DISCOVER · REVIEW · REMEDIATE
Legal

Privacy policy.

How REVIEWIT collects, uses and protects personal data on this website and in the platform.

Last updated: September 2026

1. Who we are

REVIEWIT ("we", "us") publishes this website and operates the REVIEWIT access certification platform. This policy explains how we process personal data as a controller for the website and for our commercial relationship, and how the platform processes data on behalf of our customers as a processor.

2. Data we collect on this website

  • Demo and contact requests. Name, work email, company, role and the message you send us. We use it to prepare and follow up on your request.
  • Technical data. Server logs with IP address, user agent and pages requested, kept for security and operations.
  • Cookies. This website uses no advertising or tracking cookies. Only strictly necessary technical storage is used.

3. Data processed in the platform

When a customer uses REVIEWIT, the platform processes identity directory data, resource metadata and review decisions collected from the customer's connected solutions, together with the identities of reviewers and administrators. The customer is the controller of this data; REVIEWIT acts as processor under a data processing agreement that includes the retention declaration of the platform.

4. Retention

Website request data is kept for the duration of our commercial relationship and at most three years after the last contact. Platform data is retained according to the retention module, which declares every data category with its period and purge behaviour, and which is reflected in the data processing agreement signed with each customer. Audit evidence is purged by sealed segment, never by individual record.

5. Legal bases

Our legitimate interest in responding to your request and developing our commercial relationship; the performance of a contract with our customers; and compliance with our legal obligations.

6. Recipients

Personal data is accessed only by REVIEWIT staff who need it and by the sub-processors that host and operate the platform in the region chosen by the customer. We do not sell personal data.

7. International transfers

The managed service runs on a regional foundation. A customer's data stays in the region of its subscription. Where a transfer outside that region is required, it is framed by appropriate safeguards.

8. Security

Encryption at rest and in transit, tenant isolation, secrets held in a vault, identity broker with MFA step-up, sealed audit evidence and regular penetration testing. See the Trust & Evidence page.

9. Your rights

You may request access, rectification, erasure, restriction, portability or object to processing, and lodge a complaint with your supervisory authority. For platform data, address your request to the customer organisation that is the controller; we will assist them.

10. Contact

Use the contact form and indicate that your request concerns privacy.