REDOXY · REDOXY privacy policy
Privacy explained around the actual REDOXY workflow.
This notice explains how REDOXY handles personal information across the website, requirements, WhatsApp, email, Odoo and protected workspaces.
Effective: 21 August 2026
Who is responsible and what this notice covers.
Redoxy - F.Z.C (REDOXY FZC), licence and registration number 46786, Office C1-1F-SF13927, C1 Building, Ajman Free Zone, Ajman, United Arab Emirates, is the controller of the public website and the personal information collected through its general digital channels. REDOXY is the unified customer-facing brand. If another operating entity independently determines how information is used for a specific engagement, that entity will be identified in the relevant contract or notice.
This policy covers redoxy.co, public requirement and contact routes, customer and administration workspaces, WhatsApp Business communications, email exchanges, Odoo-connected commercial records, published document access and related support. It does not replace a project-specific privacy, employment or supplier notice where one is supplied.
Information REDOXY may collect.
The information depends on how you interact with REDOXY. You may browse without identifying yourself, but a requirement, account or business exchange needs enough detail to route and respond accurately.
- Identity and business contact details, such as name, company, role, email, telephone number, country and preferred contact channel.
- Requirement and commercial context, including service or product, site and industry context, quantities, specifications, incoterms, urgency, location, delivery window, attachments and correspondence.
- Account and security information for protected workspaces, including authentication token, role, session, access event, browser user-agent, a security-derived network fingerprint, and security or MFA status. Rate limiting can temporarily use the connecting IP address in server memory.
- Communications through forms, email, telephone and WhatsApp, including the content and files you choose to send and delivery metadata made available by the channel.
- Technical and reliability data, such as page path, browser or device category, approximate region, performance measurements and browser-error messages. REDOXY does not use this website telemetry for advertising profiles.
- Document and publishing records, including uploaded media, controlled evidence requests, approval state and access history where the relevant function records it.
Why information is used.
REDOXY uses personal information only for defined business, security and legal purposes. Depending on the interaction and applicable law, processing is based on consent, steps requested before a contract, performance of a contract, compliance with a legal obligation, or another basis permitted by the law governing that processing.
- Receive, qualify, route and respond to engineering, trading, procurement, logistics, product and document-access requirements.
- Prepare quotations, coordinate delivery, maintain project communications and administer customer, supplier or partner relationships.
- Operate Odoo-connected commercial records, email delivery, WhatsApp follow-up and protected workspaces.
- Protect accounts, investigate misuse, maintain audit evidence, diagnose failures and keep the website and connected services reliable.
- Meet accounting, tax, sanctions, due-diligence, regulatory, dispute, recordkeeping and other lawful obligations.
- Send a marketing communication only where the required consent or other permission exists, identify the sender, and provide a practical way to stop future marketing. Operational replies about a requirement are not marketing.
The main website activities and their data routes.
This map connects the current public functions to their purpose and destination. A project or regulated engagement may add a more specific notice or contract schedule.
- Requirement intake
- Identity, contact and requirement details are stored in website intake and enterprise RFQ records to qualify and respond. A configured Odoo connection and notification-email service may also receive the record.
- WhatsApp continuation
- After a requirement, the website can generate a pre-filled WhatsApp link. Nothing is sent to Meta or WhatsApp by that link unless you choose to open WhatsApp and continue there.
- Protected workspaces
- Account, role, session and security data support authentication, access control, MFA, audit and misuse prevention. Browser tokens are kept in local storage.
- Downloads and uploads
- Document metadata, approval state and authorized uploads support controlled publishing and access. Only records explicitly released for public access are shown as public downloads.
- Analytics and reliability
- On hosted deployments, Vercel Web Analytics and Speed Insights measure aggregate traffic and performance. REDOXY also receives limited browser-error events for reliability and security diagnosis.
How the website connects to business systems.
A submitted website requirement is stored in REDOXY intake and enterprise RFQ records. It may also be synchronized to Odoo where configured and sent to a REDOXY notification address through an email service. The response can include a WhatsApp continuation link for you to open; the website does not automatically send that pre-filled message to WhatsApp.
Protected workspaces store an authentication token in local browser storage. Server expiry or revocation makes the token unusable, but the browser value may remain until logout, browser clearing, or application cleanup after an invalid session. The site separately remembers a temporary motion preference in session storage.
On REDOXY and Vercel-hosted domains, Vercel Web Analytics and Speed Insights provide aggregate usage and performance measurement. The current application code does not install Meta Pixel or another advertising pixel. Browser-error telemetry sends a page path, error type and technical message to help diagnose failures; do not place confidential or personal information in browser URLs.
Regional and international processing.
REDOXY operates across the GCC. The public website is hosted through Vercel; configured email delivery, Odoo and Meta/WhatsApp services use their own regional or international infrastructure. Information may therefore be processed outside the country from which it was submitted.
The applicable provider, processing location and transfer basis can vary by channel and configuration. REDOXY will provide available information about the route relevant to a verified request, subject to security and confidentiality limits, and will use an international route only where permitted by the law governing that processing.
How long information is kept.
The current system does not apply one automatic deletion timer to every RFQ, enterprise record, email, Odoo record or uploaded file. Retention is reviewed by record type and may continue while a requirement or relationship is active and for applicable contract, accounting, tax, regulatory, security, dispute or legal-hold needs.
Session-storage preferences normally end with the browser tab or session. Server-side authentication sessions expire or can be revoked, although a browser token may remain locally until logout, clearing, or application cleanup. A verified privacy request triggers a manual retention and deletion review; it does not override a lawful recordkeeping duty or independently erase copies controlled by another provider.
Privacy rights and requests.
Subject to applicable law and any valid exception, you may ask to access, correct, update, delete, restrict or stop certain processing; obtain a portable copy where the right applies; object to permitted direct marketing or other processing; withdraw consent without affecting earlier lawful processing; and ask for review of a significant solely automated decision if such a decision is used.
REDOXY may ask for proportionate information to verify identity, authority and the records concerned. Requests are reviewed manually through the privacy contact. If Saudi Arabia's Personal Data Protection Law governs the request, REDOXY will handle it without undue delay and within 30 days, subject to a justified extension permitted by that law and notice to the requester. Other jurisdictions may apply a different period.
If a request cannot be completed, REDOXY will explain the applicable reason where the law permits. You may also complain to the competent authority, including the Saudi Data & AI Authority where Saudi law applies or the competent UAE data-protection authority where UAE law applies.
Security and incident response.
The current website uses HTTPS in hosted production, authenticated workspaces, role controls, optional MFA controls, request rate limits, security-session records and application logging. No internet system can be guaranteed completely secure.
If REDOXY identifies a personal-data incident, it will contain and assess the incident and make notices required by applicable law. Report a suspected account or privacy incident promptly and do not send passwords or one-time codes by email or WhatsApp.
Children, third-party sites and external channels.
The REDOXY website is a business service and is not directed to children. REDOXY does not knowingly seek personal information from anyone under 18 through the public website.
External websites and services—including WhatsApp, map links and customer or supplier platforms—operate under their own notices and controls. Review those notices before using the external service.
Policy changes and privacy contact.
REDOXY may update this policy when the website, providers, legal requirements or business processes change. The effective date and public page will be updated, and a more prominent notice will be used when required.
For a privacy question, rights request or complaint, email remiz@redoxyksa.com. For a general business requirement, email info@redoxyksa.com.