Last updated: 20 March 2026
Redactly is the data controller for personal data collected through the Redactly platform. You can contact us at support@redactly.co.uk.
For documents uploaded to Redactly for processing, we act as a data processor on behalf of your organisation (the data controller). This policy covers both roles.
When you use Redactly, we collect:
We do not collect payment card details directly. Payments are handled by Stripe, who are subject to their own privacy policy.
We use your data to:
We do not use your documents or their contents to train AI models, and we do not sell your data to third parties.
We process your data on the following legal bases under UK GDPR:
Redactly uses the following third-party processors:
Each processor is contractually bound to process data only on our instructions and in accordance with UK GDPR requirements.
Document retention periods are configured by your organisation admin within the platform, subject to minimum periods aligned with the ICO complaint window (90 days minimum for unredacted originals). Default retention settings are 3 years for unredacted originals and 6 years for redacted records, in line with the Limitation Act 1980 and typical LGRSS FOI records schedules.
Account data is retained for the duration of your organisation's subscription. On account closure, data is deleted within 90 days unless a longer retention period is required by law.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at support@redactly.co.uk. We will respond within 30 days.
Redactly uses essential cookies only: session cookies required to keep you signed in. We do not use tracking, advertising, or analytics cookies without your explicit consent. You can manage your cookie preferences via the banner shown on your first visit.
We protect your data using encryption in transit (TLS) and at rest, row-level security on all database tables, and strict access controls. All document processing is performed server-side; unredacted content is never exposed to client-side code after finalisation.
If you have concerns about how we handle your data, please contact us first at support@redactly.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice. The date at the top of this page reflects when the policy was last updated.