictions continue to control affected source data where they impose a stricter rule.
17. Changes
RISOS may update this public DPA to reflect changes in the service, law, or subprocessors. Material changes are subject to any notice required by the governing agreement or applicable law.
Annex 1 — Details of processing
Subject matter: provision, support, security, and operation of RISOS research, intelligence, workspace, monitoring, reporting, API, and MCP services.
Duration: for the term of the services plus the applicable verified retention/deletion period.
Nature and purposes: authentication; hosting and processing customer prompts, research, workspace content and settings; evidence retrieval and organization; model-assisted extraction, synthesis and verification where permitted; report and monitor operation; developer-interface execution; support; security; abuse prevention; and deletion/export operations.
Data subjects: Customer users, administrators, business contacts, and individuals whose information Customer lawfully submits or instructs RISOS to process.
Data categories: account identifiers, business contact information, Customer Content, research prompts and subjects, workspace metadata, usage/security metadata, and other data Customer chooses to submit within the intended service scope.
Sensitive categories: none intended for the general service unless a feature expressly states otherwise.
Annex 2 — Verified technical and organizational measures
RISOS’s current controls include organization/workspace-scoped authorization, server-side handling of privileged credentials, row-level database boundaries, scoped API keys, rate and concurrency controls, authentication checks, audit/diagnostic controls, source-policy enforcement, provider-specific routing restrictions, data export and scheduled deletion controls, and protected production deployment practices. Security controls may evolve; the Privacy Policy and governing security documentation should be read together with this summary.
Annex 3 — Subprocessors
The current list is maintained at /subprocessors.
Contact
DPA and business privacy questions can be sent to hello@risos.co.