← Back to App
Privacy Policy
Last updated: April 13, 2026 · Diamond Properties Investments SRL · CUI 50535310 · Romania, EU
This policy applies to riskaix.com and all RiskAI X services.

Summary: We collect only what's necessary to run the service. We never sell your data. We never show you ads. You can request deletion of your data at any time. We are based in Romania (EU) and comply with GDPR.

1. Who We Are

RiskAI X is operated by Diamond Properties Investments SRL, a Romanian company (CUI 50535310) registered in Romania, European Union. We are the data controller for all personal data processed through riskaix.com.

For data protection questions: privacy@riskaix.com

2. What Data We Collect

Data TypeWhatWhyLegal Basis
Account dataEmail address, name (if provided)Account creation, authenticationContract
Payment dataBilling email, subscription statusPayment processing via PaddleContract
Property searchesAddresses you searchDeliver risk reports, cachingContract
Usage dataPages visited, features used, API callsPlatform improvement, rate limitingLegitimate interest
Technical dataIP address, browser type, deviceSecurity, fraud preventionLegitimate interest
CommunicationsEmails you send usSupport, product feedbackConsent / legitimate interest

We do not collect: government IDs, financial account numbers, passwords in plain text, location tracking data, or any sensitive categories of personal data under GDPR Article 9.

3. How We Use Your Data

4. Property Address Data

When you enter a property address, we process it to generate a risk report. Address data is:

5. Third-Party Services

We use the following third-party services that may process your data:

ServicePurposeData SharedLocation
PaddlePayment processingEmail, billing infoUK/EU
CloudflareCDN, Workers, KV storageIP, request dataEU edge nodes
Resend / BrevoTransactional emailEmail addressEU
Anthropic ClaudeAI analysis generationProperty address (anonymized)US (SCCs)
OpenStreetMap NominatimGeocoding addressesAddress stringEU
USGS / EMSCSeismic dataCoordinates onlyUS / EU

For transfers to the US (Anthropic), we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism under GDPR Article 46.

6. Cookies and Tracking

We use minimal cookies:

We do not use advertising cookies, third-party tracking pixels, or analytics services that identify individuals (such as Google Analytics with user IDs). We do not show advertisements.

7. Data Retention

Data TypeRetention Period
Account dataDuration of account + 2 years after deletion request
Property search cache24 hours (Cloudflare KV)
Saved properties (Portfolio)Until you delete them or close your account
Payment records7 years (Romanian fiscal law requirement)
Usage/analytics data90 days rolling
Support emails2 years

8. Your Rights Under GDPR

As an EU resident, you have the following rights:

To exercise any of these rights, email privacy@riskaix.com or use our automated endpoints:

We will respond to all requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with ANSPDCP (Romania's data protection authority) at dataprotection.ro.

9. Data Security

We implement industry-standard security measures including:

10. Children's Privacy

RiskAI X is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@riskaix.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify subscribers by email at least 14 days before the changes take effect. The "last updated" date at the top of this page always reflects the current version.

12. Contact

Diamond Properties Investments SRL
CUI 50535310 · Romania, EU

Data protection: privacy@riskaix.com
General: info@riskaix.com
GDPR requests: privacy@riskaix.com
Supervisory authority: ANSPDCP Romania

Your Data Subject Rights (GDPR Art. 15–22)

Under GDPR, you have the right to: access your data · rectify inaccurate data · erase your data ("right to be forgotten") · restrict processing · data portability · object to processing.

To submit a Data Subject Access Request (DSAR): email privacy@riskaix.com with subject line "DSAR Request". We respond within 30 days.

API endpoint: POST /api/v2/dsar — automated data export/deletion.