Legal

Privacy Policy

Last updated: September 29, 2026

Redan Compliance LLC, a Florida limited liability company (“Redan,” “we,” “us,” or “our”) operates the compliance platform available at redancompliance.com. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services.

1. Information We Collect

Account information. When you create an account, we collect your name, email address, firm name, and role. This information is required to provision your firm's workspace and manage user access.

Firm data. Data you upload to the platform — marketing materials, evidence files, CCO determination records, vendor due diligence questionnaires, and training records — is your firm's data. We process it on your behalf as a data processor.

Usage data. We collect log data including pages visited, actions taken, timestamps, and IP addresses to maintain service integrity and support your account. This data is used for security monitoring and product improvement.

Cookies and analytics. We use a product analytics provider throughout the platform and website. If you are browsing this marketing website without an account, that provider also records your session — page views, clicks, and on-screen behavior — to help us understand how visitors use the site. Form inputs are masked before capture. Session recordings are kept for 30 days; analytics events are kept for up to 84 months. Session recording is turned off inside the authenticated application — it does not run once you have signed in, and it is never used to capture anything you or your firm upload or write on the platform. We use functional cookies required for authentication and session management.

2. How We Use Your Information

We use the information we collect to: provision and operate your firm's workspace; authenticate users and enforce access controls; provide customer support; send transactional emails (account notifications, security alerts); and improve the platform.

We do not sell your data. We do not use your firm's compliance data to train machine learning models without explicit written consent.

3. Data Storage and Security

Your data is stored in a managed PostgreSQL database on U.S. cloud infrastructure and served via a global edge network. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

WORM compliance. Evidence files, audit log entries, and CCO determination records are stored as INSERT-only (Write Once, Read Many). Once written, these records cannot be altered or deleted — this is an architectural property of the platform, not just a policy. This behavior is enforced at the database policy layer and is a feature, not a limitation. It mirrors the record standards that SEC examiners expect.

Redan has self-assessed its own controls against the SOC 2 Type I criteria. We have not engaged an independent auditor and do not hold SOC 2 certification. The infrastructure providers we rely on for hosting and database services are independently SOC 2 Type II certified.

4. Data Retention

We retain your account data for as long as your subscription is active and for a reasonable period thereafter to comply with legal obligations. Evidence files and audit records stored under WORM policies are retained for the life of your account and cannot be selectively deleted.

Upon account termination, we will provide a data export upon request within 30 days. After 90 days following termination, account data may be permanently deleted from production systems.

5. The Redan MCP

The Redan MCP puts Redan's SEC knowledge base inside an assistant you already use. You paste a link we email you into Claude or ChatGPT, and then you ask it questions. A firm that gives Redan its policy manuals and fund documents can also have its people ask about those, and about the firm's public record. This section is about the MCP. The rest of this policy is about the rest of the platform.

Your firm's documents. A question about your documents is answered from your firm's records and nobody else's. The firm is fixed by the person asking, never by anything they type. Your documents are only ever read, never changed, and no link, free or firm, reaches them. Each person at your firm is given their own access to them instead.

Another firm asks for your gifts policy by its exact section number. It gets nothing back.

What we keep depends on which link you are using. On a link issued to your firm, each time you ask the MCP something we write down what you asked and the whole answer you got back. On a free link we keep neither. Not the question, not the answer, and not a stripped-down version of either. On every call, free or not, we record which tool ran, how long it took, how long the answer was when there was one, whether it failed, and what it cost us to run. We also record which link was used and whether it arrived in a header or in the URL. A call we turned away is written down as well. On a firm link, a very long answer is stored cut off at 200,000 characters, and the record says where it was cut.

You ask, “does a standing letter of authorization trip custody?” On a firm link we store that sentence, the answer that came back, and the fact that the knowledge-base search was what ran. On a free link we store that a knowledge-base search ran, how long it took and what it cost us — and nothing you typed.

We cannot take it back out. That record is write-once, the same as the rest of Redan's evidence. The database refuses to change it and refuses to delete it. The time on it is set by our server, not by your assistant. So on a firm link, treat an MCP question as a record you are creating.

On a firm link, if you put a client's name into a question by mistake, it stays there. Nobody at Redan can pull it out, and neither can we on your behalf. On a free link there is nothing to pull out, because the question was never written down.

Who can see it. Nobody at your firm can read the questions asked through the MCP. Not a colleague, not an administrator, and not the person who asked. The database enforces that, not a setting. Redan staff running the service can read a firm link's record. Free links work differently. The record of a free-link call belongs to one shared Redan account rather than to your firm, and it holds no question and no answer, so there is nothing in it for anyone to read back.

Your firm's CCO cannot pull up what you asked the MCP, and you cannot pull up what the CCO asked. On a firm link, Redan can. On a free link nobody can, because it was never kept.

How long we keep it. Indefinitely. Nothing in the platform deletes an MCP record, and the database would refuse if something tried. This is the same as the evidence records in section 4.

If something goes wrong. If a breach affecting your firm's data is confirmed, we notify you in writing within 24 hours of discovery.

What we read them for. We read them to run the service and to fix the knowledge base. On a firm link, when the MCP answers a question badly or answers one it should have refused, that record is how we find out, because somebody at Redan can read the question and the answer back. A free-link record holds neither, so it cannot tell us that. What it can tell us is that a call ran, or failed, and how often. We do not train a model on your questions. Three pieces of code read that table: one counts failures each day, one adds up what each link has spent, and one draws an internal admin screen. None of the three reads a question or an answer. Section 2 above applies here as it does everywhere else.

On a firm link, eight questions in a row come back with nothing useful on off-channel communications. That tells us a shelf of the knowledge base is thin, and we go and fill it. The same eight on free links tell us only that eight searches ran.

What leaves Redan. Your question, and only when you search the knowledge base. It goes to an approved outside provider twice. Once to reword it into the language the rulebook uses, so the search can find the right rule. Once to check whether the rules that came back actually answer you. That second call also sends the rule text itself, which is public SEC material we already hold. Nothing else of your firm's goes with it. Not your policy manuals or fund documents, not your marketing materials, not your evidence files, not a compliance record, not your firm name, not a user record. Your own words do go, so if you quote one of your policies in the question, that quote goes too. The search itself runs inside Redan's own database. Searching your firm's own documents sends nothing to an outside provider.

You ask about text-message retention. What goes out is that sentence, and then the rule paragraphs the search found. Your firm's name is in neither one.

Your link. A link works for 180 days and then stops. The email that delivers it tells you the date. We store only a scrambled copy of it, so we cannot read your link back to you or send you the one you already have. If you lose it, sign up again. You get a new link, and the old one stops working the first time you use the new one. Nothing renews a link on its own. If your firm has an account, an administrator can replace a link whenever they want, and the old one dies the moment the new one is issued. On a free link, write to us and we will switch yours off.

You delete the email with your link in it. We cannot look it up for you. Signing up again is the only way to get one.

Your email address. Signing up for a free link records your address as a marketing lead. That is how we follow up with you. Every email we send about it has an unsubscribe link in it.

You sign up on a Tuesday, and someone at Redan may email you later that week. Click unsubscribe and that stops.

6. Third-Party Service Providers

We use service providers in the following categories to operate the platform:

  • Cloud hosting and database infrastructure — database, authentication, and file storage
  • Application delivery — application hosting and edge delivery
  • Product analytics — platform-wide product analytics; session recording on this marketing website only (30-day retention), never inside the authenticated application
  • Error monitoring — PII scrubbed before transmission

Each provider has been selected for their data security posture and compliance certifications. A full named list is available under your firm's Data Processing Agreement.

7. Your Rights (GDPR / CCPA)

If you are located in the European Economic Area or California, you have rights regarding your personal data, including the right to access, correct, or request deletion of your personal account information (subject to WORM constraints on compliance records, which cannot be deleted by design). We do not sell or share your personal information.

We share personal information with service providers in the following categories: cloud hosting and database infrastructure, application delivery, automated document analysis, transactional email delivery, product analytics, and error monitoring. Each acts on our instructions and does not use your information for its own purposes.

To exercise these rights, contact us at privacy@redancompliance.com. We will respond within 30 days.

8. Children's Privacy

Redan is a business-to-business compliance platform intended for use by investment adviser firms and their employees. We do not knowingly collect personal information from anyone under the age of 18.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify account administrators by email of material changes at least 30 days before they take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

10. Contact

For privacy-related inquiries, contact us at: privacy@redancompliance.com