RiskDetected
English home
Back

AI and Data Processing Notice

Effective: 31 July 2026Version: ai-data-en-2026-07-31.1

This Notice explains the AI processing used by RiskDetected and records the explicit consent requested by the app where consent is the applicable legal basis. It should be read with the Privacy Policy and Terms of Use.

Controller/service provider:

  • Riskdetected
  • Tax/identity number: 21832867210
  • Address: Eskişehir, Türkiye
  • Email: [email protected]
  • Website: https://riskdetected.com

1. What the AI feature does

When you request an analysis, RiskDetected processes submitted workplace photographs and structured context with automated systems to:

  • identify visible safety findings;
  • suggest controls and follow-up actions;
  • classify and prioritise risk;
  • prepare structured analysis output; and
  • support later PDF/XLSX report generation.

New analyses use photographs selected from the library or taken with the camera. Earlier-version text inputs may continue to exist only in historical, export, deletion and lawful-retention workflows.

2. AI output is decision support

AI output may be inaccurate, incomplete, outdated or affected by image quality, angle, lighting, missing context, hidden conditions and model limitations. A hazard that is absent from an output may still exist.

RiskDetected does not certify that a workplace is safe, compliant or free from hazards. It does not provide an official inspection, expert report, engineering determination, medical advice or legal opinion.

A competent person must inspect the actual workplace and verify every finding, score, recommendation and report before a decision is made. Serious or imminent hazards require immediate site procedures and qualified human action; do not rely on the app alone.

3. Information processed for AI analysis

AI processing can include:

  • the submitted photographs and visible content;
  • your selected analysis method, canvas or work context;
  • the app language, content locale and explicitly selected safety profile or work jurisdiction;
  • limited onboarding context that you choose to provide;
  • machine-readable image and request metadata needed to perform and secure the analysis; and
  • output validation, provider/model, token, latency, failure and fallback information.

The app is designed to reduce EXIF, location and camera metadata before analysis. Visible content in the photograph remains available to the AI provider.

4. Sensitive and third-party information

Photographs may show employees, visitors, faces, injuries, health conditions, disability, personal protective equipment, religious, political or union indicators, children, vehicle plates, company signs, private premises, trade secrets or other sensitive information.

RiskDetected does not request facial recognition or biometric identification. However, visible content can still be personal or sensitive information.

Before submitting content, you must:

  • have lawful authority to collect, analyse, store and report it;
  • provide required notices and obtain permissions or consents from affected people;
  • obtain workplace, employer, site-owner and confidentiality approvals where required; and
  • minimise unnecessary personal, sensitive and confidential information.

Do not submit credentials, payment-card information, identity documents or content that you are not authorised to process.

5. Providers and international processing

AI requests are sent through RiskDetected’s Supabase backend. Configured providers may include:

  • Google Gemini/Google AI for requested analysis; and
  • Groq or another approved compatible provider for continuity or fallback.

Provider selection can depend on plan entitlement, availability, quality validation and service continuity. Provider changes do not change your subscription tier or grant additional paid features.

RiskDetected and its providers may process information in Türkiye, the United States, the European Economic Area and other countries in which providers or their subprocessors operate. Where required, transfers rely on applicable adequacy decisions, contractual safeguards, provider data-processing terms, statutory exceptions or explicit consent.

6. Data minimisation and provider use

RiskDetected aims to transmit only content and context needed for the requested analysis. Submitted workplace content is not provided to service providers for unrelated advertising.

You should crop or frame photographs to exclude people, personal documents, screens, vehicle plates, sensitive work areas and confidential information that are not necessary for the safety analysis.

7. Human review and user edits

Users can review and, where supported, edit findings before generating later reports. The analysis version, user edits and report snapshot may be retained for auditability, support and record integrity.

RiskDetected’s AI does not make a solely automated decision that has legal or similarly significant effects on a person. The user and the relevant competent professional remain responsible for workplace decisions.

8. Retention and deletion

Current retention rules relevant to AI processing are:

  • Free analysis photographs: 7 days.
  • Plus analysis photographs: 30 days.
  • Pro analysis photographs: while the account remains active or until the user deletes them, subject to technical deletion and lawful retention.
  • Raw AI responses and AI audit records: 30 days.
  • Analysis results and findings: until the user deletes them, the account is deleted or the processing purpose ends.

You can delete supported analyses in the app and delete the account through Profile > Delete Account. Limited legal, security, dispute and backup exceptions are described in the Privacy Policy.

9. Explicit consent

By selecting the app control that states you agree to this Notice, you expressly consent, where consent is the applicable legal basis, to:

  1. processing the photographs and context you submit to produce the requested AI-assisted safety analysis and reports;
  2. processing personal or sensitive information that may be visibly present in that content for the same limited purpose; and
  3. transferring that information to the providers and countries described in this Notice where explicit consent is the applicable transfer mechanism.

This consent does not authorise marketing, public advertising, facial recognition, biometric identification or unrelated use of submitted content.

Do not provide consent or submit content on behalf of another person unless you have authority to do so. If you do not consent where consent is required, do not start an AI analysis; the relevant AI and report features may be unavailable.

10. Withdrawing consent

You can withdraw consent for future processing at any time through Profile > Support or [email protected]. Withdrawal does not affect processing that was lawful before withdrawal.

Because submitted content is necessary for the requested AI analysis, withdrawal may prevent new analyses or related reports. Withdrawal is separate from account deletion. Use Profile > Delete Account to delete the account and associated app data, subject to the exceptions in the Privacy Policy.

11. Contact

  • Email: [email protected]
  • Address: Eskişehir, Türkiye
  • Website: https://riskdetected.com
  • In-app support: Profile > Support

For account deletion, use Profile > Delete Account; an email or support request is not required.

Questions? [email protected]

PrivacyTermsAI noticeSupport