Privacy Notice

Last updated: July 2026

This privacy notice explains how Redaktr processes personal data, the circumstances in which we do so, and the rights available to individuals whose data we handle. It reflects the requirements of the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA).

Redaktr is a document redaction and disclosure platform used by organisations to prepare responses to Data Subject Access Requests (DSARs), Freedom of Information (FOI) requests, and other disclosure obligations.

1. Who we are

Redaktr is operated by IOLIS Ltd (trading as Redaktr), a company registered in England and Wales.

For the purposes of data protection law:

  • Redaktr is a data processor in respect of customer-loaded content.
  • Redaktr is a data controller in respect of limited account and contact information relating to its own users.

If you have any questions about this notice, wish to exercise your rights, or want to make a complaint about how data is handled, you can contact us at:

Email: [email protected]

2. The personal data we process

2.1 Customer-loaded data (processor role)

When organisations use Redaktr, they upload documents and information that may contain personal data. This data is uploaded, controlled, and determined entirely by the customer.

Redaktr:

  • does not determine the purposes for which that data is processed,
  • processes that data only on documented instructions from the customer,
  • does not use customer-loaded data for any purpose of its own.

The categories of personal data processed in this context depend entirely on what the customer uploads and may include special category data.

2.2 User account data (controller role)

For users who access the Redaktr platform directly, we process the following personal data:

  • Name
  • Email address
  • Limited technical and usage data necessary to operate and secure the platform (for example, authentication and audit log records).

This data is used solely to:

  • create and manage user accounts,
  • authenticate users and keep the platform secure,
  • communicate with users about service-related matters.

We do not collect marketing profiles or additional personal information.

3. Lawful basis for processing

3.1 Contract

Where Redaktr acts as a data processor, processing is carried out to perform a contract with our customer, in accordance with Article 28 UK GDPR.

Where Redaktr acts as a data controller in respect of user account data, processing is necessary for the performance of a contract between Redaktr and the user, or to take steps at the user’s request before entering into a contract.

3.2 Legitimate interests

Where Redaktr acts as a data controller, we also rely on our legitimate interests in keeping the platform and its users secure, preventing fraud and misuse, and maintaining audit records. This includes ensuring the security of our network and information systems, which the Data (Use and Access) Act 2025 treats as a recognised legitimate interest. We only rely on this basis where our interests are not overridden by your interests or fundamental rights.

3.3 Legal obligation

In limited circumstances we process personal data to comply with a legal obligation, for example where we are required to retain records or to respond to lawful requests from regulators or law enforcement.

4. How we use personal data

Personal data is used only for the purposes set out above. In particular:

  • customer-loaded data is processed solely to provide the Redaktr service,
  • user account data is used only to enable secure access and platform operation,
  • personal data is never sold or shared for marketing purposes.

5. Data sharing

Redaktr does not disclose personal data to third parties except where:

  • required to provide the service (for example, secure infrastructure providers acting as our sub-processors under written contract),
  • required by law or regulatory obligation,
  • instructed by the customer acting as data controller.

6. International transfers

Where personal data is processed outside the UK, we ensure an appropriate transfer mechanism is in place, such as UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses). Following the Data (Use and Access) Act 2025, transfers are assessed against the UK data protection test, which considers whether the standard of protection in the destination is not materially lower than under UK law.

7. Data security

Redaktr implements appropriate technical and organisational measures to protect personal data, including:

  • access controls and authentication,
  • audit logging,
  • segregation of customer data,
  • secure storage and transmission.

Security measures are proportionate to the nature and sensitivity of the data processed.

8. Automated decision-making

Redaktr does not make decisions about individuals that produce legal or similarly significant effects based solely on automated processing of user account data. Where the platform assists customers with redaction, any decisions about the content of a disclosure remain the responsibility of the customer as data controller, subject to their own safeguards and human oversight.

9. Cookies

The Redaktr platform uses cookies that are strictly necessary for it to function, such as maintaining your login session and keeping the platform secure. These do not require consent. Where our website uses any non-essential cookies (for example, analytics), we will only set them on the basis of the applicable consent or opt-out requirements under the Privacy and Electronic Communications Regulations (PECR), as updated by the Data (Use and Access) Act 2025.

10. Data retention

Customer-loaded data

Customer-loaded data is retained only for the duration specified by the customer and in accordance with contractual arrangements. Customers are responsible for determining retention periods and deletion instructions.

User account data

User account data (such as name, email address, and related audit records) is retained for as long as the user account remains active and for a limited period thereafter for administrative, legal, and security purposes, after which it is securely deleted or anonymised.

11. Individual rights

Where Redaktr acts as a data processor, individuals should direct any rights requests (including access, rectification, or erasure) to the organisation that uploaded the data. We will assist that organisation in responding as required under our contract with them.

Where Redaktr acts as a data controller in respect of user account data, individuals have the right to:

  • be informed about how their personal data is used,
  • access their personal data,
  • request correction of inaccurate data,
  • request erasure where applicable,
  • object to or restrict processing where legally permitted,
  • request portability of data they have provided to us.

Requests can be made using the contact details above. We will respond within one month of receiving a valid request. To help us respond, we may need to verify your identity or ask you to clarify what you are looking for; where we reasonably do so, the time limit may be paused until we receive the information we need. We will carry out reasonable and proportionate searches to locate your data. If a request is complex or we receive a number of requests from you, we may extend this period by up to a further two months and will tell you if this is the case.

12. Complaints

If you have concerns about how your personal data is handled, we encourage you to contact us first at [email protected] so that we can try to resolve the matter. In line with the Data (Use and Access) Act 2025, we will acknowledge your complaint within 30 days and respond without undue delay.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at any time:

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

13. Changes to this notice

This privacy notice may be updated from time to time to reflect changes in legal requirements or our processing activities. This version has been updated to reflect the Data (Use and Access) Act 2025. The most current version will always be available on our website.