1. Who is responsible for your data
ScoRISK Trust Intelligence is the data controller for personal data collected through this website. We are headquartered in Singapore.
For any question about this policy, or to exercise any right described in it, write to contact@scorisk.io. We aim to respond within 30 days.
2. What we collect
We collect only what you type into a form. There is no analytics package on this site, no advertising pixel, and no third-party tracker. We do not buy personal data, and we do not enrich what you give us from other sources.
- Early-access form — your name and email address, which are required; and your organization, role, use case, and current approach, which are optional.
- Contact form — your name, email address, subject, and message.
- Technical data — the browser user-agent string sent with your form submission, retained alongside it to help us identify automated abuse.
- Anti-spam field — both forms contain a hidden field that a human never sees. If it is completed, we discard the submission and store nothing.
3. Why we use it, and our legal basis
Under the GDPR we must have a lawful basis for each use of your personal data. Where you are in the EU, EEA, or UK, these are the bases we rely on.
- Early-access requests — to evaluate and prioritise access and to contact you when it opens. Legal basis: your consent, given when you submit the form. You can withdraw it at any time.
- Contact messages — to answer you. Legal basis: our legitimate interest in responding to an enquiry you chose to send us.
- Abuse prevention — to identify automated or fraudulent submissions. Legal basis: our legitimate interest in keeping the service usable.
4. What we do not do
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to build advertising or behavioural profiles.
We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
Providing your data is voluntary. You are under no statutory or contractual obligation to give it to us — but without an email address we cannot contact you about early access or reply to your message.
5. Who else processes it
We use three service providers to operate this website. Each acts as a processor on our instructions, receives only what it needs, and is not permitted to use your data for its own purposes.
- Supabase — stores early-access submissions.
- Gandi — delivers our notification and confirmation email, from infrastructure in France.
- Vercel — hosts this website and serves it to your browser.
6. Where your data is held
We are established in Singapore, which is not covered by a European Commission adequacy decision. Personal data you submit is therefore transferred outside the EEA and the UK when it reaches us.
Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) together with the UK Addendum, incorporated through the data processing agreements we hold with our providers. Our email provider operates within the EU, so that leg involves no third-country transfer.
You may ask us for details of the safeguards that apply to any transfer.
7. How long we keep it
Early-access entries are kept until the early-access programme closes or you ask us to delete yours, whichever happens first. If your request does not convert into an account, we delete the entry within a reasonable period after the programme ends.
Contact messages are kept for as long as needed to handle your enquiry and any follow-up, and are then deleted.
8. Your rights
If you are in the EU, EEA, or UK, the GDPR gives you the rights below. We honour these requests wherever you are located, and we will not charge you or treat you differently for making one.
- Access — obtain confirmation of whether we hold data about you, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted, where no overriding ground for keeping it applies.
- Restriction — ask us to limit how we use your data while a question about it is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Objection — object to processing carried out on the basis of our legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing carried out before you withdrew it.
- Complain — lodge a complaint with your local supervisory authority. In Singapore, the Personal Data Protection Commission; in the EU, the authority in your country of residence.
10. Security
Traffic to and from this website is encrypted in transit using TLS. Database credentials are held server-side and are never exposed to your browser. Access to submitted data is limited to people who need it.
No system is perfectly secure and we do not claim otherwise. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you.
11. Children
This website is intended for professional audiences and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We will update this page when our practices change, and revise the date shown above. Where a change materially affects how we use data you have already given us, we will tell everyone on the early-access list directly rather than relying on this page alone.
13. Contact
Questions about this policy, requests to exercise a right, or concerns about how we have handled your data: contact@scorisk.io.