Legal

Privacy Policy

How Rukn ERM collects, uses, and protects information. We do not use advertising trackers, and we do not sell your data.

Last updated: 14 September 2026

This Privacy Policy explains how Rukn ERM (“Rukn ERM”, “we”, “us”) collects, uses, and protects information when you use the Rukn ERM mobile application, admin console, and related services (the “Service”).

Rukn ERM is a business tool used by organizations. When your organization (“your company”) provides Rukn ERM to you, your company is the controller of the data you enter, and this policy describes how we process it on your company’s behalf and for our own account-administration purposes.

1. Information we collect

  • Account information — your name, email address, role, and a securely hashed password.
  • Organization content you enter — risks, controls, incidents, actions, key risk indicators, policies, audits, findings, compliance records, comments, and any file attachments you upload.
  • Device & messaging identifiers — a push-notification token used to deliver alerts, and technical logs (IP address, device type, timestamps) needed to operate and secure the Service.
  • Biometric data — if you enable the biometric app lock, authentication happens entirely on your device using the operating system. We never receive or store your fingerprint or face data.

We do not use advertising trackers, and we do not sell your data.

2. How we use information

  • To provide, maintain, and secure the Service and your account.
  • To send operational notifications and reminders you have configured (e.g. due actions, KRI breaches).
  • To generate the reports, dashboards, and analyses you request.
  • To provide the optional AI risk assistant (see section 4).
  • To manage subscriptions and billing, and to provide support.
  • To comply with legal obligations.

3. Legal bases

Where applicable data-protection law requires a legal basis, we rely on the performance of our contract with your organization, our legitimate interests in operating and securing the Service, your consent (where requested, e.g. push notifications), and compliance with legal obligations.

4. The AI risk assistant

The AI risk assistant is optional. When you ask it a question, your question and a snapshot of your own organization’s risk data are sent to our AI provider, Anthropic, solely to generate the answer that is returned to you. This data is limited to your organization’s records, is transmitted securely, and is not used to train models. If you do not use the assistant, no data is sent to the AI provider.

5. Service providers (sub-processors)

We share data with a small set of providers only as needed to run the Service:

  • Hosting & database — our application and database are hosted with cloud infrastructure providers (currently Render and Neon).
  • File storage — attachments may be stored with a cloud object-storage provider.
  • Email delivery — transactional emails (e.g. password reset, digests).
  • Push notifications — delivered via the Expo push service and Apple/Google notification systems.
  • AI provider — Anthropic, for the AI risk assistant only, as described above.

6. International transfers

Our infrastructure may process and store data on servers located outside your country (for example, in the United States or the European Union). Where required, we put appropriate safeguards in place for such transfers.

7. Data retention

We retain your data for as long as your organization’s account is active and as needed to provide the Service. When an account is closed, we delete or anonymize the associated data within a reasonable period, unless a longer retention is required by law.

8. Security

We protect data in transit with TLS encryption, store passwords using industry-standard hashing, isolate each organization’s data, and enforce role-based access controls. No method of transmission or storage is completely secure, but we work to protect your information using appropriate measures. You can read more on our security page.

9. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below (or ask your organization’s administrator). We will respond in line with applicable law.

10. Children

Rukn ERM is a business product intended for use by organizations and is not directed to children under 16. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date above.

12. Contact us

Questions or requests about this policy or your data:
Email: support@rukn-erm.com