Skip to content
Redddie

Data processing agreement.

Last updated: 28 September 2026

Parties and scope

This data processing agreement belongs with the terms of service for the Redddie project tool and governs the processing of personal data that results from them. By registering and accepting the terms of service, you also agree to this data processing agreement; a separately signed copy is not required unless you want one — email info@redddie.com.

Under this agreement, the Customer is the controller: you decide which data about which people you enter into the Service, and for what purpose. Redddie is the processor: we process that data only on your behalf and according to your instructions, as they follow from your use of the Service.

Subject matter, nature and purpose of the processing

We process personal data only to deliver the Service: storing and showing the data you enter yourself (projects, tasks, hours and the related contacts), sending functional email (such as email verification and password reset) and handling payment for your subscription.

We do not use this data for our own purposes, do not sell it, and do not use it for profiling or advertising.

The processing lasts as long as you have a workspace with us, and ends as described under "Retention and deletion" below.

Categories of data subjects and data

Users of the Service (you and any team members you invite): name, email address, role, and password — the latter always stored hashed, never in readable form.

People you link to projects or tasks: name, email address and optionally a job title or role. This is generally not special category data; if you choose to put sensitive information into a free-text field yourself (such as a task description or comment), that is your own choice and your own responsibility as controller.

The Customer's own billing details (company name, email address, payment details) are processed directly by our payment provider Stripe on our behalf.

Redddie's obligations as processor

We process personal data only on your instructions, as they follow from your use of the Service, and not for our own purposes — unless legally required to; in that case we let you know in advance, unless the law prohibits this.

Everyone at Redddie with access to personal data is bound by confidentiality.

We take appropriate technical and organisational measures, including: passwords hashed with bcrypt and never stored in readable form, all traffic over HTTPS/TLS, access to data strictly separated per workspace (every query is scoped to your organization), rate limiting against automated attacks on the login process, and security headers that limit the impact of any browser-side vulnerability.

We report a security incident with (possible) consequences for personal data to you without undue delay, so you can decide yourself whether a report to the Dutch Data Protection Authority or to data subjects is required.

Sub-processors

To deliver the Service we engage the following sub-processors: Vercel (application hosting, EU region Frankfurt), Neon (database hosting, EU region Frankfurt), Resend (sending functional email) and Stripe (payment processing). Resend and Stripe each maintain their own data processing agreement with Standard Contractual Clauses, which applies automatically through their own terms of service; Resend is additionally certified under the EU-US Data Privacy Framework.

We will inform you if we engage a new sub-processor or change sub-processor, so you can object on reasonable grounds.

Our sub-processors are contractually required to maintain a level of protection comparable to this agreement.

Transfers outside the EU

Our own hosting partners (Vercel, Neon) process your workspace's data within the EU (Frankfurt). Some sub-processors, such as Resend and Stripe, may also process data outside the EU; in that case they rely on their own valid transfer mechanism: both use the EU Standard Contractual Clauses through their own data processing agreement, and Resend is additionally certified under the EU-US Data Privacy Framework.

Assistance with data subject rights and audits

If we ourselves receive a request from a data subject (for example someone asking for access to data you have recorded about them), we forward that request to you; the Service also lets you view, edit or delete a Person's data yourself.

On reasonable request, we provide the information needed to demonstrate our compliance with this agreement, and cooperate with a reasonable audit, provided you give advance notice and it does not place an unreasonable burden on Redddie's or other customers' operations.

Retention and deletion

As long as your workspace exists, the data remains available as you entered it. After cancelling your subscription the retention period from the terms of service applies; after that we delete your workspace's data, unless we are legally required to keep it longer (for example billing records under tax retention rules).

If you request deletion of your entire workspace earlier, we do so within a reasonable period, subject to the same statutory exception for billing records.

Term and liability

This data processing agreement applies for as long as the underlying agreement (the terms of service) is in effect, and ends automatically with it.

Liability under this data processing agreement is subject to the same limitation as in the terms of service.