Privacy Notice

Last updated: August 2026

This privacy notice explains how Redaktr processes personal data, the circumstances in which we do so, and the rights available to individuals whose data we handle. It reflects the requirements of the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA).

Redaktr is a document redaction and disclosure platform used by organisations to prepare responses to Data Subject Access Requests (DSARs), Freedom of Information (FOI) requests, and other disclosure obligations.

1. Who we are

Redaktr is operated by IOLIS Ltd (trading as Redaktr), a company registered in England and Wales, company number 11968202, registered office C5 Business Centre, C5 North Road, Bridgend Industrial Estate, Bridgend, Wales, CF31 3TP.

For the purposes of data protection law:

  • Redaktr is a data processor in respect of customer-loaded content.
  • Redaktr is a data controller in respect of limited account and contact information relating to its own users.

If you have any questions about this notice, wish to exercise your rights, or want to make a complaint about how data is handled, you can contact us at:

Email: [email protected]

2. The personal data we process

2.1 Customer-loaded data (processor role)

When organisations use Redaktr, they upload documents and information that may contain personal data. This data is uploaded, controlled, and determined entirely by the customer.

Redaktr:

  • does not determine the purposes for which that data is processed,
  • processes that data only on documented instructions from the customer,
  • does not use customer-loaded data for any purpose of its own, and does not use it to train, fine-tune or improve any machine learning model.

The categories of personal data processed in this context depend entirely on what the customer uploads and may include special category data.

2.2 User account data (controller role)

For users who access the Redaktr platform directly, we process the following personal data:

  • Name
  • Email address
  • Limited technical and usage data necessary to operate and secure the platform (for example, authentication and audit log records).

This data is used solely to:

  • create and manage user accounts,
  • authenticate users and keep the platform secure,
  • communicate with users about service-related matters.

We do not collect marketing profiles or additional personal information.

3. Lawful basis for processing

3.1 Contract

Where Redaktr acts as a data processor, processing is carried out to perform a contract with our customer, in accordance with Article 28 UK GDPR.

Where Redaktr acts as a data controller in respect of user account data, processing is necessary for the performance of a contract between Redaktr and the user, or to take steps at the user’s request before entering into a contract.

3.2 Legitimate interests

Where Redaktr acts as a data controller, we also rely on our legitimate interests in keeping the platform and its users secure, preventing fraud and misuse, and maintaining audit records. This includes ensuring the security of our network and information systems, which the Data (Use and Access) Act 2025 treats as a recognised legitimate interest. We only rely on this basis where our interests are not overridden by your interests or fundamental rights.

3.3 Legal obligation

In limited circumstances we process personal data to comply with a legal obligation, for example where we are required to retain records or to respond to lawful requests from regulators or law enforcement.

4. How we use personal data

Personal data is used only for the purposes set out above. In particular:

  • customer-loaded data is processed solely to provide the Redaktr service,
  • user account data is used only to enable secure access and platform operation,
  • personal data is never sold or shared for marketing purposes.

5. Data sharing and sub-processors

Customer-loaded data

We operate the Redaktr platform on our own dedicated infrastructure and engage no sub-processors in respect of customer-loaded data. Documents, images, video and other material loaded into a case are not passed to any third-party service for storage, conversion, redaction, analysis or any other purpose.

Service email

The platform sends service emails to users – for example account, authentication and notification messages – through Postmark, an email delivery service operated by ActiveCampaign, LLC in the United States. Postmark receives only what is needed to deliver those messages, being the recipient’s name and email address and the content of the message itself. It does not receive access to case containers or to customer-loaded documents.

Postmark acts as our processor under a written contract. ActiveCampaign, LLC is certified under the UK Extension to the EU-U.S. Data Privacy Framework for non-HR data, and the transfer is made in reliance on that certification. We verify that the certification remains active on the Data Privacy Framework list, and if it were to lapse we would put an alternative transfer mechanism in place or cease the transfer.

Other disclosures

Beyond the above, we will disclose personal data only where:

  • required by law or regulatory obligation, or
  • instructed to do so by the customer acting as data controller.

If we propose to engage any further sub-processor, we will give customers advance written notice and an opportunity to object before that sub-processor is used.

6. Where your data is held, and international transfers

The Redaktr platform and all customer-loaded data are hosted on dedicated infrastructure located in Helsinki, Finland. Customer-loaded documents and case containers do not leave that infrastructure and are not transferred to the United States.

Because Finland is within the European Economic Area, transfers of personal data from the United Kingdom to the platform are covered by the UK’s adequacy regulations for the EEA, and no additional transfer mechanism is required.

The one exception is service email. As set out in section 5, the limited account data needed to deliver those messages is transferred to Postmark in the United States in reliance on the UK Extension to the EU-U.S. Data Privacy Framework, which the Data (Use and Access) Act 2025 preserves as a partial adequacy finding for participating US businesses.

7. Data security

Redaktr implements appropriate technical and organisational measures to protect personal data, including:

  • Encryption at rest – case containers are held on LUKS-encrypted volumes,
  • Encryption in transit – all user access to the platform is over HTTPS, and files moving between the conversion platform and the Redaktr server travel over a secure channel,
  • access controls and authentication,
  • audit logging of access and review activity,
  • segregation of customer data into separate case containers,
  • dedicated infrastructure operated by us, with no third-party sub-processor handling customer-loaded data.

Security measures are proportionate to the nature and sensitivity of the data processed.

8. Automated processing and decision-making

Redaktr does not make decisions about individuals that produce legal or similarly significant effects based solely on automated processing of user account data.

Where the platform provides automated assistance – for example text recognition, detection or search – the results are suggestions to support human review, not determinations. Every decision about what is redacted, withheld or disclosed is made by the customer’s own reviewers, and the customer remains the data controller responsible for those decisions, subject to its own safeguards and human oversight.

9. Cookies

The Redaktr platform uses cookies that are strictly necessary for it to function, such as maintaining your login session and keeping the platform secure. These do not require consent. Where our website uses any non-essential cookies (for example, analytics), we will only set them on the basis of the applicable consent or opt-out requirements under the Privacy and Electronic Communications Regulations (PECR), as updated by the Data (Use and Access) Act 2025.

10. Data retention

Customer-loaded data

Customer-loaded data is retained for the duration of the case and, once a case is completed, for a period of up to 90 days during which the case remains on the system in an inactive state. At the end of that period the case and its contents are deleted.

Customers may instruct us to delete a case earlier at any point, and we will confirm the deletion in writing. Customers remain responsible for determining retention periods and deletion instructions, and for exporting anything they need to keep before deletion takes place.

User account data

User account data (such as name, email address, and related audit records) is retained for as long as the user account remains active and for a limited period thereafter for administrative, legal, and security purposes, after which it is securely deleted or anonymised.

11. Individual rights

Where Redaktr acts as a data processor, individuals should direct any rights requests (including access, rectification, or erasure) to the organisation that uploaded the data. We will assist that organisation in responding as required under our contract with them.

Where Redaktr acts as a data controller in respect of user account data, individuals have the right to:

  • be informed about how their personal data is used,
  • access their personal data,
  • request correction of inaccurate data,
  • request erasure where applicable,
  • object to or restrict processing where legally permitted,
  • request portability of data they have provided to us.

Requests can be made using the contact details above. We will respond within one month of receiving a valid request. To help us respond, we may need to verify your identity or ask you to clarify what you are looking for; where we reasonably do so, the time limit may be paused until we receive the information we need. We will carry out reasonable and proportionate searches to locate your data. If a request is complex or we receive a number of requests from you, we may extend this period by up to a further two months and will tell you if this is the case.

12. Complaints

If you have concerns about how your personal data is handled, we encourage you to contact us first at [email protected] so that we can try to resolve the matter. In line with the Data (Use and Access) Act 2025, we will acknowledge your complaint within 30 days and respond without undue delay.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at any time:

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

13. Changes to this notice

This privacy notice may be updated from time to time to reflect changes in legal requirements or our processing activities. This version has been updated to reflect the Data (Use and Access) Act 2025. The most current version will always be available on our website.