Privacy Policy
Last updated: 23 June 2026
1. About this policy
This policy explains how Bridge Point Limited, NZBN 9429030686984, trading as RiskSense (RiskSense, we, us, or our) collects, uses, stores, shares, and protects personal information when you visit risksense.cloud, sign up for a free tool or trial, use the paid product, or otherwise interact with us.
RiskSense is based in New Zealand. We operate under the New Zealand Privacy Act 2020. Where applicable, we also handle personal information consistently with the Australian Privacy Act 1988, the UK GDPR and Data Protection Act 2018, and the EU GDPR.
This policy applies to RiskSense's own handling of personal information. Where a customer, MSP, or partner uses RiskSense for its own users, that organisation is usually responsible for its own privacy notices, lawful basis, and instructions to us.
Privacy questions can be sent to [email protected].
2. Information we collect
The personal information we collect depends on how you interact with RiskSense.
Website, sales, and support interactions
- Contact details such as name, work email address, company, phone number, role, country, and message content.
- Sales, demo, partner, billing, support, and account administration communications.
- Standard website and security logs such as IP address, browser, device, page, referrer, timestamp, and approximate location derived from technical information.
- Analytics and cookie data described in section 7.
Accounts, free tools, and training-only use
- Account details such as name, work email address, company, role, country, and authentication information.
- Training activity such as modules assigned, started, completed, responses, scores, coaching interactions, timestamps, and progress records.
- Product usage, support, security, and audit records associated with the account.
Paid product and connected tenants
- Tenant and organisation details such as tenant name, domain, configuration, subscription status, partner/MSP relationship, and administrator users.
- Directory information needed to operate the Service, such as user names, work email addresses, account status, group or team information, roles, departments, job titles, manager relationships, licence/mailbox status, and similar business directory attributes.
- Integration authorisation, configuration, and operational data needed to connect to Microsoft 365, Google Workspace, email, identity, billing, and other services selected by the customer.
- Training, simulated phishing, coaching, reporting, and security awareness records, including delivery, open, click, report, completion, score, and engagement events.
- Limited email and communication metadata where needed to generate, deliver, analyse, or report on simulations and training. We do not sell this data.
- Billing and licensing information, including Eligible User counts for customer tenants.
3. How we use information
- To provide, operate, secure, monitor, and support RiskSense.
- To create, deliver, personalise, and report on security awareness training, simulated phishing, and coaching.
- To administer accounts, tenants, MSP relationships, subscriptions, billing, licensing, and support.
- To generate customer reports, training records, audit records, and risk insights for authorised administrators and MSPs.
- To communicate with you about the Service, including operational messages, security notices, support, billing, and product updates.
- To respond to sales enquiries, demo requests, contact forms, and partner enquiries.
- To improve the Service, troubleshoot issues, measure performance, and understand aggregate usage trends.
- To detect, investigate, and prevent abuse, fraud, security incidents, and unlawful activity.
- To comply with legal, tax, accounting, regulatory, and court obligations.
4. Legal bases for UK and EU data
Where UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:
- Contract: providing the Service, accounts, support, billing, and related communications.
- Legitimate interests: operating and improving a B2B security product, securing the Service, preventing misuse, supporting customers, and limited business-to-business marketing.
- Consent: optional marketing, analytics cookies where required, and other consent-based activities.
- Legal obligation: tax, accounting, regulatory, court, and lawful request obligations.
For customer-controlled product data, we generally process personal information on the customer's instructions as its processor or service provider, unless a written agreement says otherwise.
5. How we share information
We share personal information only where needed for the purposes above.
- Service providers: vendors that host, store, transmit, analyse, secure, support, or otherwise process data for us, under contractual confidentiality and security obligations.
- Customer administrators: authorised administrators may access tenant, user, training, simulation, and reporting data for their organisation.
- MSP or partner administrators: where a customer receives RiskSense through an MSP or partner, that MSP or partner may access and administer the customer tenant.
- Connected third-party services: Microsoft, Google, email, identity, billing, and other services the customer chooses to connect or use with RiskSense.
- Professional advisers: lawyers, accountants, auditors, insurers, and advisers where reasonably necessary.
- Authorities: regulators, courts, law enforcement, or other authorities where required by law or necessary to protect rights, safety, or security.
- Business transfers: a buyer, investor, or successor if RiskSense is involved in a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate protections.
We do not sell personal information or user data. We also do not share personal information with third parties for their independent advertising or marketing.
6. International transfers
RiskSense is operated from New Zealand, and our service providers may process or store personal information in New Zealand, Australia, the United Kingdom, the European Union, the United States, or other countries where they operate.
Where personal information is transferred internationally, we use safeguards appropriate to the circumstances, such as contractual protections, recognised transfer mechanisms, adequacy decisions, or equivalent protections required by applicable law.
7. Cookies and tracking
The website and Service may use cookies, pixels, local storage, and similar technologies for:
- Strictly necessary purposes: keeping the website and Service working, maintaining sessions, security, load balancing, and remembering basic preferences.
- Analytics: understanding website and product usage, performance, and aggregate trends.
- Marketing and attribution: measuring campaigns and enquiries where permitted by law and your preferences.
You can control cookies through your browser settings. You can also opt out of Google Analytics using Google's browser opt-out. Where consent is required by law, we will request it before using non-essential cookies.
8. Retention
We keep personal information only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required by law or a customer agreement.
- Website logs, analytics, and marketing data are retained for reasonable operational, security, and reporting periods.
- Sales, support, and account records are retained while the relationship is active and for a reasonable period afterwards.
- Free-tool and trial data is retained while the account is active and may be deleted after dormancy or termination.
- Paid customer data is retained during the contract term and then deleted or returned in accordance with the applicable agreement, unless we must retain it for legal, security, dispute, backup, or compliance reasons.
- Accounting, tax, and billing records are retained for the period required by applicable law.
9. Security
We use technical and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse, alteration, and disclosure. These include access controls, encryption, tenant separation, logging, monitoring, secure development practices, and vendor review processes appropriate to the nature of the data and Service.
No system is perfectly secure. If we identify a privacy or security incident affecting personal information, we will assess it and notify affected customers, individuals, and regulators where required by law.
10. Your rights
Depending on where you live and the context in which we process your information, you may have rights to:
- Access personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Request deletion of personal information.
- Object to or restrict certain processing.
- Receive a portable copy of certain information.
- Withdraw consent where processing is based on consent.
- Complain to us or to a privacy regulator.
To exercise rights for information controlled by RiskSense, email [email protected]. We may need to verify your identity before acting on a request.
If your information is held in a customer tenant, we may need to refer your request to that customer or MSP because they control the relevant data.
Relevant regulators include the New Zealand Office of the Privacy Commissioner, the Australian Office of the Australian Information Commissioner, the UK Information Commissioner's Office, and EU data protection authorities.
11. Children's privacy
RiskSense is a business service and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, contact us and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the Last updated date and notify customers where appropriate. Continued use of the Service after an update means the revised policy applies.
13. Contact
Privacy questions, data requests, or complaints: [email protected]
General questions: risksense.cloud/contact
Bridge Point Limited trading as RiskSense is based in Hamilton, New Zealand.