Profilio is a business service. We use personal data to provide, secure, support, and improve the service. Customer organizations control the customer-risk records they place in Profilio.
Scope and privacy roles
This Privacy Policy applies to the Profilio marketing website and the Profilio customer risk scoring service. It does not apply to third-party websites or services linked from Profilio.
When an organization uses Profilio to assess its customers, that organization normally decides why and how customer data is used and acts as the data controller. Profilio processes that data on the organization's instructions as its service provider or processor.
For website operations, account administration, service security, support, and our own legal obligations, the Profilio service provider may act as an independent controller. The legal entity responsible for your service is identified in the applicable Profilio agreement or order form.
Personal data we process
The categories of data depend on how you interact with us:
- Website and device data: IP address, browser and device information, requested pages, timestamps, referral information, and security or diagnostic logs.
- Account data: name, business email address, organization, user role, authentication status, multi-factor authentication settings, and session information.
- Customer-risk data: customer identifiers, customer type and subtype, identifying details, assigned risk factors, scores, risk levels, review timestamps, and related records entered by an authorized customer organization.
- Activity and audit data: user actions, configuration changes, score history, risk-level changes, report generation details, and export fingerprints.
- Support and communications: messages, attachments, feedback, and information supplied when requesting assistance.
We receive data from you, your organization, authorized users, your device or browser, and service providers that support the operation and security of Profilio.
How and why we use personal data
We process personal data to:
- provide, configure, maintain, and support Profilio;
- authenticate users and manage roles and permissions;
- calculate and preserve customer risk scores and history;
- maintain audit trails, prevent misuse, and investigate security incidents;
- generate reports and exports requested by authorized users;
- communicate about service operation, support, and material changes; and
- comply with applicable legal and regulatory obligations.
Where applicable, we rely on performance of a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent when the law requires it. Customer organizations are responsible for establishing an appropriate legal basis for customer-risk data they submit to Profilio.
Data retention
We retain personal data only for as long as needed for the purposes described in this policy. Customer-risk data is retained according to the customer organization's instructions and the applicable service agreement. Account, audit, security, and support records may be kept for longer where needed to preserve scoring history, maintain security, resolve disputes, or meet legal obligations.
Data may remain in protected backups for a limited period before being overwritten or securely deleted.
Security
Profilio uses technical and organizational safeguards designed for business risk operations. These include tenant separation, role-based access, multi-factor authentication, hardened sessions, browser security controls, audit logging, and change traceability.
No system can guarantee absolute security. Users should protect their credentials, use approved devices, and notify their organization promptly if they suspect unauthorized access.
Your privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to complain to your local data protection authority.
If your data was entered into Profilio by a customer organization, submit your request to that organization first. We support customer organizations in responding to verified requests. We may need to confirm your identity before acting on a request, and legal exceptions may apply.
Profilio is intended for organizations and professional users, not for children. We do not knowingly offer the service directly to children.
Contact and policy changes
For website, account, or service privacy questions, email privacy@profilio.tech. If an organization provided your Profilio account, contact that organization first about data it entered or controls. The legal service provider and any additional privacy contacts are identified in the applicable Profilio service agreement.
We may update this policy to reflect changes in the service, legal requirements, or our data practices. The date at the top of this page identifies the latest version. Material changes will be communicated through the service or another appropriate channel.
Privacy is part of the control model.Profilio is designed to keep access, scoring activity, and historical decisions traceable.