Legal

Privacy Policy

Last updated: 2026-07-13

This Privacy Policy explains how REDCLIFFE CONTENT PARTNERS LTD (“Redcliffe”, “we”, “us”, “our”) collects, uses, and protects information when you use our compliance intelligence platform at redcliffe.ai and app.redcliffe.ai (the “Service”).

REDCLIFFE CONTENT PARTNERS LTD is a private limited company registered in England and Wales under company number 15880789. Our registered office is 21 Dwyer House, 2 Townmead Road, London, England, SW6 2NZ. For privacy and data-protection matters, contact hello@redcliffe.ai.

Redcliffe is available through self-serve subscriptions, Enterprise agreements, and limited invitation-only evaluation arrangements. We process only the personal data we genuinely need to deliver and improve the Service, in line with applicable data protection laws including the UK and EU GDPR.

1. Information we collect

Information you provide directly

  • Account data — name, work email, phone number where provided, company, role, and any information you submit via invitation, sales, contact, or resource-download forms.
  • Content you submit — text, documents, URLs, and images you upload for Create or Review.
  • Project context — brand voice, terminology, and example materials you upload to help the Service draft regulated content.
  • Website review and monitoring data — domains, public URLs, inventory candidates, selected-page captures, change status, and linked review records where you use website workflows.
  • Machine-integration metadata — Agent Gateway client identifiers, scopes, job status, and webhook delivery metadata where an Enterprise integration is enabled.
  • Communications — emails and messages you send to us at hello@redcliffe.ai or support@redcliffe.ai.

Information we collect automatically

  • Identifier-free public funnel events — first-party page paths, page type, selected CTA destination, plan or billing choice, safe UTM tokens, and timestamps. These events do not contain names, contact details, account or user IDs, submitted content, raw IP addresses, raw referrers, user-agent strings, or browser fingerprints.
  • Anonymous public-site measurement — query-free public page paths, safe campaign tokens, browser and device category, viewport, web-performance metrics, masked click positions, and structural link or button clicks. An EU-hosted website analytics processor handles these events using memory-only browser persistence and a random anonymous identifier that is not used to identify a person, create a person profile, or follow someone across visits or domains. We do not send form values, text, element attributes, submitted content, account or user IDs, raw referrers, or raw IP addresses to this measurement dataset.
  • Service and security data — our hosting, authentication, and security providers may process technical request data such as IP address, browser or device information, and request logs to deliver and protect the Service.
  • Authentication tokens and session cookies used to keep you signed in.

2. How we use your information

  • To provide and operate the Service.
  • To process content you submit through the compliance engine and return findings, generated content, or change logs.
  • To maintain an auditable record of compliance activity.
  • To communicate with you about your account, service updates, and product changes, including commercial access where you submit a sales enquiry.
  • To provide a guide or other resource you have requested, and to send occasional analysis or product updates only where you separately opt in.
  • To improve the Service, including evaluating model performance, retrieval quality, reliability, and security.
  • To understand how aggregate audiences discover and use our public website and to improve its navigation, content, and performance.
  • To comply with legal obligations and enforce our Terms.

We do not use customer content to train public foundation models, and we do not submit your content to our AI providers as model-improvement feedback unless you explicitly ask us to do so.

Account-specific feedback may be used to improve your own Redcliffe experience. We may also use content-free operational signals and aggregated patterns to improve reliability, but we do not move submitted or generated copy, reviewer comments, source spans, brand context, or sign-off identities into another customer's account or a shared customer-content training corpus.

Routine Redcliffe support and administration is designed to use account, usage, access, and audit metadata rather than customer content. If customer-content access is needed for a specific support request, security incident, legal obligation, or regulatory obligation, access is limited, reasoned, time-bound, and logged.

3. Legal bases (UK / EU GDPR)

We process personal data on the following legal bases: performance of a contract (to deliver the Service you have requested), legitimate interests (to operate, secure, and improve the Service), consent (where explicitly requested, e.g., marketing emails), and compliance with legal obligations.

4. Sharing and processors

We do not sell your personal data. We share it only with service providers (“processors”) acting on our instructions. These include:

  • Secure cloud infrastructure providers — hosting, database, authentication, content delivery, and file storage.
  • AI service providers — compliance analysis, drafting, retrieval, matching, search, web fetch, and vision features where you use them.
  • Payment processors — subscription billing, payment processing, invoices, applicable taxes, cancellations, and refunds.
  • Transactional email providers — service emails, account notifications, and requested support or commercial replies.
  • Public-site analytics providers — anonymous public-site analytics, query-free page performance, masked heatmaps, and aggregate public interaction measurement hosted in the European Union. These providers do not receive customer-submitted compliance content through this integration.

Each processor is bound by applicable data-processing terms and safeguards. Current subprocessor and processing-location information is available to customers and qualifying prospective customers through a data-processing or security review. See Trust & Securityfor Redcliffe's public commitments.

5. International transfers

Some processors are based outside the UK and EEA. Where personal data is transferred internationally we rely on appropriate safeguards, such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses where applicable.

6. Retention

We retain personal data only as long as necessary for the purposes described above, to comply with legal obligations, or to resolve disputes. Audit-trail records associated with compliance reviews may be retained for the lifetime of the related project, and some records may be preserved where needed for security, legal, or dispute-resolution purposes.

Identifier-free public funnel events are retained for no more than 13 months. They are aggregated for product and commercial decision-making and are not used to build visitor profiles or follow a person across sessions or domains.

Anonymous public-site measurement is retained for no more than 12 months. Heatmaps and automatic interaction capture are disabled on contact, sales, and access-request forms and throughout authenticated product routes. Session replay, user identification, console-log capture, network-payload capture, and automatic error capture are disabled.

7. Your rights

Under UK and EU GDPR you have the right to access, rectify, erase, and port your personal data, to restrict or object to processing, and to withdraw consent at any time. To exercise any of these rights, contact us at hello@redcliffe.ai.

8. Security

We use industry-standard technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and security monitoring. No system is perfectly secure; where required by law, we will notify affected users without undue delay in the event of a personal data breach.

9. Cookies

We use a small number of essential cookies for authentication and access control. Our public funnel and public-site measurement do not use analytics cookies, local storage, session storage, advertising IDs, or a persistent or cross-domain visitor identifier. See our Cookies notice for details.

10. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent version. Material changes will be communicated via email or in the Service.

11. Contact

Questions about this Privacy Policy or our data practices can be sent to hello@redcliffe.ai.