Risontis – Privacy Policy

Effective date: 10 December 2025
Last updated: 17 July 2026
Applies to: the Risontis software (including the Google Workspace Marketplace add-on, the Google Sheets-based installation, and the Risontis web app), the Risontis licensing backend, and risontis.com.
Controller: Risontis, The Netherlands.
Contact: support@risontis.com

1. Scope & Principles

EU-first governance: Risontis is established in the Netherlands and applies Dutch/EU law and the GDPR.

Tenant environment: Tenants operate independently. Risontis has no routine access to the tenant’s private Google environment. Tenant-owned trading data is stored within that environment. The software communicates directly with the connected exchange and separately exchanges limited licensing data with Risontis infrastructure. Support access occurs only when information is deliberately supplied by the tenant.

Runtime model: Runtime logic is maintained in a shared, version-pinned library. Tenant configuration and operational records are stored within the tenant’s Google Sheet, Google Drive, UserProperties, and DocumentProperties, depending on data type.

Exchange credentials: Exchange API credentials are stored in the tenant’s Google UserProperties. They are used by the tenant’s Apps Script runtime to communicate with the connected exchange and are not transmitted to Risontis infrastructure during normal operation.

Support and sensitive information: Users must not share API secrets with Risontis. If credentials or other sensitive information are inadvertently supplied through a support request, Risontis will remove them as soon as reasonably possible and may require the tenant to rotate the affected credentials.

No financial advice: Risontis offers software only. All trading decisions remain the user’s responsibility.

2. Data We Process

Google account and installation identifiers (email address, sheetId):
Used for account identification, license binding, entitlement checks, billing integration, and support.
Stored in Firestore; retention per Section 8.

Licensing telemetry (status, tier, timestamps):
Used to verify entitlement and support billing disputes.
Retained while the subscription is active; billing-related records are retained per Section 8.

Billing and subscription data (billing name and contact details, customer and subscription identifiers, selected plan, invoice and transaction information):
Used to manage subscriptions, payments, invoices, refunds, and accounting obligations. Payment-card details are processed by Stripe and are not stored by Risontis.
Retention per Section 8.

Support communications (email, tickets):
Used to answer questions and resolve incidents.
Retained for 24 months after ticket closure.

System event logs:
Used for monitoring and incident response.
Retained for 30 days.

Security event data (IP address, request timestamp, request ID, rate-limit flags):
Used for fraud prevention, abuse mitigation, and security monitoring.
Retained for 30 days.

Website and analytics data (browser and device information, IP-derived information, visited pages, timestamps, referrer information, and cookie or consent preferences):
Used for website operation, security, and analytics, subject to applicable consent requirements.
Retention per Section 8.

Optional evidence (screenshots, logs, exported sheets):
Used to reproduce issues.
Deleted immediately after case resolution unless legal retention applies.

We do not store trading history, balances, strategies, or sheet content server-side. These remain within the tenant’s Google environment, including the associated Sheet, Drive storage, and Apps Script properties, unless deliberately shared for support.

3. Legal Bases Under GDPR

Contract performance (Art. 6(1)(b)): delivering the Risontis service, licensing, and support.

Legitimate interest (Art. 6(1)(f)): security logging, fraud prevention, rate limiting, and defence against abuse. This includes processing IP addresses and security-event metadata.

Legal obligation (Art. 6(1)(c)): tax and accounting retention for billing.

Consent (Art. 6(1)(a)): used for optional communications such as beta programs, and for non-essential website cookies and analytics where required. Consent is never required for core functionality.

4. Processors, Providers & Roles

Risontis acts as controller for personal data processed for licensing, billing, security, website analytics, and support purposes.

Service providers processing personal data on behalf of Risontis include:

  • Google Workspace and Google Cloud Platform: application platform and backend infrastructure (Cloud Run, Firestore, Secret Manager).
  • Stripe: billing and subscription management.
  • Website hosting and content-delivery providers: operation of risontis.com.
  • Google Analytics: website usage analytics.
  • Email and support tooling providers: handling of support communications.

The connected exchange (such as Kraken) is not a Risontis sub-processor. It is an independent service chosen by the user, with which the tenant’s runtime communicates directly under the user’s own exchange agreement.

Data Sharing & Disclosure

Risontis does not sell, rent, or trade Google user data.

Google user data accessed by the application is used solely to provide the core functionality of the service. Disclosure of Google user data may occur only in the following limited cases:

  • With Google APIs, strictly as required to operate the tenant’s Google Sheet, Google Drive storage, Apps Script runtime, and private web app under the user’s authorization.
  • With service providers acting as sub-processors for infrastructure and billing (such as Google Cloud Platform and Stripe), limited to the data necessary to perform those services.

Google user data accessed through authorized Google API scopes is used only to provide the application’s core functionality and is not disclosed to the connected exchange.

The tenant’s runtime communicates directly with the exchange configured by the user. This communication contains the account, market, order, and position data required to perform the requested trading operations under the user’s exchange agreement.

Google Analytics receives website usage data only. Tenant data accessed through Google API scopes is never shared with analytics services.

Google user data is never shared with advertisers and is not used for advertising or marketing purposes.

5. International Transfers

Risontis uses EU-based processing locations where reasonably available. Some service providers may process personal data outside the EEA. Where required, international transfers are protected through an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.

6. Security Measures

Protection of sensitive data

Risontis applies technical and organizational measures to protect Google user data and other sensitive information, including:

  • Encryption in transit using HTTPS/TLS for all communications with Google APIs and external services;
  • Strict access controls and scope minimization, ensuring data access is limited to user-authorized OAuth scopes only;
  • Regular review of security logs to detect abuse or unauthorized access.

Tenant-side (Google environment)

  • Trading logic runs inside the tenant’s own Google environment.
  • Exchange API credentials are stored in Google UserProperties; Risontis cannot access them.
  • Operational records and audit traces are stored in the tenant’s Google Drive and Apps Script properties.
  • Minimal-privilege Apps Script scopes are used, aligned with the minimum permissions required for the application’s functionality.

Backend-side (licensing & billing infrastructure)

  • Secrets are stored in Google Secret Manager.
  • Licensing payloads are cryptographically signed.
  • Backend endpoints enforce bearer-token authentication with IP, email, and sheet-based rate limiting.
  • Cloud Logging provides backend-only security-event monitoring.
  • The backend stores no tenant trading data, sheet content, or API credentials.

7. Data Subject Rights

Users may request access, rectification, deletion, restriction, objection, or data portability.

Requests can be made via support@risontis.com.

Risontis responds within one month, subject to legal obligations.

Where processing is based on consent, users may withdraw that consent at any time without affecting processing performed before withdrawal. Users also have the right to lodge a complaint with the Autoriteit Persoonsgegevens or another competent supervisory authority.

8. Retention & Deletion

Operational licensing records: retained for the duration of the subscription and deleted or anonymized within 90 days after termination unless needed for disputes, fraud prevention, or legal claims.

Billing and tax records: retained for seven years where required by Dutch law.

System and security logs (including event markers, IP addresses, request metadata, and rate-limit events): retained for 30 days.

Support communications and artifacts: retained for 24 months after ticket closure. Sensitive artifacts (logs, screenshots, exported sheets) are deleted immediately after resolution unless required for compliance.

Website and analytics data: retained for up to 14 months, or until consent is withdrawn where consent is the applicable legal basis.

Backup copies are retained according to the configured lifecycle policies of the relevant service and are deleted through the normal backup-rotation process.

Tenant-owned data (trading history, balances, strategies, sheet content) remains within the tenant’s Google environment unless deliberately shared for support.

9. Children’s Data

Risontis is not intended for persons under 18.

We do not knowingly process children’s data.

10. Changes to this Policy

Risontis may update this policy for legal or operational reasons.

Material updates will be announced via release notes or email.