Ryniqo OÜ · Legal Pack
Legal · Compliance

Compliance Statement

This Statement describes the regulatory frameworks and international standards that Ryniqo OÜ is designed in accordance with as it builds and operates the RynIQ™ Platform. We publish where we are, not where we hope to be. Alignment does not imply certification.

Version2.0EffectiveOn publication
SupersedesGoverning lawEstonia · EU
Section 01

Current posture

FrameworkStatusNotes
GDPR (Regulation (EU) 2016/679)Designed for alignmentController and processor obligations addressed across Privacy Policy, DPA, and this document.
EU AI Act (Regulation (EU) 2024/1689)Designed for alignmentDesign against Art. 5 prohibitions, Art. 13–15 transparency and oversight, and Art. 22 GDPR.
ISO/IEC 42001:2023 (AI Management System)Designed for alignmentAI governance operated as an AI-MS. Not certified.
ISO/IEC 27001:2022 principlesDesigned for alignmentControls mapped to Annex A. Certification not yet obtained.
NIST AI RMF 1.0Designed for alignmentControls mapped to Govern / Map / Measure / Manage.
SOC 2 Type IIRoadmapTarget: 2026. Auditor selection under way.
UK GDPRDesigned for alignmentIDTA / UK Addendum available where applicable.
Swiss FADPDesigned for alignmentSwiss addendum to SCCs available where applicable.
Section 02

GDPR

Ryniqo processes personal data lawfully, transparently and for specified purposes. Data subject rights are documented in the Privacy Policy. Article 28 obligations are documented in the DPA. Article 46 safeguards are documented in the DPA and are implemented via the 2021 SCCs and equivalent instruments for the UK and Switzerland.

Section 03

EU AI Act

Ryniqo does not offer general-purpose AI models. RynIQ™ is a decision-support system that operates under human oversight. Even where a use case is not classified as high-risk under Annex III, we operate against the design principles for high-risk systems: transparency, human oversight, accuracy, and robustness.

  • Article 5 prohibitions are treated as absolute.
  • Article 13 transparency: the AI Transparency Statement.
  • Article 14 human oversight: reviewers on every Brief.
  • Article 15 accuracy and robustness: evaluation programme in the Responsible AI Policy.
Section 04

ISO/IEC 42001:2023

Our AI Management System (AI-MS) is structured around the plan-do-check-act cycle defined by the standard. Policies, risks, controls, evaluations and incidents are documented and reviewed on a defined cadence. We are not certified.

Section 05

ISO/IEC 27001:2022

Controls in the Information Security Policy are mapped to Annex A of ISO/IEC 27001:2022. We are not yet certified. Any statement in this document that could otherwise be read as a certification claim is expressly qualified as alignment only.

Section 06

NIST AI RMF 1.0

Ryniqo maps its AI controls to the four functions of the NIST AI Risk Management Framework — Govern, Map, Measure, Manage — and uses the Playbook to prioritise improvements. This is a voluntary alignment; NIST does not certify.

Section 07

SOC 2 roadmap

A SOC 2 Type II audit is planned. Auditor selection is under way. Milestones will be updated on this page as they are achieved. Until an unqualified report is published, no SOC 2 claim should be inferred.

Section 08

Alignment does not imply certification

Where this Statement refers to a standard or framework, the reference describes design and operating alignment only. It does not constitute a certification, warranty of compliance, or endorsement by the relevant standards body.

Section 09

Contact

Compliance enquiries, questionnaires and DPAs: privacy@ryniqo.com and security@ryniqo.com.