1. Our commitment to the PDPA
Redijo handles personal data in line with Singapore's Personal Data Protection Act 2012 (PDPA). This document summarises how we apply the Act and how you exercise your rights as an individual.
2. Where your data lives
Your data is hosted in a single converged cloud region, under internationally recognised protection standards, with encryption in transit and at rest. We do not rely on local servers — PDPA compliance comes from appropriate cross-border transfer safeguards and the technical controls described in this policy.
3. Controller and intermediary
For your account data, Redijo is the data controller. For the personal data inside the files you upload, you are the controller and Redijo acts as a data intermediary, processing that data only on your instructions and as needed to deliver the service.
To deliver the service, Redijo engages the following data intermediaries, always under contract:
- Cloudflare — edge hosting, immutable file storage and AI gateway;
- Neon — managed Postgres database;
- Paddle — card payment processing, as merchant of record (UK/US);
- PostHog — product analytics of usage metadata, never file contents, in the United States.
4. Consent and purpose limitation
Under the PDPA, we collect, use and disclose personal data on the following bases:
- Performance of a contract — to provide the service you signed up for;
- Legal or regulatory obligation — to meet tax and regulatory requirements;
- Legitimate interests — for security, fraud prevention and product improvement;
- Consent — where applicable, for example for marketing communications, which you can withdraw at any time.
5. Your rights as an individual
The PDPA gives you, among others, the right to:
- request access to the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- withdraw consent for the collection, use or disclosure of your data;
- request that data no longer needed be ceased to be retained;
- ask how your data has been used or disclosed in the past year.
6. Exercising your rights
Send your request to privacy@redijo.com. We respond as soon as we can and, as a rule, within 30 days. We ask you to confirm your identity before we act, to protect your data.
7. Data Protection Officer
Our Data Protection Officer is your point of contact for any data-protection matter. Reach them at privacy@redijo.com.
8. Data breaches
We apply technical and organisational measures to protect data. If a data breach is likely to result in significant harm or is of a significant scale, we notify the affected individuals and the Personal Data Protection Commission (PDPC) as required by the PDPA.
9. Complaints to the PDPC
If you believe your rights have not been met, you can raise a complaint with the Personal Data Protection Commission via the official PDPC channels.