Skip to content

Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how Acumen Risk Ltd., a company incorporated in the State of Israel ("Acumen Risk", "we", "us"), collects, uses, shares, and protects personal data when you use the Acumen Cloud platform and our websites (the "Service"). For personal data processed in connection with customer accounts, Acumen Risk Ltd. is the data controller. We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Israeli Protection of Privacy Law, 5741-1981, to the extent they apply.

1. Data We Collect

  • Account data. Name, email address, organization name, role, and authentication identifiers, collected when you sign up or are invited to an account. Authentication is provided by Clerk (see Section 4).
  • Customer content. Data you enter into the platform, such as assets, locations, risk assessments, barriers, and incident records. This data may include personal data your organization chooses to include; your organization is responsible for that content.
  • Billing data. Subscription tier, billing history, and payment status. Payment card details are collected and processed directly by our Merchant of Record, Paddle, and never touch our servers.
  • Usage and log data. IP address, browser type, pages viewed, actions taken, and audit log entries, collected automatically to secure and improve the Service.
  • Support communications. Messages you send to support@acumenrisk.cloud.

2. How We Use Data and Legal Bases

  • Providing the Service (account management, hosting your data, processing assessments, support): performance of a contract.
  • Billing and account administration: performance of a contract and legal obligation.
  • Security, fraud prevention, and audit logging: legitimate interests in protecting the Service and our customers.
  • Service improvement and analytics using aggregated or de-identified data: legitimate interests.
  • Product and marketing communications: consent where required; you can opt out at any time.
  • Compliance with law: legal obligation.

We do not sell personal data and we do not use it for third-party advertising.

3. Where Data Is Stored

Customer content is hosted on Amazon Web Services (AWS) infrastructure in the il-central-1 (Tel Aviv, Israel) region. Some service providers listed below process limited personal data in other regions, including the European Union and the United States. Where personal data subject to the GDPR is transferred internationally, we rely on appropriate safeguards such as adequacy decisions (the European Commission recognizes Israel as providing adequate protection) and Standard Contractual Clauses with our providers.

4. Service Providers (Subprocessors)

We share personal data with a small number of providers who help us run the Service:

  • Amazon Web Services (AWS): cloud hosting, storage, and infrastructure (primary region il-central-1, Israel).
  • Clerk: user authentication and identity management (account and login data).
  • Paddle (Paddle.com Market Ltd. and affiliates): Merchant of Record for paid subscriptions. Paddle processes your payment and billing details as an independent data controller; see the Paddle privacy policy.
  • Geocoding provider: when you search for an address, the search text is processed server-side to return location results; queries are rate-limited and not linked to advertising profiles.

We may also disclose personal data where required by law or to protect our rights, and in connection with a merger or acquisition (in which case this policy continues to apply until updated).

5. Retention

We keep account data and customer content for as long as your account is active. After termination, customer content is retained for 30 days to allow export, then deleted or de-identified, except where longer retention is required by law (for example, billing records) or for security audit logs, which are retained for up to 24 months. Backups are purged on a rolling schedule.

6. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest, database-level tenant isolation, role-based access control, multi-factor authentication support, and append-only audit logging. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the competent authorities as required by law.

7. Your Rights

Subject to applicable law, you have the right to access, rectify, erase, and receive a portable copy of your personal data, to restrict or object to certain processing, and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with a supervisory authority, including the authority in your EU/UK member state or the Israeli Privacy Protection Authority. To exercise your rights, contact support@acumenrisk.cloud; we respond within the timeframes required by law. If your data was entered into the platform by an organization you belong to, we may refer your request to that organization as the party responsible for that content.

8. Cookies

We use strictly necessary cookies for authentication and session management. Payment pages operated by Paddle set their own cookies as described in Paddle's policies. We do not use third-party advertising cookies.

9. Children

The Service is intended for business use by adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. We will post the updated version on this page and, for material changes, notify you by email or in-product notice. The "Last updated" date above shows the current version.

11. Contact

Acumen Risk Ltd.
Email: support@acumenrisk.cloud

See also our Terms of Service and Refund Policy.