Legal
Data Processing Information
This page is written for school leaders and organisation owners who want a clear explanation of how Riabo handles organisation data.
It complements our Privacy Policy and Security & Privacy page. It is not a signed Data Processing Agreement. If your school needs a formal DPA, contact us.
Who owns uploaded data?
Your organisation owns the content it enters into Riabo — including actions, submissions, staff records created in Riabo and related work history.
Evidence files uploaded through a connected Google Drive account are stored in your organisation’s own Google Drive. Riabo stores the links and metadata needed to show those files beside the relevant work.
Controller and processor
In most school uses of Riabo, your organisation decides what information to enter and who should see it. That means your organisation typically acts as a data controller for that content.
Arukas Limited provides the Riabo platform and processes that information on your organisation’s instructions in order to deliver the service. In that role, we typically act as a data processor.
For our own business records — such as account administration, billing and support correspondence — we may act as a controller.
Organisation responsibilities
Your organisation should:
- invite only people who need access
- assign suitable roles
- remove access when someone leaves
- avoid uploading information that does not need to be in Riabo
- follow your own data-protection and child-protection policies
Role-based access
Access inside an organisation is controlled by role:
- Owners manage settings, billing and staff access
- Admins manage day-to-day actions, templates and reports
- Members complete work assigned to them
One organisation cannot browse another organisation’s workspace.
Where data is stored
Application data is hosted with Supabase in the EU. Branding images uploaded for an organisation are stored in private Supabase storage.
Evidence files are stored in the organisation’s connected Google Drive account, not in Arukas-owned file storage.
Payment details for licence purchases are handled by Stripe.
Exports
Owners and Admins can export selected reports as CSV files, including organisation summary and outstanding work reports.
A full one-click export of every organisation record is not available yet. If you need a broader extract when leaving Riabo, contact us.
Deletion requests
Organisation Owners can deactivate a person’s access so they can no longer sign in. Work history is kept so the organisation’s records are not wiped when someone leaves.
Requests to delete a personal account, close an organisation, or erase specific personal data should be sent to hello@arukas.ie. Self-service organisation deletion is not currently available in the product.
Subprocessors and connected services
Services that may process data to provide Riabo include:
- Supabase — authentication, database and private storage
- Stripe — payments
- Google — when your organisation connects Google Drive for evidence files
- Application hosting and email delivery providers used to run Riabo and send operational messages
Privacy contact
For privacy or data-processing questions about Riabo:
Arukas Limited
Sakura, Crossneen, Carlow, Ireland
hello@arukas.ie
You can also use the contact form.
These documents describe how Riabo operates today and may be updated as the product evolves.