Privacy Policy
RiskWire is a curated CVE intelligence service operated as a solo venture. This page explains what information we collect about visitors and prospects, why we collect it, and what your rights are. Written in plain English so you can actually understand it.
1. Who we are
RiskWire is operated by Rustem Ihnikulen, a sole operator based in Ukraine. Contact for privacy questions: privacy@riskwire.io.
2. What we collect
a. Marketing site (riskwire.io home page)
Standard server logs from our hosting provider (Netlify): IP address, browser user-agent, requested URL, and timestamp. This is used to keep the service running and to detect abuse. We do not add analytics tracking, ad pixels, or third-party trackers on the public marketing pages.
b. Invited dashboard access (via personalized magic link)
When a prospect visits the dashboard using a unique link we sent them, we log:
- The prospect identifier that we assigned when we created the link (e.g., "Alice @ Acme Corp")
- Timestamp of each visit
- IP address of the visit
- Approximate city and country (derived from the IP)
- Browser user-agent string
- Which page was viewed (dashboard, portfolio, etc.)
- The referring URL, if any
We use this to gauge whether a prospect is actively engaging with the product and to time our sales follow-up appropriately. This is standard practice for business-to-business sales tooling.
c. Cookies
We set one cookie, rw_session,
when you first visit the dashboard via a magic link. Its only purpose is to
remember that you were invited so subsequent visits don't require the
?k= parameter in the URL.
It's a strictly necessary cookie under EU ePrivacy rules and does not track
you across other websites. It expires after 30 days.
d. Contact form / email correspondence
If you email us or fill out a booking form, we keep the message and your contact details to respond and follow up. Standard sales-CRM stuff.
3. Why we collect it (legal basis)
For prospects in the EU / UK, our legal basis under GDPR is legitimate interest — specifically, business-to-business sales prospecting and understanding whether a prospect is engaging with our product. This interest is balanced against your rights, and we limit collection to what's necessary for those purposes.
We do not process special categories of data. We do not make automated decisions with legal effect about you.
4. Who we share it with
We do not sell your data. We share it only with:
- Netlify — our hosting provider. Server logs and the visit database live in their infrastructure. See Netlify's privacy policy.
- Namecheap — our domain registrar. Only relevant for DNS operations, not visitor data.
- Legal authorities, if required by valid legal process.
5. How long we keep it
Visit logs are retained for up to 12 months and then deleted. Prospect contact details are kept for the duration of our sales relationship plus 24 months (in case you come back to us later). You can request earlier deletion at any time (see Your rights below).
6. Your rights
Under GDPR (EU/UK), CCPA (California), and similar regimes, you have the right to:
- Ask what personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to processing based on legitimate interest
- Withdraw consent (where consent is the basis)
- Lodge a complaint with a supervisory authority
To exercise any of these, email privacy@riskwire.io from the address the data is associated with. We'll respond within 30 days.
7. Security
Data is encrypted in transit (HTTPS) and at rest (Netlify infrastructure). Access to the admin dashboard is protected by a shared secret held only by the operator. We do not store passwords, credit card details, or other sensitive credentials.
8. International transfers
Data is stored in Netlify's global infrastructure, which may include servers in the United States and elsewhere. If you're in the EU/UK, this constitutes an international transfer. We rely on Netlify's standard contractual clauses and other safeguards for these transfers.
9. Children
RiskWire is a business-to-business product not directed at anyone under 18. We do not knowingly collect data from children.
10. Changes to this policy
If we materially change how we handle data, we'll update this page and change the "Last updated" date at the top. Prospects with active engagement will be notified by email of material changes.
Contact
Questions or requests: privacy@riskwire.io