MigrationHQ by riiLogic
Back to riilogic.com

riiLogic

Privacy Policy

Last updated: 12 July 2026

Who we are

riiLogic ("we", "us") is the company behind MigrationHQ (MHQ), an enterprise identity migration platform. This policy explains what personal data we collect across riilogic.com (our website) and app.riilogic.com (the MigrationHQ platform), why we collect it, and the choices you have.

What we collect

On riilogic.com (this website)

The website sets no cookies and runs no tracking that identifies you. We use Cloudflare Web Analytics, a cookieless, privacy-first measurement tool that reports aggregate page views without fingerprinting individual visitors. Cloudflare, which serves this site, keeps standard server logs (including IP addresses) for security purposes.

When you create a MigrationHQ account

When you start a trial or sign up we collect: your name, work email address, password (stored only as a cryptographic hash — we cannot read it), company name, and optionally company size, your role, and the type of migration you're planning. We also record the referring campaign (UTM parameters), and the IP address and browser user-agent of the signup for abuse prevention. We keep a record of signup attempts, including unsuccessful ones, as part of our commercial records.

When you use the MigrationHQ platform

The platform uses strictly-necessary session cookies to keep you signed in (an HttpOnly session token and a CSRF protection token). These are not used for tracking or advertising and expire automatically. Actions taken in the platform are recorded in an audit log (who did what, when, from which IP) — this is a core product feature for migration governance, not marketing telemetry.

Directory data processed during migrations

When your organisation connects its environments, MigrationHQ processes directory data (such as user account attributes and group memberships) on your organisation's behalf and under its instructions, solely to deliver the migration service. Your organisation remains the controller of that data; we act as a processor. User passwords synchronised during a migration are never visible to us — synchronisation is designed so that cleartext passwords never reach our systems.

How we use personal data

  • To provide, secure, and support the MigrationHQ service.
  • To provision and manage your trial or subscription.
  • To contact you about your account or, where permitted, about the product.
  • To prevent abuse and keep the platform secure.
  • To meet our legal and accounting obligations.

We do not sell personal data, and we do not use it for third-party advertising.

Who we share it with

We use a small number of service providers to run MigrationHQ:

  • Microsoft Azure — cloud hosting (UK South region).
  • Cloudflare — content delivery, security, bot protection, and cookieless web analytics.
  • Stripe — payment processing. Card details go directly to Stripe and never touch our systems.

These providers process data only to provide their services to us. We may also disclose data where required by law.

How long we keep it

Account data is kept for the life of your account and deleted or anonymised after closure, subject to legal retention requirements. Audit logs are retained as part of the service's governance record. Signup/lead records are retained as commercial records. Directory data processed during a migration is retained under your organisation's instructions.

Your rights

Depending on where you are, you may have rights under data protection law (such as the UK GDPR and EU GDPR) to access, correct, delete, or restrict the processing of your personal data, and to complain to a supervisory authority. To exercise any right, contact us at the address below. If your data was processed on behalf of your employer (for example, directory data during a migration), we may refer your request to them as the controller.

Security

MigrationHQ is built security-first: encrypted transport everywhere, passwords stored only as hashes, tenant data isolated per organisation, secrets held in a managed key vault, and every administrative action audited. No system is perfectly secure, but security is the product's foundation, not an afterthought.

Contact

Privacy questions and requests: privacy@riilogic.com

Changes

If we make material changes to this policy we will update this page and revise the date at the top. Significant changes affecting account holders will be notified in the product.

© 2026 riiLogic. All rights reserved. Terms of Service · riilogic.com