Skip to content

Privacy Policy

How TekRisk collects, uses, and protects your personal information in compliance with the GDPR, CCPA/CPRA, and other applicable privacy laws.

Last updated: April 12, 2026

1. Introduction

TekRisk® ("TekRisk", "we", "us", or "our") operates the TekRisk platform accessible at tekrisk.com (the "Service"), which provides industrial risk analysis software for the chemical, oil & gas, and related industries.

This Privacy Policy describes how we collect, use, disclose, and protect personal information about visitors to our website and users of our Service. It applies to individuals located anywhere in the world, including residents of the European Economic Area (EEA), the United Kingdom, Switzerland, and the United States.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

2. Who We Are (Data Controller)

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, TekRisk is the data controller of the personal information processed through the Service.

Privacy inquiries: privacy@tekrisk.com EU Data Protection Officer: dpo@tekrisk.com Postal address: available upon request at privacy@tekrisk.com

If you are located in the EEA or the UK, you may contact our DPO directly for any matter related to the processing of your personal information.

3. Information We Collect

Account information: email address, full name, password hash, profile picture, role, company, country, and preferred language.

Authentication data: credentials used for email/password sign-in and OAuth identifiers when you sign in with Google (Google account ID and basic profile information).

Service content: projects, industrial sources, chemical parameters, weather data, receptors, simulation inputs and outputs that you upload or generate within the Service. This content may include technical descriptions of facilities and processes.

Usage and technical data: IP address, browser type and version, device identifiers, operating system, pages viewed, timestamps, referring URLs, crash logs, and diagnostic information.

Cookies and similar technologies: as described in our Cookie Policy.

Billing information (if you subscribe to a paid plan): name, billing address, tax identifiers, and transaction metadata. Payment card data is processed directly by our payment provider; we do not store full card numbers.

Communications: messages you send us, including support requests, feedback, and invitations you extend to collaborators.

4. Purposes and Legal Bases for Processing

We process your personal information for the following purposes and on the following legal bases under Article 6 of the GDPR:

a) Provision of the Service — to create and manage your account, run simulations, store your projects, and deliver core features. Legal basis: performance of a contract.

b) Security and integrity — to detect fraud, abuse, and unauthorized access, and to maintain audit logs. Legal basis: legitimate interests and, where applicable, legal obligation.

c) Service improvement and analytics — to understand how the Service is used and to enhance features. Legal basis: legitimate interests, or consent where required.

d) Communications — to respond to inquiries, notify you of material changes, and send transactional messages. Legal basis: performance of a contract and legitimate interests.

e) Marketing communications — where permitted by law and only with your prior consent, to send product updates or promotional materials. You may withdraw consent at any time.

f) Compliance with legal obligations — to comply with applicable law, respond to lawful requests, and enforce our Terms of Service. Legal basis: legal obligation.

We do not sell your personal information, and we do not use it for solely automated decision-making that produces legal or similarly significant effects on you.

5. Recipients and Subprocessors

We share personal information with trusted service providers acting as data processors under written agreements. Our principal subprocessors include:

• Amazon Web Services, Inc. — cloud hosting, authentication (Amazon Cognito), storage (Amazon S3), and database services. Primary region: us-east-1 (United States). • Google LLC — OAuth authentication (Google Sign-In) and AI model services (Google Gemini via LangGraph) used by our Leopold analysis assistant. • Mapbox, Inc. — map tiles and geolocation services used within the Service's mapping components.

We may also disclose personal information to: (i) professional advisors (lawyers, auditors, accountants) bound by confidentiality; (ii) competent authorities, courts, or regulators when required by law or to protect rights; and (iii) acquirers in the event of a merger, acquisition, or asset sale, subject to appropriate safeguards.

6. International Data Transfers

TekRisk is based in the United States, and most of our infrastructure is located there. If you access the Service from the EEA, the UK, or Switzerland, your personal information will be transferred to and processed in countries outside your region, including the United States.

Where required, we implement appropriate safeguards for international transfers, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and, where applicable, reliance on the EU-U.S. Data Privacy Framework. You may request a copy of the safeguards in place by writing to privacy@tekrisk.com.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.

General retention periods: • Active account data: for as long as your account is active. • Data after account deletion: up to 90 days for backups and operational recovery, after which it is deleted or anonymized. • Audit logs: up to 24 months for security and compliance purposes. • Billing records: for the period required by applicable tax and accounting laws (typically up to 7 years).

You may request earlier deletion subject to applicable legal retention requirements.

8. Your Privacy Rights

Depending on where you reside, you may have the following rights with respect to your personal information:

• Access — request confirmation of processing and a copy of your data. • Rectification — correct inaccurate or incomplete data. • Erasure ("right to be forgotten") — request deletion of your data, subject to applicable exceptions. • Restriction — request that we temporarily limit processing. • Objection — object to processing based on legitimate interests or for direct marketing. • Portability — receive your data in a structured, commonly used, machine-readable format. • Withdraw consent — withdraw consent at any time where processing is based on consent, without affecting prior lawful processing. • Lodge a complaint — with a competent data protection authority.

To exercise any of these rights, contact us at privacy@tekrisk.com. We will respond within the timeframes required by applicable law (generally 30 days under the GDPR and 45 days under the CCPA/CPRA, subject to permitted extensions). We will verify your identity before fulfilling requests. You will not be discriminated against for exercising your rights.

9. Notice to California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA") grants you additional rights.

Categories of personal information collected in the last 12 months: identifiers (name, email, IP address), commercial information (subscription details), internet or other electronic network activity information (usage logs, interactions), approximate geolocation (from IP), professional or employment information (company, role), and inferences drawn from the foregoing to the extent applicable.

Sources: directly from you, automatically from your device, from third-party sign-in providers (Google), and from our service providers.

Business purposes: to provide, secure, and improve the Service, process transactions, communicate with you, and comply with legal obligations.

Disclosures for business purposes: we disclose personal information to the service providers listed in Section 5.

Sale or sharing: we do NOT sell or share (as those terms are defined by the CCPA, including sharing for cross-context behavioral advertising) your personal information, and we have not done so in the preceding 12 months.

Sensitive personal information: we do not use or disclose sensitive personal information for purposes that would require a right-to-limit notice under the CCPA.

California rights: (i) right to know; (ii) right to delete; (iii) right to correct; (iv) right to opt out of sale/sharing (not applicable, as we do not sell or share); (v) right to limit use of sensitive personal information (not applicable); (vi) right to non-discrimination. You may exercise these rights by emailing privacy@tekrisk.com. Authorized agents may submit requests on your behalf with written proof of authorization.

10. Notice to EEA, UK, and Swiss Residents (GDPR)

If you are located in the EEA, the UK, or Switzerland, the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection grant you the rights listed in Section 8, plus the right to lodge a complaint with your local supervisory authority.

You may contact our EU Data Protection Officer at dpo@tekrisk.com for any question regarding the processing of your personal information or the exercise of your rights.

11. Notice to Other U.S. State Residents

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, and other U.S. states with comprehensive privacy laws may have rights similar to those described above, including the right to access, correct, delete, and port their personal data, and to opt out of targeted advertising, sale of personal data, and certain profiling activities.

We do not engage in sale of personal data or in targeted advertising. To exercise your rights or to appeal a decision, please contact privacy@tekrisk.com.

12. Children's Privacy

The Service is intended for professional users and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 16 (or under 13 in jurisdictions covered by the U.S. Children's Online Privacy Protection Act, COPPA).

If you believe that a child has provided us with personal information, please contact privacy@tekrisk.com, and we will take steps to delete such information.

13. Information Security

We implement technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS) and at rest, role-based access controls through Amazon Cognito and CASL-based authorization, audit logging, least-privilege access for personnel, and periodic security reviews.

No method of transmission over the Internet or electronic storage is 100% secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent authorities and, where required, affected individuals in accordance with applicable law.

14. Cookies and Similar Technologies

We use cookies and similar technologies to operate and improve the Service. For detailed information about the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.

15. Automated Processing and AI Features

The Service includes AI-assisted features, including the "Leopold" assistant powered by large language models (e.g., Google Gemini). These features analyze inputs you provide to assist with risk assessment drafting.

We do not use your personal information for solely automated decision-making producing legal or similarly significant effects on you. AI-generated outputs are advisory; users remain responsible for reviewing and validating results before relying on them.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our Service, or legal requirements. When we make material changes, we will notify you by email and/or by posting a prominent notice within the Service at least 30 days before the changes take effect, except where a shorter notice period is required by law.

The "Last updated" date at the top of this page indicates when it was last revised.

17. Contact Us

For any questions, complaints, or requests regarding this Privacy Policy or our data practices, please contact us at:

TekRisk — Privacy Team Email: privacy@tekrisk.com EU Data Protection Officer: dpo@tekrisk.com