Last updated: 23 August 2026
The Risk House respects your privacy. This Privacy Policy explains what personal data we collect through our website, portals and Digital Experience Center tools, why we collect it, how we protect it, and the rights available to you as a Data Principal under the Digital Personal Data Protection Act, 2023 and other applicable Indian law.
This policy covers personal data we handle as a Data Fiduciary — that is, data collected through this website, our client, partner and employee portals, our assessment tools, and our sales, delivery and support activities. Where we process data on behalf of a customer as part of a managed service or implementation engagement, we act as a Data Processor and the terms of the relevant contract govern that processing.
We use personal data to respond to your enquiries and prepare quotations; to deliver, support and renew the products and services you buy; to generate and explain the results of the assessment tools you choose to use; to manage portal access and security; to send service communications and, where you have opted in, relevant updates about our offerings; and to meet our legal, tax and regulatory obligations.
Where consent is required, we ask for it clearly and specifically at the point of collection, and we tell you what the data will be used for. You may withdraw consent at any time, and withdrawal is as easy to exercise as giving it — though it will not affect processing already carried out, and it may limit our ability to provide a service. We also process data for certain legitimate uses permitted by law, such as fulfilling an order you placed or complying with a legal requirement.
Our website uses cookies and similar technologies to keep sessions working, remember preferences and understand how the site is used. Essential cookies are required for the site to function; analytics and preference cookies are optional and are set only where permitted. You can control cookies through your browser settings, though blocking essential cookies may affect site functionality.
We do not sell personal data. We share it only where necessary: with technology vendors and OEMs when a licence, subscription or support case must be registered in your name; with service providers who host, secure or support our systems under confidentiality obligations; with professional advisers; and with authorities where disclosure is required by law or to protect our rights. Vendors and providers are permitted to use the data only for the purpose for which it was shared.
Some of the platforms we and our vendors use may store or process data outside India. Where personal data is transferred outside the country, we take reasonable steps to ensure it remains protected by appropriate contractual and security safeguards, and we transfer data only to territories permitted under applicable law.
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as a legal, contractual or accounting obligation requires. Enquiry and assessment data for prospects that do not progress is reviewed periodically and erased when it is no longer required. Portal accounts are deactivated and their data removed after the associated engagement ends, subject to retention obligations.
We apply reasonable security safeguards appropriate to the sensitivity of the data, including access control on a need-to-know basis, encryption of data in transit, hardened hosting, logging and monitoring, vendor due diligence and staff awareness training. No system can be guaranteed completely secure, but in the event of a personal data breach we will notify the Data Protection Board and affected individuals as required by law.
Subject to applicable law, you have the right to:
We respond to verified requests within the timelines set by applicable law and may ask for information to confirm your identity before acting.
Our website and services are intended for business users and are not directed at children. We do not knowingly collect personal data of children, and where consent of a parent or lawful guardian would be required, we do not process such data without it. If you believe a child’s data has been provided to us, please contact us so we can remove it.
We may update this Privacy Policy as our services, systems or legal obligations change. The revised version takes effect when published on this page and the “last updated” date above will change. Where a change materially affects how we use your data, we will take reasonable steps to bring it to your attention.
To exercise any of the rights above, or to raise a concern about how your personal data has been handled, please reach us through the contact page on this website and mark your message for the attention of our Grievance Officer. We will acknowledge your request and respond within the period required by applicable law. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.