1. Scope
This Privacy Policy applies to information processed through the Riposte website, the Riposte application, founder-led services such as the RFP Rescue Sprint, qualification forms, support communications and related business interactions.
Depending on the context, Riposte may act as the organization responsible for deciding how personal information is used or as a service provider processing information on behalf of a business customer.
This policy does not govern the privacy practices of third-party websites or services that Riposte does not control.
2. Information We Collect
We may collect the following categories of information.
Information you provide directly
This may include:
- Name
- Work email address
- Telephone number, when provided
- Company name
- Job title
- Company website
- Details about an RFP, proposal or business opportunity
- Information submitted through contact, qualification or lead-generation forms
- Communications with Riposte
- Account and workspace information
- Feedback and support requests
Information received through LinkedIn
When you submit a LinkedIn Lead Gen Form associated with Riposte, LinkedIn provides Riposte with the information you choose to submit, which may include your name, work email address, company and job title.
Riposte uses that information to:
- Evaluate whether an opportunity may be suitable for the RFP Rescue Sprint
- Respond to your inquiry
- Schedule a discussion
- Provide requested information
- Follow up about relevant Riposte services
Do not submit confidential RFPs or proposal documents through a LinkedIn Lead Gen Form.
Account and product-usage information
When you use the Riposte application, we may collect:
- Account identifiers
- Workspace membership and permissions
- Authentication and session information
- Opportunities created
- Documents uploaded
- Requirements extracted
- Generated outputs
- Edits and approvals
- Export activity
- Usage records
- Audit and security logs
- Error and diagnostic information
Technical information
We may collect limited technical information such as:
- IP address
- Browser and device type
- Operating system
- Referring page
- Date and time of access
- Authentication-session information
- Basic security and diagnostic logs
3. Customer Documents and Content
Customers may provide documents and other content such as:
- RFPs
- RFQs
- SOWs
- Client requirements
- Previous proposals
- Case studies
- Resumes
- Capability materials
- Project descriptions
- Certifications
- Methodologies
- Clarification questions
- Generated and edited response materials
We refer to this material as "Customer Content."
Customers are responsible for ensuring that they have the right and authorization to upload and process Customer Content through Riposte.
Customer Content may include personal information about employees, consultants, client contacts or other individuals. Business customers are responsible for providing required notices and obtaining appropriate permissions for that information.
Do not upload:
- Classified information
- Protected health information
- Export-controlled information
- Payment-card data
- Social Security numbers
- Government identification numbers
- Information prohibited by law or contract
- Documents that you are not authorized to provide
- Highly sensitive information unless Riposte has expressly agreed in writing to process it
4. How We Use Information
Riposte may use information to:
- Operate and provide the website and application
- Create and manage accounts and workspaces
- Authenticate users
- Process RFPs and supporting documents
- Extract and organize requirements
- Match requirements against approved supporting material
- Generate compliance matrices and response-pack content
- Identify missing, partial or unsupported information
- Export customer-requested deliverables
- Deliver RFP Rescue Sprints
- Respond to inquiries and support requests
- Schedule demonstrations and qualification discussions
- Communicate about services requested by the user
- Protect the security and integrity of Riposte
- Detect misuse, fraud or unauthorized access
- Monitor performance and diagnose errors
- Improve product functionality and user experience
- Maintain records required for legal, accounting or operational purposes
- Enforce agreements and comply with applicable law
Riposte does not intentionally use Customer Content to create advertising profiles.
Riposte does not use Customer Content to advertise third-party products.
5. AI and Automated Processing
Riposte uses artificial-intelligence and machine-learning services to help process Customer Content and generate reviewable outputs.
Depending on the workflow, Customer Content may be:
- Parsed into text
- Divided into smaller excerpts
- Converted into numerical representations known as embeddings
- Compared against requirements
- Sent in relevant excerpts to an AI model provider
- Used to generate structured requirements, evidence matches, compliance findings and draft response material
Third-party providers
Riposte currently uses third-party providers including:
- OpenAI for AI model and embedding services
- Supabase for authentication, database and file-storage infrastructure
These providers process information on Riposte's behalf to provide their respective services.
AI-generated output may be incomplete or inaccurate. Riposte requires customers to review, edit and approve output before relying on it or submitting it to another party.
Riposte does not guarantee that an output is legally compliant, contractually compliant, complete, accurate or suitable for submission.
Riposte does not intentionally use Customer Content to train a proprietary Riposte foundation model.
7. Data Retention
Riposte retains information only for as long as reasonably necessary for the purposes described in this policy.
Retention may depend on:
- How long an account or workspace remains active
- The duration of a customer relationship
- Whether information is needed to provide a requested service
- Customer deletion activity
- Security, fraud-prevention and audit requirements
- Contractual requirements
- Legal, accounting or regulatory obligations
- The need to resolve disputes or enforce agreements
- Backup and disaster-recovery processes
Uploaded files and product records may remain available until the customer deletes them, the associated workspace is deleted or Riposte processes an approved deletion request.
Some information may remain in limited backups, logs or legally required records for an additional period.
8. Security
Riposte uses administrative, technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration or destruction.
Measures may include:
- User authentication
- Workspace-based access controls
- Private file-storage locations
- Role-based permissions
- Logging of selected account and administrative activity
- Access restrictions for service providers
- Secure transmission provided by the underlying hosting and infrastructure services
No method of Internet transmission or electronic storage is completely secure. Riposte cannot guarantee absolute security.
Customers should use strong passwords, protect account credentials and promptly report suspected unauthorized access.
9. Your Privacy Choices and Rights
Depending on where you live and applicable law, you may have rights concerning your personal information, including the right to:
- Request access to personal information
- Request correction of inaccurate information
- Request deletion
- Request a portable copy of certain information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of marketing communications
- Appeal the denial of a privacy request where applicable
- Receive information without unlawful discrimination for exercising a privacy right
To submit a request, contact: contact@tryriposte.com
Riposte may need to verify your identity and authority before processing a request.
Where Riposte processes information on behalf of a business customer, the request may need to be directed to that customer. Riposte may forward the request to the relevant customer or assist that customer in responding.
Riposte may retain information where permitted or required by law.
10. Marketing Communications
You may receive communications from Riposte when you:
- Submit a website form
- Submit a LinkedIn Lead Gen Form
- Request information
- Schedule a meeting
- Participate in a pilot or RFP Rescue Sprint
- Create an account
- Otherwise ask Riposte to contact you
You may opt out of promotional email by using the unsubscribe method in the message or contacting contact@tryriposte.com.
Riposte may still send non-promotional messages concerning an account, transaction, security matter or requested service.
12. International Data Transfers
Riposte and its service providers may process information in countries other than the country where the user is located.
Those countries may have different data-protection laws.
Where required, Riposte will use contractual or other legally recognized safeguards for international transfers of personal information.
13. Children's Privacy
Riposte is intended for business users and is not directed to children under 13.
Riposte does not knowingly collect personal information directly from children under 13.
If you believe a child has provided personal information to Riposte, contact contact@tryriposte.com.
14. Changes to This Policy
Riposte may update this Privacy Policy as the service, business practices or legal requirements change.
The revised policy will be posted on this page with an updated "Last updated" date.
If a change materially affects how previously collected information is used, Riposte will provide additional notice where required.
15. Contact Us
Questions, concerns and privacy requests may be sent to:
- Company
- Riposte
- Operated by
- Riposte LLC
- Website
- https://tryriposte.com
Please do not email confidential RFPs, resumes, client records or proposal documents until Riposte has confirmed an appropriate intake process.