Governance
Vendor & Subprocessor Management
The third-party providers we rely on to deliver Risely, and how we assess and manage them.
Last reviewed: July 2026
Delivering Risely relies on trusted third-party providers. This page describes how we assess and manage the information security and data protection risks that come with third-party services, and where to find the current list of the subprocessors we use.
Our approach
Our objective is to manage the information security and data protection risks that arise when third-party vendors, service providers, and subprocessors process, store, or transmit Risely or Risely customer data. This applies to all third parties we engage whose services involve access to, or processing of, company or customer data, including cloud infrastructure providers, AI model providers, and software-as-a-service tools.
Subprocessors
We maintain a register of the subprocessors and service providers we engage. The current, complete list, with each provider’s purpose and location, is published in the Subprocessors section of our Trust Center.
All AI providers are engaged via their commercial API terms, under which customer data submitted through the API is not used to train their foundation models. We inform customers of material changes to the subprocessor register in accordance with their data processing agreements.
Assessing vendors
Before engaging a vendor that will process company or customer data, we review the vendor’s security posture, including available certifications and attestations (such as SOC 2 or ISO/IEC 27001), the vendor’s data protection terms, and the categories of data the vendor will access. Vendors are provided only the minimum data necessary for the service.
Contractual requirements
Vendors that process personal data on our behalf must be bound by appropriate data protection terms, such as a data processing agreement or equivalent provisions, covering confidentiality, security measures, breach notification, and data deletion or return at the end of the engagement. Where personal data is transferred across borders, appropriate safeguards such as Standard Contractual Clauses apply.
Ongoing review
We review the subprocessor register and the security posture of critical vendors at least annually, including the continued validity of their certifications and data protection terms.
Vendor offboarding
When a vendor engagement ends, we ensure that access credentials are revoked and that company and customer data held by the vendor is returned or deleted in accordance with contractual terms.
Questions
If you have any questions about this policy, contact us at [email protected].
Questions about this policy? [email protected]
