Redpine Technology AB, reg. no. 559499-8824, a Swedish company ("Redpine", "we", "us", "our"), respects your privacy. This Privacy Policy explains how we collect, use, share and protect personal data about you when you visit our website at redpine.ai and its sub-domains (the "Website"), interact with us (e.g. through demo requests, marketing or support), or use the Platform.
Effective Date: date of last update. We may update this Policy as described in Section 13.
Scope. This Policy covers personal data Redpine processes as a controller, that is, where Redpine determines the purposes and means of processing. Where Redpine processes personal data as a processor on behalf of a Content Partner or an Authorized User/Recipient, our role is governed by a separate Data Processing Agreement (the "DPA"), not this Policy. The Cookie Policy forms part of this Policy.
1. Who We Are and How to Contact Us
1.1 Controller. Redpine Technology AB is the controller of personal data described in this Policy.
1.2 Contact. For any privacy question, data-subject request, or to exercise your rights, contact us at legal@redpine.ai.
2. Categories of Personal Data We Collect
Depending on how you interact with us, we may process:
- Identification and contact data: name, business email, phone, role/title, employer, country.
- Account and credential data: username, hashed password, API keys, organization identifier.
- Commercial data: billing address, payment method (tokenized; processed by our payment processor), invoices, order history.
- Communications data: emails, support tickets, chat transcripts, meeting notes, recordings where lawfully obtained.
- Usage data: logs of Platform access, including IP address, device and browser type, timestamps, API key used, endpoints called, request and response metadata, error logs, and aggregated usage metrics.
- Marketing data: preferences, event attendance, marketing engagement metrics, and feedback, survey and research responses.
- Cookies and similar technologies: see the Cookie Policy.
3. How We Collect Personal Data
- Directly from you, when you fill in forms, sign up, contact us, attend events or accept these terms.
- Automatically, through your interactions with the Website or the Platform (e.g. logs, cookies).
- From third parties, from your employer (when you act for it), from public sources, from analytics providers, payment processors, identity-verification services, and Content Partners.
4. Why We Process Personal Data and Legal Bases
| Purpose | Categories | Legal basis |
|---|---|---|
| To operate the Website, deliver the Platform, authenticate users, and provide the services you request | Identification, account, usage, communications | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| To respond to enquiries, demo requests, and support | Identification, communications | Legitimate interests; pre-contractual steps |
| To bill, collect payments and keep accounting records | Commercial, contact | Contract; legal obligation |
| To operate, secure, monitor and improve the Platform; detect and prevent misuse | Usage, account | Legitimate interests |
| To comply with law (accounting, tax, anti-money-laundering, export-control, sanctions, regulatory requests) | Identification, commercial, communications | Legal obligation |
| To market to business prospects and to you, the Content Partner or Authorized User/Recipient, and to contact you for product feedback, surveys and research (consistent with applicable opt-in / opt-out rules) | Marketing, identification | Legitimate interests; consent where required |
| To investigate and enforce our rights and the rights of Content Partners (incl. AUP enforcement, audits, dispute defense) | Account, usage, communications | Legitimate interests; legal claims (Art. 9(2)(f)) |
| With your separate consent, for any purpose described to you at the time | As described | Consent (Art. 6(1)(a)) |
Note on Platform queries. If you submit queries to the Platform (including via the API/MCP) that contain personal data of others, you (or your organization) are the controller of that data and Redpine processes it on your instructions under the DPA. This Policy does not govern that processing, your own privacy notice should describe it.
5. Disclosures and Sharing
We share personal data only as described below, and never sell it.
- Service providers / sub-processors — cloud hosting, observability, payment processing, customer-support tooling, email and analytics, identity-verification, and security providers, bound by confidentiality and data-protection commitments. A current list is available on request.
- Content Partners — aggregated, anonymized usage data; query-level information only as expressly permitted in the API Access Terms (e.g. with your consent or where required by law).
- Professional advisers — lawyers, auditors, insurers, where reasonably necessary.
- Government, regulators and courts — where required by law, regulation or legal process, or to protect our or others' rights.
- Corporate transactions — in the context of a merger, acquisition, reorganisation, or sale of all or substantially all our assets, subject to safeguards.
6. International Transfers
6.1 Redpine is based in the EEA. Where personal data is transferred to a country that does not offer an adequate level of protection (under EU/UK rules), we use an appropriate transfer mechanism, including: the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable); approved certification or codes of conduct; or adequacy decisions where they apply. Supplementary measures are applied where the recipient country requires them. A list of countries to which we transfer personal data is available on request.
7. Data Retention
7.1 We keep personal data only for as long as needed for the purposes set out above. As a guide:
- Account and contract data for the term of the relationship and up to ten (10) years after termination for tax, accounting and limitation purposes.
- Usage and security logs — typically twelve (12) to twenty-four (24) months, longer where needed for security investigations or required by law.
- Marketing data — until you opt out, plus a short suppression period.
- Support communications — typically three (3) years.
7.2 After the relevant period, we delete, anonymize or aggregate the data.
8. Security
8.1 We maintain technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure or destruction, as described in the Trust & Security Policy at redpine.ai/legal/trust-and-security. No system is perfectly secure; you also play a role by keeping credentials confidential and reporting suspected incidents to legal@redpine.ai promptly.
9. Your Rights
You have rights to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure (right to be forgotten) where applicable;
- request restriction of processing;
- object to processing based on legitimate interests or direct marketing;
- request portability of data you provided to us;
- withdraw consent at any time (without affecting prior lawful processing); and
- lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (IMY); in the UK, the ICO; or your local data-protection authority.
9.1 US state privacy laws (California, Virginia, Colorado, Connecticut, Utah and others). If you are a resident of a US state with applicable privacy law, you have rights to know about, access, correct, delete and (for some states) limit our use of certain personal data, and to opt out of "sale" or "sharing" for cross-context behavioral advertising and certain targeted advertising. We do not sell personal data in the everyday sense. To exercise these rights, contact legal@redpine.ai or use the link "Do Not Sell or Share My Personal Information" where shown on the Website. We will not discriminate against you for exercising any right.
9.2 How to exercise rights. Email legal@redpine.ai with sufficient information for us to verify your identity. We will respond within the time required by applicable law (usually within thirty (30) days under the GDPR/UK GDPR; up to forty-five (45) days under most US state laws), and may extend that period where permitted. There is no fee unless your request is manifestly unfounded or excessive.
9.3 Authorized agents. You may use an authorized agent to submit a request, subject to verification.
10. Cookies and Similar Technologies
10.1 Our use of cookies is described in the Cookie Policy. You can manage your cookie choices via the Cookie banner on the Website or your browser settings.
11. Children
11.1 The Website and Platform are not directed to children under eighteen (18) (or the relevant majority age in your jurisdiction), and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact legal@redpine.ai and we will take appropriate action.
12. Automated Decision-Making and Profiling
12.1 We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. The Platform may use AI to generate Outputs from Content; Outputs are not directed at, and do not produce decisions about, individuals.
13. Changes to this Policy
13.1 We may update this Policy from time to time. Material changes are notified by a Website notice and, where appropriate, by email. Continued use of the Website or the Platform after the change takes effect is acceptance.
14. Contact
All privacy questions and data-subject requests: legal@redpine.ai.
Redpine Technology AB
Sweden, reg. no. 559499-8824