Data protection
Written to be checked rather than believed. Everything below can be verified against the schema and the network tab, and where something is a commitment rather than a mechanism, it says so.
Summary
The short version
- Pricing a quote involves no personal data at all. There is no account, no login and no field for a name.
- We hold personal data in two places and no others: the contact form, and the mailbox behind our published address. Both are listed below with what is kept and for how long.
- No cookies, no analytics, no trackers and no third-party requests. The site loads nothing from anyone else, which you can confirm in your browser's network tab.
- Records are stored in Frankfurt, inside the EU.
- We sell nothing and share nothing for marketing. There is no advertising on this platform and never will be.
Processing activity 1
Quote records
Every configuration priced by the engine is appended to an audit ledger, for the traceability a distributor needs under the Insurance Distribution Directive. A record contains six fields and none of them identify anyone:
| Field | Content |
|---|---|
id | A random identifier generated by the database |
created_at | When the quote was priced |
active_vertical | Which of the four risk verticals |
selected_components | The true or false state of each cover component |
total_monthly_premium | The premium the server computed |
compliance_status | A fixed status string |
No IP address, no device or browser fingerprint, no session identifier and no cookie is recorded against a quote. Two people pricing the same cover produce records that are indistinguishable apart from their timestamps.
Because these records identify nobody, they fall outside the GDPR and are kept indefinitely as the audit trail they exist to be. The ledger refuses edits and deletions by design.
Processing activity 2
Contact enquiries
If you use the contact form, we store what you typed so we can reply. Nothing more is inferred, appended or enriched.
| Question | Answer |
|---|---|
| What we store | Your name, email address, organisation if you give one, the enquiry type and your message |
| What we do not store | Your IP address, any tracking identifier, or anything you did not type |
| Why we may hold it | Legitimate interests under Article 6(1)(f): you asked us a business question and we need to answer it |
| How long | Twelve months from your last contact, then deleted |
| Who sees it | The project owner. It is not shared, sold or passed to any third party |
| Automated decisions | None. Nothing about you is scored, profiled or decided by a machine |
The twelve-month limit is enforced by a scheduled job in the database, not by someone remembering to run a query. A retention policy nobody implements is a statement, not a safeguard.
Processing activity 3
Email correspondence
We publish anil@riskrouter.eu, so anything you send there is personal data we hold. Saying the form was the only such place would have been convenient and wrong.
| Question | Answer |
|---|---|
| What we store | Your message and whatever your mail client puts in it: your address, your name as you send it, and the technical headers of the message |
| Where it sits | A Microsoft 365 mailbox. Microsoft is the processor for that mailbox, under its own data protection terms |
| Why we may hold it | Legitimate interests under Article 6(1)(f), the same basis as the form: you wrote to us and we need to answer |
| How long | Twelve months from our last exchange, then deleted |
| Who sees it | The project owner. It is not shared, sold or passed to any third party |
One honest difference from the form: that twelve-month limit is a rule a person applies, not a scheduled job in a database. If the difference matters to you, use the form — it is enforced there, and we would rather you knew which of the two we can prove.
Your device
What we keep in your browser
No cookies are set by this site, for any purpose, including analytics. There is nothing to consent to because nothing is tracked.
The demo console saves one value in your browser's local storage: the address of the pricing engine it should call, so you do not have to retype it. It never leaves your device, we cannot read it, and clearing your site data removes it. Nothing else is stored client-side.
Sub-processors
Who else touches the data
| Provider | Role | Where |
|---|---|---|
| Cloudflare | Serves the pages and runs the pricing engine | Processed at the network location nearest to you, which may be outside the EEA. Nothing is stored there. |
| Supabase | Hosts the database holding quote records and contact enquiries | Frankfurt, Germany |
| Microsoft | Runs the mailbox behind our published address, so anything you email us passes through it | Microsoft 365, under Microsoft’s own data protection terms |
That is the complete list. There is no analytics provider, no email marketing platform, no customer data platform and no advertising network, because the site makes no requests to any of them. Open your network tab and count. Microsoft appears only because we publish an email address; it touches nothing the platform itself stores.
Request routing through Cloudflare means the processing of a request in transit can happen outside the EEA even though the stored record does not. We would rather state that plainly than claim an EU-only guarantee the architecture does not support.
Your rights
What you can ask for
Where we hold personal data about you, which means the contact form and our mailbox and nothing else, you can ask us to give you a copy, correct it, delete it, restrict what we do with it, or object to us holding it at all. Ask through the contact form or at anil@riskrouter.eu, and we will act within one month.
Because our basis is legitimate interests rather than consent, you can object at any time and we will stop unless we have a compelling reason not to. In practice, for a business enquiry, there will not be one.
If you are unhappy with how we handle it, you can complain to the Belgian Data Protection Authority, the Gegevensbeschermingsautoriteit or Autorité de protection des données, or to the supervisory authority in your own member state.
Accountability
Who is responsible
RiskRouter is a validation prototype operated by its project owner rather than by an established company. No legal entity, registered address or data protection officer is published here, because publishing one that does not exist would be worse than publishing none. Both will appear before any production processing begins, and this page will be updated when they do.
Where a licensed distributor deploys this platform for their own customers, that distributor is the controller for their customers' data and we would be a processor acting on their instructions under a written agreement. Nothing on this page changes that division.
For anything concerning your data, including the rights set out above, write to anil@riskrouter.eu or use the contact form. Both reach the same person, which is the whole of the organisation today.
If anything here does not match what the system does, treat it as a defect. Tell us and we will fix the page or the code, whichever is wrong.