Requilink is developed and distributed by Altirratech EU, a Cyprus based entity that complies with the EU General Data Protection Regulation (GDPR). This policy has two parts, because our role under the GDPR depends on how you interact with Requilink:
- Part A applies when you use this website or our hosted demo. Here Altirratech is the data controller.
- Part B applies when you deploy the self-hosted Requilink product on your own infrastructure. Here your organisation is the controller and Altirratech is a data processor.
When you use this website (requilink.ai) or our hosted demo, Altirratech is the data controller for the personal data described below. For any question, or to exercise your rights, contact info@requilink.ai.
Cookies and tracking
The website sets no advertising or tracking cookies. The only information stored in your browser is your theme preference (light or dark), which stays on your device and is never sent to us.
Website technical logs
For security and stability, our servers automatically record basic technical information: IP address, browser type, and timestamps. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in preventing abuse and keeping the site available. These logs are anonymized or deleted within 30 days.
Demo requests
If you ask for access to the hosted demo, we collect your name, email, and company, and optionally your role and a short message. We use this to set up your demo and to respond to your request. The legal basis is taking steps at your request before any contract and our legitimate interest in answering enquiries (Art. 6(1)(b) and (f) GDPR). We keep this information while we handle and follow up on your request, and remove it within 180 days of the request being closed, or sooner if you ask us to.
Demo accounts and demo content
When a demo account is provisioned for you, we store your login and any requirements content you create during the trial. This is removed when the trial ends, typically within 7 days, with an automatic clean-up shortly after. The demo is for evaluation only: please do not enter real confidential, personal, or regulated data into it.
Who we share data with
We do not sell your personal data. We rely on a small number of processors only to run this website and the demo: our hosting provider (Contabo, Germany) and our email provider. Both operate within the European Union and process data only on our instructions.
Your rights
You can access, rectify, erase, restrict, or object to the processing of your personal data, and request data portability. To exercise any of these, email info@requilink.ai. You may also lodge a complaint with the Cyprus Office of the Commissioner for Personal Data Protection (www.dataprotection.gov.cy) or the authority in your own country.
The following applies to the Requilink product deployed on your own infrastructure, where your organisation is the data controller and Altirratech is a data processor.
1. Data Controller vs Data Processor
Requilink is a self-hosted application deployed on the customer's own infrastructure. This distinction is critical under GDPR:
- The Customer (the organisation deploying Requilink) is the Data Controller. They determine which personal data is stored, for what purpose, and for how long.
- Altirratech EU is the Data Processor. We provide the software and optional support, but we do not host, store, or access customer data unless explicitly engaged for remote troubleshooting with the customer's consent.
We enter into Data Processing Agreements (DPA) with each customer upon request to formalise this relationship.
2. What Data Requilink Processes
Because Requilink runs inside the customer's network, the types of data processed depend entirely on how the customer configures and uses the platform.
2.1 User Account Data
When a customer deploys Requilink, they create user accounts for their team. This typically includes:
- Name
- Email address
- Role / permissions within the platform
- Authentication credentials (hashed passwords or SSO tokens)
Legal basis: Contract performance (Art. 6(1)(b) GDPR), necessary to provide the service.
2.2 Requirements and Document Data
The core function of Requilink is storing and managing engineering requirements. This data may include technical specifications, traceability links, verification results, baselines, audit trails, and associated metadata.
The customer determines what content is stored. Requilink does not scan, analyse, or transmit this content for any purpose other than providing the requested functionality within the customer's own deployment.
Legal basis: Contract performance (Art. 6(1)(b) GDPR).
2.3 AI Feature Data
Requilink includes optional AI features (quality checks, INCOSE compliance, link suggestions, derivation, translation, chat). AI processing occurs in one of two ways:
| Configuration | Data Flow | GDPR Implication |
|---|---|---|
| On-prem model (vLLM, Ollama, llama.cpp) | Data never leaves the customer's network. | No third-party data transfer. Full data sovereignty. |
| Third-party provider (OpenAI, Anthropic, etc.) | Customer explicitly configures an API key. Selected data is sent to the provider only for the requested operation. | Customer is responsible for the lawful basis of this transfer. We recommend a DPA with the provider. |
AI outputs are always presented as drafts, and an engineer must review and accept them. No AI feature performs silent modifications.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR), as the customer deliberately configures this feature and controls the provider.
2.4 Technical Data / Logs
The application server generates logs for operational purposes (request timestamps, error traces, user actions for audit trail). These logs are stored within the customer's deployment and are subject to the customer's own retention policies.
Altirratech EU does not receive these logs unless the customer explicitly shares them for troubleshooting.
3. Data Sovereignty and Storage
- All data stays on the customer's infrastructure. Requilink is deployed via Docker Compose on the customer's own servers (on-premise, air-gapped, or private cloud).
- No SaaS, no third-party storage. There is no cloud backend, no telemetry, and no data lake.
- Database: Customer's own PostgreSQL instance (typically within the same Docker network).
- Backups: The customer is responsible for their own backup strategy. Requilink supports immutable baselines and full export for offline archiving.
4. Data Retention and Deletion
- Retention: Controlled entirely by the customer. Requilink stores data until the customer deletes it via the application interface, baseline archival, or database management.
- Deletion: When a customer terminates their use of Requilink, all data remains within their infrastructure. Altirratech EU holds no copy.
- User accounts: Customers can delete individual users or purge all data at any time.
5. Security Measures
Requilink is designed for safety-critical engineering environments. The following measures are built into the platform:
| Measure | Detail |
|---|---|
| Authentication | JWT-based session management. Optional SSO/LDAP/SAML (on the roadmap). |
| Access control | Global roles plus per-project roles and per-document permissions (read / write / admin). Document locking prevents concurrent edits. |
| Encryption at rest | Dependent on the customer's PostgreSQL configuration (TDE or filesystem-level encryption recommended). |
| Encryption in transit | HTTPS/TLS required for all API and WebSocket connections. |
| Audit trail | Every create, update, delete, baseline, and approval action is logged with timestamp and user identity. Immutable and exportable. |
| Network isolation | The application runs entirely within the customer's Docker network. No outbound connections are required unless AI features are configured with a third-party provider. |
6. Your Rights Under GDPR
As a data subject of a Requilink customer, you have the following rights:
| Right | How It Applies |
|---|---|
| Right of access (Art. 15) | Request from your organisation (the Data Controller) what data is stored about you in Requilink. |
| Right to rectification (Art. 16) | Correct inaccurate personal data via the user profile settings in Requilink. |
| Right to erasure (Art. 17) | Request deletion of your account and associated data from your organisation's Requilink administrator. |
| Right to data portability (Art. 20) | Export your data. Requilink supports export in Word, Excel, and CSV formats. |
| Right to object (Art. 21) | Object to processing of your data. Contact your organisation's Data Protection Officer. |
To exercise these rights, please contact the organisation that deployed Requilink (your Data Controller). If you need assistance identifying your Data Controller, contact us at the address below.
You also have the right to lodge a complaint with the Cyprus Data Protection Commissioner (www.dataprotection.gov.cy).
7. International Data Transfers
- When AI is configured with an on-prem model, no data crosses borders.
- When AI is configured with a third-party provider, the customer selects the provider and is responsible for ensuring adequate safeguards (for example, Standard Contractual Clauses or adequacy decisions) under Chapter V GDPR.
- Altirratech EU does not transfer personal data to third countries for its own purposes.
8. Data Processing Agreement (DPA)
We offer a standard DPA to all customers upon request. The DPA reflects the processor-to-controller relationship and covers:
- Processing instructions and scope
- Confidentiality obligations
- Sub-processing (none for on-prem; provider-dependent for AI)
- Security measures (as described in Section 5)
- Deletion and return of data
- Audit rights
To request a DPA, email info@requilink.ai with your organisation name and deployment details.
9. Changes to This Policy
We may update this Privacy Policy to reflect legal or product changes. Material changes will be communicated via the Requilink distribution channels. Continued use after the effective date constitutes acceptance of the updated policy.
10. Contact Information
For privacy inquiries, DPA requests, or GDPR-related questions:
| Entity | Altirratech EU |
|---|---|
| info@requilink.ai | |
| Website | https://requilink.ai |
| Parent company | https://altirratech.eu |
| Jurisdiction | Cyprus (EU) |
This document is provided for informational purposes and does not constitute legal advice. Organisations deploying Requilink should consult their own legal counsel regarding GDPR compliance.