Privacy & Data Protection
Data Classification
How we categorize data by sensitivity so that each type receives the appropriate level of protection.
Last reviewed: July 2026
The Data Classification Policy provides a way to categorize the data processed by Risely’s people, software, and systems. It establishes a framework for classifying data based on its sensitivity, value, and criticality. By understanding the types of data we hold, their classification, and the appropriate access level, we can map the right level of protection to each and keep critical data secure.
This policy applies to all data handled, managed, stored, or transmitted by Risely. Where there is uncertainty about how a specific data element should be classified or handled, we encourage anyone to contact us at [email protected] for guidance.
Data classification definitions
Risely’s data is classified as follows.
Public data
This data or information may be shared with any person, organization, or system regardless of their relationship with Risely. This classification is not limited to information meant for public consumption. It also includes any information that requires no special handling or safeguarding from disclosure. The distribution of such data does not expose Risely, its customers, or its partners to any harm.
Examples include product blogs, company websites, press releases, marketing collateral, and career pages.
Company internal data
This data is accessible to all staff within Risely and may be required for the smooth operational functioning of the organization. Such information is not made available to parties outside Risely but may be shared if requested.
Examples include information security policies and procedures, HR policies, leave policies and holiday lists, and operational procedures.
Company confidential data
This data is accessible by pre-authorized team members and is not made generally available within Risely. Unauthorized access or disclosure could cause significant financial or material loss and pose a risk to Risely if exposed. Such exposure can break contractual obligations and may adversely impact Risely, its partners, employees, and eventually its customers. This information needs to be protected from unauthorized access and changes. Access may also be limited to specific individuals or groups, such as executives, HR, or legal teams.
Examples include employee salaries, legal documents, internal product specifications, customer lists, strategy documents, internal roadmaps, design documents, and internal memos and emails.
Customer confidential data
This data, if accessed by unauthorized parties, may adversely affect Risely’s customers. This includes data that Risely is required to keep confidential, either by law or under a customer agreement. We protect such information from unauthorized access and unauthorized modification, and we safeguard it when it is stored, processed, used, and transmitted.
Unauthorized access to such data can violate contractual confidentiality agreements with customers, cause a security incident, or affect customer and industry confidence.
Examples include data provided by customers by using our system, information on customer accounts, and personally identifiable information of customers or their customers.
Personal data
This data, if accessed by unauthorized parties, may adversely affect the privacy of individuals. Personal data refers to any data relating to an identifiable individual. This includes data that Risely is required to safeguard, either by law, such as GDPR for the data of individuals in the EU, or under a customer agreement. We protect such information from unauthorized access and unauthorized modification, and we safeguard it when it is stored, processed, used, and transmitted.
Unauthorized access to such data may potentially violate the law, break contractual data protection agreements with customers, cause a security incident, or affect customer and industry confidence.
Examples include name, email, phone number, IP address, political views, cookies, personal health records, and credit card information.
Personal health records, credit card information, and other sensitive personal data may be subject to additional laws based on the location of the individual the data belongs to. For example, HIPAA regulations apply to the personal health information of individuals in the US.
Questions
If you have any questions about how we classify and handle data, contact us at [email protected].
Questions about this policy? [email protected]
