Security & Privacy

Your school's information should stay your school's information.

Riabo is designed so that each organisation has its own private workspace, with access controlled by role.

This page explains the practical steps built into Riabo to help protect your information and keep access appropriate.

Organisation separation

Each organisation has its own private workspace.

In Riabo, school information belongs to an organisation. Actions, staff records, reports and file links are tied to that organisation — not shared in a common public pool.

People can only open organisations they belong to. Database rules and application checks are designed so one school cannot browse another school's actions, staff, reports or files.

Access

People only see what their role allows.

Access in Riabo is based on organisation roles. The aim is simple: the people who lead the organisation get the tools to manage it, and everyone else sees the work they need to do.

  • Owner

    Leads the organisation

    Manages settings, billing and staff access — including who is invited and who can sign in.

  • Admin

    Runs the day-to-day work

    Creates and follows up on actions, works with templates and groups, and can use reports and insights.

  • Member

    Completes assigned work

    Sees and completes the actions assigned to them. They do not manage organisation settings or school-wide reports.

Files

Files are kept with the organisation they belong to.

When your school connects Google Drive, evidence files are uploaded into that organisation's Drive folder. Riabo stores the related records and links in your private workspace so the file stays connected to the right school and the right piece of work.

Access follows organisation membership and role permissions. Evidence files are not published as open public downloads. Supported files include common school formats such as PDF, Word, Excel, CSV and PowerPoint, up to 100 MB per upload.

Branding images used for your organisation are stored privately and shared only where the product needs to display them.

Accounts

Access changes when your team changes.

People join an organisation through an invitation into that school's workspace. Sign-in uses a secured account with email and password, including password reset when needed.

If someone's responsibilities change, an Owner can update their role. If they leave, an Owner can remove their access so they can no longer use that organisation — without deleting the school's record of work.

Responsibility

Riabo helps schools control access. Schools still decide what belongs in Riabo.

Good access control is a partnership. Riabo provides the workspace and the role controls. Your school decides who should be invited, what belongs in the system, and when access should be removed.

Riabo provides the workspace and access controls. Each organisation remains responsible for deciding what information it enters and who should be allowed to see it.

  • Invite only the staff who need access
  • Choose roles that match people's responsibilities
  • Remove access promptly when someone leaves
  • Avoid uploading information that does not need to be in Riabo
  • Follow your school's own data-protection policies
  • Use strong, unique passwords and keep them private

Privacy

Built with data protection in mind.

Riabo is designed to support organisations in meeting their data-protection responsibilities. That includes keeping each school's workspace separate, limiting access by role, and giving Owners control over who can sign in.

The formal Privacy Policy and Terms set out the legal detail. This page is the plain-English companion for school leaders who want to understand how the product is built.

Leaving Riabo

You should not feel trapped in the system.

Riabo already provides CSV exports for key reports, including organisation summary and outstanding work. Those exports are available to Owners and Admins.

A full self-service download of every organisation record is not available yet. If your school decides to leave, contact us about closing the account and handling the remaining organisation data.

If a subscription ends without renewal, the organisation becomes read-only until access is restored. Your information is not wiped automatically at that point.

Common questions

Quick answers for school leaders.

Can another school see our data?

No. Each organisation’s records are kept in its own workspace. Users only access organisations they belong to, and database policies are designed to block cross-organisation browsing of actions, staff, reports and files.

Can members see everything in the organisation?

No. Members focus on the work assigned to them. They do not get the same view of staff directories, reports or organisation settings that Owners and Admins have. They may still see colleague names where the product needs them for everyday work.

What happens when a member of staff leaves?

An Owner can deactivate their access so they can no longer sign in to that organisation. The organisation’s records are kept so your history of work is not wiped when someone leaves.

Are uploaded files public?

No. Evidence files are stored in your organisation’s connected Google Drive folder, not on a public web page. Riabo keeps the related records and links inside your private organisation workspace.

Can we export our information?

Owners and Admins can export selected reports as CSV, including organisation summary and outstanding work. A full one-click export of every organisation record is not available yet. If you are leaving Riabo, contact us about closing the account and handling remaining data.

Where can I find the legal privacy documents?

The Privacy Policy, Terms of Service, Cookie Policy and Data Processing Information are linked from the website footer. The Security & Privacy page explains the practical product controls in plain English.

Questions

Still have a security or privacy question?

If there is something you would like to understand before using Riabo, send me a message. I would rather answer the question clearly than hide it behind technical language.