How we treat your data.
This policy covers personal data TeraDact collects through this website and through commercial contact with us. It does not cover data processed inside a customer deployment of Redactor+, where the customer is the controller and TeraDact has no access to the content being redacted.
Last updated 25 August 2026.
Who we are
TeraDact is the controller for personal data collected through this website and through commercial contact with us. For anything in this policy, including subject access requests, write to bizdev@teradact.com.
Where a customer runs Redactor+ in their own environment, that customer is the controller for the material being redacted. TeraDact does not receive, store or process that content, because the models run locally inside the customer boundary.
What we collect
If you contact us or request a demo, we collect the details you give us: your name, work email, organisation, organisation type and whatever you write in the message field.
If you consent to analytics, we collect aggregate usage data about which pages are visited and how visitors move through the site. We do not build advertising profiles and we do not attempt to identify individual visitors from this data.
Why we use it, and our lawful basis
We use demo and contact details to respond to your enquiry and to carry out pre-contract discussions. Our lawful basis is legitimate interests, or the steps necessary to enter into a contract where you are asking us to quote or procure.
We use analytics only where you have given consent, which is our lawful basis for those cookies. Withdrawing consent is as easy as giving it.
International transfers
We operate in the UK, the EU, the US, Australia and Canada. Where personal data collected in the UK or EEA is transferred outside it, we rely on UK and EU adequacy decisions where they apply, and on Standard Contractual Clauses with the UK International Data Transfer Addendum where they do not.
Product deployments are a separate matter. Redactor+ is designed so that the data being redacted stays inside the customer environment, which means a deployment can be run entirely in-country with no transfer at all.
How long we keep it
Enquiry and demo correspondence is kept for up to 24 months from our last contact, unless a commercial relationship starts, in which case it is kept for the life of that relationship and any period required for tax and contractual records.
Analytics data is retained in aggregate form for up to 14 months.
Your rights
Under the UK GDPR and EU GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable form. Where processing relies on consent, you can withdraw it at any time.
To exercise any of these, write to bizdev@teradact.com. We will respond within one month. If you are not satisfied with our response, you can complain to the Information Commissioner's Office in the UK, or to your local supervisory authority in the EEA.
How we protect it
We hold ISO 27001 and SOC 2 certification, along with Cyber Essentials Plus, ISO 27017 and ISO 27018. Access to personal data is limited to the people who need it, and every access is logged.
Security questionnaires and DPIA packs are available on request.
Changes to this policy
If we change how we handle personal data we will update this page and revise the date at the top. Where a change materially affects you, we will tell you directly rather than relying on you to check.
Data protection enquiries, subject access requests and DPIA packs all go to the same place.