This Data Processing Agreement ("DPA") forms part of the agreement between Redule FZ LLC ("Processor") and the customer ("Controller") and governs the processing of personal data through the Redule platform.
The Controller determines the purposes and means of processing personal data. Redule acts as Processor, processing personal data only on the Controller's documented instructions, including those set out in this DPA and the Terms of Service.
Redule processes personal data such as contact details, conversation history, and lead information that the Controller submits or connects to the platform, in order to provide the contracted services — including messaging, AI-assisted conversation, lead scoring, and follow-up automation.
Where the Controller connects a Facebook or Instagram Page, this includes lead form submissions retrieved from Meta on the Controller's behalf (typically name, phone number, email address, and the Controller's custom form answers).
Redule will:
Redule implements appropriate technical and organisational measures, including:
These measures are reviewed and improved over time. No system is completely secure, and Redule does not warrant absolute security.
The Controller authorises Redule to engage the following sub-processors, each bound by written terms imposing equivalent data-protection obligations:
Redule remains responsible for sub-processor performance and will provide reasonable notice before adding or replacing a sub-processor.
Personal data may be processed in the jurisdictions where Redule and its sub-processors operate. Where international transfers occur, they are conducted under appropriate safeguards consistent with applicable law, including the UAE Personal Data Protection Law and, where applicable, India's Digital Personal Data Protection Act, 2023.
Redule will assist the Controller, by appropriate technical and organisational measures, in fulfilling obligations to respond to data subject requests for access, rectification, erasure, restriction, portability, and objection.
Redule will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and reasonable scheduling. Redule will respond to reasonable security questionnaires from the Controller.
In the event of a personal data breach, Redule will notify the Controller without undue delay and provide information reasonably required for the Controller to meet its own notification obligations.
Upon termination, Redule will, at the Controller's choice, delete or return personal data within 90 days, save where retention is required by law. The Controller may request deletion of specific data at any time by emailing info@redule.com; such requests will be actioned within 30 days.
Where the Controller connects a Meta (Facebook/Instagram) Page, Redule's handling of data received from Meta APIs adheres to Meta's Platform Terms and Developer Policies. Lead data retrieved from Meta is used solely to enable the Controller to contact and follow up with those leads, is never sold or shared with other customers or third parties for their own purposes, and can be stopped at any time by disconnecting the Page from Settings → Integrations.
For data protection matters, contact Redule FZ LLC, Dubai, United Arab Emirates, at info@redule.com.