Skip to main content
RiskZeroCertifiers

Legal

Privacy policy

What we collect, why, and what you can do about it.

Last updated: September 2026. This policy should be reviewed by legal counsel before publication.

Who we are

RiskZero Certifiers ("RiskZero", "we") is the controller of personal information collected through this website and in the course of providing certification services. Contact us through thecontact form.

Information we collect

  • Quote and contact requests. Name, work email, organization, role, and the details you provide about your scope and requirements.
  • Certification clients. Contact details of client personnel, audit records, and evidence examined during audits, which may include personal information held in client systems. Packages reach us through the riskzero.us platform.
  • Website usage. Server logs including IP address, browser type, pages visited, and referring page. We do not use advertising trackers.
  • Verification requests. The details you send when asking us to verify a certificate, used to answer the request and detect misuse.

How we use it

  • To respond to inquiries and prepare proposals.
  • To plan, conduct, and report certification audits, and to make certification decisions.
  • To answer certificate verification requests, which concern organizations, not individuals.
  • To meet our obligations under ISO/IEC 17021-1, including record retention.
  • To operate, secure, and improve this website.

Legal bases

We process personal information to perform contracts with clients, to comply with legal and regulatory obligations, and in our legitimate interests in responding to inquiries, operating the website, and maintaining the integrity of certification.

Sharing

We share information with service providers who host our systems under contract, including the riskzero.us platform through which packages are submitted and examined, and with authorities where the law requires. We do not sell personal information. Audit evidence is treated as confidential under our certification agreement and ISO/IEC 17021-1.

Retention

Certification records are retained for the duration of the certification cycle plus one further cycle. Inquiry data is retained for 24 months from last contact. Web server logs are retained for 90 days.

Your rights

Depending on where you are, you may have rights to access, correct, delete, or restrict use of your personal information, to object to processing, and to data portability. To exercise them, contact us through thecontact form. You may also complain to your data protection authority.

Cookies

This website uses no advertising or cross-site tracking cookies. Any analytics we use are configured to avoid identifying individuals. Essential cookies may be used for form protection.

Changes

We will post any changes to this policy on this page and update the date above.