Privacy Policy

Last updated: April 2026

1. Who we are

De-Risk Matrix Company AS, org.nr 937 716 125 ("we", "us", "our") is the data controller responsible for personal data processed through the De-Risk Matrix application (app.deriskmatrix.com).

Contact: hello@deriskmatrix.com

2. What data we collect

CategoryDataSource
AccountFull name, email addressYou provide at registration
OrganisationCompany name, organisation number, websiteYou provide or fetched from public registries
UsageGoals, targets, data points, risk drivers, actions, strategiesYou enter in the application
AI analysis inputCompany website content, uploaded annual reports (PDF), financial contextYou initiate analysis
TechnicalIP address, browser type, session dataAutomatically — for security and operation

We do not collect payment card data directly — payments are handled by our payment processor.

3. How we use your data

PurposeLegal basis (GDPR)
Provide and operate the ServicePerformance of contract (Art. 6(1)(b))
User authentication and account managementPerformance of contract
AI-assisted goal and risk analysisPerformance of contract / Legitimate interest
Improve and develop the ServiceLegitimate interest (Art. 6(1)(f))
Service-related communications (security, updates)Performance of contract / Legal obligation
Marketing emails (only with explicit consent)Consent (Art. 6(1)(a))
Comply with legal obligationsLegal obligation (Art. 6(1)(c))

We do not sell your data to third parties. We do not use your data for advertising.

4. AI processing — important notice

When you use AI-powered features (Company Analyzer, AI Goal Generator), content you provide — such as website URLs, uploaded PDF documents, and company context — is transmitted to Anthropic, PBC (provider of Claude AI) for processing. Anthropic acts as a data processor on our behalf.

Anthropic does not use data submitted via the API to train its models. A Data Processing Agreement (DPA) is in place with Anthropic. See anthropic.com/legal/privacy.

Do not upload documents containing sensitive personal data (identity numbers, health data, confidential employee information) unless you have a lawful basis to do so.

5. Third-party processors

ProcessorPurposeLocation
Supabase Inc.Database, authentication, file storageEU (Frankfurt, Germany)
Anthropic, PBCAI language model (Claude)USA — Standard Contractual Clauses
Vercel Inc.Application hosting, serverless functionsUSA — Standard Contractual Clauses
BrønnøysundregistrenePublic company data (org.nr lookups)Norway — public API, no personal data

Where processors are located outside the EU/EEA, transfers take place under Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Data retention

We retain your data for as long as your account is active. If you close your account, we will delete or anonymise your personal data within 90 days, unless we are required to retain it longer by applicable law.

7. Your rights (GDPR)

Under GDPR you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Restriction — ask us to limit processing
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — for any consent-based processing, at any time

Email us at hello@deriskmatrix.com. We will respond within 30 days. You may also lodge a complaint with the Norwegian data protection authority: datatilsynet.no.

8. Cookies and local storage

We use browser localStorage to store session preferences and draft data locally on your device. We use session cookies required for authentication (managed by Supabase Auth). We do not use third-party tracking or advertising cookies.

9. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email at least 30 days before they take effect.

10. Contact

De-Risk Matrix Company AS · Org.nr 937 716 125
hello@deriskmatrix.com