Trust Center
Security, privacy, and how we handle your data
Risely protects the data that customers and their people entrust to us. We run a documented information security and privacy program, and we publish the policies behind it in full on this page, so you can see exactly how we handle your data, who we share it with, and the controls we operate.
Risely is a product of Culturro Inc. Where we process personal data on behalf of a customer organization, we act as a data processor and process that data only on the customer’s documented instructions.
Controls
The practices we operate to protect your data. Each links to the policy it comes from.
Data protection & privacy
We process personal data lawfully, for limited and explicit purposes, and only what is necessary. Individuals can exercise their rights of access, correction, deletion, portability, objection, and restriction.
Access control & least privilege
Access follows need-to-know and least-privilege principles using role-based access, with access to production systems reviewed quarterly and promptly revoked on role change or exit.
Authentication
Multi-factor authentication is enforced on company accounts, single sign-on is used where possible, and stored credentials are encrypted.
Encryption
Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest, with cryptographic keys managed securely by our infrastructure provider.
Infrastructure & cloud security
Risely runs on Google Cloud Platform with customer data hosted in the United States. Our cloud providers are held to encryption, data segregation, logging, and incident-response requirements.
Vulnerability management
We run continuous internal vulnerability scanning and package monitoring, plus periodic external scans and penetration tests, with severity-based remediation targets tracked to resolution.
Backups & resilience
Critical customer data is backed up automatically to encrypted snapshots (AES-256) within Google Cloud in the United States, retained on a rolling basis, with restoration tested at least annually.
Business continuity
We maintain business-continuity and disaster-recovery plans, with redundancy considered where availability cannot otherwise be assured, reviewed and tested at least annually.
Incident & breach response
We operate a documented incident-management framework for timely detection, response, and post-incident learning, and notify affected customers of a personal-data breach as required by law and contract.
Secure development
Security is built into our software development lifecycle, with change-management controls governing changes to production systems.
AI governance
Users always know Merlin is an AI coach. It is scoped to coaching, customer data is not used to train foundation models, and organization administrators receive session summaries and engagement metrics, never raw conversation transcripts.
Vendor & subprocessor management
Subprocessors are assessed for their security posture, bound by data-protection terms, given only the minimum data necessary, and reviewed at least annually.
Subprocessors
The third parties we rely on across our product and business operations. We give each only the minimum data necessary.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting and infrastructure | United States |
| OpenAI | AI language and speech-to-text services for coaching | United States |
| Anthropic | AI language services for coaching | United States |
| Google (Gemini / Vertex AI) | AI language and text-to-speech services for coaching | United States |
| ELTV Technologies Pvt. Ltd | Engineering, operations, and support (Culturro affiliate) | India |
| Microsoft Clarity | Product usage analytics | United States |
| SendGrid (Twilio) | Transactional email delivery | United States |
| Google Workspace | Email, collaboration, and identity | United States |
| Stripe | Payment processing | United States |
| Chargebee | Subscription billing and management | India |
| Apollo | Sales engagement and CRM | United States |
| Google Analytics (GA4) | Website and product analytics | United States |
| Meta / LinkedIn | Advertising and conversion measurement | United States |
Customer data is hosted in the United States. Our India affiliate, ELTV Technologies, may access it remotely to provide engineering, operations, and support, under safeguards such as Standard Contractual Clauses. The subprocessors that process customer personal data in delivering the coaching service, and that are named in our Data Processing Agreement, are Google Cloud Platform, OpenAI, Anthropic, Google, and ELTV Technologies; the remaining entries are service providers we use across email, billing, analytics, and sales. All AI providers are engaged via commercial API terms under which customer data submitted through the API is not used to train their foundation models. Locations shown are each provider’s primary jurisdiction; global providers may process data in other regions under their own terms. Customers are informed of material changes to this register in accordance with their data processing agreements.
Resources
Our security and privacy policies, published in full. Each opens as its own page.
Privacy & Data Protection
Security Controls
Infrastructure & Operations
Resilience & Incident Response
Secure Development
Governance
Internal procedures. The following operational procedures support the policies above and are available to customers under NDA on request: Access Control Procedure, Compliance Procedure, Personal Data Breach Notification Procedure, Network Security Procedure, Incident Management Procedure, Business Continuity Plan Procedure, SDLC Procedure. For a copy, contact [email protected].
Frequently asked questions
Where is my data hosted?
Customer data is hosted on Google Cloud Platform in the United States.
Is my data used to train AI models?
No. Customer data is not used by Risely or by its large language model providers to train foundation models. LLM providers are engaged via commercial API terms that exclude API data from model training.
Can organization administrators read coaching conversations?
No. Administrators of customer organizations receive AI-generated session summaries and engagement metrics. They do not receive raw conversation transcripts.
How do I request deletion of my data?
Contact us at [email protected]. We authenticate every request and complete verified deletions within 30 days. On contract termination, customer data is deleted within 30 days of the termination date or the customer’s request.
What rights do I have over my personal data?
You can request to be informed about, access, correct, delete, port, object to, or restrict the processing of your personal data. Requests are acknowledged and fulfilled within one month of receipt.
How is my data encrypted?
Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Backup snapshots are encrypted with AES-256. Cryptographic keys are managed securely by our infrastructure provider.
Who are Risely’s subprocessors?
Risely’s subprocessors include Google Cloud Platform (hosting); OpenAI, Anthropic, and Google (AI language and speech services); the Culturro affiliate ELTV Technologies in India; and additional service providers for email, billing, analytics, and sales. See the Subprocessors section above for the full list.
Does Risely act as a data controller or a data processor?
Where Risely processes personal data on behalf of a customer organization, it acts as a data processor and processes that data only on the customer’s documented instructions. For cross-border transfers, Risely relies on safeguards such as Standard Contractual Clauses.
Is Merlin a human or an AI?
Merlin is an AI coach, and users always know they are interacting with an AI, not a human. It is designed for leadership and professional-skills coaching and redirects users to appropriate human resources for matters outside its scope, such as medical, mental-health, legal, or HR-policy questions.
Have a question that is not answered here? Email [email protected].
