Redule - Agentic AI OS
Redule - Agentic AI OS
  • Core
  • Agents
  • Solutions
    • 🏢
      Real EstateBrokerages & NRI investors
    • 🏥
      HealthcareClinics & practices
    • 🎓
      Study AbroadImmigration consultants
    • 📚
      Coaching CentersTraining institutes
    • 🛍️
      Retail & E-commerceShops & D2C brands
    • 🏋️
      Fitness & WellnessGyms & studios
  • Voice AICOMING SOON
  • Pricing
  • Blog
  • FAQ
Home / Data Processing Agreement

Data Processing Agreement

Last updated: 13 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Redule FZ LLC ("Processor") and the customer ("Controller") and governs the processing of personal data through the Redule platform.

1. Roles

The Controller determines the purposes and means of processing personal data. Redule acts as Processor, processing personal data only on the Controller's documented instructions, including those set out in this DPA and the Terms of Service.

2. Scope of processing

Redule processes personal data such as contact details, conversation history, and lead information that the Controller submits or connects to the platform, in order to provide the contracted services — including messaging, AI-assisted conversation, lead scoring, and follow-up automation.

Where the Controller connects a Facebook or Instagram Page, this includes lead form submissions retrieved from Meta on the Controller's behalf (typically name, phone number, email address, and the Controller's custom form answers).

3. Processor obligations

Redule will:

  • Process personal data only on documented instructions from the Controller
  • Ensure personnel with access are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in responding to data subject requests
  • Notify the Controller without undue delay of any personal data breach
  • Delete or return personal data at the end of the engagement

4. Security measures

Redule implements appropriate technical and organisational measures, including:

  • Encryption in transit using TLS/HTTPS across the platform
  • Encryption of sensitive credentials and access tokens at rest
  • Role-based access controls, so users only access data within their own workspace
  • Tenant isolation between customer workspaces
  • Audit logging of key actions within the platform
  • Regular backups and monitored error alerting

These measures are reviewed and improved over time. No system is completely secure, and Redule does not warrant absolute security.

5. Sub-processors

The Controller authorises Redule to engage the following sub-processors, each bound by written terms imposing equivalent data-protection obligations:

  • Anthropic — AI processing of conversations and lead data (scoring, summaries, suggested replies)
  • Bird (MessageBird) — delivery of WhatsApp, Instagram, and Facebook messages
  • Stripe — payment processing (billing data only; no customer lead data)
  • Hosting provider — storage and operation of the platform infrastructure

Redule remains responsible for sub-processor performance and will provide reasonable notice before adding or replacing a sub-processor.

6. International transfers

Personal data may be processed in the jurisdictions where Redule and its sub-processors operate. Where international transfers occur, they are conducted under appropriate safeguards consistent with applicable law, including the UAE Personal Data Protection Law and, where applicable, India's Digital Personal Data Protection Act, 2023.

7. Data subject rights

Redule will assist the Controller, by appropriate technical and organisational measures, in fulfilling obligations to respond to data subject requests for access, rectification, erasure, restriction, portability, and objection.

8. Audits and information

Redule will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and reasonable scheduling. Redule will respond to reasonable security questionnaires from the Controller.

9. Breach notification

In the event of a personal data breach, Redule will notify the Controller without undue delay and provide information reasonably required for the Controller to meet its own notification obligations.

10. Deletion and return

Upon termination, Redule will, at the Controller's choice, delete or return personal data within 90 days, save where retention is required by law. The Controller may request deletion of specific data at any time by emailing info@redule.com; such requests will be actioned within 30 days.

11. Meta Platform data

Where the Controller connects a Meta (Facebook/Instagram) Page, Redule's handling of data received from Meta APIs adheres to Meta's Platform Terms and Developer Policies. Lead data retrieved from Meta is used solely to enable the Controller to contact and follow up with those leads, is never sold or shared with other customers or third parties for their own purposes, and can be stopped at any time by disconnecting the Page from Settings → Integrations.

12. Contact

For data protection matters, contact Redule FZ LLC, Dubai, United Arab Emirates, at info@redule.com.

Redule - Agentic AI OS
Redule - Agentic AI OS

The AI-assisted CRM for regulated sales. AI agents for WhatsApp, Instagram and Facebook. Lead scoring and follow-ups in 20 languages. Built in Dubai, deployed worldwide.

REDULE FZ LLC
Dubai Free Zone, UAE · Founded 2023
info@redule.com
Products
VisaVaultEstateOSVoice AIDebtZero
Platform
ai agentsArchitectureIntegrationsPricing
Enterprise
SecurityDPATermsStatus
Company
AboutBlogCareersContact
© 2026 Redule FZ LLC · Built in 🇦🇪 Dubai, serving the world
PrivacyTermsDPARefund