1 Who we are
RedlinerHQ is provided by Fold33, LLC ("Fold33", "we", "us"). Our privacy contact is contact@redlinerhq.app.
We have two roles:
- Controller for data about visitors to redlinerhq.app, people who contact us or ask us to set up a workspace, and our Customers' business contacts and billing. This policy is our notice to you about that data.
- Processor for personal data in the portal. The business that uses RedlinerHQ (the "Customer") is the controller and decides why the data is processed. We process it only on the Customer's instructions, under our Data Processing Addendum. The Customer's own privacy notice applies too.
2 Visitors to redlinerhq.app
rhq-theme). It never leaves your browser, and you can clear it at any time.The Get started form. We receive your company name, setup admin's name and work email, sign-in and file-storage choices, email domains, expected reviewer count, monthly or yearly preference, any note, and your confirmation that you may accept the Terms (including the DPA) for the business and have read this policy. We record the Terms version and submission time. A workspace created from that application keeps that acceptance record.
What we do with it. We use it only to set up your workspace and to write to you about it. We keep it as an application record: it is our own data about a prospective Customer, not Customer content. When you send the form, we email a confirmation to the address you gave and a notice to our own mailbox. We do not add you to a mailing list or send you marketing email.
How long we keep it. The admin's email address is kept readable only until we have emailed the setup link, or told you we cannot take the application on. After that we keep only a one-way hash of it, so that the first sign-in can be matched to the invited address. We delete an application 30 days after we decide on it. An application we never decide on is deleted 90 days after it was sent. The two emails are kept as our mailbox keeps email (see section 6).
Your setup link. When we set up your workspace, we email the admin a one-time setup link. It works once and expires after 14 days. We keep only a hash of the link and of the admin's email address, not the link or the address themselves. On the admin's first Microsoft sign-in we record the organisation's Microsoft tenant id, which is an identifier, not content.
3 People who use the portal
This section applies if a Customer gave you access to its RedlinerHQ portal: as a freelancer, reviewer, member of staff or admin.
The activity log. For each thing you do, we record:
- the time, the Customer, and your account id;
- what happened: for example signing in, agreeing to the Customer's confidentiality terms, opening a document, saving markup, replying, downloading, printing, saving a finished copy, a blocked copy or print attempt, being paused for opening too many documents, or asking for more time on a folder;
- the document's id, where there is one; and
- a short detail, such as a count, the version of the terms you agreed to, or a hashed key for a folder.
The log refers to you and to documents by id. It does not contain your name, your email address, document names or folder names, and it does not record your IP address or browser. Each record is chained to the one before it with a hash, so changes can be detected.
Admins also appear in the log for what they do, such as changing settings, adding or removing people, suspending someone or reviewing a flagged event.
4 Our Customers' contacts and billing
We hold the names and business email addresses of the people we deal with at our Customers, and the Customer's billing details: billing contact, company name and address, tax ids, invoices and payments.
Payments by card or US bank account (ACH) are taken by Stripe, on Stripe's own pages. We never see or store card or bank account numbers: we keep only the Stripe customer id and, to show you which method is on file, its type, brand or bank name and last four digits.
Our staff run the service from an internal console. For each Customer it shows the connection, status, counts, health and bills. It does not show documents, markup, people or activity records. Every change made through it is logged.
5 Why we process data (legal bases)
If you are in the EEA, UK or Switzerland, the law asks us to name a legal basis for each use.
| What | Why | Legal basis |
|---|---|---|
| Portal data | To provide the portal to the Customer | We process it on the Customer's instructions. The Customer, as controller, chooses its basis: commonly its legitimate interests in protecting its documents and managing its work, or its contract with you. |
| Contact form and support messages | To answer you | Our legitimate interest in answering questions about our service, or steps you asked for before a contract. |
| Get started form and setup links | To set up your workspace and write to you about it | Steps you asked for before a contract; our legitimate interest in setting up the service for the firms that ask for it. |
| Customer contacts and billing | To run our contract with the Customer, bill and keep accounts | Performance of a contract; legal obligations such as tax records; our legitimate interest in running our business. |
| Security and abuse limits | To protect the service and the people who use it | Our legitimate interest, and the Customer's, in a secure service. |
6 How long we keep data
| Data | How long |
|---|---|
| Activity log | 24 months by default. The Customer can choose from 6 to 120 months, or place a legal hold that keeps everything until it is lifted. Deleted when the Customer leaves. |
| Sessions, suspensions, trial seats, direct access, email hashes and settings | Until they change, or until the Customer leaves. |
| Get started applications | Deleted 30 days after we decide on them, or 90 days after they were sent if we never decide. The admin's email address is readable only until we send the setup link or tell you we cannot take the application on; after that we keep only a one-way hash of it. |
| Setup links | A link works once and expires 14 days after we send it. We keep only a hash of it. |
| Contact form, Get started and support emails | For as long as needed to answer the request, provide support and keep necessary business or dispute records. We review mailbox records and remove them when those purposes no longer require them; legal preservation duties can require longer retention. |
| Customer contacts | During the relationship and afterwards only as needed for outstanding support, accounts, Agreement records, disputes or legal duties. |
| Invoices and payment records | For the period required by applicable tax and accounting law, and longer only for an unresolved payment dispute or legal preservation duty. |
| Hosting logs | Operational logs in Microsoft Azure are kept for up to 30 days. Cloudflare keeps its logs under its own policies. |
| Browser storage | Session storage clears when you close the tab. The theme choice stays until you clear it. |
When a Customer leaves, we remove its active portal data within 30 days. Residual copies can remain in protected backups for approximately 37 days under the standard 30-day retention and 7-day soft-delete settings. They are restricted to recovery and security purposes and expire with the backup cycle. Legally required records may be retained longer.
We keep a minimal business record that the portal existed: its id, business name, sign-in address, connection identifiers, status, billing settings, health counts and recorded Terms acceptance. Business and billing records may themselves contain personal data. They do not include the Customer's Documents, Markup, people list or Activity Log.
8 International transfers
Our standard API and service-record storage deployment is in Central US (Iowa, United States). Our email, hosting, identity and payment providers may also process data in other countries, as described on the Subprocessors page. The Customer's own storage location is controlled by its Microsoft 365 or Google Workspace arrangements.
Our initial onboarding is for US businesses. If a planned use involves an international transfer that requires additional safeguards, the Customer must tell us before enabling that processing. We must agree and put the required safeguards in place first, as described in DPA section 12. These pages alone do not execute Standard Contractual Clauses, appoint an EU or UK representative, or establish a Data Privacy Framework certification. We assess other international processing, such as a direct enquiry, under the law that applies to it.
9 Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its use, receive it in a portable form, and withdraw consent where we rely on it. You can also complain to your data protection authority.
10 Security
We use HTTPS, account and storage access controls, federated production storage access, and a hash-chained Activity Log. Portal activity records use account ids rather than names; business records and support emails have different needs. The measures and the Customer's responsibilities are in Annex 2 of our DPA. No system is perfectly secure. We notify the Customer of a breach as the DPA requires, and notify affected individuals or authorities where the law requires us to do so.
11 Children
RedlinerHQ is a service for businesses. It is not meant for children under 16, and we do not knowingly collect their personal data.
12 Changes to this policy
We will update this policy when what we do changes, and change the "Last updated" date at the top. If a change is significant, we will tell our Customers before it applies.
13 Contact
Fold33, LLC. Email contact@redlinerhq.app.