ProfilioBack to site
Trust and transparency

Privacy Policy

This policy explains how personal data is handled when you visit the Profilio website or use the Profilio customer risk scoring service.

Last updated29 July 2026
Plain-language summary

Profilio is a business service. We use personal data to provide, secure, support, and improve the service. Customer organizations control the customer-risk records they place in Profilio.

01

Scope and privacy roles

This Privacy Policy applies to the Profilio marketing website and the Profilio customer risk scoring service. It does not apply to third-party websites or services linked from Profilio.

When an organization uses Profilio to assess its customers, that organization normally decides why and how customer data is used and acts as the data controller. Profilio processes that data on the organization's instructions as its service provider or processor.

For website operations, account administration, service security, support, and our own legal obligations, the Profilio service provider may act as an independent controller. The legal entity responsible for your service is identified in the applicable Profilio agreement or order form.

02

Personal data we process

The categories of data depend on how you interact with us:

  • Website and device data: IP address, browser and device information, requested pages, timestamps, referral information, and security or diagnostic logs.
  • Account data: name, business email address, organization, user role, authentication status, multi-factor authentication settings, and session information.
  • Customer-risk data: customer identifiers, customer type and subtype, identifying details, assigned risk factors, scores, risk levels, review timestamps, and related records entered by an authorized customer organization.
  • Activity and audit data: user actions, configuration changes, score history, risk-level changes, report generation details, and export fingerprints.
  • Support and communications: messages, attachments, feedback, and information supplied when requesting assistance.

We receive data from you, your organization, authorized users, your device or browser, and service providers that support the operation and security of Profilio.

03

How and why we use personal data

We process personal data to:

  • provide, configure, maintain, and support Profilio;
  • authenticate users and manage roles and permissions;
  • calculate and preserve customer risk scores and history;
  • maintain audit trails, prevent misuse, and investigate security incidents;
  • generate reports and exports requested by authorized users;
  • communicate about service operation, support, and material changes; and
  • comply with applicable legal and regulatory obligations.

Where applicable, we rely on performance of a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent when the law requires it. Customer organizations are responsible for establishing an appropriate legal basis for customer-risk data they submit to Profilio.

04

Cookies and similar technologies

The public Profilio landing page does not intentionally use advertising or cross-site tracking cookies. The authenticated service may use strictly necessary cookies or comparable browser storage to maintain sessions, protect accounts, remember security choices, and provide requested functionality.

If optional analytics or other non-essential technologies are introduced, this policy and any required consent controls will be updated before they are used.

05

Sharing and international transfers

Personal data may be shared with:

  • authorized users and administrators of the customer organization;
  • vetted hosting, infrastructure, security, communications, and support providers acting under contractual safeguards;
  • professional advisers, auditors, or transaction counterparties where reasonably necessary; and
  • courts, regulators, law enforcement, or other parties when required by law or needed to protect legal rights and service security.

Where data is transferred outside its country of origin, we use safeguards required by applicable law, such as adequacy decisions or approved contractual clauses.

06

Data retention

We retain personal data only for as long as needed for the purposes described in this policy. Customer-risk data is retained according to the customer organization's instructions and the applicable service agreement. Account, audit, security, and support records may be kept for longer where needed to preserve scoring history, maintain security, resolve disputes, or meet legal obligations.

Data may remain in protected backups for a limited period before being overwritten or securely deleted.

07

Security

Profilio uses technical and organizational safeguards designed for business risk operations. These include tenant separation, role-based access, multi-factor authentication, hardened sessions, browser security controls, audit logging, and change traceability.

No system can guarantee absolute security. Users should protect their credentials, use approved devices, and notify their organization promptly if they suspect unauthorized access.

08

Your privacy rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to complain to your local data protection authority.

If your data was entered into Profilio by a customer organization, submit your request to that organization first. We support customer organizations in responding to verified requests. We may need to confirm your identity before acting on a request, and legal exceptions may apply.

Profilio is intended for organizations and professional users, not for children. We do not knowingly offer the service directly to children.

09

Contact and policy changes

For website, account, or service privacy questions, email privacy@profilio.tech. If an organization provided your Profilio account, contact that organization first about data it entered or controls. The legal service provider and any additional privacy contacts are identified in the applicable Profilio service agreement.

We may update this policy to reflect changes in the service, legal requirements, or our data practices. The date at the top of this page identifies the latest version. Material changes will be communicated through the service or another appropriate channel.

Privacy is part of the control model.Profilio is designed to keep access, scoring activity, and historical decisions traceable.