Privacy Notice

Last updated: 19 August 2026

1. Who we are

RiskReady 31000 (“RiskReady”, “the service”) is operated by Commtac Consult Ltd, trading as Commtac. Commtac Consult Ltd is the data controller for the personal data described in this notice: we decide what data is collected, why, and how it is used. Questions, requests or complaints about privacy can be sent to pete@commtac.co.

2. Personal data we collect and why

  • Account data (name, email address, login credentials, sign-in provider, assigned role such as Admin, Consultant or Company) — to create and secure your account and control access to assessments. Legal basis: performance of a contract.
  • Client and organisation records (company name, website, contact phone numbers and email addresses, staff names, emails and job roles you enter) — to let consultants set up client organisations and invite raters. Legal basis: performance of a contract and our legitimate interest in providing the service to our business customers.
  • Assessment content (questionnaire answers, risk appetite ratings, free-text comments, AI interview transcripts and voice recordings you choose to submit) — to score ISO 31000:2018 readiness, produce gap analysis, multirater variance heatmaps and reports. Legal basis: performance of a contract.
  • Support communications (messages and emails you send us) — to answer queries and improve the service. Legal basis: legitimate interests.
  • Usage, device and log data (IP address, browser and device identifiers, pages viewed, timestamps, error reports) — for security, fraud and abuse prevention, service reliability and product improvement. Legal basis: legitimate interests and legal obligation.
  • Marketing data (email address, preferences) — only where you have asked to hear from us. Legal basis: consent, which you can withdraw at any time.

We do not need or want special category data. Please do not enter health, criminal or other sensitive personal data into assessment free-text fields.

3. Who we share data with

  • Service providers and subprocessors — cloud hosting, database and authentication infrastructure, email delivery, AI processing for the interview and transcription features, and error/analytics tooling. They act on our instructions under written terms.
  • Merchant of Record — Paddle.com Market Ltd acts as our reseller and Merchant of Record for all orders, and handles order processing, subscription management, payments, tax compliance, invoicing and refunds. Paddle processes payment data under its own privacy notice.
  • Your organisation — where you take part in a multirater assessment, aggregated and, where relevant to the exercise, role-attributed results are visible to the consultant and organisation administrators who commissioned it.
  • Professional advisers — legal, accounting and audit advisers where needed.
  • Authorities — where we are required to disclose by law, or to establish, exercise or defend legal claims.

We do not sell personal data.

4. International transfers

Some of our providers process data outside the UK and EEA. Where that happens we rely on a UK/EU adequacy decision, or we put in place the UK International Data Transfer Addendum or the EU Standard Contractual Clauses together with appropriate technical safeguards. You can ask us for details of the safeguards used.

5. Retention

Account and organisation records are kept for as long as the account is active and for up to 12 months after closure, so access can be restored and disputes resolved. Assessment content and reports are kept for the life of the account unless you delete them earlier, and are then removed within 30 days. Billing and tax records are kept for as long as required by law (typically 7 years, largely held by Paddle). Security and server logs are kept for up to 12 months. When data is no longer needed it is deleted or irreversibly anonymised.

6. Your rights

Subject to UK GDPR and EU GDPR, you have the right to access your personal data, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where consent is our basis. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk). Email pete@commtac.co to exercise a right; we respond within one month and will tell you if we need longer.

7. Security

We apply appropriate technical and organisational measures, including encryption of data in transit, access controls and role-based permissions, row-level database authorisation so users only reach their own organisation's records, least-privilege administrative access, and logging of privileged actions. No online service can be guaranteed completely secure, so please use a strong, unique password and keep your credentials confidential.

8. Cookies and similar technologies

We use essential cookies and local storage to keep you signed in, hold your session and remember interface preferences; the service cannot function without them. Where we use analytics cookies they are limited to understanding aggregate usage and improving the product. We do not use advertising or cross-site marketing cookies. You can clear or block cookies in your browser settings, but blocking essential cookies will prevent sign-in. Paddle may set cookies during checkout under its own notice.

9. Changes to this notice

We may update this notice as the service evolves. We will change the date above and, for material changes, notify account holders by email or in-app notice.