In force since August 17, 2026
Effective: 17.08.2026 Version 1.2
The controller responsible for the processing of personal data described in this Privacy Policy is:
redact.al DOOEL
Vehbi Dibra Br. 70
1250 Debar
Republic of North Macedonia
Email: info@redact.al
redact.al has been designed according to the principle of Privacy by Design.
Document contents processed through the standard redact.al application are analysed and modified locally within your browser.
The texts and documents you process, recognised entities and the mapping table between original information and pseudonyms ("Vault") are not transmitted to redact.al or its service providers as part of the standard document-processing functionality.
The Named Entity Recognition ("NER") model is downloaded to your browser and performs document analysis locally. The text being analysed is not transmitted to our servers for NER processing.
Under the current architecture of the Service, redact.al does not have server-side access to document contents processed locally in your browser.
When you register for and use redact.al, we may process:
Where a trial is configured to convert automatically into a paid subscription, we may retain evidence of the Customer's contractual acceptance of that conversion, including the applicable terms, time of acceptance and IP address.
When acceptance of the Terms and Conditions must be documented, we may retain the accepted version, time of acceptance and IP address used.
Legal basis: Art. 6(1)(b) GDPR where processing is necessary for entering into or performing a contract.
Where records are retained after the end of the contractual relationship for the establishment, exercise or defence of legal claims, the legal basis is Art. 6(1)(f) GDPR.
Where retention is required by applicable accounting, tax or other law, the legal basis is Art. 6(1)(c) GDPR.
We process information relating to the Customer's access entitlement, including:
This information is used to determine whether a user is entitled to access the Service.
Access may be re-checked on sign-in and following periods of inactivity.
Document contents are not involved in this access check.
Legal basis: Art. 6(1)(b) GDPR.
When our servers are accessed, technical access data may be recorded in server log files, including:
This data is processed to operate the Service securely, diagnose technical problems and detect attempted attacks or abusive access.
Full server access logs are automatically deleted within a maximum of 24 hours.
We do not use full server logs for advertising, user profiling or behavioural analytics.
IP addresses contained in standard server access logs are not intentionally linked to user accounts for analytics or marketing purposes.
Legal basis: Art. 6(1)(f) GDPR, based on our legitimate interest in maintaining the security, stability and integrity of the Service.
We use technical security measures, including fail2ban, to protect our infrastructure against automated attacks, repeated unauthorised access attempts and similar abusive activity.
fail2ban evaluates relevant server log information during the server-log retention period.
Where abusive behaviour is detected, the relevant IP address may be added to a firewall block list.
The firewall block list contains:
The firewall block list does not intentionally associate blocked IP addresses with document contents.
Depending on the severity and frequency of detected abusive activity, an IP address may remain blocked for up to 365 days.
Legal basis: Art. 6(1)(f) GDPR, based on our legitimate interest in protecting the Service, our infrastructure and our users against abusive or malicious access.
If you contact us through our contact form or by email, we may process:
We use this information to respond to and manage your request.
Where your request concerns entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR.
For other enquiries, the legal basis is Art. 6(1)(f) GDPR, based on our legitimate interest in responding to enquiries and maintaining business communications.
If retention is required by law or is reasonably necessary for the establishment, exercise or defence of legal claims, the relevant records may be retained beyond completion of the enquiry.
To maintain account security and make security-relevant account activity traceable, we record certain events together with a timestamp.
These may include:
Where necessary to document confirmation of a security-relevant or contractual action, the IP address used for that action may also be stored.
Document contents, recognised entities and pseudonym mappings are not included in the audit log because those contents are not transmitted to our servers through the standard document-processing functionality.
Where an account provides a data export function, the export contains personal data relating to the requesting user. It does not provide information about unrelated users.
Legal basis: Art. 6(1)(f) GDPR, based on our legitimate interests in account security, abuse prevention, documenting security-relevant actions and demonstrating compliance.
Where an audit entry is necessary for performing the contract, Art. 6(1)(b) GDPR may also apply.
If you visit redact.al through a partner or referral link, the referral link may contain a referral identifier that indicates which partner referred you to redact.al.
The referral identifier is carried through the relevant referral journey and may be submitted together with an enquiry, trial request or other referral-enabled form.
redact.al does not use a referral cookie, localStorage, IndexedDB or another persistent identifier on your device for partner attribution.
We may process:
We use this information to:
Referral information is not used for behavioural advertising, cross-site tracking or profiling.
Legal basis: Art. 6(1)(f) GDPR, based on our legitimate interests in operating and administering our partner programme, accurately attributing customers and enquiries, calculating partner commissions and preventing referral abuse.
Through the standard browser-based document-processing functionality, redact.al does not receive:
Active documents may be stored locally in your browser using browser storage technologies such as IndexedDB so that refreshing the page or restarting the browser does not necessarily cause your work to be lost.
This locally stored information remains on the device and within the browser environment unless you or your browser remove it.
Under the current standard architecture, this document content is not transmitted to redact.al.
If you voluntarily provide document contents to us for a specific support or troubleshooting request, the processing of that information is treated separately as described in this Privacy Policy.
redact.al uses cookies and local browser storage only for the purposes described below.
redact.al uses a functional authentication cookie to maintain an authenticated session after sign-in.
The authentication cookie contains a session identifier and is used only as necessary to provide account access and maintain the signed-in session.
The authentication cookie is strictly necessary for the authenticated Service and does not require consent where applicable law provides an exemption for storage or access that is necessary to provide a service expressly requested by the user.
The associated processing of personal data is based on Art. 6(1)(b) GDPR where it is necessary to provide the Service.
Deleting the authentication cookie will normally end the signed-in session.
redact.al does not use cookies for partner or referral attribution.
redact.al does not use third-party advertising cookies, behavioural tracking cookies or third-party analytics cookies.
Partner attribution is handled through referral information carried in the referral journey and submitted server-side, as described in section 3.7.
Local browser storage, including IndexedDB, may be used for the local document-processing functionality described in section 4.
Document contents stored through this functionality remain locally within the browser environment and are not transmitted to redact.al through the standard document-processing functionality.
Local document storage is used only to support the document-processing functionality requested by the user.
The infrastructure used to provide redact.al is hosted by:
Hetzner Online GmbH Industriestr. 25 91710 Gunzenhausen Germany
Our production infrastructure, including hosting, backup and operational infrastructure described in this Policy, is currently hosted within the European Union.
For transactional emails, including account registration, password reset, access notifications and contractual notifications, we use:
IONOS SE Elgendorfer Str. 57 56410 Montabaur Germany
Transactional email may contain account, access or contractual information necessary for the relevant communication.
Where Hetzner or IONOS processes personal data on behalf of redact.al, we use contractual arrangements required by applicable data-protection law, including data-processing agreements where required.
Personal data may also be disclosed where reasonably necessary to:
We do not sell personal data to advertisers.
We do not disclose document contents processed locally through the standard redact.al application because those contents are not transmitted to us.
redact.al DOOEL is established in the Republic of North Macedonia.
The production infrastructure described in this Privacy Policy is currently hosted within the European Union.
Where personal data is transferred between North Macedonia and the European Union, or otherwise transferred internationally, redact.al handles such transfers in accordance with the applicable data-protection laws governing the relevant transfer.
Where the GDPR requires safeguards for a transfer of personal data outside the European Economic Area, we will use an applicable lawful transfer mechanism where required.
If our hosting locations, administrative access arrangements or international-transfer practices materially change, we will update this Privacy Policy accordingly.
We retain personal data only for as long as necessary for the purposes for which it is processed, subject to legal retention requirements and legitimate requirements relating to legal claims and security.
Unless a longer period is required or justified under applicable law, the following periods generally apply:
Where data is retained solely because of a legal obligation or for the establishment, exercise or defence of legal claims, it will no longer be used for unrelated purposes.
Certain personal data is required in order to create an account, enter into a contract and provide access to redact.al.
In particular, a valid email address is required for account creation, authentication, account communications and contractual administration.
There is generally no statutory requirement for you to provide an email address to redact.al.
However, without the information required to create and administer an account, we cannot enter into or perform a contract for use of the Service.
Where additional information is required for billing, tax or legal compliance purposes, failure to provide that information may prevent us from processing an order, issuing correct invoices or continuing the contractual relationship.
Referral information is not required in order to use the core redact.al Service.
redact.al does not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
We do not use personal data for advertising profiling.
Automated document analysis performed locally in the browser is used to assist with document processing and does not constitute an automated decision about the user for the purposes described above.
Referral attribution is used to identify the partner associated with an enquiry, trial or subscription and is not used to make automated decisions that produce legal or similarly significant effects concerning the user.
Depending on the processing activity, redact.al relies on one or more of the following legal bases:
Examples of our legitimate interests include:
References to a Customer accepting, approving or agreeing to contractual terms, automatic trial conversion or similar contractual matters refer to contractual acceptance and do not necessarily constitute consent to the processing of personal data under data-protection law.
We use technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include, where applicable:
Passwords are stored as cryptographic hashes rather than in plain text.
No method of transmission or storage can provide absolute security. We therefore review and adapt security measures where appropriate in light of technical developments and relevant risks.
Depending on the circumstances and subject to the conditions and limitations provided by applicable law, you may have the right to:
Where you object to processing based on Art. 6(1)(f) GDPR, we will assess the objection in accordance with applicable law.
These rights are not absolute and may be subject to statutory conditions, exceptions and retention obligations.
To exercise your rights, contact us at:
Email: info@redact.al
or write to:
redact.al DOOEL Vehbi Dibra Br. 70 1250 Debar Republic of North Macedonia
We may request information reasonably necessary to verify your identity before acting on a request.
You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe that the processing of your personal data infringes applicable data-protection law.
In the Republic of North Macedonia, the competent national data-protection authority is:
Agency for Personal Data Protection of the Republic of North Macedonia (AZLP)
Where the GDPR applies to the processing of your personal data, you may also have the right to lodge a complaint with a competent supervisory authority in the European Union, including in the Member State of your habitual residence, place of work or the place of the alleged infringement, as provided by applicable law.
You may also contact redact.al directly at info@redact.al so that we can review your concern.
We may amend this Privacy Policy to reflect changes in:
The current version will be made available through the redact.al website.
Where a change materially affects how we process personal data, we will provide additional notice where required by applicable law.
This Privacy Policy was originally drafted in English.
Translations may be provided for convenience.
Unless mandatory applicable law requires otherwise, the English-language version is the authoritative version.
Where translated versions are published, we aim to keep them consistent with the current English version.
In the event of a discrepancy between a translation and the English version, the English version prevails to the extent permitted by applicable law.
redact.al DOOEL
Vehbi Dibra Br. 70
1250 Debar
Republic of North Macedonia
Contact: info@redact.al