Privacy Policy

Last updated: September 18, 2026

RiskBright is committed to protecting personal information and handling it responsibly and transparently.

RiskBright is a trading name of Shermika Blaise Robinson, a sole trader established in England and Wales (“RiskBright”, “we”, “us” or “our”).

This Privacy Policy explains how we collect, use, share and protect personal information in connection with the RiskBright website, platform and related services.

For privacy enquiries, please contact us at hello@riskbright.co.uk.

1. Who we are

RiskBright provides AML support software primarily for UK estate agencies.

Our contact details are:

RiskBright

Shermika Blaise Robinson

Office By31 Curthill House

60 Water Lane

Cheshire

SK9 5AJ

Wilmslow

United Kingdom

Email: hello@riskbright.co.uk

2. Our role in relation to personal data

RiskBright may process personal data in different capacities depending on the circumstances.

For personal information relating to RiskBright users, account administration, subscriptions, support, security and operation of our business, RiskBright generally acts as a data controller.

Where an estate agency enters personal data relating to its customers or other individuals into RiskBright for the purpose of using the Customer Journey or other platform functionality, the estate agency will generally determine why that information is being processed. In those circumstances, the estate agency will generally act as the data controller and RiskBright will act as its data processor.

Where RiskBright acts as a processor, our processing is also governed by our Data Processing Agreement.

3. Personal information we collect

The information we collect depends on how RiskBright is used.

Account and contact information

We may collect:

  1. your name;
  2. email address;
  3. telephone number;
  4. agency or business name;
  5. account information; and
  6. information you provide when registering or managing your account.

Information entered into RiskBright

Users may enter information relating to customers, transactions or matters when using RiskBright.

Depending on the feature being used and the information supplied by the user, this may include:

  1. customer names;
  2. property addresses;
  3. agency file or matter references;
  4. customer or party type;
  5. company and ownership information;
  6. information relating to customer due diligence;
  7. answers to AML-related questions;
  8. source of funds information;
  9. beneficial ownership information; and
  10. other information voluntarily entered by the user.

Users should only enter personal information where it is reasonably necessary and where their organisation has an appropriate lawful basis or other authority to process that information.

Payment and subscription information

Payments are processed by our payment provider, Stripe.

We may receive information relating to your subscription, payment status, transactions, billing and Stripe customer reference.

RiskBright does not need to store your full payment-card details in order to provide the Service.

Support and communications

If you contact us, we may process:

  1. your name and contact details;
  2. correspondence;
  3. support requests; and
  4. other information you choose to provide.

Technical and security information

When you access RiskBright, we may process technical information necessary to operate and secure the Service, including:

  1. IP address;
  2. sign-in information;
  3. authentication information;
  4. security and administrative activity; and
  5. information required to investigate technical or security issues.

Cookies and browser information

RiskBright uses cookies and similar browser technologies for purposes including authentication, security and remembering certain preferences.

More information is available in our Cookie Policy.

4. Where personal information comes from

We generally obtain personal information:

  1. directly from RiskBright users when they register, contact us or use the Service;
  2. from estate agencies when their authorised users enter information into RiskBright;
  3. from our service providers where necessary to administer accounts, payments or the Service; and
  4. from official or publicly accessible sources where a RiskBright feature allows users to access or search such information.

Where an estate agency enters information about a customer or another individual, that information has been provided to RiskBright by the relevant agency rather than collected directly from that individual by RiskBright.

5. How we use personal information

We may process personal information to:

  1. create and administer RiskBright accounts;
  2. provide and operate the RiskBright Service;
  3. authenticate users and protect account security;
  4. provide Customer Journeys and other requested functionality;
  5. generate Journey documents requested by users;
  6. provide RiskBright calculators, searches and resources;
  7. process and administer subscriptions and payments;
  8. provide customer support;
  9. communicate with users about the Service;
  10. maintain, troubleshoot and improve the platform;
  11. detect and prevent misuse, fraud and security incidents;
  12. maintain appropriate business and administrative records;
  13. comply with applicable legal obligations; and
  14. establish, exercise or defend legal rights.

Where we act as a processor for an estate agency, we process customer personal data to provide the relevant RiskBright functionality on the agency's instructions and subject to our Data Processing Agreement.

6. Our lawful bases for processing

Where RiskBright acts as a controller, the lawful basis we rely on depends on the purpose for which the personal information is processed.

We may rely on:

Contract — where processing is necessary to provide RiskBright, administer your account or subscription, or take steps requested by you before entering into a contract.

Legitimate interests — where processing is reasonably necessary for our legitimate business interests, including operating and securing RiskBright, preventing misuse, providing support, maintaining appropriate business records and improving the Service, provided those interests are not overridden by the rights and interests of the individual.

Legal obligation — where processing is necessary for us to comply with a legal obligation.

Consent — where consent is the appropriate lawful basis, including for optional cookies or similar technologies where consent is required. Where we rely on consent, you may withdraw it.

Where RiskBright acts solely as a processor, the relevant estate agency, as controller, is responsible for determining the appropriate lawful basis for its processing.

7. Customer Journey information

RiskBright's Customer Journey is designed to support an estate agency's own AML assessment and record-keeping process.

Information entered into a Journey is processed for the purpose of providing the Journey and generating the requested Journey document.

RiskBright is designed not to retain a completed Customer Journey as a customer record once the Journey document has been generated.

The generated document is provided to the user so that the estate agency can download it and retain it within its own records.

The estate agency is responsible for downloading, reviewing and retaining any Journey document it requires for its own AML or regulatory record-keeping purposes.

RiskBright does not use Journey information to make the estate agency's final AML assessment or decision.

Temporary technical copies may exist for a limited period where necessary for system operation, security, backup or recovery. These will be subject to appropriate retention and deletion controls.

8. AI and HMRC Guidance Search

RiskBright uses artificial intelligence technology to provide certain functionality, including HMRC Guidance Search.

Information submitted to AI-assisted functionality may be processed by our AI service provider where necessary to provide the requested functionality.

Users should not enter customer-identifying information into HMRC Guidance Search.

RiskBright does not use HMRC Guidance Search to make automated AML decisions about individuals.

RiskBright's Customer Journey and AI-assisted features do not make solely automated decisions that produce legal or similarly significant effects on individuals.

9. Who we share personal information with

We use third-party service providers to operate RiskBright.

Depending on the functionality used, these may include providers of:

  1. database services;
  2. cloud and file storage;
  3. payment processing;
  4. artificial intelligence services;
  5. transactional email;
  6. website and application hosting; and
  7. optional embedded video services.

Our service providers may include MongoDB, Amazon Web Services (including Amazon S3), Stripe, OpenAI, Resend and Vercel.

We only provide service providers with information reasonably necessary for the relevant service, subject to the applicable contractual and data-protection arrangements.

RiskBright may also interact with official or external information sources, including Companies House.

Where you leave RiskBright to access an external website or service, that organisation may process information under its own privacy policy.

Optional embedded services such as YouTube or Vimeo may process information when their content is enabled or played, subject to the applicable cookie and consent settings and their own privacy practices.

We may also disclose personal information where required by law, regulation, court order or a competent authority, or where reasonably necessary to establish, exercise or defend legal rights.

RiskBright does not sell personal information to advertisers.

10. International transfers

Some of our service providers may process personal information outside the United Kingdom, including in the United States.

Where this involves a restricted international transfer of personal information, we will take steps to ensure that an appropriate transfer mechanism or safeguard is used where required by UK data-protection law.

Depending on the circumstances, this may include applicable UK adequacy regulations or approved contractual safeguards.

You can contact us at hello@riskbright.co.uk if you require further information about the safeguards relevant to your personal information.

11. How long we keep personal information

We do not keep personal information for longer than reasonably necessary for the purposes for which it is processed, taking account of legal, contractual, security and operational requirements.

Our current retention approach includes:

  1. unfinished work: up to 30 days;
  2. HMRC Guidance Search and AI search information: up to 30 days;
  3. sign-in records: approximately 7 days;
  4. completed Customer Journeys: not retained as customer records after the Journey document has been generated;
  5. generated Journey documents: not retained by RiskBright as the estate agency's long-term AML record; and
  6. account information: retained while the account is active and, where necessary, for an appropriate period afterwards for legitimate business, contractual or legal purposes.

Some information may remain temporarily within secure backups, logs, caches or other technical systems until it is overwritten or deleted in accordance with the relevant technical retention cycle.

Where information must be retained for legal, accounting, fraud-prevention, dispute or security purposes, we may retain the minimum information necessary for the applicable period.

The ICO's storage-limitation principle requires organisations not to keep personal data for longer than necessary and to be able to justify their retention periods.

12. Security

We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include:

  1. secure authentication;
  2. password protection;
  3. access controls;
  4. encryption or secure storage where appropriate;
  5. controls against repeated unauthorised sign-in attempts; and
  6. administrative and security activity logging.

Our third-party infrastructure providers also maintain their own security measures.

No internet-based service can guarantee absolute security.

Users are responsible for maintaining the confidentiality and security of their RiskBright login credentials.

13. Your data-protection rights

Depending on the circumstances and applicable law, you may have rights in relation to your personal information, including the right to:

  1. request access to your personal information;
  2. request correction of inaccurate or incomplete information;
  3. request erasure of your personal information;
  4. request restriction of processing;
  5. object to certain processing;
  6. request data portability where applicable; and
  7. withdraw consent where processing is based on consent.

These rights are not absolute and may depend on the circumstances and lawful basis for processing.

Where your request concerns information that RiskBright processes solely on behalf of an estate agency, the relevant estate agency is normally responsible for responding to your request as controller.

RiskBright will provide reasonable assistance to its controller customers in accordance with applicable data-protection law and our Data Processing Agreement.

To exercise a right relating to information for which RiskBright is controller, contact hello@riskbright.co.uk.

14. Right to object

Where RiskBright relies on legitimate interests as its lawful basis for processing your personal information, you may have the right to object to that processing.

Please contact hello@riskbright.co.uk if you wish to exercise this right.

15. Complaints

If you have concerns about how RiskBright handles your personal information, please contact us at:

hello@riskbright.co.uk

We would welcome the opportunity to address your concerns.

You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's data-protection regulator.

Information about your rights and making a complaint is available from the ICO.

Information Commissioner's Office

16. Cookies

RiskBright uses cookies and similar technologies for authentication, security, preferences and other functionality.

Some cookies are strictly necessary for RiskBright to operate.

Optional third-party content, including embedded video services, is subject to the applicable cookie and consent settings.

Please see our Cookie Policy for more information.

17. Third-party websites and services

RiskBright may contain links to official registers, government websites and other third-party websites or services.

RiskBright does not control the privacy practices of those organisations.

If you access an external service, you should review the privacy information provided by that organisation.

18. Providing personal information

Certain information is necessary for us to provide RiskBright.

For example, we require appropriate account information to create and administer an account. If required information is not provided, we may be unable to create an account, process a subscription or provide some or all of the Service.

Information entered about an estate agency's customers is determined by the agency using RiskBright and should be limited to information that is appropriate and necessary for the relevant purpose.

19. Changes to this Privacy Policy

We may update this Privacy Policy where our Service, processing activities, service providers or legal requirements change.

Where a change is material, we will take reasonable steps to bring it to the attention of affected users where appropriate.

The current version will be published on the RiskBright website with its latest revision date.

20. Contact us

If you have questions, requests or concerns about this Privacy Policy or our handling of personal information, please contact:


RiskBright

A trading name of Shermika Blaise Robinson


Office By31 Curthill House

60 Water Lane

Cheshire

SK9 5AJ

Wilmslow

United Kingdom


Email: hello@riskbright.co.uk