Skip to main content

Data, Security & Privacy

When you connect Requidex to an AI service, data returned by the connection is sent to that service for processing. Choose an account and configuration approved by your organisation before using live records. Read-only access still involves sharing data.

This page covers customer-connected AI tools and custom integrations. Read it alongside our Privacy Policy and Terms & Conditions, including your applicable data-processing agreement. It explains practical considerations; it does not replace those documents or establish that a particular use is compliant.

What data goes to the AI provider?

With a hosted AI client such as ChatGPT or Claude, the flow is:

  1. You ask a question in the AI client
  2. The client requests data through Requidex MCP using the connection's credentials
  3. Requidex checks access and returns the tool result to the client
  4. The AI service processes the result to answer your question

Tool results can include personal and commercially sensitive information, depending on the endpoint, fields, and access: for example worker names, user email addresses, assignments, timesheets, rates, or invoice values. Review the relevant endpoint reference. Connecting does not itself upload the entire database, but repeated requests can retrieve many records.

The provider may also process your prompts, conversation history, uploaded files, and generated reports. Asking the assistant to hide names in its final answer does not remove names already returned to it. Minimise the data before it reaches the service.

How is access limited?

Requidex OAuth connections grant read scopes to eligible company admin accounts within their companies. API-key connections use the key's configured scopes and company or agency restrictions. Hirers should review the company access they authorise; agencies should use supported agency-scoped endpoints for their accessible records. See Authorization and Scopes.

Do not assume every API-key tool is read-only: available operations and required scopes are documented individually. For analysis, use read scopes only. A prompt asking for one project narrows a request; it does not reduce the credential's underlying access.

Requidex applies API security controls and records request audit information, including query parameters and response summaries. Do not put credentials or unnecessary personal data into queries. Your AI provider and custom application have their own logging and storage arrangements.

Will OpenAI or Anthropic train on the data?

Check the exact product, account, and settings. Paying for a personal subscription does not make it a business workspace.

ServiceWhat to check
OpenAI business productsOpenAI states that business data is not used for training by default. Check the applicable workspace terms and any data-sharing opt-in in its enterprise privacy guidance
OpenAI APIAPI data is not used for training by default unless you opt in. Retention varies by feature and configuration; review API data controls
Anthropic commercial productsAnthropic states that commercial chats and coding sessions are not used for training by default, with exceptions for voluntary sharing such as feedback or programme participation. Review its commercial training policy
Personal accounts and coding assistantsVerify the terms and privacy settings for the account actually used. Do not apply API or enterprise guarantees to a personal ChatGPT or Claude account, or assume a coding tool's name determines its data terms

Not used for training does not mean not retained. Check conversation storage, safety monitoring, feedback, deletion, backups, processing locations, and any contractual exceptions. A zero-retention arrangement must cover the specific product and feature you use; it is not implied by connecting MCP.

Provider references reviewed on 9 September 2026. Policies and available controls can change; confirm them when approving or renewing an integration.

How does this relate to Requidex's own AI features?

Section 9 of our Privacy Policy describes AI-assisted worker document verification provided by Requidex. That is a different processing arrangement from connecting your organisation's own AI account to MCP or sending API results to a model through your application.

Do not treat statements about Requidex's contracted AI services, retention, or hosting as guarantees for your separately selected provider. If you need confirmation of which arrangement applies, contact support@requidex.com before sending live data.

What should our organisation check for GDPR?

Our Terms & Conditions, section 10, describe the Client as controller and Requidex as processor for Client Data containing personal data. A customer-selected AI provider's role depends on the arrangement and processing purposes; connecting it does not automatically make it a Requidex subprocessor.

Ask your privacy or security lead to review:

  • The purpose, lawful basis, and information given to affected workers and users
  • The controller and processor roles, applicable contracts, and any required data-processing agreement
  • The data needed, retention and deletion arrangements, and handling of individual rights
  • Whether the use requires a data protection impact assessment (DPIA); complete one before processing likely to result in high risk

These checks apply to both hirers and agencies. Access to a record does not by itself establish permission to share it for a new purpose. See the ICO's AI accountability guidance.

Confirm storage and processing locations, overseas access, and the safeguards required for any restricted international transfers. Requidex's hosting location does not determine where a connected provider processes its copy. See the ICO's international transfer guidance.

How can we share less data?

  • Prototype with fictional data, including screenshots and example reports
  • Filter to the necessary companies, projects, dates, and records
  • Use supported fields parameters to select only needed response fields
  • Prefer summary tools when totals answer the question; small groups and identifiers can still reveal personal information
  • Keep credentials in the client's authentication configuration or server-side secret storage
  • Review report recipients, shared conversations, and export permissions before sharing outputs

For example, a project-cost comparison may only need project-level totals. Fetching individual worker records adds exposure without necessarily improving that report.

Does an AI-built dashboard need to send live data to AI?

No. An assistant can build a dashboard using documentation and fictional data. The finished application can call Requidex from its own backend without a model processing live results. If you add AI-generated explanations, decide explicitly which fields reach the model and where its outputs are stored. The application still needs authentication, viewer authorisation, and secure storage.

What happens when we disconnect?

Remove the connection from the AI client and review the credentials that enabled it. Revoke a dedicated API key when it is no longer needed; contact Requidex support if you need help invalidating OAuth access. Do not assume removing a client configuration invalidates every credential or stops separate scheduled jobs.

Disconnecting does not delete conversations, downloaded reports, application snapshots, or copies already held by another service. Handle those through the relevant provider and your application's deletion process, subject to applicable retention obligations.