Privacy Policy

Last updated: 16 September 2026

Requio ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what we collect, how we use it, who we share it with, and the choices you have — both when you use the Requio platform and when you interact with our website and marketing.

Who We Are

  • Requio is a B2B requirements management platform operated by Requio Ltd, a UK-registered company.
  • Contact email: hello@requio.co.uk
  • Website: https://requio.co.uk
  • If you have any questions about this policy or your data, you can contact us using the details above.
  • Requio is a business product. It is not intended for, or directed at, children under 16.

Our Role: Controller and Processor

Requio holds two different kinds of personal data, and our responsibilities differ between them.

  • Controller — for account, billing and marketing data. This is information about you as a Requio user or subscriber, and we decide how it is used.
  • Processor — for the content your organisation puts into the platform. Requirements, packs and uploaded documents often name real people: your colleagues, customers or stakeholders. Your organisation remains the controller of that content, and we process it only on their instructions.
  • If you are named inside content held by one of our customers, that organisation is responsible for your data. Please contact them directly to exercise your rights, and we will support them in responding.

Information We Collect

We keep what the platform needs to work, and little else.

  • Account — your name, work email address, the name of your workspace, and the roles you have been given within it.
  • Password — stored only as a salted hash. We cannot see or recover your password.
  • Account status — whether your email has been verified, and the date you were last active, which we use to send inactivity reminders you can turn off.
  • Billing — your workspace plan, seat count and billing method, plus a Stripe customer and subscription reference. Card details go to Stripe directly and never reach our systems.
  • Audit records — a history of actions taken in your workspace: who did what, to which item, and when. This is the review and approval trail the product exists to provide, so it cannot be switched off.
  • Refused sign-ins — when someone tries and fails to sign in to your workspace, we record the email address that was typed, the reason it was refused, and the IP address and browser it came from. This is a security record, so that a Workspace Admin can see attempts to get into their workspace; only a Workspace Admin can see it. No person is named as having done it, because an attempt on an account may not have been made by its owner.
  • AI usage records — which AI feature was used, which model answered, and how many tokens it cost. We do not keep the content of AI requests or responses in these records.
  • Marketing — your email address if you subscribe to our newsletter, and your email preferences.

Content You Put Into Requio

Most of what Requio holds is your own working material rather than personal data about you.

  • Projects, Digital Requirements Packs, requirements, user stories, process maps, comments and supporting notes.
  • Documents you upload, including reference material used to ground AI suggestions.
  • Documents submitted by people outside your workspace through a secure upload link. For these we collect the name they give, their organisation if they provide one, and the file with its name, size and type. Files are scanned for malware before they can be used.
  • This content may contain personal data about other people. Please include only what is necessary, and do not put special category data (such as health or biometric information) into the platform.

What We Do Not Collect

  • We do not collect telephone numbers, job titles, team size, or demographic information.
  • We do not record IP addresses or browser user-agent strings as you use the platform, though our hosting providers may log them briefly for security and abuse prevention. There are two exceptions: a refused sign-in, which is recorded as a security measure — see Information We Collect; and our public website, where analytics receives your IP address to derive an approximate location, and only if you accept cookies — see Website Analytics.
  • We do not knowingly collect special category personal data.
  • We do not sell your data, and we do not use it for advertising or ad targeting.

How We Collect Your Data

  • Directly from you, when you create a workspace, accept an invitation, or use the platform.
  • From your colleagues, when an administrator invites you to a workspace or assigns you a role.
  • Automatically as you use the service, in the form of audit records, AI usage counts and error diagnostics.
  • From our public website and sign-up pages, if you accept analytics cookies — see Website Analytics.
  • From external contributors who submit documents to a workspace through a secure upload link.
  • When you subscribe to our newsletter or contact us directly.

How We Use Your Data

  • Run the platform: your workspace, projects, packs and the review and approval workflow.
  • Authenticate you and keep your account secure.
  • Provide AI assistance, such as suggestions, quality checks, summaries and process maps.
  • Take payment, manage your subscription, and apply the limits of your plan.
  • Send service messages you cannot opt out of while you hold an account: email verification, password resets, invitations, and notices about your account or billing.
  • Send marketing email where you have opted in, which you can stop at any time.
  • Diagnose faults, prevent abuse, and improve reliability.
  • Meet legal and regulatory obligations.

AI Processing

Requio uses AI to draft and check requirements content. This means some of your content leaves our systems, so it is worth being precise about what happens.

  • When you use an AI feature, the content needed for that specific request is sent to Google's Gemini API, processed, and the response is returned to you. Only what the request needs is sent.
  • We do not use your content to train AI models. Requio has no model-training pipeline of any kind.
  • We use the paid Gemini API, not the free tier. Google's terms for paid use state that content submitted through it is not used to train or improve their models.
  • Google does not restrict this processing to a particular country. Their terms for paid use say the data may be stored temporarily or cached in any country in which Google or its agents maintain facilities.
  • We record that a request happened and what it cost in tokens, but not what it contained.
  • Workspaces on eligible plans may supply their own AI provider key, in which case requests are made against that key instead of ours.
  • AI output is generated automatically and can be wrong. It is a drafting aid: nothing becomes part of an approved pack without a person reviewing and approving it.
  • We do not make decisions about you by automated means that produce legal or similarly significant effects.

Legal Basis for Processing (UK/EU GDPR)

  • Contract — to provide the platform to you and your organisation and to take payment for it.
  • Consent — for marketing email, and for analytics cookies on our public website. You may withdraw either at any time without affecting your account.
  • Legitimate interests — to secure the service, prevent abuse, diagnose faults, and improve the product in ways you would reasonably expect.
  • Legal obligation — where the law requires it.
  • Where we act as a processor for customer content, we process it on our customer's documented instructions under our agreement with them.

Sub-Processors

We use the following providers to run Requio. Each may process personal data on our behalf, is permitted to act only on our instructions, and is bound by appropriate data protection terms.

ProviderPurposeWhat it processes
Amazon Web ServicesApplication hosting, database and file storageAll account data and content held in the platform, in the London region (eu-west-2)
VercelHosting for the website and application front endRequests to the site, processed primarily in the United States and potentially elsewhere. Your workspace content is not held there — it stays in AWS London.
Google (Gemini API)AI suggestions, quality checks, summaries and process mapsThe specific workspace content needed for each AI request. Google may process it in any country in which it operates; this is not restricted to a region.
StripePayment processing and subscription billingBilling contact and payment details, provided to Stripe directly and processed in the United States
MailgunService email: verification, password resets, invitationsYour name, email address and the message content
LoopsMarketing and lifecycle emailYour email address, workspace name and plan, processed in the United States
SentryError monitoring and diagnosticsTechnical error data, and a session replay around an error
PostHogAnalytics for our public website and sign-up pagesAnonymous records of pages visited and sign-up steps reached, processed in the EU (Frankfurt), and only if you accept cookies

Several of these providers process data outside the UK — see International Transfers below. Each of them in turn uses its own suppliers: in particular Loops, our marketing email provider, passes contact data to its suppliers, which include an AI provider and a data-enrichment service, and publishes that list at loops.so/subprocessors. We keep our own list current when we change providers.

Data Storage and Security

  • Data is hosted on Amazon Web Services in their London region (eu-west-2). Traffic is encrypted in transit using TLS, and our database is encrypted at rest.
  • Passwords are stored as salted bcrypt hashes and are never stored in plain text.
  • Access to a workspace is limited to the people your administrators invite, with permissions determined by the role they are given.
  • Files submitted through secure upload links are scanned for malware before they can be opened or indexed.
  • We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse or disclosure.

Data Retention

  • Account data is kept for as long as your workspace is active.
  • Content belongs to your organisation and is kept until they delete it or close their workspace.
  • Audit and version history is kept for the life of the workspace, because it is the record of who approved what and when.
  • Records of refused sign-ins are kept for the life of the workspace too, as part of that same history.
  • Marketing contacts are kept until you unsubscribe, after which we keep a minimal record of the fact that you opted out so we do not contact you again.
  • If you want your account closed or your personal data deleted, contact support@requio.co.uk and we will action it, subject to any records we must keep by law.

International Transfers

  • Your workspace and its content are held in the UK, on Amazon Web Services in London. Several of the providers listed above, however, process data outside it.
  • Stripe processes billing data in the United States. Loops, which sends our marketing and lifecycle email, processes contact data in the United States. Vercel, which hosts our website, processes requests primarily in the United States. Google may process AI requests in any country in which it operates.
  • Where data is transferred internationally, we rely on appropriate safeguards — standard contractual clauses, the UK International Data Transfer Addendum, or the EU–US and UK–US Data Privacy Frameworks, depending on the provider.

Your Rights (UK/EU)

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Withdraw consent at any time
  • Request data portability
  • To exercise your rights, contact support@requio.co.uk.
  • If your data sits inside a customer's workspace, we will pass your request to that organisation, as they control it.
  • You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local EU data protection authority.

US Privacy Rights

  • If you are located in the United States, you may have rights under applicable state privacy laws (such as the CCPA/CPRA), including the right to request access to or deletion of your personal information.
  • We do not sell personal data and do not engage in targeted advertising based on sensitive personal information.

Error Monitoring

  • We use Sentry, a third-party error-monitoring service, to help us detect and fix technical issues with our website and application.
  • When an error occurs, Sentry may capture a replay of your on-screen session in the moments around that error (such as page interactions) to help us diagnose the problem. This is used solely to improve the reliability of our service, and does not use cookies.

Website Analytics

We measure how people find and move through our public website and sign-up pages, so we can see where it is confusing and fix it. This runs only if you accept cookies, and never inside the platform itself.

  • We use PostHog, an analytics provider. Our PostHog project is hosted in the EU, and this data is processed in Frankfurt, Germany.
  • Nothing is recorded, and no information about you leaves your browser, until you accept our cookie banner. Until you do, the analytics software is not even downloaded to your device — so if you reject it, nothing is ever loaded, nothing is ever sent, and no cookies are set.
  • We record a small, fixed set of moments: which of our public pages you visit, and the steps of signing up — starting the form, submitting it, reaching the "check your inbox" page, and verifying your email address.
  • We do not record what you type. Your name, email address, workspace name and password are never sent to our analytics provider.
  • Your IP address is used to derive an approximate location, such as country or region. We do not build a profile against a named person.
  • None of this runs on pages inside the platform. Once you are signed in and working on your projects, nothing there is measured by analytics.
  • You can change your mind at any time using the "Cookies" link in our website footer.

Cookies and Browser Storage

  • We use analytics cookies on our public website and sign-up pages, and only where you have accepted them. They let us see which pages people visit and where they give up while signing up — see Website Analytics.
  • We do not use advertising or ad-targeting cookies, and we do not sell your data.
  • To keep you signed in, we store an access token in your browser local storage. This is strictly necessary for a service you have asked for and does not require consent under UK PECR.
  • A small number of strictly necessary cookies may be set to operate the site, for example to remember a preview or access setting. These are not used to track you.
  • Your answer to the cookie banner is remembered in your browser so you are not asked on every visit. The "Cookies" link in our website footer re-opens that choice at any time. Rejecting stops any further analytics immediately; where analytics was running, our provider keeps one small entry in your browser for the sole purpose of remembering that you opted out, and where it was not, any entry left by an earlier acceptance is removed.

Changes to This Policy

  • We may update this Privacy Policy from time to time as Requio evolves. The latest version will always be available on our website, with the updated date shown at the top.