EvRiskoEvRiskoIT risk managementmade simple
HomeHow to usePricingBlogContact Us
☰
HomeHow to usePricingBlogContact Us
Sign InSign Up
Sign InSign Up
Legal

EvRisko Privacy Notice

Effective date: 01 October 2026 · Last updated: 01 October 2026
General
Terms and conditions Acceptable use policy Refund & cancellation policy
Privacy and Security
Privacy notice Cookie notice Data Processing Addendum Security annex

This Privacy Notice explains how TechComply collects, uses, discloses, and protects personal information when you visit our website, create an Account, use the Services, contact us, or otherwise interact with us.

1. Who we are

TechComply is the data processor in regards to the provision of the EvRisko web application and the related services. Client is the data controller and decides how its personal data is used in connection to the Services.

TechComply
Amsterdam, the Netherlands
Email: techcomplynl@gmail.com

2. Information we collect

We may collect:

•Account and company information:
–name;
–work email address;
–job title;
–company name;
–company size, industry, and location;
–username and authentication information;
–billing and subscription details;
–communications with us; and
–account preferences.
•Questionnaire and risk information:
–questionnaire responses;
–details on IT systems, processes, suppliers, controls, and risks;
–information about remediation activities;
–risk scores, classifications, and recommendations; and
–report and dashboard information.

Note: Client should not enter passwords, payment card details, private encryption keys, or unnecessary special category Personal Data into questionnaire fields.

•Technical and usage information:
–account details;
–IP address;
–browser and device information;
–operating system;
–log-in and access times;
–pages and features used;
–error logs;
–approximate location derived from IP address; and
–cookies and similar technologies.

Payment information

Payments are processed by Stripe. We may receive limited information such as payment status, transaction identifier, card type, billing country, and the last four digits of a payment card. We do not generally receive or store full payment-card numbers.

3. How we use information

We use information to:

•create and administer Accounts;
•provide dashboards, reports, recommendations, and remediation actions;
•process subscriptions and payments;
•authenticate users and maintain account security;
•provide Client support;
•communicate about the Services, billing, and service changes;
•monitor performance and troubleshoot problems;
•detect fraud, abuse, and security incidents;
•comply with legal obligations;
•enforce our agreements; and
•create aggregated or de-identified statistics and improve the Services.

Where permitted by law, we may send marketing communications. You can opt out at any time using the unsubscribe link or by contacting us.

4. Legal bases

Where GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Creating and managing an AccountPerformance of a contract
Providing the ServicesPerformance of a contract
Processing paymentsPerformance of a contract and legal obligations
Security and fraud preventionLegitimate interests and legal obligations
Product analytics and service improvementLegitimate interests, consent where required
Direct marketingConsent or legitimate interests, where permitted
Legal claims and complianceLegal obligations and legitimate interests

5. Client Data and our role

When a business Client submits Personal Data through the Services, Client acts as data controller and TechComply acts as data processor under the GDPR. The Data Processing Addendum applies to that processing.

For information about our own website, account administration, billing, marketing, security, and support activities, we may act as an independent data controller.

6. Sharing information

We may share information with the following natural or legal entities with the sole purposes of providing you the Services:

•hosting and cloud infrastructure providers;
•payment processors;
•authentication, email, analytics, monitoring, and support providers;
•professional advisers;
•auditors and insurers;
•regulators, courts, law-enforcement authorities, or other bodies where legally required; and
•a purchaser or successor in connection with a merger, acquisition, financing, or sale of assets.

We do not sell personal information. We do not disclose Client Data to third parties except as necessary to provide the Services, operate our business, comply with law, or as otherwise described in this Notice.

7. International transfers

Some service providers may process information outside your country. Where required, we use appropriate transfer safeguards, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, and supplementary security measures.

8. Retention

We retain information only for as long as reasonably necessary for the purposes described in this Notice, including to:

•provide the Services;
•maintain business and financial records;
•resolve disputes;
•enforce agreements;
•prevent fraud and abuse; and
•comply with legal obligations.

After an Account is terminated, Client Data is generally deleted or anonymized within 30 days, subject to backups, legal retention requirements, and the Data Processing Addendum.

9. Your data protection rights

Depending on your location, you may have the right to:

•request access to Personal Data;
•request correction;
•request deletion;
•request restriction of processing;
•object to processing;
•request data portability;
•withdraw consent;
•object to direct marketing; and
•lodge a complaint with a data protection authority.

Requests may be sent by using the contact form. We may need to verify your identity before addressing your inquiry further.

10. Cookies

Our website uses cookies and similar technologies for essential operation, authentication, security, preferences, analytics, and marketing where applicable.

For more information, see our Cookie Notice.

11. Security

We use reasonable technical and organizational safeguards designed to protect Personal Data. However, no online service is completely secure. Clients are responsible for configuring their Accounts and access controls appropriately. More information on our security controls can be found in our Terms & Conditions and Security Annex.

12. Children

The Services are intended for business users and are not directed to children. We do not knowingly collect Personal Data from children.

13. Changes

We may update this Privacy Notice from time to time. We will post the updated version and change the “Last updated” date. Where legally required, we will provide additional notice. We will not obtain your approval for the implementation of said changes.

14. Contact and complaints

Questions or requests should be sent to:

TechComply
Amsterdam, the Netherlands
Email: techcomplynl@gmail.com

You may also contact the relevant data protection authority in your country of residence or operation.

EvRiskoEvRiskoIT risk managementmade simple
GeneralPrivacy and Security
© 2026 EvRisko