How REDA One LLC collects, uses, and protects personal data — both on this website and within the REDA AI platform.
This Privacy Policy explains how REDA One LLC, 5 Independence Way, Suite 300, Princeton, NJ 08540, United States ("REDA AI", "we", "us") collects and processes personal data.
It covers two very different situations, and the distinction matters:
Where you use the platform, the Master Subscription Agreement governs our handling of your data. If anything in this Policy conflicts with the Master Subscription Agreement in respect of Client Data, the Master Subscription Agreement controls.
We do not store your Salesforce data. The REDA AI managed package runs inside your own Salesforce organisation. Conversation history, logs, and usage records are created as records in your org, under your control. When an AI Agent runs, your instructions are sent directly from your Salesforce organisation to the AI provider — they do not pass through, and are not stored on, infrastructure operated by REDA AI.
Website forms are submitted to Salesforce Web-to-Lead and create a lead record in REDA One LLC’s own Salesforce organisation. We use this to respond to your enquiry and for related sales and marketing follow-up. Our lawful basis is our legitimate interest in responding to business enquiries, or your consent where required by local law.
We do not sell personal data. We do not rent personal data. We do not use website analytics data to make automated decisions about you.
The website uses cookies and similar technologies. Strictly necessary cookies support core site functionality. In addition, we use the following non-essential technologies:
Our website also loads front-end code from a public content delivery network (unpkg) on some pages, and is hosted by Netlify. These providers process technical connection data such as your IP address in order to deliver the page to you.
Your choice. Analytics cookies are not set unless you accept them. When you first visit, we ask; if you decline, no analytics cookies are placed and no analytics data is collected from you. You can change your choice at any time using the Cookie Preferences link in the footer of any page.
You can also block or delete cookies through your browser settings, and opt out of Google Analytics across all sites using Google’s opt-out browser add-on. Declining non-essential cookies does not affect your ability to use the site.
REDA AI is an integration and orchestration platform. The managed package is installed into, and operates entirely within, your organisation’s own Salesforce environment.
We do not host your data. Conversation history, incident logs, credit and usage records created by the Services are stored as records inside your own Salesforce organisation, subject to your own retention, sharing, and backup policies. REDA AI operates no database, no application server, and no storage of its own in the path of your data.
Our access is limited and at your invitation. We access data in your Salesforce organisation only for troubleshooting or support, and only where you have asked us to and granted access. We do not export data from your Salesforce organisation.
For personal data within your Salesforce organisation, your organisation is the controller and REDA AI is a processor, processing only on your documented instructions. See Section H of the Master Subscription Agreement.
When an AI Agent runs, the content of the request — which may include CRM records, customer information, documents, and conversation text — is transmitted from your Salesforce organisation directly to a third-party AI provider for processing, and the response is returned to your organisation. This content does not pass through infrastructure operated by REDA AI.
REDA AI does not train, fine-tune, or otherwise develop artificial-intelligence models, and does not use your data to do so. REDA AI does not operate any AI model. How an AI provider treats request content is governed by that provider’s own terms, which we do not control and cannot vary.
Which AI provider processes your requests depends on the Processing Tier your administrator selects for each Agent. The designated providers, the disclosures that apply to each, and the steps required to enable them are set out in Section B3A of the Master Subscription Agreement. Your administrator controls this choice.
We use the following sub-processors in connection with the platform:
For the website, we use Netlify (hosting), Google (analytics), Wistia (video), and Calendly (scheduling).
AI providers and platform vendors contract on standard, non-negotiable terms. We are not able to impose bespoke data-protection obligations on them; we rely on their published terms and data processing agreements, which we will make available or point you to on request. We will give at least thirty (30) days’ notice before adding a material new sub-processor affecting personal data, as set out in Section H3 of the Master Subscription Agreement.
Your data may be transferred outside the country in which you are located. Where you use the primary Processing Tiers, AI processing takes place in the United States. Where your administrator has enabled the Economy Tier, AI processing for Agents on that Tier takes place in the People’s Republic of China, under terms governed by the laws of that jurisdiction.
Enabling a Processing Tier is your organisation’s instruction to make the resulting transfer. Your organisation is responsible for determining that the transfer is lawful in its own jurisdiction. Where required, transfers are made under appropriate safeguards such as Standard Contractual Clauses. See Sections B3A and H5 of the Master Subscription Agreement.
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to processing, and to withdraw consent. Residents of California and certain other jurisdictions have additional rights, including the right to know what personal data is collected and to opt out of its sale — we do not sell personal data.
How to exercise them depends on which context applies:
You may also lodge a complaint with your local data protection supervisory authority.
We implement and maintain commercially reasonable technical and organisational security measures to protect personal data within the managed package, within systems we operate or control, and in respect of the credentials we issue.
We cannot and do not warrant the internal security of third parties — including Salesforce, AI providers, and the website vendors listed above — whose systems we neither operate nor audit. Those dependencies are addressed in Sections B2, B3, and B3A of the Master Subscription Agreement.
If we become aware of a personal data breach affecting data within systems we operate or control, we will notify affected customers without undue delay and in any event within seventy-two (72) hours. Where a breach occurs at a sub-processor, we will pass on that provider’s notification without undue delay after we receive it; we have no ability to detect or investigate incidents inside a sub-processor’s systems.
To report a suspected vulnerability or unauthorised access, contact security@reda.one.
Under the GDPR and comparable laws, responsibility depends on who decides the purpose of the processing. For personal data inside your Salesforce organisation, your organisation is the controller and decides what data enters the Services and why; REDA AI is a processor, acting on your instructions. For the website, we are the controller of the limited data described in Sections 2 and 3.
We offer a Data Processing Agreement to customers who require one. Request one at legal@reda.one.
We may update this Policy. The revised version will be posted at this URL with a new effective date. Where a change is material and affects active subscribers, we will give notice as provided in Section K10 of the Master Subscription Agreement.
For privacy questions, data subject requests, or to request a Data Processing Agreement, contact our legal team. For security matters, use security@reda.one.
Contact legal@reda.one