1 About these Terms
These Terms of Service ("Terms") are an agreement between Fold33, LLC ("Fold33", "we", "us"), which provides RedlinerHQ, and the business that accepts them ("Customer", "you"). Our contact for the Agreement is contact@redlinerhq.app.
The agreement is made up of any order form, quote or online sign-up we agree with you (an "Order"), these Terms, and our Data Processing Addendum ("DPA"), which forms part of these Terms. Together they are the "Agreement". The DPA controls matters about processing Personal Data; for other conflicts, the Order comes before these Terms. Accepting these Terms includes accepting the DPA.
The person who accepts these Terms confirms that they are authorised to bind the Customer. RedlinerHQ is for business use. It is not offered to consumers.
Inside RedlinerHQ, the Customer can ask its Authorised Users to accept confidentiality terms before they see any Document. Those terms are between the Customer and its Authorised Users. We record each acceptance for the Customer, but we are not a party to them.
2 Definitions
Capitalised words have these meanings.
- Active User
- An Authorised User who signs in to or uses the Service at least once in a calendar month (UTC), other than an Admin. An Admin who is also a Document Reviewer counts when they review a Document, including opening, playing, annotating, replying, resolving notes, exporting, downloading or printing. Administration alone does not count.
- Activity Log
- The record the Service keeps for the Customer of sign-ins, opens, saves, downloads, prints, exports, admin actions and similar events.
- Admin
- A person authorised to administer the Customer's portal through its configured Microsoft Entra ID admins group, its invited setup-admin access, or its approved Google admin list.
- Authorised User
- Anyone the Customer allows to use its portal, including its staff, freelancers and outside reviewers.
- Customer Data
- Data the Customer or its Authorised Users provide to, or make available through, the Service. It includes Documents, Markup, Settings and the Activity Log.
- Document Reviewer
- An Authorised User who reviews Documents in the Service. Every Authorised User other than an Admin is one; an Admin is one only while the Customer gives them that role in the portal.
- Customer Storage
- The SharePoint sites or folders, or Google shared drives, that the Customer connects to the Service. They stay in the Customer's own Microsoft 365 or Google Workspace.
- Documents
- Supported PDF files and audio recordings in the Customer Storage.
- Fees
- The amounts payable under section 7.
- Markup
- Highlights, comments, replies, drawings, timed audio notes and other annotations made in the Service, and the finished copies and summaries made from them.
- Personal Data
- Has the meaning given in the DPA.
- Protections
- The switches the Customer sets for its portal: downloads, printing, copying text, the name watermark, hiding the page when the window is in the background, confidentiality terms, one session per person and the bulk-open pause.
- Service
- RedlinerHQ, the review portal at app.redlinerhq.app, and the related services we provide under the Agreement.
- Settings
- The Customer's portal configuration: folder mappings, roles, expiry dates, Protections, sharing, retention, logo, webhook and similar settings.
3 The Service
RedlinerHQ lets Authorised Users view and mark up Documents in a web browser. The Service reads Documents from the Customer Storage the Customer connects as its source, and writes Markup and finished copies to a separate site, folder or drive the Customer chooses as its workspace. It never writes to the source.
We do not maintain our own library of Documents or Markup. They pass through our servers while the Service is used. PDF processing uses memory. Preparing an audio review copy uses a private temporary file, which is deleted after processing, including failed conversions. Review copies, notes and finished exports are saved to Customer Storage. Account, access, activity, billing and support records are described in our Privacy Policy and the DPA.
We may improve and change the Service. During a paid term we will not make a change that materially reduces its core functions or its security without telling the Customer first.
Parts of the Service depend on Microsoft 365 or Google Workspace. Those are the Customer's own providers. We are not responsible for their availability or for changes their providers make.
We do not commit to an uptime level or service credits unless an Order says so.
4 Accounts, Admins and Authorised Users
We set up a portal for the Customer with its own sign-in address. Authorised Users sign in with a Microsoft or Google account. We never see or store their passwords.
The Customer decides who its Admins are, who can reach which folders, with which role (viewer, annotator or exporter), and until when.
The Customer is responsible for its Admins and Authorised Users, for what they do in the Service, and for keeping their accounts secure, including requiring multi-factor authentication where its identity provider allows.
Authorised Users use the Service under the Customer's account. They are not parties to these Terms, but the Customer must make sure they follow sections 5 and 6.
First-line support for Authorised Users, such as sign-in problems, is given by the Customer's Admins. We support the Customer's Admins, and Authorised Users where the Customer allows it in Settings.
5 Customer responsibilities
The Customer controls its Customer Storage and the access it gives us. In particular, the Customer:
- chooses which sites, folders or drives to connect, and grants the Service read access to its source and write access to its workspace;
- decides who has access, and removes access when it should end;
- chooses the Protections that apply, and whether Authorised Users can see each other's Markup;
- follows our setup guidance and, where relying on portal restrictions, removes reviewers' direct storage access and sharing links that would let them bypass those restrictions; and
- can revoke our access at any time, which stops the Service working for the storage concerned.
The Customer must have every right, permission and notice needed for the Documents, and for its Authorised Users' Personal Data, to be processed through the Service. That includes duties under privacy law and duties of confidentiality it owes to others.
The Customer is responsible for the accuracy and legality of Customer Data, and for keeping its own copies and retention of Documents and Markup in its Customer Storage.
The Customer must tell us promptly if it learns of any unauthorised use of its portal.
6 Acceptable use
The Customer must not, and must make sure its Authorised Users do not:
- use the Service for anything unlawful, or to handle material they have no right to;
- try to reach folders, documents or data they have not been given, or another customer's portal;
- share sign-in accounts, or let anyone else use theirs;
- probe, scan or test the Service's security without our written permission, or work around its Protections, rate limits or access controls;
- interfere with the Service or put an unreasonable load on it;
- knowingly connect or upload files containing malware;
- resell, sublicense or provide the Service to anyone other than Authorised Users;
- reverse engineer the Service, except as the law allows; or
- use the Service to build a competing product.
We may investigate a suspected breach of this section and act under section 8.
Tell us before using the Service for a workload that requires a specific agreement, certification or handling arrangement, such as a HIPAA business associate agreement or a restricted international data transfer. Do not use it for that workload until we have agreed the necessary arrangements in writing. The Service does not claim a certification simply because a hosting provider has one.
7 Fees and billing
Free trial. A new Customer may use the Service free of charge for a trial period, on these terms unless the Order or we in writing say otherwise.
(a) Length. The trial lasts 21 days. It starts on the day the Customer's workspace first completes the required steps of the setup checklist in the portal, not on the day the Customer applies, and ends at the end of its last day (UTC).
(b) Reviewers. During the trial at most 10 Document Reviewers ("Reviewers") may use the Service. A Reviewer takes a seat the first time they sign in, or when an Admin adds them or gives them a folder directly; an Admin takes one when they are given the Document Reviewer role. Once every seat is taken, no further Reviewer can sign in or be added until an Admin releases a seat; a Reviewer whose seat is released loses access for the rest of the trial. An Admin who is not also a Document Reviewer never takes a seat, and taking the role away frees theirs. A larger trial is available on request for teams of 100 or more Reviewers, at our discretion.
(c) Fees. No Fees are charged for the trial period. If a payment method is saved when the trial ends, the Service continues on a monthly term (section 7.2), and the first month is charged only for the days from the end of the trial: the band's monthly Fee multiplied by the days remaining in that month and divided by the days in the month, on the Active Users from the end of the trial. Discounts in the Order apply. A yearly term (section 7.3) is paid in full in advance; paying one during the trial ends the trial on the day it is paid and starts the yearly term.
(d) At the end. If no payment method is saved when the trial ends, the workspace is locked: Reviewers cannot sign in, and Admins can only add a payment method. Nothing is deleted because a trial ended. Saving a payment method, once our payment processor has confirmed it (a bank account may take a few business days to verify), reopens the workspace at once and ends the trial. Fees start from the day it reopens.
(e) Changes. We may extend a trial, change its number of seats or end it early, and will tell the Customer's Admins by email when it starts, when 7 days, 3 days and 1 day are left, when it ends and the workspace is locked, and when it reopens.
(f) A workspace left locked. If a workspace stays locked for 30 days, we may end the Agreement and offboard the Customer under section 10. We decide this case by case, give the Admins notice before offboarding, and do not do it automatically.
(g) No warranty during the trial. During the trial the Service is provided as is, without the commitment in section 14.1, as for previews under section 14.3.
8 Suspension
We may suspend all or part of the Customer's access to the Service if:
- payment is overdue as described in section 7.9;
- the Customer or its Authorised Users breach section 6, or their use threatens the security or integrity of the Service or of other customers; or
- the law requires it.
Where it is reasonable to do so, we will tell the Customer before suspending. We will limit a suspension to what is needed and lift it promptly once the cause is resolved.
A suspension does not end the Agreement. While a suspension caused by the Customer lasts, Fees continue to apply.
Separately, the Customer's Admins can suspend any of their own Authorised Users at any time. Access stops on that person's next request.
9 Term and termination
The Agreement starts when the Customer accepts these Terms or signs an Order, and runs for the term agreed. Monthly terms continue each month until ended. A yearly purchase covers twelve months from its stated start month; renewal requires an agreed renewal Order or another yearly purchase. We do not automatically charge another year solely under these Terms.
Either party may end a monthly term by giving 30 days' written notice.
Either party may end the Agreement by written notice if the other materially breaches it and does not fix the breach within 30 days of being told, or if the other becomes insolvent or stops doing business.
When the Agreement ends, access to the Service ends, and the Customer pays any Fees owed up to the end date. Sections 7 (for amounts owed), 10, 11, 12, 15, 16 and 18 continue to apply.
10 What happens to data at the end
When the Agreement ends, we offboard the Customer within 30 days. Offboarding deletes what we hold for the Customer: its Activity Log, its session, suspension and trial seat records, its Settings (including folder mappings, direct access grants, email hashes and webhook settings) and its logo.
We keep a minimal record that the portal existed: its id, name, sign-in address, the identifiers of the Customer's tenant and connected storage, its status, its billing settings and its error and webhook-delivery counts. We also keep our own internal record that we offboarded it. We keep invoices and payment records for as long as tax and accounting law requires. None of these contains Documents, Markup or the Activity Log.
Documents, Markup, finished copies and the Customer's people list are in the Customer Storage. We do not delete or change them, so there is nothing to return. The Customer should remove the RedlinerHQ app and its grants, or our Google service account, from its storage.
Before the end date, Admins can export the Activity Log as a CSV file from the portal. Offboarding removes records from active systems. Residual copies may remain in protected backups for approximately 37 days under the standard 30-day backup retention and 7-day soft-delete settings. Those copies are restricted to recovery and security purposes and expire with the backup cycle. Records required by law may be retained longer. Backups of our service records are not backups of the Customer's Documents, and we do not offer routine recovery of offboarded records.
Emails and webhook events that were already delivered to the Customer stay with the Customer.
11 Customer Data and our licence
The Customer owns Customer Data. We claim no rights in it except those in this section.
The Customer grants us a non-exclusive, worldwide, royalty-free licence, for the term of the Agreement, to host, copy, transmit, display and otherwise process Customer Data only as needed to provide, secure and support the Service, and as the DPA allows.
We process Personal Data in Customer Data as the Customer's processor, under the DPA.
We may use counts and measurements about how the Service runs, such as numbers of users and opens, error rates and performance, to operate, bill for and improve the Service. We will not use them in a way that identifies the Customer to anyone else, or identifies any person or Document.
If the Customer or its Authorised Users send us suggestions or feedback, we may use them without obligation.
We and our licensors own the Service and all intellectual property in it. The Customer receives only the right to use the Service under the Agreement.
We do not sell Customer Data or use Documents, recordings, Markup or Activity Logs to train AI models. Feedback rights do not give us permission to use confidential Customer Data for unrelated purposes.
12 Confidentiality
Each party will keep the other's confidential information confidential, use it only for the Agreement, and share it only with its employees, contractors and advisers who need it and are bound by similar duties. Customer Data is the Customer's confidential information. Our pricing and non-public information about the Service are ours.
This does not apply to information that is or becomes public through no fault of the receiving party, that it already knew, that it developed independently, or that it received lawfully from someone else. If the law requires a party to disclose confidential information, it will tell the other party first where the law allows, and disclose only what is required.
These duties last for five years after the Agreement ends, and for as long as the information remains a trade secret or, for Customer Data, for as long as we hold it.
13 Security
We maintain the measures in Annex 2 of the DPA. Service storage access is scoped to the connected source and workspace, using federated identity in production. Admin setup tools may request broader delegated read access to browse locations the Admin can already access. We use HTTPS, access controls and a hash-chained Activity Log. Billing and webhook secrets are separate from storage sign-in credentials and are protected by access controls.
Protections discourage misuse and record supported events; they cannot guarantee that misuse is prevented or detected. PDF and audio data reach the Authorised User's browser, where a skilled person may extract them. Screenshots, cameras and external recording cannot be prevented. Permitted downloads, prints and exports leave the portal and are outside its access controls. The Activity Log records supported portal events, not everything a person does on their device.
The Customer remains responsible for the security of its Customer Storage, its identity provider and its devices.
We will tell the Customer about a Personal Data breach as the DPA sets out.
Except as the Agreement states, we do not promise that the Service is free of vulnerabilities or will prevent every unauthorised access.
14 Warranties and disclaimers
Each party confirms it has authority to enter into the Agreement. For paid service, we will use reasonable skill and care and provide the core functions substantially as described in our documentation. Tell us promptly about a material failure and give us a reasonable opportunity to fix it. If we cannot, the Customer may end the affected Service and receive a refund of prepaid Fees for its unused period. This is the remedy for this service commitment; it does not remove rights under the DPA or rights the law does not allow us to exclude.
Otherwise, the Service is provided "as is". To the extent the law allows, we disclaim all other warranties, whether express or implied, including merchantability, fitness for a particular purpose, non-infringement, and that the Service will be uninterrupted or error-free.
Features we describe as a preview or beta are provided as is, without the commitment in section 14.1.
15 Limitation of liability
To the extent the law allows, neither party is responsible to the other for indirect, incidental, special, consequential or punitive losses, including lost profits, revenue, goodwill or data where those losses are indirect or consequential, even if warned that they might occur.
Each party's total financial responsibility to the other for all claims arising out of or relating to the Agreement is limited to the greater of US $1,000 or the Fees paid or payable for the Service in the twelve months before the first event giving rise to the claims. Related events count together. This limit applies regardless of the type of claim, including claims under the DPA and section 16, subject to section 15.3.
Sections 15.1 and 15.2 do not limit the Customer's obligation to pay Fees, liability for fraud or deliberate misconduct, or any responsibility or remedy that the law does not allow the parties to exclude or limit. They do not restrict individuals' privacy rights or a regulator's powers.
16 Indemnities
We will defend the Customer against a third-party claim that the Service, as we provide it, infringes that third party's intellectual property rights, and pay the damages finally awarded or agreed in a settlement we approve. If such a claim is made or likely, we may change the Service so it no longer infringes, get the right for the Customer to keep using it, or end the Agreement and refund Fees paid in advance for the period after it ends. This does not cover claims arising from Customer Data, from combining the Service with anything we did not provide, or from use in breach of the Agreement.
The Customer will defend us against a third-party claim arising from Customer Data (including a claim that the Customer did not have the rights described in section 5.2), or from use of the Service by the Customer or its Authorised Users in breach of section 6, and pay the damages finally awarded or agreed in a settlement the Customer approves.
The party claiming protection must tell the other promptly, let it control the defence and settlement, and give reasonable help at its cost. No settlement may admit fault by, or impose an obligation on, the protected party without its consent.
17 Changes to these Terms
We may publish updated Terms. They apply to new acceptances and renewals that agree to that version, not retroactively to earlier events. We will give existing Customers at least 30 days' notice of a material change by email. A material change to an existing Agreement requires the Customer's acceptance or an agreed renewal Order; publishing it does not change a recorded acceptance. If we cannot agree, either party may end a monthly term under section 9.2 or decline a yearly renewal.
The "Last updated" date at the top of this page shows when these Terms last changed.
18 General
19 Contact
Fold33, LLC. Email contact@redlinerhq.app.