Privacy policy.
How personal data is handled on this website and in the REQOPS product, and how to exercise your rights.
01This website
- No cookies, no trackers, no analytics. This site sets no cookies and runs no third-party analytics or advertising scripts.
- The contact form is relayed, not stored. What you type is passed to our inbox by FormSubmit, an email-forwarding service. This website keeps no copy, and we use it only to reply.
- The demo stays in your browser. The product demo runs on simulated sample data held locally; nothing you do in it is transmitted to us.
02The product, and whose data it holds
REQOPS is a governance observatory for employee work activity — who is doing what, on which system, checked against which policies. Its core records are employee-monitoring data, and they are treated as the highest-sensitivity data in the product.
When an organisation deploys REQOPS, that organisation is the controller of the records: it decides what is monitored, under which policies, and who may look. REQOPS runs in the customer's environment — customer records live on infrastructure the customer controls, and are not sent to us. Where we process anything on a customer's behalf, we do so as a processor, under a data processing agreement, on documented instructions.
03What the product records
| Records | What they are | Class |
|---|---|---|
| Monitoring records | Who did what, where, when, and whether policy allowed it. Team members see redacted versions of sensitive work categories; managers' access is logged with a reason. Your administrators decide which categories count as sensitive, and work that has not been classified yet is treated as sensitive until it is. | Confidential |
| Audit log | Who looked at whom, and why — hash-chained so edits are detectable. Protected harder than what it audits. | Restricted |
| Accounts & invites | Name, email, sign-in identity, role; invited addresses and their invite tokens. | Internal · personal data |
| Policies & notices | The monitoring rules, and the ledger proving staff were told about monitoring. No one's personal behaviour in here. | Internal |
04Controls the product applies to its own operation
- Notice before monitoring. A policy cannot be enforced against people until they have seen it and acknowledged it — the notice ledger is a first-class product record, built to satisfy workplace-surveillance notice laws (for Australian deployments, including the NSW Workplace Surveillance Act).
- A reason before a look. Manager access to monitoring evidence requires a recorded reason, saved beside their name in an append-only log.
- Least privilege, deny by default. Two roles, checked on the server on every request; sensitive work categories are redacted for non-managers before a response is built. Anything the system cannot place in a category is redacted too — the default protects, never exposes.
- No AI processing. The product currently makes no AI model calls, and no customer data reaches any model provider. If that ever changes, an AI transparency statement will be published first, with its own kill switch.
05Your rights
Anyone whose personal data we process can ask to see it, export it, correct it, or delete it. Send the request to hello@reqops.io; we acknowledge promptly and respond within one month. Where your records are held by your employing organisation as controller, we route the request to them and support them in meeting the clock. Deletion is physical, not just logical — see the data retention policy for exactly what deletion means here, including the 35-day backup expiry window.
06Who else touches data
The full public list, with regions and purposes, is the sub-processor list. The short version: sign-in is handled by Auth0 (we never see or store passwords), and hosting for the demo site is the only other party. No analytics vendors, no advertising networks, no AI providers.
07International transfers and agreements
Where personal data crosses borders, transfers rest on a data processing agreement incorporating the standard contractual clauses, with a technical-and-organisational-measures annex that matches what the security pages say. For breaches involving personal data, affected customers are notified without undue delay and regulators within 72 hours where GDPR applies.
08Contact
Privacy questions, requests, or complaints: hello@reqops.io. If you are not satisfied with our response, you may complain to your local supervisory authority — in Australia, the Office of the Australian Information Commissioner (OAIC).