Skip to content

Governance

Vendor & Subprocessor Management

The third-party providers we rely on to deliver Risely, and how we assess and manage them.

Last reviewed: July 2026

Delivering Risely relies on trusted third-party providers. This page describes how we assess and manage the information security and data protection risks that come with third-party services, and where to find the current list of the subprocessors we use.

Our approach

Our objective is to manage the information security and data protection risks that arise when third-party vendors, service providers, and subprocessors process, store, or transmit Risely or Risely customer data. This applies to all third parties we engage whose services involve access to, or processing of, company or customer data, including cloud infrastructure providers, AI model providers, and software-as-a-service tools.

Subprocessors

We maintain a register of the subprocessors and service providers we engage. The current, complete list, with each provider’s purpose and location, is published in the Subprocessors section of our Trust Center.

All AI providers are engaged via their commercial API terms, under which customer data submitted through the API is not used to train their foundation models. We inform customers of material changes to the subprocessor register in accordance with their data processing agreements.

Assessing vendors

Before engaging a vendor that will process company or customer data, we review the vendor’s security posture, including available certifications and attestations (such as SOC 2 or ISO/IEC 27001), the vendor’s data protection terms, and the categories of data the vendor will access. Vendors are provided only the minimum data necessary for the service.

Contractual requirements

Vendors that process personal data on our behalf must be bound by appropriate data protection terms, such as a data processing agreement or equivalent provisions, covering confidentiality, security measures, breach notification, and data deletion or return at the end of the engagement. Where personal data is transferred across borders, appropriate safeguards such as Standard Contractual Clauses apply.

Ongoing review

We review the subprocessor register and the security posture of critical vendors at least annually, including the continued validity of their certifications and data protection terms.

Vendor offboarding

When a vendor engagement ends, we ensure that access credentials are revoked and that company and customer data held by the vendor is returned or deleted in accordance with contractual terms.

Questions

If you have any questions about this policy, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]