Privacy Policy
This privacy notice for REDAMP SECURITY s.r.o. ("we", "us", or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
- Visit our website at https://app.redamp.io , or any website of ours that links to this privacy notice
- Download and use our mobile application (Redamp.io), or any other application of ours that links to this privacy notice
- Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at [email protected].
Definitions
Partner: an entity that provides the Service to its customers through the Redamp.io partner program and, to that extent, acts as an independent data controller of personal data. A Partner is not considered a third party for the purposes of this policy when processing personal data in connection with providing the Service to its customer.
Data Controllers and Processing Roles
For Partner-Managed Accounts, a Partner acts as an independent data controller with respect to any Customer Data it accesses or processes under its own agreement with the Customer.
Redamp.io acts as a data controller or data processor (as applicable) for its own processing activities related to the operation, security, and improvement of the Services.
Redamp.io does not determine the legal basis on which a Partner processes Customer Data and relies on the Partner’s representations that such processing is lawful.
Summary of key points
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we receive any information from third parties? We do not receive any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties.
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by contacting us via https://redamp.io/contact , or by contacting us at our physical service address: REDAMP SECURITY s.r.o., Palackého třída 879/84, 612 00 Brno, CZ. We will consider and act upon any request in accordance with applicable data protection laws.
Table of contents
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE PROCESS YOUR INFORMATION?
- WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
- WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
- HOW LONG DO WE KEEP YOUR INFORMATION?
- HOW DO WE KEEP YOUR INFORMATION SAFE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- CONTROLS FOR DO-NOT-TRACK FEATURES
- DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
- HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- Names
- Email addresses
- Usernames
- Passwords
- Contact or authentication data
- Billing addresses
Sensitive Information. We do not process sensitive information.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
- Application Data:
- App names and package IDs
- App version numbers
- Installation dates
- Location Data:
- Safe Surfing feature that utilizes VPN services to safeguard your DNS traffic, ensuring a shielded browsing experience. This feature needs access to location in the background to get information about Wifi network SSID under all conditions even after restart of mobile device. This feature require to recognize Wifi network SSID change to work properly and secure users of our applications.
- Device and Network Data:
- Network details, including SSID, BSSID, cellular provider, DNS, and default gateway IP address
- Device identifier
- Device Settings and Permissions Data:
- Whether the app has access to your camera (this is optional)
- Whether biometrics are enabled on your device
- Operating System and Device Specifications Data:
- Operating System Name (e.g., Android, iOS)
- Version of the Operating System
- Any installed patches or updates
- Build details
- Firmware version
- Other additional data related to the operating system
- Device Details Data:
- Type of device (e.g., smartphone, tablet)
- Manufacturer of the device (e.g., Samsung, Apple)
- Specific model of the device
- Notification token, which may be used for app-specific notifications
- Device Settings Data:
- Whether the device is rooted
- Status of the Bluetooth connection
- Status of the NFC connection
- Whether USB debugging is enabled
- If location services are active
- The level of biometric security in use (e.g., fingerprint, facial recognition)
- Any security systems enabled on the device
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To save or protect an individual\'s vital interest. We may process your information when necessary to save or protect an individual's vital interest, such as to prevent harm.
- Analyzing potential threats and vulnerabilities related to the apps installed on your device, your device settings or your device status.
- Enhancing our ability to protect you by understanding the digital ecosystem of your mobile device.
- Preventing any potential threats that might harm your device or data.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
- Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time.
- Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
In Short: We may share information in specific situations described in this section and/or with the following third parties.
We may need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Partners and Partner-Managed Accounts: Where a Customer account is created or managed by a Partner, the Partner may be granted access to Customer Data through the Services based on the authorization status indicated by the Partner during onboarding.
Redamp.io relies on the Partner’s contractual obligation to obtain all necessary permissions, consents, or other lawful authorizations from the Customer prior to enabling such access.
The Customer is able to view the Partner’s access status within the Services and may modify or revoke Partner access at any time, subject to the functionality of the Services.
Partner access to Customer Data is not enabled by default and depends on the account configuration selected at onboarding or subsequently modified by the Customer or the Partner acting on the Customer’s behalf.
Where Customer Data is accessed by a Partner, such processing is carried out under the legal basis determined by the Partner in its relationship with the Customer (for example, performance of a contract or consent).
Redamp.io enables Partner access based on the Partner’s assertion that it has obtained the required lawful authorization and does not independently validate such authorization.
Partners are contractually required by Redamp.io to obtain all necessary permissions, consents, and authorizations before accessing Customer Data.
A Partner is solely responsible for the lawfulness of its access to and processing of Customer Data and for compliance with applicable data protection laws.
Customers are encouraged to review their Partner access settings within the Services and to contact the Partner directly regarding any questions about the Partner’s access to Customer Data.
5. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
6. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security, and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
- Storage: All collected data is stored in a secure environment, with state-of-the-art encryption and protective measures in place to ensure the safety of your information. Our internal policies mandate the use of encryption for all sensitive data stored on company devices, including laptops, desktops, smartphones, and tablets, to ensure the security and confidentiality of personal information. All data is securely stored on servers located within the European Union, ensuring full compliance with EU data protection regulations.
- Internal Communication: All internal communication is conducted over encrypted channels. Internal email communication is secured using S/MIME (end-to-end encryption), ensuring that only the sender and the intended recipient(s) can read the content and attachments.
- Internal Access: Access to this data within our company is strictly regulated. Only key personnel with appropriate permissions and clearances can access and process this data. Identity and access management system is implemented on our side.
- Data Sharing: We do not sell, share, distribute, donate, or otherwise transfer your data to third parties (i.e., we do not provide or disclose your data to any person or entity outside our organization). We will not undertake any action whose purpose or effect would be to circumvent this commitment.
If a customer uses the Service through a partner account (MSP / reseller), such partner may have access to the customer’s data to the extent necessary to manage and support the customer’s account. In such cases, the partner does not act as a third party, but as an independent data controller of its customer’s personal data and is responsible for its own processing activities.
Customer data always remains under the control of the relevant data controller (the partner or the customer), and Redamp.io uses it solely for the purpose of providing the Service.
- Profiling: We do not use the data collected to profile users or for any other purpose other than analyzing and preventing threats.
6.1 Error Tracking and Performance Monitoring
To ensure the stability and reliability of our platform, we use Sentry, an error tracking and performance monitoring tool. Our instance of Sentry is self-hosted and fully operated on our own servers. No data is transmitted to or processed by third parties or by Sentry.io (Functional Software, Inc.).
Sentry enables us to identify, diagnose, and resolve technical issues by collecting technical information such as:
- Error messages and stack traces
- Browser and device information
- Operating system details
- URL paths and timestamps
- Anonymized internal user identifiers (if applicable)
All data collected through Sentry is stored and processed exclusively by us and is used solely for the purpose of debugging and improving the functionality and security of our services. We do not use this data to personally identify users.
This processing is carried out in accordance with our internal data protection policies and applicable privacy laws.
7. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data, we may have collected from children under age 18, please contact us at [email protected].
8. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: In some regions, such as the European Economic Area (EEA) and United Kingdom (UK), you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
In some regions (like the EEA and UK), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section \"HOW CAN YOU CONTACT US ABOUT THIS NOTICE?\" below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority .
If you are located in Switzerland, you may contact Federal Data Protection and Information Commissioner .
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section \"HOW CAN YOU CONTACT US ABOUT THIS NOTICE?\" below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
- Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.
If you have questions or comments about your privacy rights, you may email us at [email protected].
9. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (\"DNT\") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
10. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: Yes, if you are a resident of California, you are granted specific rights regarding access to your personal information.
California Civil Code Section 1798.83, also known as the \"Shine The Light\" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below, and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g. backups, etc.).
11. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated \"Revised\" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
12. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at [email protected] or contact us at our physical service address: REDAMP SECURITY s.r.o. Palackého třída 879/84 612 00 Brno, Czech Republic.
13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances. To request to review, update, or delete your personal information, please visit: https://redamp.io/contact. We will respond to your request within 30 days.