This is a plain-English summary of where your data is stored and how it is handled. It does not replace the Privacy Policy, Terms of Service or the Trust & Security page, which are the documents that bind us; read those for the full detail.
Where your data is stored
Your account data, your knowledge base, your chat conversations and (for RIFT) your practice billing records are stored in Australia, in Sydney. Your billing data with us is stored there too. Data is not moved offshore to run the products. The exceptions, listed in the Privacy Policy, are the services we rely on: chat messages are sent to OpenAI to generate answers, emails are delivered through Resend, payments are processed by Stripe, and RIKO's technical error reports go to Sentry (configured so that message contents and personal information are left out, and not connected to RIFT at all).
Encryption and backups
The live database is encrypted at rest, meaning the data is scrambled on disk rather than only protected by a password. All connections use HTTPS.
Backups are taken every night, encrypted before they leave the server, and stored in Australia. They are restore-tested so they work when needed. Backups are never used to train AI models, and neither is any of your data.
Chat messages are stored per clinic
Every conversation your RIKO widget has is stored against your clinic only, and shown only in your RIKO dashboard. Another clinic cannot see your conversations and you cannot see theirs. Conversation logs are kept for up to 12 months and then deleted or anonymised. For RIFT, resolved items and the record of emails sent to patients are kept for up to 24 months as your audit trail, then deleted.
Keep patient details out of support conversations
When you contact us, describe the problem without including patient names, dates of birth, contact details, appointment details or anything else that identifies a person. This applies to the support form in the dashboard, to email, and above all to RIKO Help, the help-centre chat bubble: it answers from these help articles only and is not the place for anyone's personal information. If we need to look at a specific record to solve your problem, we will arrange that with you securely rather than by email.
Requesting deletion of your data
You can ask us to delete an individual person's data (for example a single visitor's conversation) or all of your clinic's data at any time.
- In the RIKO dashboard at
/app/dashboard, click Support in the header. - Choose the Account category, give the request a subject such as "Data deletion request", and say what you would like deleted. Do not paste the personal details themselves into the form; describe the record and we will confirm the details with you securely.
- Click Send message. You will receive a confirmation email and we reply by email.
You can also email contact@rapidintelligence.com.au. We respond to privacy requests within 30 days. Some records must be kept for legal reasons (billing records for 7 years under Australian tax law, for example); the Privacy Policy sets out the retention periods.
After a subscription is cancelled, account data is kept for 90 days so you can export it, and then permanently deleted without you needing to ask.
Requesting the MSA or DPA
The Master Services Agreement (MSA) and Data Processing Agreement (DPA) are the signed contracts some practices need in addition to the online Terms. They are sent on request.
- In the RIKO dashboard at
/app/dashboard, click Support in the header. - Choose the category Legal - MSA / DPA request. The subject and message fill in with a ready-to-send request; add anything specific you need.
- Click Send message. We reply by email with the documents.
Clinics that ticked the regulated-industry box at signup accepted a click-through DPA at that point; a countersigned copy can still be requested the same way.
The documents themselves
- Privacy Policy: what we collect, why, who processes it, how long it is kept, and your rights.
- Terms of Service: the agreement your account runs under, including trials, billing, cancellation and RIFT's usage-banded pricing.
- Trust & Security: the clinic-facing overview of hosting, encryption, backups and how each product handles data.
- Acceptable Use Policy: what the products may and may not be used for.