Legal

Privacy Policy

Last updated: 28 July 2026

This policy describes how RedactNode ("we", "us") handles data when your organisation deploys the Safe Zone Portal, Tanda Proxy, and Tanda Guard products (together, the "Service"). It is written to match what the Service actually does, not generic boilerplate.

What we mask, and what we never see

When you send a prompt through the Safe Zone Portal, Tanda Proxy scans it for Malaysian-specific identifiers — MyKad numbers, phone numbers, bank account numbers, and matriculation IDs — before the prompt ever reaches an external AI provider. Detected values are replaced with placeholder tokens and the real values are held in memory (Redis) for a maximum of 60 seconds, solely to restore them once the AI's response comes back. After that window, or once the response is returned, the mapping is deleted.

We do not store the content of your prompts. Our audit log records only a one-way cryptographic hash of each prompt and which categories of data were detected (e.g. "a MyKad number was found") — never the number itself, and never in a form that can be reversed back to the original text.

What we do store

  • Account information for people who log into the portal (email address, hashed password).
  • Audit log entries: a prompt hash, the categories of PII detected, and a timestamp.
  • Standard operational logs (request timing, error rates) with PII already masked before logging.

Third-party AI providers

Masked prompts are forwarded to the AI provider your organisation has configured (for example DeepSeek or Google AI Studio). That provider processes only the masked version — it never receives your organisation's raw MyKad numbers, banking details, or other configured PII categories. Review your chosen provider's own data handling terms, particularly if it processes data outside Malaysia.

Data retention

Token-to-value mappings live in Redis for up to 60 seconds. Audit log entries are retained according to your organisation's configured retention period (90 days by default on paid plans) and can be exported or purged by your administrator at any time from the Compliance Dashboard.

Your rights

If your organisation is subject to Malaysia's Personal Data Protection Act (PDPA), your administrator or Data Protection Officer is the right contact for data subject access, correction, or deletion requests, since we do not retain the underlying personal data ourselves. For questions about this policy, contact privacy@redactnode.ai.

Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and notify administrators of material changes directly.