Legal

Privacy & Data Use Notice

RiskComms Global Outlook

Last updated: September 25, 2026

RiskComms Global Outlook is a benchmarking survey for crisis, risk, and emergency communication practitioners. This notice explains what happens to your data when you take part.

Who runs this survey

RiskComms Global Outlook is operated by RiskComms FZCO, a Dubai-registered consultancy. RiskComms FZCO is the data controller — the entity that decides why and how your information is processed. Questions or requests relating to your data can be sent to phil@riskcomms.com.

What we collect

Two categories of data pass through this platform:

Survey responses. Your answers to the benchmarking questionnaire — role, sector, region, organisational practices, and views on crisis and risk communication readiness. These are collected to build the Nexus Readiness Score and the wider practitioner benchmarking dataset.

Optional contact details. If you enter an email address to receive the findings, a project update or a follow-up invitation, it is stored in a separate contact record. A limited internal reference may allow us to locate the associated survey submission to deal with a request, such as deletion. We do not use this reference to identify your answers in research analysis or reporting.

We collect limited technical information needed to run, secure and improve the survey, including browser/device information, approximate location derived from IP address, timestamps, security logs and standard Base44 application analytics. We do not use advertising pixels or sell personal data.

Why we process it

  • ·Your consent, given when you submit the survey and, separately, when you provide an email address. You can withdraw consent at any time by contacting us.
  • ·Our legitimate interest in producing accurate, useful research for the crisis and risk communication field — provided that interest doesn't override your own rights.

How your data is used

Aggregated and anonymised survey data feeds the Nexus Readiness Score, sector comparisons, and any published reports or articles drawn from the research. Nobody outside the RiskComms team sees individual, identifiable responses. Where quotes or examples are used publicly, they're stripped of anything that could identify you unless you've explicitly agreed otherwise.

Email addresses, where supplied, are used only for the purpose you gave them for — sending you results, or occasional updates about this specific research project. They are not added to general marketing lists without a separate, clear opt-in, and they are never sold or rented to third parties.

Where your data lives

The platform runs on Base44, a third-party hosting and application platform that processes data on our behalf as a data processor. Base44 states that its servers are currently located in the United States, and by default all workspace data — including survey responses and email addresses — is stored there. If you're taking part from the EEA, the UK, or another jurisdiction with its own data-transfer rules, this means your data crosses into the US as part of that processing.

Base44 relies on its own sub-processors to provide that infrastructure — its current sub-processor list is available at Base44's published list. Beyond Base44 and the sub-processors it uses to run the platform, no other third party receives your data unless we're required to disclose it by law.

How long we keep it

This is a longitudinal study. We run it yearly, and part of its value lies in tracking how practitioner sentiment and organisational readiness shift over time. For that reason, survey response data is retained indefinitely, rather than deleted after a fixed period. You can still ask us to delete your own responses at any point — see “Your rights” below — but by default, your answers stay part of the longer-running dataset.

Email addresses are kept only until the purpose they were given for has been fulfilled, then deleted or anonymised, unless you've opted in to future editions of the survey.

Your rights

Depending on where you're based, you may have the right to:

  • ·ask what data we hold about you, and get a copy of it
  • ·have inaccurate data corrected
  • ·ask us to delete your data
  • ·object to or restrict how we process it
  • ·receive your data in a portable format
  • ·withdraw consent at any point, without affecting anything already done under that consent

To exercise any of these, write to phil@riskcomms.com. We'll respond within a reasonable timeframe — typically one month for requests covered by GDPR-equivalent frameworks. If you're not satisfied with our response, you're entitled to lodge a complaint with your local data protection authority.

Keeping it secure

We apply reasonable technical and organisational measures to protect your data against loss, misuse, or unauthorised access — encrypted transmission, access controls on the admin backend, and limiting who on the team can view raw responses. No system is perfectly secure, but we treat this seriously.

Children

This survey is intended for working professionals. It isn't directed at children, and we don't knowingly collect data from anyone under 18.

Changes to this notice

We may update this notice as the project develops. The date at the top will always show the latest revision. Material changes — anything that affects how your data is used — will be flagged clearly on the survey site.

Contact

RiskComms FZCO

IFZA Business Park, DDP, Building A1, Dubai Digital Park, Dubai Silicon Oasis

Premises No. 8844-001, Makani No. A1-3641379065

Dubai, United Arab Emirates

phil@riskcomms.com

← Take the surveyAboutContactriskcomms.com ↗