RedactNode
Legal

Privacy Policy

Last updated: 28 July 2026

This policy describes how RedactNode ("we", "us") handles data when your organisation deploys the Safe Zone Portal, Tanda Gateway, and Tanda Guard products (together, the "Service"). It is written to match what the Service actually does, not generic boilerplate.

What we mask, and what we never see

When you send a prompt through the Safe Zone Portal, Tanda Gateway scans it for Malaysian-specific identifiers — MyKad numbers, phone numbers, bank account numbers, and matriculation IDs — before the prompt ever reaches an external AI provider. Detected values are replaced with placeholder tokens and the real values are held in a bounded, temporary Redis mapping, solely to restore them inside the protected workflow once the AI's response comes back. The deployment controls the retention window; the current default is 60 seconds.

Raw prompt content is not written to audit content. The audit log records a cryptographic digest of each prompt, detected categories, and masked conversation detail where the audit workflow requires it — never the underlying raw value.

What we do store

  • Account information for people who log into the portal (email address, hashed password).
  • Audit log entries: a prompt hash, the categories of PII detected, and a timestamp.
  • Standard operational logs (request timing, error rates) with PII already masked before logging.

Third-party AI providers

Masked prompts are forwarded to the AI provider your organisation has configured (for example DeepSeek or Google AI Studio). That provider processes only the masked version — it never receives your organisation's raw MyKad numbers, banking details, or other configured PII categories. Review your chosen provider's own data handling terms, particularly if it processes data outside Malaysia.

Data retention

Token-to-value mappings live in Redis for the configured bounded window. Audit log entries are retained according to your organisation's configured retention period (90 days by default on paid plans) and can be exported or purged by your administrator at any time from the Compliance Dashboard.

Your rights

If your organisation is subject to Malaysia's Personal Data Protection Act (PDPA), your administrator or Data Protection Officer is the right contact for data subject access, correction, or deletion requests, since we do not retain the underlying personal data ourselves. For questions about this policy, contact privacy@redactnode.ai.

Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and notify administrators of material changes directly.