Privacy

Privacy and data handling

Last updated 25 May 2026

Who we are

NeedsIQ is operated by the same company that runs the insurance academy training platform you may already know. Our contact email for any privacy query is [email protected].

What data we hold

When you create an adviser account we store your name, email and a securely hashed password. When you use NeedsIQ Adviser to build a case we store the fact-find answers, the AI-generated draft adviser notes, the captured client decisions and the rendered Demands and Needs draft letter against your account.

Fact-find content can include personal data of your client (name, age, dependants, income, mortgage, health notes). You, the regulated adviser, are the data controller for that information. NeedsIQ is your data processor.

How we use it

We process your data to provide the NeedsIQ service: generating draft report content and adviser-facing review notes, rendering draft reports, supporting your account. We do not sell your data. We do not train shared models on your data. We use the Anthropic API to generate the draft content; the request and response are not retained by Anthropic for training purposes under the API terms.

How long we keep it

Active accounts. Your cases, drafts and submission packs remain in your account for as long as you have an active subscription so you can retrieve them on demand for compliance review.

FCA retention. UK regulated firms must keep client files for at least five years from the end of the relationship (longer for pension and protection cases). On request we will store your case files in encrypted form for the full retention period your network requires.

Cancelled accounts. When you cancel, your live account is closed within 30 days and your client data is archived in encrypted cold storage for the regulatory retention window. After that window your data is permanently deleted.

Your rights

You can access, export or delete your account data at any time. To request a data export or deletion, email [email protected] from the address on file. We respond within 30 days, the statutory window under UK GDPR.

If your client makes a subject access or deletion request about their own data, contact us and we will help you fulfil it. The adviser remains the controller and is responsible for processing the request.

Security

Data is encrypted in transit (TLS 1.3 to needsiq.com, behind Cloudflare) and at rest. Production access is limited to a small ops team with audit logging on every privileged change. We use the Stripe-hosted Checkout and Customer Portal for all payment information; we never store card numbers ourselves.

Sub-processors

We use a small set of third parties to deliver the service:

  • Hetzner Cloud (Finland, EU) for hosting and database.
  • Cloudflare for TLS and edge caching.
  • Stripe Payments Europe for subscriptions and billing.
  • Anthropic for AI generation (request/response not used for training).
  • Resend for transactional email.

Changes to this policy

When we materially change this policy we will email account holders and post the updated copy here with the new date.