Legal

Privacy

rheAI is used to describe how a company really works, so the information you enter is sensitive. This page says plainly what we do with it. Questions: help@rheai.app.

What we collect

Account details: your name, work email and the organisation you belong to.

Readiness content you enter: services, processes, systems, vendors, risks, controls, test results and any evidence files you upload.

Usage records needed to run the product: sign-in events, audit-log entries for changes to readiness records, and views of anything you share with an auditor.

Why we process it

To provide the workspace you asked for: mapping your control boundary and producing readiness material you can hand to an independent auditor.

To keep the workspace secure and accountable, which is why record changes and auditor views are logged.

To support you when you contact help@rheai.app.

Who can see it

Members of your organisation, according to the role you gave them.

Anyone you deliberately create a read-only auditor link for. You can revoke those links at any time.

Our processors: the hosting, database, storage and AI providers needed to run the product. We do not sell your data and we do not use your readiness content to train public models.

Where it lives and how long

Data is stored in managed cloud infrastructure with access controls and encryption in transit and at rest. Evidence files sit in private buckets that are only reachable through your workspace.

We keep your content while your workspace is active. Ask us to delete it and we will remove it, except where we must keep a limited record for legal or accounting reasons.

Your choices

You can ask for a copy of your data, correct it, or have it deleted. Email help@rheai.app and we will confirm within a reasonable period.

You can remove a member, revoke an auditor link or delete individual records yourself from the workspace.