Knowledge base Rise Up

About your Data

  • Updated
Overview

At Rise Up, protecting your data is a fundamental commitment. Our approach is simple, transparent, and designed for European clients.

Your data belongs to you. We host it in France, we protect it, and we do not exploit it.

 

A platform designed for European clients

Rise Up is developed by a European company and complies with GDPR requirements as well as the security standards expected by European businesses.

  • Your data remains under your control
  • It is never resold
  • It is never used to train AI models

Rise Up acts only on its clients' instructions, within a strict and auditable contractual framework.

 

Where is your data stored?

Primary hosting, France (EU)

Rise Up data is hosted in France, within the European Union. This includes:

  • Personal data (users, identifiers, metadata)
  • Imported content (documents, videos, files, knowledge bases)
  • Indexes and data required for search and learning functionalities

Data remains within Rise Up's infrastructure and is not transferred outside the European Union by default.

 

Security and governance

Rise Up maintains ISO 27001 certification, which covers:

  • Access and authorization management
  • Environment separation
  • Action traceability
  • Incident and risk management

Security is integrated from the design stage and continuously monitored to guarantee the protection of your data.

 

Use of artificial intelligence

Rise Up uses AI technologies to enhance your learning experience and deliver key features. When AI is used, we follow strict principles:

Common principles for all AI usage

  • Only relevant content excerpts are transmitted, never full documents — so a provider processing your data can never reconstruct an entire file, only the specific fragment needed to answer a request.
  • Minimization and pseudonymisation mechanisms limit personal data exposure
  • Data is not used to train models
  • Data is not resold
  • Retention is limited to technical needs only

Data transmitted to AI providers

When Rise Up uses an AI provider, complete client content is never transmitted. Instead:

  • Only text excerpts or structured queries are sent
  • These are used solely to generate the requested response or learning activity
  • Typically, includes: learning context, recent conversation snippets (anonymized), and relevant content excerpts
  • Data is processed only to fulfill the immediate request
  • Providers retain data temporarily for security and abuse prevention only

Response reliability

Rise Up implements controls to ensure accuracy and reliability:

  • Internal consistency checks validate AI responses against provided context
  • Safety filters prevent inappropriate or harmful output
  • Source citation shows users the origin of information
  • User feedback mechanisms allow reporting of errors

AI is used as an assistive tool, not as an autonomous source of truth.

 

GDPR and Rise Up's role

Rise Up acts as a data processor under the GDPR. We commit to:

  • Processing data only on behalf of our clients
  • Ensuring confidentiality and security
  • Assisting clients in meeting their regulatory obligations

We apply strict security and confidentiality measures to guarantee you complete peace of mind.

FAQ & Troubleshooting

  • Issue: I can't find where my organization's data is physically hosted.
    Solution: All Rise Up data — personal data, imported content, and search/learning indexes — is hosted in France, within the EU, and is not transferred outside the EU by default.

    Issue: I'm not sure whether AI features send our full documents to a third party.
    Solution: Only relevant text excerpts or structured queries are sent to an AI provider when needed — never full documents or complete client content.

    Issue: I'm concerned our data could be used to train AI models.
    Solution: Rise Up does not use client data to train AI models, and does not resell data, under any circumstance.
     
  • Where exactly is our data stored?
    — In France, within the European Union, across personal data, imported content, and the indexes used for search and learning features.

    Does Rise Up ever access our data outside our instructions?
    — No. Rise Up acts only on its clients' instructions, within a strict and auditable contractual framework, and acts as a data processor under the GDPR.

    What happens to data sent to an AI provider?
    — Only the excerpt or structured query needed for the specific request is sent, is used solely to generate that response, and is retained only temporarily by the provider for security and abuse prevention.

    Can AI-generated answers be trusted as final?
    — AI responses go through internal consistency checks and safety filters, and include source citations, but AI is used as an assistive tool, not as an autonomous source of truth.

    What certification does Rise Up hold?
    — Rise Up maintains ISO 27001 certification, covering access management, environment separation, action traceability, and incident and risk management.
  • Data Protection Officer: dpo@riseup.ai
    Contact Support
     

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request