Privacy Policy
Last updated: 2025 · Version: 1.0
This privacy policy explains how RaskAI.lt collects, uses, stores, and transfers personal data when you use the RaskAI website, request form, AI analysis features, provider workspace, or other RaskAI services.
1. Who we are
RaskAI.lt is an AI-powered B2B platform connecting business clients with verified AI solution providers. The platform accepts the client's problem in free text, processes it using artificial intelligence, and organises a competitive quote process.
2. Who this policy applies to
This policy applies to:
- —Website visitors.
- —Buyers who describe a need for an AI solution, automation, system, or technical project.
- —AI developers, agencies, freelancers, and other providers who register or participate in the RaskAI quote process.
- —Persons who communicate with RaskAI via email, forms, or platform-sent links.
3. What data we collect
The type of data depends on how you use the platform:
Buyers (request submitters)
- ·Name and email address.
- ·Phone number (optional).
- ·Problem description in free text.
- ·Budget and timeline indication.
- ·File attachments (if uploaded).
Providers (service providers)
- ·Legal entity name and representative.
- ·Email address.
- ·Skills and specialisation description (Tier 1 / Tier 2).
- ·Portfolio and reference information.
Automatically collected data
- ·IP address and browser type.
- ·Session data and cookies (see Cookie Policy for details).
- ·Page and form usage statistics.
AI analysis data
- ·Problem summary and structured specification (Spec_JSON), generated from your description.
- ·Price and timeline estimates.
- ·Match signal for provider search.
- ·This data is linked to your request and processed under this policy.
4. Sandbox, AI analysis, and real order
RaskAI operates in two clearly separate modes, which differ in data flows:
AI processes your problem description, generates a technical specification and a preliminary price indication. At this stage, information is not passed to providers. Data is used only to show you what the platform can do with your problem.
Upon your confirmation of interest, a provider pool is formed and providers are notified of the opportunity to submit a quote. Only the information necessary to evaluate the quote is shared. Direct contact details are not disclosed until the appropriate stage of the process.
5. Why we use data
We process personal data for the following purposes and legal bases:
6. AI models and automated analysis
- —RaskAI may use AI model providers to process free text, generate a problem summary, technical specification, preliminary price, timeline, risks, and clarification questions.
- —RaskAI AI analysis supports operational decisions, but should not be relied upon as the sole unquestioned basis for significant decisions where law requires human review.
- —A user may request explanation, contest a decision, or request human review if AI analysis or the matching process has a material impact on their rights, obligations, or commercial interest.
- —RaskAI does not send AI models excessive personal data, passwords, API keys, personal identity codes, or other sensitive data that is not necessary to evaluate the request.
- —RaskAI does not use confidential client requests to train public AI models, unless separately and explicitly agreed otherwise. Aggregated or anonymised signals may be used to improve system quality.
7. What data providers see
- —Providers receive only the information necessary to evaluate the quote, submit a price and timeline, and execute the project.
- —Until the appropriate stage of the process, RaskAI may not show the buyer's direct contact details, to protect the process and reduce platform circumvention risk.
- —Providers may not use received information for other purposes, may not transfer it to third parties without justification, and may not attempt to move payments or communication outside the RaskAI process if prohibited by the agreement.
- —If an intermediary channel is used, RaskAI may store communication metadata and messages for audit, dispute resolution, security, and quality control purposes.
8. Who we share data with
RaskAI shares data only with recipients necessary for platform operation:
Providers
Only the request summary and technical specification required for the quote.
AI model providers (e.g. OpenAI)
Problem description for problem analysis — without excessive personal data.
Payment processors (Stripe)
Data necessary to process payment.
Infrastructure providers (Vercel, Airtable)
Data required for platform operation.
Automation tools (Zapier)
For process execution and sending notifications.
We do not sell data to third parties for commercial purposes.
9. International data transfers
Some service providers may be located or have servers outside the European Economic Area. In such cases, RaskAI applies appropriate safeguards: European Commission-approved standard contractual clauses, data processing agreements, regional data storage settings, or other lawful mechanisms.
10. How long we retain data
Data may be retained longer if required by law or if a dispute is ongoing.
11. Your rights
Under GDPR you have the right to:
- —Receive information about how we process your data.
- —Access your personal data.
- —Request correction of inaccurate or completion of incomplete data.
- —Request deletion of data where there is a legal basis.
- —Request restriction of data processing.
- —Object to data processing where we rely on legitimate interest.
- —Receive your data in a structured, commonly used format (data portability right).
- —Withdraw consent where data is processed on a consent basis.
- —Request human intervention if solely automated decision-making with legal or similarly significant effect is applied.
- —Lodge a complaint with the State Data Protection Inspectorate (vdai.lrv.lt).
12. Security
- —We use technical and organisational measures to protect data from unauthorised access, loss, alteration, or disclosure.
- —API keys and integration secrets are stored server-side and are not exposed in the browser or public logs.
- —Access to data is granted only to those persons and providers who need it to perform their functions.
- —If a data security incident occurs, RaskAI assesses the risk and, where required by law, notifies the supervisory authority and affected persons.
14. Minors
RaskAI is intended for business and professional users. The platform is not intended for children. If we become aware that we have received personal data of a minor without appropriate basis, we will take steps to remove it.
15. Privacy policy changes
We may update this privacy policy when RaskAI features, service providers used, legal requirements, or data processing practices change. The latest version is published on the RaskAI.lt website. We will notify you of material changes by email or a prominent notice on the website.