1. Our commitment
Redijo protects personal data with GDPR-grade controls and honors the privacy rights granted under US state laws, such as the California Consumer Privacy Act (CCPA) as amended. This document summarizes how we handle data and how you exercise your rights.
2. Where your data lives
Your data is hosted in a single converged cloud region, under internationally recognized protection standards, with encryption in transit and at rest. We do not rely on local servers — our protection comes from appropriate cross-border transfer safeguards and the technical controls described in this policy.
3. Controller and processor
For your account data, Redijo is the controller. For the personal data inside the files you upload, you are the controller and Redijo acts as a processor, handling that data only on your instructions and as needed to deliver the service.
To deliver the service, Redijo engages the following processors, always under contract:
- Cloudflare — edge hosting, immutable file storage and AI gateway;
- Neon — managed Postgres database;
- Paddle — card payment processing, as merchant of record (UK/US);
- PostHog — product analytics of usage metadata, never file contents, in the United States.
4. How we handle data
We collect, use and disclose personal data on the following bases:
- Performance of a contract — to provide the service you signed up for;
- Legal obligation — to meet tax and regulatory requirements;
- Legitimate interests — for security, fraud prevention and product improvement;
- Consent — where applicable, for example for marketing, which you can withdraw at any time.
We do not sell your personal data and we do not share it for cross-context behavioral advertising.
5. Your privacy rights
Depending on your state, you may have the right to:
- know and access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your personal data;
- opt out of the sale or sharing of your data (we do neither);
- not be discriminated against for exercising these rights.
6. Exercising your rights
Send your request to privacy@redijo.com. We respond as soon as we can and, as a rule, within 45 days. We ask you to confirm your identity before we act, to protect your data.
7. Privacy contact
Our privacy team is your point of contact for any data-protection matter. Reach them at privacy@redijo.com.
8. Data breaches
We apply technical and organizational measures to protect data. If a breach is likely to create a meaningful risk to individuals, we notify those affected and the relevant authorities within the timeframes required by applicable law.
9. Complaints
If you believe your rights have not been met, you can raise a complaint with your state attorney general or the relevant privacy authority. We would also like the chance to put it right — reach us first at the address above.