Contents
- 1About this addendum
- 2Definitions
- 3Roles and scope of processing
- 4Duration of processing
- 5Customer instructions and lawful basis
- 6Sub-processors
- 7Security measures
- 8International transfers
- 9Data subject rights
- 10Data breach notification
- 11Audit and records
- 12Return and deletion of data
- 13Liability and governing law
- Annex I: List of parties and description of transfer
- Annex II: Technical and organizational measures
- Annex III: List of sub-processors
1 · About this addendum
1.1This Data Processing Addendum ("DPA") forms part of the Reqio Terms of Service and is incorporated into and governed by those Terms. By using the Reqio service, you (the controller or Data Fiduciary) and K S Poorvik, an individual operating under the trade name Reqio ("Reqio", the processor or Data Processor), agree to be bound by this DPA in addition to the Terms of Service.
1.2This DPA governs how Reqio processes personal data on your behalf when you use the Reqio service to collect end-user feedback. Together, the Terms of Service and this DPA constitute the complete agreement between the parties on data processing matters.
1.3Where applicable law requires a written data processing agreement between a controller and a processor, including Article 28 of the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act 2023 of India (DPDP Act), this DPA is intended to satisfy that requirement.
1.4Reqio recommends that you have this document reviewed by legal counsel in your jurisdiction before relying on it for regulatory compliance purposes.
2 · Definitions
2.1Controller (or Data Fiduciary under the DPDP Act)
The party that determines the purposes and means of processing personal data. Under this DPA, the controller is you, the customer.
2.2Processor (or Data Processor under the DPDP Act)
The party that processes personal data on behalf of the controller. Under this DPA, the processor is Reqio.
2.3Personal data
Any information relating to an identified or identifiable natural person, or digital personal data as defined under the DPDP Act.
2.4Data subject (or Data Principal under the DPDP Act)
The individual whose personal data is being processed. Under this DPA, data subjects are the end users who interact with the Reqio widget embedded on your website.
2.5Sub-processor
Any third party engaged by Reqio to process personal data on Reqio's behalf in connection with providing the service.
2.6Processing
Any operation or set of operations performed on personal data, including collection, storage, use, disclosure, or deletion, whether or not by automated means.
3 · Roles and scope of processing
3.1You are the controller. You determine what personal data your end users submit through the Reqio widget and the purposes for which it is collected. Reqio is the processor. Reqio processes personal data solely to provide and operate the service on your behalf.
3.2Reqio processes the following categories of personal data on your behalf:
- Anonymous browser identifiers.
- Optional email addresses.
- Optional external user identifiers, where you enable the identity feature.
- Revenue attributes (monthly recurring revenue, plan name, or external identifiers), where you pass them in an identity token.
- Feature request text, votes, and comments.
- Page URLs and optional context strings.
- Browser and device diagnostics submitted at the time of a widget interaction.
- Screenshots of the visible portion of the page (the viewport) at the time of a report, where the end user chooses to attach one.
- The content and headers of inbound email replies from end users who reply to Reqio notification emails, stored in the associated conversation thread.
3.3Reqio does not process personal data for its own purposes beyond what is strictly necessary to provide the service, unless required by applicable law.
3.4Customer-directed disclosures
Where you retrieve personal data through the API, connect a third-party AI agent through the MCP server, connect a project integration using your own credentials (such as Slack, Jira, or Linear, which receive notifications containing end-user request titles and message excerpts), or run the optional GitHub agent workflow (which transmits end-user content, including request text, conversation threads, screenshots, and browser diagnostics, to an AI model provider under your own account and API key), Reqio discloses that personal data on your documented instruction. The recipient is engaged by you, not by Reqio: it acts as your own processor or independent recipient, and it is not a Reqio sub-processor under Section 6 or Annex III. You are responsible for the lawfulness of each such disclosure, for informing your data subjects about it, and for putting in place any data-processing terms required between you and the recipient.
4 · Duration of processing
4.1For the purposes of Article 28(3)(a) of the GDPR, Reqio processes personal data under this DPA for the duration of the agreement between you and Reqio: from the date you first use the service until the termination or expiry of your account, plus any retention period stated in the "Data retention" section of the Reqio Privacy Policy or required by applicable law.
4.2At the end of that period, Reqio returns or deletes the personal data in accordance with Section 12 (Return and deletion of data).
5 · Customer instructions and lawful basis
5.1Reqio processes personal data only on your documented instructions, as set out in the Terms of Service and this DPA, and as strictly necessary to comply with applicable law.
5.2You warrant that you have a lawful basis under applicable law (including the GDPR and the DPDP Act) to collect and process the personal data of your end users through the Reqio widget, and that you have provided end users with an appropriate privacy notice.
5.3You must not instruct Reqio to process personal data in a manner that would violate applicable law. If Reqio reasonably believes that an instruction would result in a breach of applicable law, Reqio will promptly notify you and reserves the right to pause processing under that instruction until you provide a revised instruction.
6 · Sub-processors
6.1Reqio engages the sub-processors listed in Annex III to this DPA to assist in providing the service. Each sub-processor is bound by a written agreement that imposes data-protection obligations equivalent to those in this DPA.
6.2Reqio will give you reasonable advance notice of any intended change to its sub-processor list. You can object to such a change by notifying Reqio at support@reqio.app within 14 days of the notice. If Reqio cannot accommodate the objection without materially affecting the service, you can terminate the agreement.
6.3Providers you engage directly, including the AI model providers used by the optional GitHub agent workflow, the third-party agents you connect over the MCP server, and the project integrations you authorize with your own credentials (such as Slack, Jira, or Linear), are not Reqio sub-processors and do not appear in Annex III. Reqio has no contract with them and does not control them. Section 3.4 governs those disclosures.
7 · Security measures
7.1Reqio implements appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, disclosure, or destruction. These measures are described in detail in Annex II to this DPA and include:
- Encryption of data in transit using TLS.
- Encryption of sensitive stored secrets using AES-256-GCM.
- Passwordless login using one-time codes that are bcrypt-hashed at rest, single use, expiring, and rate limited with attempt lockout.
- Access controls limiting access to personal data to those who require it to provide the service.
- Rate limiting and abuse detection on authentication and widget endpoints.
7.2Reqio reviews and updates its security practices periodically to maintain a level of protection commensurate with the risks presented by the processing.
8 · International transfers
8.1Reqio is operated from India. Some sub-processors (including Vercel and Neon) store and process personal data in the United States or other countries outside India and the European Economic Area.
8.2Reqio relies on its sub-processors' own compliance frameworks, including Standard Contractual Clauses or equivalent safeguards where required under applicable law, for cross-border transfers.
8.3By using the service, you acknowledge that end-user personal data is transferred to and processed in countries whose data protection laws differ from those in your jurisdiction.
8.4For personal data of data subjects in the European Economic Area or European Union, the parties hereby incorporate by reference the Standard Contractual Clauses issued under Commission Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor), with the Customer as the data exporter and controller and Reqio as the data importer and processor. These clauses apply to and govern such transfers. Where these Standard Contractual Clauses conflict with the remaining provisions of this DPA in respect of the data they cover, the Standard Contractual Clauses shall prevail. The optional and docking clauses are deemed selected to the extent applicable. Annexes I, II, and III of this DPA serve as Annexes I, II, and III of the Standard Contractual Clauses.
8.5For personal data of data subjects in the United Kingdom, the parties further incorporate by reference the UK Information Commissioner's International Data Transfer Addendum to the EU Standard Contractual Clauses (the 'UK IDTA'). The UK IDTA is deemed to form part of the Standard Contractual Clauses as they apply to UK transfers and shall prevail over any conflicting provisions of this DPA for the data it covers.
9 · Data subject rights
9.1As the controller, you are responsible for responding to requests from data subjects (or Data Principals) exercising their rights under applicable law, including rights of access, correction, deletion, restriction, and portability.
9.2Reqio will provide reasonable assistance to help you fulfil such requests, to the extent technically feasible. To request assistance, contact Reqio at support@reqio.app. Reqio will respond within 30 days.
9.3On written request, Reqio will delete or return personal data it holds on behalf of a specific data subject within 30 days, subject to any legal retention obligations.
10 · Data breach notification
10.1If Reqio becomes aware of a security incident affecting personal data processed under this DPA, Reqio will notify you without undue delay, and in any event within 72 hours of becoming aware of the incident.
10.2The notification will include, to the extent known at the time:
- The nature of the incident.
- The categories and approximate number of data subjects affected.
- The categories and approximate volume of personal data involved.
- The likely consequences.
- The measures taken or proposed to address the incident.
10.3You are responsible for notifying the relevant supervisory authority or data subjects as required by applicable law. Reqio will cooperate with your investigation and remediation efforts.
11 · Audit and records
11.1Reqio maintains records of its processing activities under this DPA as required by applicable law.
11.2On written request, Reqio will make available to you the information reasonably necessary to demonstrate compliance with this DPA. Reqio reserves the right to fulfil this obligation by providing a written description of its current security measures or a relevant third-party audit summary where one is available.
11.3Reqio does not routinely permit physical on-site audits given the nature of the service, but will cooperate with reasonable information requests at no additional cost.
12 · Return and deletion of data
12.1On termination or expiry of the agreement, Reqio will, at your election, return or securely delete all personal data processed under this DPA within 30 days of your written request.
12.2This obligation does not apply to the extent Reqio is required by applicable law to retain the data, in which case Reqio will continue to protect that data in accordance with this DPA and will not process it for any other purpose.
12.3Data export requests must be submitted to support@reqio.app before account deletion. Once an account is permanently deleted, recovery is not possible.
13 · Liability and governing law
13.1The liability of each party under this DPA is subject to the limitations set out in the Reqio Terms of Service.
13.2This DPA is governed by and construed in accordance with the laws of India. Any dispute arising out of or relating to this DPA shall be subject to the exclusive jurisdiction of the courts located in India.
13.3If any provision of this DPA is found to be unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force and effect.
Annex I: List of parties and description of transfer
IThis Annex I forms part of this DPA and of the Standard Contractual Clauses incorporated under Section 8.4.
I.A.1A. List of parties: data exporter
The data exporter is the Customer, as identified in the agreement between the Customer and Reqio (the account holder who accepts the Reqio Terms of Service). Role: controller. Contact details: the name and email address associated with the Customer's Reqio account. Activities relevant to the transfer: operating a website or product that embeds the Reqio widget to collect end-user feedback. Signature and date: the data exporter is deemed to have signed this Annex by accepting this DPA.
I.A.2A. List of parties: data importer
The data importer is K S Poorvik, an individual operating under the trade name Reqio, with principal place of business at #786, 1st stage, 2nd cross, Sangameshwara ext., Hassan, Karnataka, India. Contact: support@reqio.app. Role: processor. The data importer is not established in the EU or UK and has not appointed a representative in the EU or UK under Article 27 GDPR or its UK equivalent; the data exporter and data subjects can contact the data importer directly at support@reqio.app. Activities relevant to the transfer: providing the Reqio feedback platform as described in part B of this Annex. Signature and date: the data importer is deemed to have signed this Annex by publishing this DPA and providing the service under it.
I.B.1B. Description of transfer: categories of data subjects
- End users of the Customer's website or product who interact with the Reqio widget (submitting feature requests, votes, comments, and conversation messages).
- The Customer's authorized dashboard users (team members invited to the Customer's projects).
I.B.2B. Description of transfer: categories of personal data
- End-user identifiers: an anonymous browser identifier, plus email address and name where the end user or the Customer's identity token provides them.
- Feedback content: feature requests, comments, votes, and conversation messages.
- Page URL and technical context of submissions.
- Screenshots of the visible portion of the page (the viewport) attached to reports, where the end user chooses to attach one.
- IP address.
- Optional Customer-supplied CRM attributes carried in a signed identity token (such as plan name or revenue figures).
- For dashboard users: name, email address, and authentication data.
I.B.3B. Description of transfer: sensitive data
None intended. Reqio does not solicit special categories of personal data and instructs the Customer not to submit such data or permit its collection through the widget.
I.B.4B. Description of transfer: frequency
The transfer is continuous, for the duration of the agreement.
I.B.5B. Description of transfer: nature and purpose of the processing
Hosting, storage, and transmission of personal data as necessary to provide the Reqio feedback platform on the Customer's behalf: widget intake of end-user submissions, dashboard triage, two-way conversations, notifications, and MCP access, as described in the agreement.
I.B.6B. Description of transfer: duration of processing and retention
As set out in Section 4 of this DPA: the term of the agreement plus the retention periods stated in the "Data retention" section of the Reqio Privacy Policy.
I.B.7B. Description of transfer: onward transfers
Personal data is disclosed to the sub-processors listed in Annex III, for the purposes stated there, under written agreements imposing equivalent data-protection obligations. Disclosures made at the Customer's direction through the API, the MCP server, a project integration the Customer connects (such as Slack, Jira, or Linear), or the Customer's own agent workflow go to recipients the Customer engages under its own agreements (including AI model providers billed to the Customer's account); these are disclosures on the Customer's documented instructions under Section 3.4, not onward transfers to Reqio sub-processors.
I.CC. Competent supervisory authority
The competent supervisory authority is determined in accordance with Clause 13 of the Standard Contractual Clauses. Where the data exporter is established in an EU or EEA member state, it is the supervisory authority of that member state. Where the data exporter is not established in the EU or EEA but falls within the territorial scope of the GDPR under Article 3(2), it is the supervisory authority of the member state in which the EU representative appointed by the data exporter under Article 27 GDPR is established or, where the data exporter has not appointed one, the supervisory authority of the member state in which the relevant data subjects are located. Any such representative is the data exporter's own; the data importer has not appointed a representative in the EU or UK (see part A of this Annex). For transfers subject to UK law, the competent authority is the UK Information Commissioner's Office.
Annex II: Technical and organizational measures
IIThis Annex II describes the technical and organizational measures implemented by Reqio as the data importer and processor. Reqio is operated by a single individual. Reqio does not hold SOC 2 or ISO 27001 certification and does not operate a dedicated security team; the measures below reflect what is actually implemented.
II.1Encryption
- Data in transit is encrypted using TLS (HTTPS).
- The database is encrypted at rest by the hosting provider (Neon).
- Stored secrets (the per-project identity signing secret and third-party integration credentials) are envelope-encrypted at the application layer using AES-256-GCM, with master keys held as environment secrets.
II.2Authentication and credentials
- Dashboard login is passwordless: a one-time code is sent by email. Codes are bcrypt-hashed at rest, single use, expiring, and rate limited with attempt lockout.
- Identity, unsubscribe, and inbound-reply tokens are signed with HMAC-SHA256.
- MCP access uses opaque, database-backed OAuth tokens bound to a single project audience.
II.3Access control and tenant isolation
- Capability-based access control: every request is checked against per-project membership and a permission matrix.
- Access to production systems, stored secrets, and personal data is restricted to the sole operator. The Service is operated by a single individual with no additional personnel.
II.4Logging and auditability
- An activity log records privileged actions.
- Server logs are retained for up to 90 days, as stated in the Privacy Policy.
II.5Abuse prevention
- Rate limiting and abuse controls on authentication, widget, and API endpoints, backed by an ephemeral store (Upstash).
- Inbound webhooks are verified using the Standard Webhooks signature scheme before processing.
II.6Data subject controls
- Notification emails include RFC 8058 one-click unsubscribe.
- Personal data is returned or deleted on termination in accordance with Section 12.
II.7Organizational measures
- Database hosting (Neon) provides automatic continuous backups with point-in-time restore. Deleted records persist in that backup history until it expires on the host's rolling retention schedule, and in no case longer than 30 days after deletion; backups are used for no purpose other than restoring the service after data loss or corruption, and a deletion that predates a restore is re-applied promptly after the restore. Reqio does not run separate manual backups, and restores have not yet been formally tested.
- As the sole operator, Reqio monitors logs and alerts for security incidents. On becoming aware of a personal-data breach, Reqio assesses it promptly and notifies affected customers within 72 hours, consistent with Section 10.
- The Service is operated by a single individual, and no employees or contractors have access to personal data. If Reqio engages personnel or contractors in future, they will be bound by written confidentiality obligations before they receive access.
Annex III: List of sub-processors
IIIThe controller has authorized the use of the sub-processors listed below. Reqio keeps this list current and gives notice of changes as described in Section 6.2.
III.1Current sub-processors and their purposes:
- Neon: managed PostgreSQL database hosting. Stores all structured application data, including end-user widget submissions.
- Vercel: application hosting, serverless compute, and cookieless web analytics. Processes all request data passing through the application.
- PostHog (EU region): product analytics for Reqio's own marketing site and dashboard, subject to the visitor's consent. Processes the account holder's own usage of Reqio. Does not process end-user personal data collected via the widget: the widget carries no analytics instrumentation, and server-side analytics events identify accounts and projects only, never a requester.
- Resend: transactional email delivery and inbound email receiving. Processes recipient email addresses and email content where email notifications or email replies are enabled.
- Upstash: rate limiting and ephemeral storage. Processes short-lived request identifiers used for abuse prevention.
- Dodo Payments: payment processing, acting as Merchant of Record. Processes subscriber email addresses and billing data. Does not process end-user personal data collected via the widget.
- Cloudflare: email routing, where used for inbound email delivery. Processes email metadata and content in transit.
III.2Each sub-processor is bound by a written agreement imposing data-protection obligations equivalent to those in this DPA.