Privacy Policy
Version 2.1 — Effective Date: 4 June 2026. Last Updated: 4 June 2026.
Who We Are
KinetiRisk is a trading style of High Peak Pro Ltd.
- Company Name: High Peak Pro Ltd
- Company Registration Number: 11682424 (registered in England)
- Registered Office: Bartle House, 9 Oxford Court, Manchester, Greater Manchester, England, M2 3WQ
- Trading As: KinetiRisk
1. Introduction & Scope
This Privacy Policy explains how High Peak Pro Ltd (trading as KinetiRisk) collects, uses, stores, and protects your personal data when you use the KinetiRisk Service.
Applicable law. We are a UK company regulated by the Information Commissioner's Office (ICO). This policy is written under UK GDPR (as retained under the Data Protection Act 2018). Where we have customers in the European Union, EU GDPR (Regulation 2016/679) also applies.
This policy covers: personal data (your name, email, organisation); Customer Data (risks, projects, team members, audit logs); and AI Analysis Outputs (risk scores, reasoning summaries, recommendations). Contact legal@kinetirisk.com for jurisdiction-specific queries.
2. Data We Collect & How We Use It
2.1 Personal Data (You as a User)
What we collect: name, email address, organisation; account preferences; login history, IP address, device information; payment information (via Stripe — we do not store card details directly).
How we use it: create and manage your account; send transactional emails; enforce billing and subscription terms; comply with legal obligations; aggregate anonymised analytics.
Legal basis: Contract — Article 6(1)(b) GDPR; legitimate interest — Article 6(1)(f) GDPR; legal obligation — Article 6(1)(c) GDPR.
2.2 Customer Data (Your Risk Data)
What we collect: projects, programmes, portfolios; risks (title, description, category, probability/impact scores); mitigation actions and responsible parties; team member information and access logs; audit trails of all changes.
How we use it: enable you to use the KinetiRisk Service; generate AI risk analysis; provide escalation notifications and reports; comply with data subject rights requests.
No model training. We do not use your Customer Data or AI Analysis Outputs to train, fine-tune, or improve any AI model. Your data is never used for model training and is not shared with third parties for this purpose.
2.3 AI Analysis Outputs
What we collect: AI-generated risk scores (1–25 scale); AI-generated reasoning summaries; AI-generated mitigation recommendations.
We do not use AI Analysis Outputs to train any AI model. You own the AI Analysis Outputs subject to use restrictions in the Terms of Service.
2.4 Data Sent to AI Providers
When you use AI risk scoring, we transmit to OpenAI or Anthropic: risk title and description; project context and category; historical risk data (if applicable). Data is encrypted in transit (TLS 1.3) and processed transiently. We have contracted with both providers to ensure your data is not used to train their models. Returned data is stored in the EU.
3. Data Residency & Security
3.1 Data Location. All Customer Data and Personal Data is stored within the European Union. Primary data centre: EU region (PostgreSQL database hosted on Replit EU infrastructure). Backups: EU region (retained for 90 days after deletion).
3.2 Security Practices:
- In transit: TLS 1.3+
- At rest: AES-256-GCM application-level encryption (per sensitive field, applied before database persistence); additionally protected by platform-native AES-256 storage encryption
- Role-based access control (Super Admin, Team Member, Viewer)
- Audit logging of all data access events
- Minimum necessary access principle
- Hosted on Replit (EU region) under a Data Processing Agreement
- Regular security audits and penetration testing
4. Your Rights & Account Deletion
4.1 Your Rights Under GDPR
- Right of Access (Article 15): Request a copy of all personal data we hold about you, free of charge, within one month.
- Right to Rectification (Article 16): Request correction of inaccurate personal data.
- Right to Erasure (Article 17): Request deletion of your personal data, subject to our legitimate grounds for retention.
- Right to Data Portability (Article 20): Receive your personal data in a structured, machine-readable format (CSV or JSON).
- Right to Object (Article 21): Object to processing where we rely on legitimate interest as the legal basis.
- Right to Lodge a Complaint: UK: Information Commissioner's Office (ICO) — 0303 123 1113. EU: your local EU data protection authority.
4.2 How to Exercise Your Rights. Email: legal@kinetirisk.com. We will respond within one month.
4.3 Account Deletion. Request deletion via Settings → Account → Delete Account. 30-day hold period, then permanent deletion. Backups are purged within 90 days. What is retained: anonymised audit records (compliance), billing records (6 years under UK law).
5. Third-Party Processors & Integrations
Sub-processors we use (all bound by GDPR-compliant Data Processing Agreements): Replit (cloud infrastructure, EU), OpenAI (AI risk analysis), Anthropic (AI risk analysis), Stripe (payment processing), Resend (transactional email), Better Auth (authentication), Microsoft Graph API and Google Tasks API (task push), Microsoft Teams and Google Chat (escalation notifications), Google Analytics (web analytics, opt-in only).
No Data Sales or Marketing Sharing. We do not sell your personal data to third parties, share your Customer Data with competitors, or use your risk data for marketing or profiling.
6. Cookies & Analytics
Cookies we use:
- Essential cookies: Login session management, security — always active
- Preference cookies: Remembering your UI display settings — always active (functional)
- Analytics cookies: Google Analytics — aggregate usage understanding — opt-in only
We do not use tracking pixels, advertising cookies, or ad network cookies. When you first visit KinetiRisk, a cookie consent banner will appear. You can change your preferences at any time in Settings → Privacy.
7. Data Retention
- Account data (name, email, profile): until account deletion
- Login history and IP logs: 90 days, then deleted
- Payment records: 6 years (UK tax and fraud prevention)
- Active risks, projects, portfolios: until you delete them or your account is deleted
- Audit logs: 1 year, then deleted
- Backups: 90 days from creation, EU region
8. Data Breaches & Security Incidents
If we discover a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
To report a security vulnerability: security@kinetirisk.com. We will acknowledge receipt and respond within 72 hours.
9. Children
KinetiRisk is a professional B2B service intended for use by organisations and business professionals. It is not intended for persons under the age of 18. We do not knowingly collect personal data from minors.
10. Changes to This Policy
Material changes will be announced by email at least 30 days before the change takes effect. Non-material changes will be announced at or before the time they take effect. Continued use of the Service after the notice period constitutes your acceptance of the updated policy.
11. Governing Law & Dispute Resolution
This Privacy Policy is governed by the laws of England and Wales, and by UK GDPR as enforced by the ICO. Contact us first at legal@kinetirisk.com — we aim to respond within 5 business days.