Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how RiseCite ("RiseCite", "we", "us") collects, uses and protects personal data when you use risecite.com and the RiseCite AI-visibility service (together, the "Service"). We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

1. Who we are (data controller)

The data controller for the processing described in this policy is HERC PRIME DOO, a company registered in Serbia — full company details available on request via hello@risecite.com.

2. What data we collect

  • Audit inputs — the company name, website domain, category, competitor names and buyer questions you submit when running a free AI-visibility audit.
  • Contact email — if you choose to receive your report by email. Providing an email is optional; you can view your teaser results without it.
  • Scan results — the responses we obtain from AI engines about the brands and questions you submitted, and the scores and recommendations we derive from them.
  • Account data — name, email and organization details, if you become a customer with a login.
  • Technical and usage data — server logs (IP address, user agent) kept for security, and privacy-friendly, cookie-less aggregate analytics if enabled.

3. Why we process it (legal bases)

  • Running your audit and showing results — steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR).
  • Emailing you your report — performance of your request (Art. 6(1)(b) GDPR).
  • Sending occasional AI-visibility tips — only with your explicit, unticked-by-default opt-in consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time via the unsubscribe link in any email.
  • Providing and billing the paid Service — performance of a contract (Art. 6(1)(b) GDPR).
  • Security, abuse prevention and Service improvement — our legitimate interests (Art. 6(1)(f) GDPR).

4. Who we share data with (processors)

We use a small number of service providers, bound by data-processing agreements:

  • Hosting — our application and database run on managed server infrastructure located in the EU.
  • Email delivery — Brevo (Sendinblue SAS, France) sends transactional report emails and, with your consent, tips emails.
  • AI engine providers — to produce your audit we send the buyer questions (and the brand and competitor names you provided) to large-language-model APIs such as OpenAI, Anthropic, Google and Perplexity. We do not send your contact email or account data to these providers.
  • Analytics — if enabled, we use privacy-first, cookie-less analytics (Plausible) that does not track you across sites and stores no personal profiles.

Where a provider processes data outside the EU/EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an adequacy decision.

5. How long we keep data (retention)

  • Audit records and scan results — up to 24 months from the audit, so we can show progress over time; deleted earlier on request.
  • Contact email — until you unsubscribe or ask us to delete it.
  • Account and billing data — for the duration of the contract plus statutory retention periods (e.g. accounting law).
  • Server logs — up to 30 days.

6. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data rectified;
  • have your data erased ("right to be forgotten");
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with your local supervisory authority.

To exercise any of these rights, email hello@risecite.com. We respond within one month.

7. Cookies

The public website uses no advertising or cross-site tracking cookies. Logged-in customers receive strictly necessary storage (a session token) required to keep them signed in.

8. Security

Data is encrypted in transit (TLS), access to production systems is restricted and authenticated, and API keys and credentials are stored outside the codebase. No method of transmission or storage is 100% secure, but we take industry-standard measures to protect your data.

9. Changes to this policy

We may update this policy as the Service evolves. The "Last updated" date above reflects the latest version; material changes will be highlighted on this page or announced by email to customers.

10. Contact

Questions about privacy? Email hello@risecite.com.