Privacy Policy

CypherLayer Technologies Private Limited (Re-Doc)·Effective July 07, 2026

Welcome to Re-Doc.

Re-Doc is a document anonymization and redaction platform designed to help individuals and organizations identify, redact, replace, and anonymize sensitive information contained within documents while preserving the original document structure and layout wherever possible.

This Privacy Policy explains how Re-Doc collects, uses, stores, processes, shares, and protects information when you use our website, applications, APIs, and related services (collectively, the "Services").

We believe privacy policies should be understandable rather than filled with unnecessary legal jargon. Our goal is to clearly explain what information we collect, why we collect it, how it is processed, and the choices available to you.

By accessing or using Re-Doc, you acknowledge that you have read and understood this Privacy Policy.

DPDP Notice for Indian Users

Where the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 apply, this Privacy Policy, together with any just-in-time notices shown during account creation, document upload, payment, support interactions, or use of the Services, is intended to explain:

  • ·the personal data we collect;
  • ·the specific purposes for which it is processed;
  • ·how uploaded documents and generated outputs are handled;
  • ·how you may withdraw consent where processing is based on consent;
  • ·how you may exercise applicable privacy rights;
  • ·how you may raise a privacy-related grievance; and
  • ·how you may contact Re-Doc regarding personal data processing.

Re-Doc acts as a Data Fiduciary or equivalent role for personal data it controls directly, such as account information, authentication information, billing information, analytics information, support information, and website usage information.

Where Re-Doc processes personal data contained in customer-uploaded documents on behalf of a customer, Re-Doc generally acts as a Data Processor or equivalent role, and the customer is generally responsible for determining the purpose, lawful basis, authority, and instructions for such processing.

Re-Doc's privacy and data-handling practices are designed to support compliance with applicable data protection obligations, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, where applicable.

Nothing in this Privacy Policy should be understood as a certification under the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, GDPR, HIPAA, ISO 27001, SOC 2, or any other privacy, security, healthcare, or regulatory framework.

1. Who We Are

Re-Doc is operated by CypherLayer Technologies Private Limited, a company incorporated in India.

Although our company is based in India, customer documents are primarily stored and processed using infrastructure located within the European Union. Certain specialized processing services may operate in other jurisdictions as described in this Privacy Policy and our Subprocessor List.

If you have any questions regarding this Privacy Policy, you may contact us using the information provided at the end of this document.

2. Scope of this Privacy Policy

This Privacy Policy applies to:

  • ·the Re-Doc website;
  • ·the Re-Doc web application;
  • ·APIs provided by Re-Doc;
  • ·customer support interactions;
  • ·trial and paid subscriptions;
  • ·enterprise deployments unless superseded by a separate written agreement.

This Privacy Policy applies to both personal information relating to users of our Services and documents that users voluntarily upload for processing.

It does not apply to third-party websites, services, or applications that are not operated by Re-Doc, even if those services are linked from our website.

3. Definitions

For the purposes of this Privacy Policy:

"Account"means the registered profile used to access the Services.
"Customer"means the individual or organization using Re-Doc.
"Document"means any file uploaded to Re-Doc for processing, including but not limited to PDFs, Microsoft Word documents, scanned documents, images, and other supported file formats.
"Uploaded Content"means any document, text, metadata, or related information that a Customer submits to Re-Doc for processing.
"Generated Output"means any document, redacted file, anonymized document, pseudonymized document, extracted text, or other output produced by the Services.
"Personal Information"means information relating to an identified or identifiable individual, as defined under applicable privacy laws.
"Processing"means any operation performed on information, including collection, storage, organization, extraction, analysis, redaction, anonymization, replacement, transmission, deletion, or destruction.
"Subprocessor"means a third-party service provider engaged by Re-Doc to perform specific services on our behalf, such as cloud hosting, authentication, document conversion, payment processing, or AI-assisted document processing.

4. Our Privacy Principles

We designed Re-Doc around several core privacy principles.

We collect only what is necessary.

We aim to minimize the amount of information required to operate the Services.

Your documents remain yours.

Uploading a document to Re-Doc does not transfer ownership of that document to us. We process uploaded content solely to provide the Services requested by you.

We do not sell your data.

Re-Doc does not sell customer information or uploaded documents to third parties.

We do not use uploaded documents to train our own AI models.

Uploaded documents and generated outputs are processed solely for the purpose of providing the Services requested by you. We do not use customer documents to develop or train proprietary machine learning or artificial intelligence models.

We retain documents only for a limited period.

Uploaded documents and generated outputs are retained only for the period necessary to provide the Services or as otherwise described in this Privacy Policy. Customers may request earlier deletion where supported.

We strive for transparency.

Where we engage third-party service providers to operate parts of the platform, we identify their roles and describe how they are involved in processing customer information.

5. Relationship Between You and Re-Doc

When you upload a document to Re-Doc, you instruct us to process that document according to the options and workflows you select.

Depending on how the Services are used:

  • ·you may act as the controller (or equivalent under applicable law) of the information contained within uploaded documents; and
  • ·Re-Doc generally acts as a processor or service provider that processes documents on your behalf.

Nothing in this Privacy Policy transfers ownership of uploaded documents or generated outputs to Re-Doc.

Customers remain responsible for ensuring they have the necessary rights, permissions, and legal basis to upload and process documents using the Services.

6. Information We Collect

To provide the Services, we collect only the information reasonably necessary to operate, secure, maintain, and improve the platform.

The information we collect falls into the following categories.

A. Account Information

When you create or access a Re-Doc account, we may collect information such as:

  • ·Your name
  • ·Email address
  • ·Authentication identifier
  • ·Profile information associated with your sign-in method
  • ·Organization or company name (where applicable)
  • ·Subscription or billing plan
  • ·Account preferences

If you choose to sign in using a third-party authentication provider such as Google, we receive only the information necessary to authenticate your account and create or maintain your Re-Doc profile. We do not receive or access your Google password.

B. Uploaded Documents and Customer Content

When you use Re-Doc, you may upload documents for processing. These documents may contain personal information, confidential business information, regulated data, or other sensitive content depending on the nature of the document. Examples include:

  • ·Legal documents
  • ·Medical records
  • ·Financial documents
  • ·Insurance claims
  • ·Government forms
  • ·Contracts
  • ·HR records
  • ·Identity documents
  • ·Invoices
  • ·Reports
  • ·Customer correspondence

We process uploaded documents solely to perform the services requested by you, including document analysis, redaction, anonymization, pseudonymization, text replacement, entity detection, document conversion, and related processing functions.

Unless otherwise agreed, we do not review uploaded documents manually except where necessary to investigate a customer-reported technical issue, provide requested support, maintain platform security, or comply with applicable law.

C. Generated Outputs

During processing, Re-Doc creates one or more outputs based on your requested workflow. These may include:

  • ·Redacted documents
  • ·Anonymized documents
  • ·Pseudonymized documents
  • ·Converted document formats
  • ·Extracted text
  • ·Replacement mappings
  • ·Processing reports
  • ·Downloadable output files

Generated outputs are treated with the same level of protection as uploaded documents and are retained according to the applicable retention period unless deleted earlier.

D. Document Metadata

To operate the platform efficiently, we may store limited metadata associated with uploaded documents. Depending on the workflow, this may include:

  • ·Original filename
  • ·File size
  • ·File type
  • ·Upload timestamp
  • ·Processing status
  • ·Processing duration
  • ·Job identifiers
  • ·Download status
  • ·Retention schedule

We do not intentionally use document metadata to profile users or for advertising purposes.

E. Technical and Usage Information

Like most online services, we automatically collect certain technical information when you access the Services. This may include:

  • ·IP address
  • ·Browser type
  • ·Device information
  • ·Operating system
  • ·Language preferences
  • ·Time zone
  • ·Session identifiers
  • ·Pages visited
  • ·Feature usage
  • ·Error diagnostics
  • ·Performance metrics
  • ·Security events

This information helps us maintain platform reliability, detect misuse, improve performance, and troubleshoot issues.

F. Authentication Information

Re-Doc currently supports authentication using Google Sign-In. When you authenticate using Google, we receive only the information necessary to identify your account and enable secure access to the Services, such as your name, email address, and authentication identifier, subject to the permissions you authorize.

We do not access your Google Drive, Gmail, contacts, calendar, or other Google services unless explicitly stated and separately authorized.

G. Payment Information

If you purchase a subscription or other paid services, payment processing is handled by trusted third-party payment providers. Re-Doc does not store complete credit card or debit card numbers on its own systems. We may receive limited billing information necessary to:

  • ·verify subscription status;
  • ·manage invoices;
  • ·process refunds where applicable;
  • ·comply with financial and tax obligations.

H. Analytics Information

We use analytics tools to understand how users interact with the Services and to improve functionality and performance. Analytics information may include:

  • ·Pages visited
  • ·Navigation flow
  • ·Session duration
  • ·Device type
  • ·Browser information
  • ·Approximate geographic region
  • ·Interaction events
  • ·Feature usage

We use analytics only to improve the Services and do not use analytics data to build advertising profiles or sell customer information.

I. Customer Support Information

When you contact Re-Doc for support, we may collect information such as:

  • ·Your email address
  • ·Support requests
  • ·Correspondence
  • ·Diagnostic information voluntarily provided by you
  • ·Attachments submitted as part of a support request

Where possible, we encourage customers to avoid sending unnecessary sensitive information during support interactions.

J. Information We Do Not Intentionally Collect

Except where it is contained within documents that you choose to upload, Re-Doc does not intentionally collect:

  • ·Biometric information
  • ·Government-issued identification numbers
  • ·Health information
  • ·Financial account information
  • ·Precise location information
  • ·Children's personal information

If such information is contained within an uploaded document, it is processed solely to provide the requested document-processing services.

7. How We Use Information

We use the information described above only for legitimate business and operational purposes, including to:

  • ·provide the Services requested by you;
  • ·authenticate users and manage accounts;
  • ·process uploaded documents;
  • ·generate requested outputs;
  • ·perform OCR, document conversion, and AI-assisted document analysis where required;
  • ·maintain platform security and detect misuse;
  • ·investigate technical issues and respond to support requests;
  • ·process subscription payments;
  • ·improve platform performance, reliability, and usability;
  • ·comply with applicable legal obligations; and
  • ·enforce our Terms of Service.
We do not use uploaded documents or generated outputs to train Re-Doc's own artificial intelligence or machine learning models.

8. How Re-Doc Processes Uploaded Documents

Re-Doc is designed to process documents solely for the purpose of providing the services requested by our customers, such as document anonymization, redaction, pseudonymization, text replacement, document conversion, and related document processing workflows.

The processing activities performed depend on the type of document uploaded and the workflow selected by the customer. A typical document processing workflow may include one or more of the following stages.

Secure Upload

Documents are transmitted to Re-Doc over encrypted network connections using industry-standard Transport Layer Security (TLS).

Once received, documents are stored within Re-Doc's processing infrastructure for the duration necessary to complete the requested processing workflow and according to the applicable retention period.

Document Analysis

Depending on the document format, Re-Doc may perform one or more document analysis operations, including:

  • ·extracting machine-readable text;
  • ·identifying document structure;
  • ·recognizing tables and layouts;
  • ·detecting images or embedded objects;
  • ·identifying handwritten or printed content where supported; and
  • ·preparing the document for downstream processing.

The specific analysis performed varies depending on the document type and requested functionality.

Optical Character Recognition (OCR)

Where uploaded documents contain scanned pages or image-based text, Re-Doc may perform Optical Character Recognition (OCR) to convert visual text into machine-readable text.

OCR processing may be performed using trusted third-party service providers acting on Re-Doc's behalf.

Document Conversion

Some workflows require documents to be converted between supported formats in order to preserve formatting, layout, or compatibility with downstream processing. For example, documents may be temporarily converted between PDF and Microsoft Word formats where necessary to perform requested processing operations.

Document conversion is performed only as required to provide the requested Services.

AI-Assisted Document Processing

To identify sensitive information and generate requested outputs, Re-Doc may use artificial intelligence models for tasks such as:

  • ·entity detection;
  • ·contextual analysis;
  • ·anonymization;
  • ·pseudonymization;
  • ·synthetic text replacement;
  • ·document classification;
  • ·redaction recommendations; and
  • ·related language processing tasks.

Where supported by the underlying AI service provider, Re-Doc routes requests through Zero Data Retention (ZDR) endpoints or equivalent processing options designed to minimize provider-side retention.

AI providers engaged by Re-Doc process customer information solely for the purpose of providing the requested Services and not to provide services directly to the customer.

Output Generation

Following processing, Re-Doc generates one or more output files based on the workflow selected by the customer. Depending on the requested operation, outputs may include:

  • ·redacted documents;
  • ·anonymized documents;
  • ·pseudonymized documents;
  • ·converted document formats;
  • ·extracted text;
  • ·processing reports; or
  • ·other workflow-specific outputs.

Generated outputs are made available to the customer through the Services and are protected using the same security measures applied to uploaded documents.

Temporary Processing by Service Providers

To provide certain features, Re-Doc may engage carefully selected service providers that perform specialized processing on our behalf. These services may include:

  • ·document hosting;
  • ·document conversion;
  • ·OCR;
  • ·authentication;
  • ·payment processing;
  • ·analytics;
  • ·AI-assisted document analysis; and
  • ·infrastructure operations.

These providers process customer information only for the specific services they are engaged to perform and are selected based on technical capability, security practices, and operational reliability.

Human Access

Re-Doc is designed to process documents automatically. We do not routinely review customer documents manually. Authorized personnel may access uploaded documents only where reasonably necessary to:

  • ·investigate customer-reported technical issues;
  • ·provide requested customer support;
  • ·investigate suspected abuse or security incidents;
  • ·maintain the integrity or security of the Services; or
  • ·comply with applicable legal obligations.

Access to customer information is restricted to personnel with an operational need to know and is subject to appropriate internal access controls.

Data Location

Re-Doc is operated by a company incorporated in India. Customer documents are primarily stored and processed using infrastructure located within the European Union.

Certain processing activities may be performed by carefully selected third-party service providers located in other jurisdictions where required to provide OCR, document conversion, authentication, payment processing, or AI-assisted document processing. Where such providers are engaged, Re-Doc takes reasonable steps to ensure that appropriate contractual, technical, or organizational safeguards are in place consistent with applicable law.

Customer Control

Customers remain in control of the documents they upload. Customers may:

  • ·download generated outputs;
  • ·delete documents before the scheduled retention period where supported;
  • ·request earlier deletion through customer support; or
  • ·configure shorter retention periods where available under their subscription or enterprise agreement.

9. Third-Party Service Providers and Subprocessors

Re-Doc uses trusted third-party service providers and subprocessors to operate, secure, process, and improve the Services.

These providers help us with functions such as:

  • ·cloud hosting and infrastructure;
  • ·authentication;
  • ·payment processing;
  • ·analytics;
  • ·document conversion;
  • ·optical character recognition;
  • ·AI-assisted document processing;
  • ·application monitoring;
  • ·customer support; and
  • ·security and reliability operations.

Some subprocessors may process uploaded documents, extracted text, generated outputs, document metadata, or related information where necessary to provide the specific workflow selected by the customer. For example, a document may be processed by a service provider where OCR, format conversion, AI-assisted detection, redaction, anonymization, pseudonymization, or output generation is required.

We require our subprocessors to process information only for the purposes for which they are engaged and to apply appropriate technical and organizational safeguards.

Where supported by the relevant AI provider and configuration, Re-Doc routes AI-assisted processing through Zero Data Retention or similar provider-side settings designed to limit retention of prompts, document content, and model outputs.

Re-Doc does not permit third-party AI providers to use uploaded documents or generated outputs to train Re-Doc-specific models.

A current list of Re-Doc's main subprocessors, including their purpose, role, and processing category, is available in our Subprocessor List.

Re-Doc may update its subprocessors from time to time as the Services evolve. Where required by applicable law, contract, or enterprise agreement, Re-Doc will provide notice of material changes to subprocessors.

10. International Data Processing

Re-Doc is operated by a company incorporated in India. However, Re-Doc is designed so that uploaded documents are not intentionally transferred to India for document storage or document processing.

Customer documents are primarily stored and processed on infrastructure located within the European Union.

Certain specialized processing activities may be performed by trusted third-party service providers located in other jurisdictions where necessary to provide the Services. These activities may include optical character recognition, document extraction, document conversion, AI-assisted document processing, authentication, analytics, payment processing, security, or infrastructure operations.

For example, depending on the workflow selected by the customer, document content, extracted text, document metadata, or generated outputs may be processed by subprocessors located outside the European Union.

Where Re-Doc engages service providers in other jurisdictions, we take reasonable steps designed to ensure that appropriate contractual, technical, and organizational safeguards are in place.

These safeguards may include:

  • ·using service providers with documented security and privacy commitments;
  • ·limiting processing to the specific purpose required for the selected workflow;
  • ·using provider-side retention controls where available;
  • ·using Zero Data Retention or similar settings for AI-assisted processing where supported;
  • ·restricting access to customer content on a need-to-know basis;
  • ·applying retention limits to uploaded documents and generated outputs; and
  • ·entering into data protection terms, data processing agreements, or other contractual safeguards where required.

If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with cross-border transfer requirements, your information may be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction.

Where required by applicable law, Re-Doc relies on appropriate transfer mechanisms, contractual protections, or other safeguards for such transfers.

Enterprise customers may receive additional cross-border transfer terms through a separate Data Processing Addendum or written agreement.

11. Data Retention and Deletion

Re-Doc retains information only for as long as reasonably necessary to provide the Services, maintain platform security, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations. Different categories of information may be retained for different periods depending on their purpose.

Uploaded Documents and Generated Outputs

Unless a shorter retention period is agreed or a customer requests earlier deletion, uploaded documents and generated outputs are retained for up to 30 days.

After the applicable retention period, uploaded documents and generated outputs are scheduled for deletion from Re-Doc's active processing systems.

Customers may request earlier deletion, including immediate deletion where technically supported, by contacting Re-Doc support or using available deletion features within the Services.

Document Metadata

Re-Doc may retain limited document metadata for operational, audit, billing, security, and support purposes. This may include information such as:

  • ·filename;
  • ·file type;
  • ·file size;
  • ·upload timestamp;
  • ·processing status;
  • ·job identifier;
  • ·retention schedule;
  • ·account identifier; and
  • ·error or processing status information.

Document metadata does not normally include the full contents of the uploaded document.

Document metadata may be retained for a longer period than the document itself where necessary for account management, billing, audit logs, dispute resolution, security investigations, or compliance with legal obligations.

Account Information

Account information is retained for as long as your account remains active or as needed to provide the Services.

If you delete your account or request account deletion, we will delete or anonymize account information unless retention is required for legal, tax, accounting, security, dispute resolution, or legitimate business purposes.

Payment and Billing Records

Payment and billing records may be retained for the period required by applicable tax, accounting, financial, and regulatory obligations.

Payment information is processed primarily by our payment service providers. Re-Doc does not store complete credit card or debit card numbers on its own systems.

Logs and Technical Records

Re-Doc may retain application logs, API logs, security logs, and diagnostic records to maintain platform reliability, investigate errors, prevent misuse, and protect the Services. These logs may include information such as:

  • ·account identifier;
  • ·timestamp;
  • ·IP address;
  • ·browser or device information;
  • ·API request metadata;
  • ·processing status;
  • ·error messages; and
  • ·operational events.

Where logs contain customer-specific information, Re-Doc may delete or anonymize such logs upon request where technically feasible and legally permitted.

Backups

Uploaded documents and generated outputs are not intentionally included in Re-Doc's code or application backups.

Re-Doc may maintain backups of application code, configuration, and operational systems for business continuity and disaster recovery purposes.

If any customer information is present in backups or replicated systems, it will be handled according to applicable retention, security, and deletion procedures.

Deletion Requests

Customers may request deletion of uploaded documents, generated outputs, account information, or related information by contacting Re-Doc.

We will respond to deletion requests within a reasonable period, subject to technical feasibility and any legal, security, tax, accounting, contractual, or compliance obligations that require continued retention.

Where immediate deletion is requested for uploaded documents or generated outputs, Re-Doc will take reasonable steps to delete the applicable files from active systems as soon as technically practicable.

Enterprise Retention Terms

Enterprise customers may agree to shorter retention periods, immediate deletion workflows, custom deletion schedules, or other retention terms through a separate written agreement, Data Processing Addendum, or enterprise subscription arrangement.

Where an enterprise agreement conflicts with this Privacy Policy, the enterprise agreement will apply to the extent of that conflict.

12. Security Measures

Re-Doc takes reasonable technical and organizational measures designed to protect customer information, uploaded documents, generated outputs, and account information against unauthorized access, loss, misuse, alteration, or disclosure.

Because Re-Doc processes documents that may contain sensitive, confidential, or regulated information, we design our platform with security, limited access, retention control, and responsible processing in mind.

Transmission Security

Documents and account information are transmitted to Re-Doc over encrypted network connections using Transport Layer Security (TLS) or similar industry-standard encryption protocols.

Customers are responsible for accessing the Services through secure networks, protecting their devices, and ensuring that files downloaded from Re-Doc are stored and shared securely.

Infrastructure Security

Re-Doc hosts its primary application and document-processing infrastructure on cloud servers located within the European Union.

Uploaded documents and generated outputs are stored within access-controlled infrastructure for the limited retention period described in this Privacy Policy.

Re-Doc applies server-side access controls, infrastructure configuration controls, and operational safeguards designed to restrict unauthorized access to production systems.

Uploaded documents and generated outputs are not intentionally included in Re-Doc's code or application backups.

Access Controls

Access to production systems and customer information is restricted to authorized personnel who require access for operational, support, security, or legal purposes. Re-Doc does not routinely review uploaded documents manually. Authorized personnel may access uploaded documents or generated outputs only where reasonably necessary to:

  • ·provide customer-requested support;
  • ·investigate technical issues;
  • ·troubleshoot failed or incomplete processing jobs;
  • ·detect or prevent misuse of the Services;
  • ·respond to security incidents;
  • ·comply with applicable legal obligations; or
  • ·protect the rights, safety, or integrity of Re-Doc, customers, or third parties.

Automated Processing by Default

Re-Doc is designed to process uploaded documents through automated workflows.

Where possible, document analysis, OCR, conversion, AI-assisted detection, redaction, anonymization, pseudonymization, and output generation are performed automatically without routine human review.

This helps reduce unnecessary human exposure to customer documents.

Data Minimization

Re-Doc aims to collect and retain only the information reasonably necessary to provide and operate the Services.

Uploaded documents and generated outputs are retained for a limited period and are scheduled for deletion according to the applicable retention period.

Document metadata, account information, billing information, logs, and technical records may be retained for longer where necessary for security, audit, billing, support, legal, or operational purposes.

Backup Practices

Uploaded documents and generated outputs are not intentionally included in Re-Doc's code or application backups.

Re-Doc may maintain backups of application code, configuration, and operational systems for continuity, recovery, and maintenance purposes.

Where any customer information is present in backups or replicated systems, it is handled according to applicable security, retention, and deletion procedures.

Subprocessor Security

Re-Doc uses third-party service providers and subprocessors for functions such as hosting, authentication, OCR, document conversion, AI-assisted processing, payments, analytics, and infrastructure operations.

We select providers based on their technical capabilities, operational reliability, and security commitments.

Where subprocessors process uploaded documents, extracted text, generated outputs, or related information, they are expected to process such information only for the purpose of providing the relevant service to Re-Doc.

AI Processing Safeguards

Where supported by the relevant provider and configuration, Re-Doc routes AI-assisted processing through Zero Data Retention or similar provider-side settings designed to limit retention of prompts, document content, and model outputs.

Re-Doc does not use uploaded documents or generated outputs to train its own artificial intelligence or machine learning models.

Re-Doc also does not permit third-party AI providers to use uploaded documents or generated outputs to train Re-Doc-specific models.

Logs and Monitoring

Re-Doc may maintain application logs, API logs, diagnostic logs, and security-related records to operate the Services, investigate technical issues, detect misuse, and protect the platform.

These logs may include operational metadata such as timestamps, account identifiers, IP addresses, API request metadata, processing status, error messages, and security events.

Where logs contain customer-specific information, Re-Doc may delete or anonymize such logs upon request where technically feasible and legally permitted.

Incident Response

If Re-Doc becomes aware of a security incident affecting customer information, uploaded documents, generated outputs, or other personal information processed through the Services, we will take reasonable steps to investigate, contain, and remediate the incident.

Where required by applicable law, contract, or enterprise agreement, Re-Doc will notify affected customers, users, regulators, competent authorities, or other relevant parties of a reportable personal data breach.

Where the Digital Personal Data Protection Act, 2023 or the Digital Personal Data Protection Rules, 2025 apply, Re-Doc will handle reportable personal data breach notifications in accordance with applicable DPDP requirements, including notifying affected Data Principals and/or the Data Protection Board of India where Re-Doc is required to do so.

Where Re-Doc processes customer-uploaded documents as a processor on behalf of a customer, Re-Doc may notify the customer of the incident and support the customer in meeting its own breach notification obligations, unless applicable law requires Re-Doc to notify directly.

Customer Responsibilities

Customers are responsible for maintaining the confidentiality of their accounts and for ensuring that they have appropriate authorization to upload and process documents through Re-Doc. Customers should:

  • ·use secure devices and networks;
  • ·protect access to their Google account or other authentication method;
  • ·restrict access to downloaded outputs;
  • ·review generated outputs before sharing or relying on them;
  • ·delete documents when they are no longer needed; and
  • ·promptly notify Re-Doc if they suspect unauthorized access or misuse of their account.

Security Limitations

No online service, hosting environment, transmission method, or processing system can be guaranteed to be completely secure.

While Re-Doc takes reasonable measures designed to protect customer information, we cannot guarantee that unauthorized access, cyber incidents, service interruptions, data loss, or other security events will never occur.

13. Cookies and Analytics

Re-Doc uses cookies and similar technologies to operate the website and Services, maintain secure sessions, remember user preferences, understand usage patterns, and improve platform reliability.

Cookies are small text files placed on your device when you visit a website or use an online service.

Essential Cookies

We use essential cookies and similar technologies that are necessary for the Services to function properly. These may be used to:

  • ·keep users signed in;
  • ·maintain secure sessions;
  • ·prevent unauthorized access;
  • ·remember basic account or interface preferences;
  • ·support authentication;
  • ·detect errors or misuse; and
  • ·maintain platform security.

Essential cookies are required for core functionality and cannot usually be disabled without affecting the operation of the Services.

Analytics Cookies

Re-Doc uses analytics tools to understand how users interact with our website and Services. These tools may collect information such as:

  • ·pages visited;
  • ·session duration;
  • ·browser type;
  • ·device type;
  • ·approximate geographic region;
  • ·referring pages;
  • ·feature usage;
  • ·clicks, scrolling, and interaction events;
  • ·performance information; and
  • ·error or usability signals.

We currently use analytics providers such as Google Analytics and Microsoft Clarity. Analytics information helps us improve product usability, diagnose performance issues, understand which features are useful, and maintain a better user experience.

Microsoft Clarity

We may use Microsoft Clarity to understand how users interact with our website or application interface. Microsoft Clarity may collect usage information such as clicks, scrolling, navigation patterns, device information, browser information, and session interaction data.

We use this information to identify usability issues, improve user experience, and troubleshoot product flows.

Analytics tools are not used to intentionally process uploaded document contents.

Google Analytics

We may use Google Analytics to understand website traffic, user journeys, engagement, device information, browser information, and general usage patterns.

Google Analytics helps us understand how users discover and use Re-Doc so that we can improve the Services.

No Sale of Customer Information

Re-Doc does not sell customer information, uploaded documents, generated outputs, or document metadata.

We do not use uploaded documents or generated outputs for advertising profiling.

Marketing Cookies

Re-Doc does not currently use third-party advertising cookies for behavioral advertising.

If we introduce marketing or advertising cookies in the future, we will update this Privacy Policy or provide additional notice where required by applicable law.

Managing Cookies

Most browsers allow users to control cookies through browser settings.

You may be able to block or delete cookies through your browser; however, disabling certain cookies may affect the functionality, security, or availability of the Services.

14. Your Privacy Rights

Depending on where you are located and how you use the Services, you may have certain rights regarding your personal information.

Re-Doc will respond to privacy rights requests in accordance with applicable data protection laws, including where applicable the General Data Protection Regulation, the UK GDPR, the Digital Personal Data Protection Act, 2023, and other applicable privacy laws.

Rights You May Have

Subject to applicable law, you may have the right to:

  • ·request access to personal information we hold about you;
  • ·request correction of inaccurate or incomplete personal information;
  • ·request deletion of personal information;
  • ·request restriction of certain processing activities;
  • ·object to certain processing activities;
  • ·withdraw consent where processing is based on consent;
  • ·request a copy of certain information in a portable format;
  • ·request information about how your personal information has been processed;
  • ·submit a grievance or complaint regarding our handling of your personal information; and
  • ·nominate another person to exercise certain rights on your behalf where permitted by applicable law.

These rights may be subject to limitations, exemptions, identity verification requirements, and legal or contractual restrictions.

Uploaded Documents and Third-Party Personal Information

Re-Doc is a document-processing platform. Uploaded documents may contain personal information relating to individuals other than the account holder or customer representative.

In many cases, the customer that uploads the document determines the purpose and means of processing the personal information contained within that document.

Where Re-Doc processes uploaded documents on behalf of a customer, Re-Doc generally acts as a processor or service provider. In such cases, individuals whose personal information appears in uploaded documents may need to direct their privacy rights requests to the customer that uploaded the document.

If Re-Doc receives a rights request relating to personal information contained in a customer-uploaded document, we may redirect the request to the relevant customer, seek instructions from the customer, or assist the customer in responding to the request where required by applicable law or contract.

Account Information Requests

If you have a Re-Doc account, you may request access to, correction of, or deletion of account information associated with your account.

Certain information may be retained where necessary for security, fraud prevention, tax, accounting, legal compliance, dispute resolution, contract enforcement, or legitimate business purposes.

Document Deletion Requests

Customers may request deletion of uploaded documents and generated outputs before the scheduled retention period.

Where technically supported, Re-Doc will take reasonable steps to delete the relevant uploaded documents and generated outputs from active systems as soon as technically practicable.

Document metadata, logs, billing records, and account information may be retained separately where necessary for operational, security, legal, tax, accounting, audit, or compliance purposes.

Withdrawal of Consent

Where Re-Doc relies on consent to process personal information, you may withdraw that consent at any time.

Withdrawal of consent will not affect processing that occurred before the withdrawal.

If you withdraw consent required for certain Services, some features may no longer be available.

Complaints and Grievances

If you have concerns about how Re-Doc handles your personal information, you may contact us using the contact details provided at the end of this Privacy Policy.

We will review and respond to privacy-related requests and grievances in accordance with applicable law.

Depending on your location, you may also have the right to lodge a complaint with a data protection authority or other competent regulator.

For DPDP-related communications, support@re-doc.com is the contact point authorised by Re-Doc to receive privacy requests, withdrawal requests, correction or deletion requests, nomination-related requests, and grievances relating to personal data processing.

How to Exercise Your Rights

To exercise your privacy rights, contact us at:

support@re-doc.com

To protect customer information and account security, we may need to verify your identity before responding to a request.

We may also request additional information to help us locate the relevant account, document, processing job, or transaction.

We will respond to valid requests within the timeframe required by applicable law.

Where the Digital Personal Data Protection Act, 2023 or the Digital Personal Data Protection Rules, 2025 apply, Re-Doc will aim to respond to applicable access, correction, updating, erasure, nomination, and grievance-related requests within the period required under applicable law, including the ninety-day period specified under applicable DPDP requirements where relevant.

15. Legal Bases and Processing Purposes

Where applicable data protection laws require a legal basis for processing personal information, Re-Doc processes personal information only where a valid legal basis is available.

The legal basis may depend on the type of information, the context in which it is processed, the jurisdiction involved, and whether Re-Doc is acting as a controller, processor, service provider, data fiduciary, or equivalent role under applicable law.

Re-Doc does not claim that use of the Services automatically makes a customer compliant with any specific privacy, security, healthcare, financial, or regulatory law. Customers are responsible for determining whether their use of the Services is appropriate for their own legal, regulatory, contractual, and compliance obligations.

Account and Service Information

We may process account information, authentication information, subscription information, support information, and technical information where necessary to:

  • ·create and manage user accounts;
  • ·authenticate users;
  • ·provide access to the Services;
  • ·process subscriptions and payments;
  • ·provide customer support;
  • ·maintain platform security;
  • ·prevent misuse;
  • ·comply with legal obligations; and
  • ·enforce our agreements.

Depending on the context, the legal basis for this processing may include performance of a contract, compliance with legal obligations, legitimate interests, consent, or other lawful bases recognized under applicable law.

Uploaded Documents and Generated Outputs

When a customer uploads documents to Re-Doc, the customer is responsible for ensuring that it has the necessary rights, permissions, authority, and lawful basis to upload and process those documents.

Re-Doc processes uploaded documents and generated outputs primarily on the customer's instructions and for the purpose of providing the requested document-processing Services.

Depending on the customer's use case and applicable law, the customer may act as the controller, data fiduciary, business, or equivalent decision-maker for the personal information contained in uploaded documents.

Re-Doc generally acts as a processor, service provider, data processor, or equivalent role when processing uploaded documents on behalf of a customer.

Consent-Based Processing

Where processing is based on consent, the person providing consent may withdraw that consent at any time, subject to applicable law and the limitations described in this Privacy Policy.

Withdrawal of consent does not affect processing that occurred before consent was withdrawn.

Legitimate Business Purposes

Where permitted by applicable law, Re-Doc may process certain information for legitimate business purposes, including:

  • ·maintaining and improving the Services;
  • ·securing the platform;
  • ·preventing fraud, abuse, and misuse;
  • ·diagnosing errors;
  • ·responding to support requests;
  • ·maintaining audit and operational records;
  • ·enforcing contractual rights; and
  • ·protecting Re-Doc, customers, users, and third parties.

Legal Obligations

Re-Doc may process and retain certain information where necessary to comply with applicable legal, tax, accounting, regulatory, law-enforcement, dispute-resolution, or contractual obligations.

Customer Responsibility

Customers are responsible for ensuring that their use of Re-Doc, including the upload and processing of documents containing personal, confidential, sensitive, regulated, or third-party information, complies with applicable laws and obligations.

This includes obtaining any required consents, authorizations, notices, approvals, or legal bases before uploading documents to the Services.

16. Children's Privacy

Re-Doc is not intended for use by children.

The Services are intended for use by individuals and organizations that have the legal authority to upload, process, redact, anonymize, pseudonymize, or otherwise transform documents.

Re-Doc does not knowingly create accounts for, market to, or directly collect account information from children.

However, because Re-Doc is a document-processing platform, uploaded documents may contain personal information relating to children or minors where such information is included by the customer in the documents submitted for processing.

Where a customer uploads documents containing information relating to children or minors, the customer is responsible for ensuring that it has the necessary rights, permissions, notices, consents, authorizations, and legal basis to process that information using the Services.

If Re-Doc becomes aware that it has collected account information directly from a child without appropriate authorization, we will take reasonable steps to delete that information.

If you believe that a child has provided personal information directly to Re-Doc without appropriate authorization, please contact us using the contact details provided at the end of this Privacy Policy.

Users of Re-Doc must be at least 18 years old or must use the Services only through an authorized organization, parent, guardian, or other person legally permitted to act on their behalf.

17. Changes to this Privacy Policy

Re-Doc may update this Privacy Policy from time to time to reflect changes in our Services, processing practices, subprocessors, legal requirements, security practices, or business operations.

When we update this Privacy Policy, we will revise the "Effective Date" at the top of the policy.

If we make material changes that significantly affect how we collect, use, store, share, or process personal information or uploaded documents, we may provide additional notice where appropriate. This may include notice through the Services, by email, through an account notification, or by other reasonable means.

Your continued use of the Services after an updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.

Where required by applicable law or contract, we will obtain consent or provide additional notice before applying material changes to certain processing activities.

We encourage customers to review this Privacy Policy periodically to stay informed about how Re-Doc handles information.

18. Contact Information and Grievance Redressal

If you have questions, concerns, requests, or complaints regarding this Privacy Policy or Re-Doc's handling of personal information, you may contact us at:

CypherLayer Technologies Private Limited

Operator of Re-Doc

Privacy and Grievance Contact: support@re-doc.com

You may contact us for matters including:

  • ·privacy rights requests;
  • ·deletion requests;
  • ·correction or access requests;
  • ·account-related privacy concerns;
  • ·document retention or deletion queries;
  • ·questions regarding subprocessors;
  • ·security or data handling concerns; and
  • ·complaints regarding the processing of personal information.

Re-Doc will review privacy-related requests and grievances within a reasonable period and respond in accordance with applicable law.

To protect customer information and prevent unauthorized disclosure, we may ask you to verify your identity or provide additional information before responding to certain requests.

If your request relates to personal information contained in a document uploaded by a Re-Doc customer, we may need to refer the request to that customer or process the request based on that customer's instructions, where applicable.

Nothing in this section limits any rights you may have to contact a competent data protection authority, regulator, or other legal authority where applicable.