Privacy Policy
Privacy Policy
Effective Date: 19 August 2026
Version: 1.3
Controller: Reqme SAS
Address: Halle Héméra, 132 rue Fondaudège, 33000 Bordeaux, France
Email and Privacy Contact: hi@reqme.co
1. Introduction
At Reqme, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share your personal information through our platform and website in compliance with global privacy regulations including GDPR, CCPA/CPRA, and other applicable laws.
2. Who This Policy Applies To
This policy also applies to visitors who interact with a service provider’s public request page or AI chat assistant hosted on Reqme. When you submit a request or message the assistant, Reqme acts as a processor on behalf of that service provider (the controller), and as an independent controller for platform security, abuse prevention, and service improvement.
This policy applies to the following types of users:
- Visitors – Website browsers
- Registered Users – Users with an account
- Service Providers – Business users managing services
- Clients – Customers requesting services
- Event Participants – Webinar/demo registrants
3. Data We Collect
Identity & verification data: where you use features that require identity or business verification, our verification provider processes government-issued ID documents, proof of address, bank identity documents (RIB), company-registration extracts, and — where facial verification is used — biometric data derived from a facial image. The facial check is performed by the provider on its own hosted page; Reqme receives only a pass/fail result and does not store biometric data. Document images used for verification are processed in memory for extraction only and are not stored in Reqme’s file storage.
| Category | Examples |
|---|---|
| Account Data | Name, email, company info, login details, user preferences |
| Payment Data | Billing details, transaction history (processed via Stripe/PayPal) |
| Service Data | Service requests, AI-generated documents, chat records |
| Signature Metadata | When you sign a document through the platform, we record metadata about the signing action (see the list in our Terms) so that the signature can be evidenced later. We act as an independent controller for this record: we determine what it contains, and we keep it to show that our service worked as described. Our legal basis is Article 6(1)(f) — our legitimate interest, and that of the parties to the document, in being able to evidence a signature that is later disputed. |
| Technical Data | IP address, device info, OS, browser, referrer, usage metrics |
| Marketing Data | Newsletter opt-in, campaign performance, feedback forms |
We follow data minimization principles by collecting only the data necessary to provide and improve our services.
Bank Account Details for Service Providers
If you are registered as a Service Provider on our platform and provide bank account details (e.g., IBAN) for the purpose of receiving payments or tracking payment status, we will process and store this information as follows:
- Purpose: To allow clients to view payment instructions and to support service tracking (e.g., using the “Mark as Paid” function).
- Legal basis: Contractual necessity and legitimate interest under GDPR.
- Storage: Bank details are stored securely and never shared with clients unless you explicitly include them in invoices or service pages.
- Retention: This information will be kept for as long as your provider account is active and for up to 5 years after deactivation, unless you request earlier deletion and no legal retention obligation applies.
- Access & Control: You may request access, update, or deletion of your stored bank account information at any time via hi@reqme.co.
4. Legal Bases for Processing (GDPR)
Identity and business verification (KYC): Article 6(1)(b) — verification is necessary to provide the payment and e-invoicing features you request. Facial (biometric) verification, where used, is carried out by our verification provider under Article 9(2)(a) explicit consent, which it obtains at the point of capture.
| Purpose | Legal Basis |
|---|---|
| Account setup & feature access | Contractual necessity (includes free-tier use) |
| Delivering core services | Contractual necessity / Legitimate interest |
| Processing payments | Contractual necessity / Legal obligation |
| Improving platform performance | Legitimate interest |
| Marketing communications | Consent |
| AI-powered features | Consent / Legitimate interest |
Note: Even if no formal contract is signed, using our platform constitutes an implied agreement when you request services or generate content.
5. Use of AI Technology
Our AI systems (using AI model providers OpenAI and Google, via our processing gateway) support:
- Smart service request handling
- Document generation (contracts, invoices)
- Predictive analytics and suggestions
Key Points:
- No sensitive user data is used to train models
- Outputs may require human review and are provided “as-is”
- You can opt out of AI features by contacting hi@reqme.co
- Automated decisions (e.g., pricing suggestions) use input tags, service type, and request data
Messages and content you provide are transmitted through our AI processing gateway to these providers solely to generate a response. AI interaction records are retained for up to 30 days by default before deletion. Automated redaction removes certain contact details (email addresses and phone numbers) but is not comprehensive, and messages you send to the assistant may be processed by the model in full. We do not use your personal data to train AI models. See our AI Data Use statement for details.
Automated Processing & AI Features
We use AI‑powered functionality to assist in service management, including but not limited to document generation, request classification and quotes. This involves automated processing of your personal data.
- Purpose: To improve platform efficiency, provide personalised suggestions and automate certain tasks.
- Legal basis: Legitimate interest and consent (where required).
- Your rights: You have the right to request human review of any decision based solely on automated processing that significantly affects you. You may withdraw consent or opt out of certain AI features at any time via hi@reqme.co.
- Data used for model improvement: We may use aggregated, anonymised data derived from your platform usage for AI model training and improvement. No personal identifiers are retained for this purpose unless you separately consent.
6. How We Share Your Data
| Service Provider | Role | Purpose |
|---|---|---|
| Stripe, Mollie, Paysera, Monobank, PayPal | Independent controllers | Payment processing |
| Didit | Verification provider (processor) | Identity verification (KYC) |
| Dokapi | Data Processor | E-invoicing (Peppol) & KYC documents |
| OpenAI, Google | Data Processor | AI feature delivery (via our gateway) |
| Langfuse | Data Processor | AI monitoring / tracing (EU) |
| AWS | Data Processor | Hosting, email, queue, realtime (US) |
| Amplitude | Data Processor | Product analytics (EU) |
| Appzi | Data Processor | In-product feedback (US) |
| ipgeolocation.io | Data Processor | Security notifications (Pakistan, IP only) |
Where a third party processes personal data on our behalf (a processor), that processing is governed by data-protection terms as required by Article 28 GDPR. Payment institutions and banks act as independent controllers under their own regulatory obligations. A current list of our providers is available at reqme.co/subprocessors.
7. International Data Transfers
Some providers are located outside the EEA, including in the United States (e.g. AWS hosting, OpenAI and Google AI processing) and, for specific functions, Ukraine (Monobank, for payment execution) and Pakistan (ipgeolocation.io, which receives only an IP address). Transfers rely on EU Standard Contractual Clauses, the EU-US Data Privacy Framework where the recipient is certified, or another lawful mechanism such as Article 49(1)(b) where a transfer is necessary to perform a contract with you.
If data is transferred outside the EU/EEA (e.g., to the U.S.), we rely on:
- EU Standard Contractual Clauses (SCCs)
- Data encryption and minimization
- Binding third-party data protection commitments
8. Cookies & Tracking Technologies
We use cookies for:
- Website performance
- Analytics and behavior tracking
- Marketing and personalization
You can adjust preferences in your browser or via our Cookie Policy.
9. Data Retention
| Data Type | Retention Period |
|---|---|
| Account Data | While account is active + 6 months |
| Service Data | 2 years after last activity or deletion request |
| Technical Logs | 12 months |
| Backups | Up to 90 days (encrypted and secured) |
| Signature evidence records | Up to 10 years from the date of signing |
You can request deletion of your data at any time.
10. Data Security Measures
We use enterprise-grade safeguards including:
- AES-256 encryption at rest & TLS 1.3 in transit
- Role-based access controls and 2FA
- Logging, monitoring, and vulnerability scanning
- Secure access policies and staff NDAs
11. Breach Notification
In case of a personal data breach affecting your rights, we will:
- Notify impacted users and relevant authorities within 72 hours
- Provide details of the breach, what data was affected, and mitigation steps
- Offer guidance on how to protect yourself
12. Your Privacy Rights (EU/UK)
You have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Request deletion (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability
- Withdraw consent at any time
- File a complaint with the CNIL or your regional data authority
Contact: hi@reqme.co
EU/UK Representative: Please contact hi@reqme.co
13. U.S. State Privacy Rights (CCPA, CPRA, VCDPA, etc.)
If you’re a U.S. resident, your rights may include:
- Right to know what data we collect and why
- Right to delete your data
- Right to access and receive your data in portable format
- Right to opt out of data sale (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
- Right to opt out of automated decision-making
- Right to file a complaint with the FTC
hi@reqme.co and select Privacy category during request creation— Response within 45 days.
14. Children’s Privacy
Our services are not directed at individuals under 16. We do not knowingly collect or process data from children. If you’re a parent or guardian and believe your child has shared data with us, please contact us for deletion.
15. Data Protection Impact Assessments
For high-risk processing activities (e.g., AI-driven decision-making), we conduct DPIAs (Data Protection Impact Assessments) as required by GDPR Article 35.
16. Changes to This Policy
We may update this policy due to:
- Changes in law
- New product features
- Updated data practices
You will be notified of material changes via:
- Email (if provided)
- In-app notification
- Updated “Effective Date” at the top of this page
17. Contact Us
For questions, complaints, or to exercise your rights:
📧 Support & General: hi@reqme.co
🔒 Privacy Inquiries: create Privacy request in https://reqme.co or send an e-mail hi@reqme.co
📍 Supervisory Authority:
CNIL – Commission Nationale de l’Informatique et des Libertés
3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
www.cnil.fr

