How Raidu collects, uses, and protects personal information.
This Privacy Policy describes how Raidu Inc. (“Raidu”, “we”, “us”) handles personal information collected through our public website at raidu.com and any sub-domains, our marketing communications, and our products (the “Services”).
This policy does not cover the in-product processing of customer end-user data through the Raidu AI Firewall, AI Console, or Governance Explainability products. Raidu software runs inside each customer’s own cloud, and that data is never transmitted to Raidu. The terms that govern personal data in the customer relationship are set out in our Data Processing Addendum, and the third parties involved are listed on our Sub-processors page.
If you are an end user of one of our customers, please refer to that customer’s privacy notice for information about how your data is processed.
If you authenticate using a third-party identity provider such as Google, the provider shares profile information with us according to your privacy settings on that platform. We typically receive your name, email, and a unique identifier.
When you visit raidu.com or use the Services, we automatically collect:
We use the information described above for the following purposes:
We do not sell personal information.
We share personal information with the following categories of recipients:
We will not share your personal information with third parties for their own marketing purposes without your consent.
Depending on where you live, you may have the following rights regarding your personal information:
To exercise any of these rights, email us at the address in section 11. We will respond within the timeframe required by applicable law.
You can also:
Raidu is headquartered in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our service providers operate. We rely on standard contractual clauses or other approved mechanisms to transfer personal information out of the European Economic Area, the United Kingdom, and Switzerland. Section 13 of our Data Processing Addendum sets out the clauses, modules, and options we rely on, together with the UK Addendum and the Swiss modifications.
We employ administrative, technical, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit, access controls, audit logging, and a SOC 2 Type II program in progress. No system is perfectly secure; we cannot guarantee the security of information in transit or at rest.
We retain personal information for as long as is necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Marketing engagement data is retained for up to 24 months from your last interaction. Account data is retained for the life of your account and a reasonable period thereafter. Audit logs and security records may be retained for longer periods as required by law or contractual obligations.
The Services are intended for businesses and their employees and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can delete it.
We may update this Privacy Policy from time to time. The effective date at the top of this page reflects the most recent change. For material changes, we will provide a more prominent notice through the Services or by email, where appropriate. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
For questions, requests, or complaints relating to this Privacy Policy, contact:
Raidu Inc. Privacy Lead, acting Data Protection Officer: Ali Sarafzadeh Email: privacy@raidu.com Website: raidu.com
Raidu has not appointed a formal Data Protection Officer under Article 37 GDPR. Raidu is not a public authority, and its core activities involve neither large-scale regular and systematic monitoring of data subjects nor large-scale processing of special categories of data, so the Article 37(1) threshold is not met. The Privacy Lead named above discharges the equivalent responsibilities and is the point of contact for data subjects and supervisory authorities. We review this position at least annually. Section 17 of our Data Processing Addendum sets out the full reasoning.