Who we are and scope
DarkRisk (Pty) Ltd (“DarkRisk”, “we”, “us”, or “our”) provides third-party risk management software, websites, and related support and professional services (together, the “Services”). This Privacy Policy applies when you visit darkrisk.io or another website that links to it, use our Services, communicate with us, attend an event, apply for a role, or otherwise interact with DarkRisk.
We are a responsible party under South Africa's Protection of Personal Information Act 4 of 2013 (“POPIA”) for personal information we determine how and why to process. Where a customer submits personal information to the Services and controls its processing, DarkRisk generally acts as that customer's operator or processor. The customer's privacy notice and instructions govern that processing, and requests about that information should usually be directed to the customer.
We apply POPIA as our primary privacy framework and, where applicable to a particular processing activity, the EU General Data Protection Regulation (“GDPR”) and other applicable data protection laws. “Personal information” in this policy includes “personal data” under the GDPR and, where POPIA applies, information relating to an identifiable natural or existing juristic person.
Information we process
The information we process depends on how you interact with DarkRisk.
Account and business contact information
Name, work email address, telephone number, employer, role, account credentials, team membership, communication preferences, and records of our communications.
Customer and service information
Information entered, uploaded, connected, or generated when customers use the Services. This may include vendor records, assessments, questionnaires, evidence, comments, remediation activity, risk findings, contact details, and other customer-directed content (“Customer Data”).
Transaction information
Subscription, contract, billing, invoicing, and payment status information. Payment card data may be handled directly by our payment provider rather than stored by DarkRisk.
Device and usage information
IP address, browser and device type, operating system, approximate location inferred from IP, referring pages, dates and times of access, pages or features used, diagnostic events, log data, and security activity.
Public and third-party risk information
Business and technical information obtained from public websites, public records, security datasets, customers, vendors, integration partners, and other lawful sources. Although this information usually concerns organisations and their digital assets, it may sometimes include professional contact details or other personal information.
Sales, events, support, and recruitment
Information you provide when requesting a demonstration, subscribing to an update, attending an event, asking for support, completing a survey, or applying for a role. Recruitment information may include a CV, qualifications, employment history, interview notes, references, and work-eligibility details.
Please do not provide special personal information, sensitive personal data, or information about children unless it is necessary, authorised, and agreed with DarkRisk in writing.
How we collect information
- Directly from you, including when you create an account, contact us, complete a form or assessment, or use the Services.
- From your organisation or other users, such as an account administrator who invites you or a customer who asks you to complete a vendor assessment.
- Automatically, through service logs, cookies, and similar technology when you use our websites or Services.
- From lawful third-party and public sources, including business partners, integrations you authorise, security data providers, company websites, professional networks, and public databases.
If you provide personal information about another person, you must be authorised to do so and must give that person any notice or obtain any consent required by law.
Purposes and legal bases
We process personal information to:
- provide, administer, support, and secure the Services;
- create accounts, authenticate users, and manage permissions;
- deliver assessments, risk insights, reports, and customer-requested workflows;
- process subscriptions, invoices, payments, and contractual records;
- respond to enquiries, demonstrations, support requests, and feedback;
- monitor reliability, prevent abuse, investigate incidents, and troubleshoot;
- analyse and improve the performance, usability, and functionality of our Services;
- send service messages and, where permitted, relevant marketing communications;
- manage suppliers, business partners, events, and recruitment;
- establish, exercise, or defend legal claims and enforce our agreements; and
- comply with law, lawful requests, and regulatory obligations.
Where the GDPR applies, we rely on one or more of these legal bases: performance of a contract or steps requested before entering one; compliance with a legal obligation; our legitimate interests or those of a third party, where those interests are not overridden by your rights; and consent, where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
Under POPIA, we process information where permitted by law, including where you consent, where processing is necessary for a contract, where it complies with a legal obligation, protects a legitimate interest of the data subject, or pursues our or a third party's legitimate interests in a lawful and proportionate way.
We do not sell customer data
DarkRisk does not sell Customer Data or personal information. We do not share Customer Data with third parties for their own advertising, and we do not use Customer Data to train general-purpose artificial intelligence models.
We may create aggregated or de-identified information that cannot reasonably be linked to an identifiable person or customer. We may use that information for analytics, security research, benchmarking, and improving our Services, subject to our contractual commitments and applicable law.
Third-party services and platform policies
DarkRisk relies on carefully selected infrastructure providers, subprocessors, and other third parties to deliver the Services. Our current third-party and subprocessor disclosures are maintained at trust.darkrisk.io. That list may change as our Services develop; any changes remain subject to our customer agreements and applicable data protection requirements.
If you connect a third-party account or integration, we receive and use the data authorised through that connection only to provide, secure, and support the requested functionality. We comply with applicable provider API terms and do not use data received through a customer-authorised integration to train general-purpose AI or machine-learning models. You can usually revoke an integration through the relevant provider or your DarkRisk account settings.
Third-party websites and services have their own privacy practices. This policy does not govern a third party acting independently of DarkRisk.
International transfers
DarkRisk and its service providers may process information in South Africa and other countries. Those countries may have privacy laws that differ from the laws where you live.
For transfers from South Africa, we apply POPIA section 72 and use a permitted transfer basis, such as adequate protection under applicable law or a binding agreement, consent where appropriate, or another statutory ground. For personal data protected by the GDPR, we use an approved transfer mechanism where needed, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.
Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, meet our contractual commitments, maintain security and audit records, resolve disputes, and comply with legal, tax, accounting, and regulatory requirements.
Retention periods vary according to the nature and sensitivity of the information, the potential risk from unauthorised use or disclosure, customer instructions, and legal requirements. When retention is no longer authorised or required, we delete, destroy, or de-identify the information in accordance with applicable law and our technical capabilities. Backup copies may remain for a limited period until securely overwritten.
Security
We use reasonable and appropriate technical and organisational measures designed to preserve the confidentiality, integrity, and availability of personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Learn about our security programme and vulnerability reporting process at security.darkrisk.io. Please report suspected security issues through the channels listed there, rather than in a public forum.
If a compromise of personal information occurs, we will investigate and notify affected parties and regulators when required by applicable law.
Your privacy rights
Depending on where you are and which law applies, you may have the right to:
- be informed about our collection and use of your personal information;
- ask whether we process your information and request access to it;
- request correction of inaccurate, incomplete, outdated, or misleading information;
- request deletion or destruction where we are no longer authorised to retain it;
- object to or request restriction of certain processing;
- withdraw consent where processing is based on consent;
- object at any time to direct marketing;
- receive certain information in a structured, commonly used, machine-readable format;
- object to a decision based solely on automated processing that has legal or similarly significant effects, where applicable; and
- complain to DarkRisk or an applicable supervisory authority.
To make a request, email [email protected]. Describe the request and the account or interaction it concerns. We may ask for information reasonably necessary to verify your identity and authority. Rights are not absolute; we may decline or limit a request where permitted by law, including to protect another person's rights or comply with a legal retention duty. We will explain our decision where required.
If DarkRisk processes the information solely for a customer, we may direct the request to that customer or assist it in responding. Authorised agents may submit requests where applicable law allows, subject to verification of their authority.
Marketing choices
You can opt out of promotional email at any time by using the unsubscribe link in the message or contacting us. We may still send non-promotional messages that are necessary for your account, a transaction, security, or the operation of the Services.
We send direct marketing only as permitted by applicable law. Under POPIA, this includes obtaining consent where required and giving you a clear way to object to future marketing at no charge.
Children
The Services are designed for organisations and are not directed to children under 18. We do not knowingly collect a child's personal information through the Services without the authorisation required by law. If you believe a child has provided personal information to us improperly, please contact us so that we can investigate and take appropriate action.
Trademarks
DarkRisk, the DarkRisk name and logo, and the names, logos, product names, service names, designs, and slogans associated with our Services are trademarks or other protected brand assets of DarkRisk (Pty) Ltd. This policy does not grant permission to use them. Other names and marks belong to their respective owners. See our Terms of Service for the rules governing use of our Services and intellectual property.
Changes to this policy
We may update this policy as our Services, practices, or legal obligations change. The effective date at the top shows when the current version applies. If a change is material, we will provide additional notice where required, such as through the Services, on our website, or by email. Earlier versions may be requested from our compliance team.
Contact and complaints
Questions, privacy requests, or concerns can be sent to our Information Officer and compliance team at [email protected]. Please contact us first if you have a concern; we will investigate and aim to resolve it fairly and promptly.
You may also lodge a complaint with the South African Information Regulator at [email protected] or through its complaints service. If the GDPR applies, you may complain to the data protection authority in the EEA country where you live or work, or where you believe an infringement occurred.