Compliance Statement
This Statement describes the regulatory frameworks and international standards that Ryniqo OÜ is designed in accordance with as it builds and operates the RynIQ™ Platform. We publish where we are, not where we hope to be. Alignment does not imply certification.
| Version | 2.0 | Effective | On publication |
|---|---|---|---|
| Supersedes | — | Governing law | Estonia · EU |
Current posture
| Framework | Status | Notes |
|---|---|---|
| GDPR (Regulation (EU) 2016/679) | Designed for alignment | Controller and processor obligations addressed across Privacy Policy, DPA, and this document. |
| EU AI Act (Regulation (EU) 2024/1689) | Designed for alignment | Design against Art. 5 prohibitions, Art. 13–15 transparency and oversight, and Art. 22 GDPR. |
| ISO/IEC 42001:2023 (AI Management System) | Designed for alignment | AI governance operated as an AI-MS. Not certified. |
| ISO/IEC 27001:2022 principles | Designed for alignment | Controls mapped to Annex A. Certification not yet obtained. |
| NIST AI RMF 1.0 | Designed for alignment | Controls mapped to Govern / Map / Measure / Manage. |
| SOC 2 Type II | Roadmap | Target: 2026. Auditor selection under way. |
| UK GDPR | Designed for alignment | IDTA / UK Addendum available where applicable. |
| Swiss FADP | Designed for alignment | Swiss addendum to SCCs available where applicable. |
GDPR
Ryniqo processes personal data lawfully, transparently and for specified purposes. Data subject rights are documented in the Privacy Policy. Article 28 obligations are documented in the DPA. Article 46 safeguards are documented in the DPA and are implemented via the 2021 SCCs and equivalent instruments for the UK and Switzerland.
EU AI Act
Ryniqo does not offer general-purpose AI models. RynIQ™ is a decision-support system that operates under human oversight. Even where a use case is not classified as high-risk under Annex III, we operate against the design principles for high-risk systems: transparency, human oversight, accuracy, and robustness.
- Article 5 prohibitions are treated as absolute.
- Article 13 transparency: the AI Transparency Statement.
- Article 14 human oversight: reviewers on every Brief.
- Article 15 accuracy and robustness: evaluation programme in the Responsible AI Policy.
ISO/IEC 42001:2023
Our AI Management System (AI-MS) is structured around the plan-do-check-act cycle defined by the standard. Policies, risks, controls, evaluations and incidents are documented and reviewed on a defined cadence. We are not certified.
ISO/IEC 27001:2022
Controls in the Information Security Policy are mapped to Annex A of ISO/IEC 27001:2022. We are not yet certified. Any statement in this document that could otherwise be read as a certification claim is expressly qualified as alignment only.
NIST AI RMF 1.0
Ryniqo maps its AI controls to the four functions of the NIST AI Risk Management Framework — Govern, Map, Measure, Manage — and uses the Playbook to prioritise improvements. This is a voluntary alignment; NIST does not certify.
SOC 2 roadmap
A SOC 2 Type II audit is planned. Auditor selection is under way. Milestones will be updated on this page as they are achieved. Until an unqualified report is published, no SOC 2 claim should be inferred.
Alignment does not imply certification
Where this Statement refers to a standard or framework, the reference describes design and operating alignment only. It does not constitute a certification, warranty of compliance, or endorsement by the relevant standards body.
Contact
Compliance enquiries, questionnaires and DPAs: privacy@ryniqo.com and security@ryniqo.com.