Privacy Statement
Privacy, built into how Redwood works
At Redwood, privacy is part of how our Products, Services, and business are designed and operated.
Our customers rely on Redwood to automate mission-critical business processes. That trust depends on handling Personal Data responsibly, securely, and transparently.
This Privacy Statement explains what Personal Data we collect, how and why we use it, when we share it, how we protect it, and your privacy choices and rights.
This Statement applies when Redwood processes Personal Data for its own purposes, including through our websites, marketing, sales, events, customer relationships, support operations, and certain Product usage.
When Redwood processes Personal Data on behalf of a Client, that processing is governed by the applicable Agreement and Data Processing Agreement (“DPA”). This Statement does not modify or expand those contractual rights or obligations.
How we operate
Depending on the context, Redwood may act as:
Processor or Service Provider. When Redwood processes Personal Data on behalf of a Client, we process it in accordance with the applicable Agreement, the Client’s documented instructions, and Applicable Data Protection Laws.
Controller or Data Fiduciary. Redwood determines how and why Personal Data is processed for activities such as our websites, marketing, sales, events, account management, billing, security, and business operations.
These roles may have different names under Applicable Data Protection Laws.
What Personal Data we collect
The information we collect depends on how you interact with Redwood.
Website and digital interaction data
This may include:
- IP address and approximate location derived from it, including where used to determine applicable privacy and cookie controls;
- browser, device, and operating-system information;
- pages viewed, referring URLs, searches, and website interactions;
- cookie and browser-storage identifiers;
- advertising and campaign attribution information;
- chatbot interactions; and
- session and interaction information where permitted by law.
Business contact and marketing data
This may include:
- name and business contact information;
- employer, job title, country or region, industry, and business interests;
- event and webinar participation;
- marketing preferences;
- communications with Redwood;
- interactions with our emails, advertisements, websites, campaigns, and content; and
- information provided when requesting content, pricing, a demonstration, or other information.
We may receive this information directly from you or, where permitted by law, from business partners, event organizers, public sources, professional networks, advertising platforms, and business-information providers.
Account, commercial, and support data
This may include:
- account users and administrators;
- usernames, roles, and permissions;
- billing, subscription, and customer relationship records;
- support tickets and interactions; and
- communications with our support and account teams.
Product usage and operational data
Depending on the Product and deployment model, this may include:
- authentication and login information;
- roles and access configurations;
- feature usage and configuration information;
- system, application, and audit logs;
- job and workflow metadata;
- performance and diagnostic information;
- security events; and
- device, network, and connection information.
The information available to Redwood varies by Product, configuration, and deployment model.
Data associated with our Products
Client Data
“Client Data” means data submitted to the Products by a Client or its Users. Client Data excludes Aggregated and Anonymized Data.
Client Data may include workflows, scripts, execution data, files, integrations, and Personal Data contained within them.
Clients determine what Client Data they submit and are responsible for the content, accuracy, legality, reliability, appropriateness, and ownership or right to use that Client Data.
Where Redwood processes Personal Data within Client Data as a processor or service provider, we process it in accordance with the Agreement, the Client’s documented instructions, the DPA, and Applicable Data Protection Laws.
Sensitive Personal Data
For SaaS deployments, Clients should limit Personal Data submitted through the Products to what is relevant and necessary for their access and use of the Products.
Except as expressly permitted under an Order Form, Clients must not submit through the Products sensitive data, including personal health information, credit card data, personal financial data, or other data that may impose specific data security or privacy obligations on Redwood in addition to or different from those specified in the Agreement.
Test or diagnostic data provided for Support should be suitably anonymized where required by the DPA.
Telemetry Data
“Telemetry Data” means data generated by a Client’s configuration and usage of the Products, such as product configuration, metadata, system logs, diagnostic information, and job definitions and configurations.
Redwood uses Telemetry Data to operate, secure, support, maintain, analyze, and improve our Products and Services, subject to Applicable Data Protection Laws and our contractual commitments.
Aggregated and Anonymized Data
“Aggregated and Anonymized Data” means data that is combined with data from multiple sources or Clients and de-identified in accordance with applicable law so that neither the Client nor any identifiable individual can reasonably be re-identified through normal commercial means.
Redwood may use Aggregated and Anonymized Data for generalized statistical, analytical, or benchmarking insights and to improve the Products, Services, and Support.
Why we use Personal Data
We may use Personal Data to:
- provide, operate, secure, and support our Products and Services;
- administer accounts, authentication, billing, and customer relationships;
- provide Support and service communications;
- prevent fraud, abuse, and security threats;
- monitor and improve performance and reliability;
- understand and improve our websites, Products, Services, and features where permitted;
- comply with law and enforce or defend our legal rights; and
- conduct sales and marketing activities.
Marketing and communications
We may use business contact information, professional information, marketing preferences, event activity, content downloads, website and campaign interactions, email engagement, and advertising information to:
- respond to requests;
- provide product and company communications;
- invite you to events and webinars;
- identify Products, Services, or content that may be relevant to your organization;
- manage customer and prospect relationships;
- measure and improve campaigns; and
- advertise our Products and Services.
Redwood does not use Personal Data contained in Client Data for its independent advertising or direct-marketing purposes unless expressly authorized by the Client and permitted by Applicable Data Protection Laws.
Where consent is required for marketing, we obtain it. Where applicable law permits another legal basis, such as legitimate interests, we process Personal Data subject to applicable requirements and rights.
You can unsubscribe from marketing emails at any time. We may retain limited information necessary to honor your opt-out.
Legal grounds for processing
Our legal grounds depend on the activity and applicable law.
Where the GDPR or UK GDPR applies, our typical legal grounds include:
| Purpose | Typical legal ground |
| Provide contracted Products and Services | Contract |
| Administer accounts and customer relationships | Contract and/or legitimate interests |
| Security and fraud prevention | Legitimate interests and/or legal obligations |
| Respond to requests and provide communications | Contract and/or legitimate interests |
| Business-to-business marketing | Legitimate interests or consent, as applicable |
| Non-essential cookies and similar technologies | Consent where required |
| Legal and compliance activities | Legal obligations and/or legitimate interests |
The legal ground for a particular activity depends on its circumstances.
Other jurisdictions may provide different lawful grounds for processing.
For Personal Data Redwood processes on behalf of a Client, the Client is responsible for establishing the appropriate legal basis or other authority for its processing.
Global privacy requirements
Redwood operates globally. We apply privacy requirements based on the Personal Data we process, where processing occurs, and the laws that apply.
India
Where India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable implementing rules apply, Redwood processes digital Personal Data in accordance with applicable Indian data protection law.
Where Redwood acts as a Data Fiduciary, we process Personal Data for lawful purposes based on consent or another ground permitted under applicable Indian law.
Individuals in India may exercise applicable rights as those rights become effective, including rights relating to information about processing, correction and erasure, grievance redressal, and nomination.
Where Redwood processes Personal Data on behalf of a Client, Redwood assists the Client as required by our contractual commitments and applicable law.
Australia
Where Australian privacy law applies, individuals may request access to or correction of their Personal Data and may submit privacy complaints using the contact information below.
Redwood may disclose Personal Data to recipients outside Australia, including Redwood Affiliates and service providers. Where practicable and required by applicable law, information about the countries in which relevant overseas recipients are likely to be located will be made available through our processing-location, Sub-processor, or other applicable privacy information.
AI Features
“AI Features” are Product features that use large language models to produce content (“Outputs”) in response to prompts, queries, pre-configured context, conditions, triggers, or other information submitted to or otherwise processed with an AI Feature (“Inputs”).
Use of AI Features is optional and activated only if a Client enables or purchases the applicable AI Feature.
Redwood does not use Inputs to train or otherwise improve the large language models of third-party providers underlying those AI Features.
Redwood may use Inputs and Outputs that constitute Aggregated and Anonymized Data to improve the Products, Services, and Support, in accordance with the applicable Agreement and Applicable Data Protection Laws.
How Redwood protects data
Redwood uses appropriate technical and organizational measures designed to protect Personal Data, taking into account the nature, scope, context, and purposes of processing.
Depending on the Product and configuration, these may include encryption, secure data-transfer mechanisms, role-based access controls, Single Sign-On, authentication controls, audit logging, and security monitoring.
Access to Personal Data is limited according to role and business need. Our security measures may evolve to reflect technological developments and industry practices, subject to our contractual commitments and Applicable Data Protection Laws.
Clients are responsible for properly and securely configuring and using the Products, securing account authentication credentials, managing permissions and integrations, and taking appropriate steps to secure and back up Client Data.
Where Personal Data is processed and transferred
Redwood may process Personal Data in countries where Redwood, its Affiliates, and service providers operate.
Where required by Applicable Data Protection Laws, we use appropriate safeguards for international transfers, including Standard Contractual Clauses, UK transfer mechanisms, adequacy decisions, or other legally recognized mechanisms, as applicable.
For Personal Data processed on behalf of a Client, processing and international transfer commitments are governed by the Agreement and DPA.
For other Personal Data, information about relevant overseas processing locations will be made available where required and practicable.
Sharing Personal Data
For Personal Data Redwood processes for its own purposes, we may share information as appropriate with:
- cloud and infrastructure providers;
- support, security, and monitoring providers;
- communications and collaboration providers;
- analytics, marketing, and advertising providers;
- event and webinar providers;
- customer relationship management and sales platforms;
- professional advisers;
- Redwood Affiliates and business partners; and
- government authorities or other parties where required by law.
Where providers process Personal Data on our behalf, we use appropriate contractual and other safeguards.
When Redwood processes Personal Data on behalf of a Client, Redwood uses Sub-processors and makes disclosures in accordance with the Agreement, DPA, the Client’s documented instructions, and Applicable Data Protection Laws.
A current list of Redwood’s Sub-processors is available on our website.
Redwood does not sell or share Personal Data processed on behalf of Clients except as permitted by the Agreement, DPA, Client instructions, and Applicable Data Protection Laws.
For Personal Data Redwood processes for its own purposes, Redwood does not sell Personal Data for monetary consideration. Where applicable laws define “sale,” “sharing,” or targeted or cross-context behavioral advertising more broadly, we provide applicable disclosures and choices.
Data retention
We retain Personal Data for as long as necessary for the purposes for which it was collected or as required by Applicable Data Protection Laws, contractual obligations, security requirements, or legitimate recordkeeping purposes.
Retention depends on the type and purpose of the information. For example:
- Personal Data processed on behalf of a Client is retained and deleted according to the Agreement and DPA;
- account and commercial records may be retained during the relationship and for an appropriate period afterward;
- security and operational records may be retained as necessary to protect and operate our systems;
- marketing information may be retained while we have an appropriate purpose, subject to applicable law and your choices; and
- limited information may be retained to honor opt-out requests.
Security incidents
Redwood maintains processes to identify, investigate, respond to, and manage security incidents.
Where Redwood confirms a Data Breach affecting Personal Data processed on behalf of a Client, we notify the Client and provide relevant information in accordance with the DPA and Applicable Data Protection Laws.
Where Redwood is responsible for regulatory or individual notification, we provide notification as required by law.
Your privacy rights and choices
Depending on applicable law, you may have rights to:
- access information about your Personal Data;
- correct or delete Personal Data;
- restrict or object to certain processing, including direct marketing;
- withdraw consent;
- obtain or transfer certain Personal Data;
- opt out of certain sale, sharing, targeted advertising, or profiling activities; and
- submit a grievance or complaint to Redwood or an applicable authority.
These rights are subject to applicable legal conditions and exceptions.
For Personal Data Redwood processes on behalf of a Client, please generally direct your request to that Client. Redwood assists Clients with such requests as required by the DPA and Applicable Data Protection Laws.
To exercise rights relating to Personal Data for which Redwood is responsible, contact us using the information below or use our available privacy request mechanisms. We may need to verify your identity.
Where applicable law gives you the right to appeal our decision on a privacy request, instructions for submitting an appeal will be included in our response.
U.S. state privacy rights
Residents of California and certain other U.S. states may have additional rights under applicable state privacy laws, including rights relating to access, correction, deletion, portability, and certain opt-outs.
Where required, applicable disclosures and opt-out mechanisms are available through Your Privacy Choices.
We will not unlawfully discriminate against you for exercising applicable privacy rights.
Certain U.S. laws may require additional disclosures for specific categories of Personal Data or processing. Where applicable, Redwood provides those disclosures separately.
Cookies, browser storage, and similar technologies
Redwood and our service providers use cookies, browser storage, pixels, tags, and similar technologies to:
- provide, authenticate, and secure our websites;
- remember preferences;
- understand website performance and usage;
- support chat and customer communications;
- measure content and marketing campaigns;
- personalize experiences; and
- support advertising activities.
Location-based privacy controls
Your available privacy choices and default cookie settings may vary based on your location and applicable law. We may use your IP address or similar information to determine which privacy controls and defaults to present.
Where prior consent is required, non-essential technologies are disabled until you provide the required consent. Where applicable law instead provides an opt-out right, certain technologies may operate unless you exercise that right.
Where required, Redwood recognizes applicable browser-based opt-out preference signals, such as Global Privacy Control (“GPC”), for processing covered by those signals.
Strictly necessary technologies may operate without consent where permitted by law because they are needed to provide, secure, or maintain requested functionality.
Managing your choices
You can manage available choices through our preference center and, where applicable, Your Privacy Choices.
Your available options may differ based on your location. You can revisit and change your preferences at any time.
If you access our websites from another jurisdiction, or if we cannot reliably determine your location, the privacy controls presented to you may change.
Third-party services
Our websites and Services may integrate with third parties that process Personal Data on Redwood’s behalf or for their own purposes.
Where a third party independently determines how it processes Personal Data, its privacy statement governs that processing.
Children
Redwood provides enterprise Products and Services intended for organizations and business users and does not intentionally direct its Products or marketing to children.
We do not knowingly collect children’s Personal Data in circumstances where doing so would violate applicable law.
Contact and grievance redressal
Questions, privacy requests, complaints, or grievances may be submitted to:
Redwood Software
8010 Towers Crescent Dr, Suite 210, Vienna, VA 22182, USA
Where required by applicable law, Redwood will make available information regarding any designated Data Protection Officer, grievance contact, or other privacy representative.
We respond to privacy requests and complaints in accordance with applicable law.
Updates to this Privacy Statement
We may update this Statement as our Products, Services, business practices, and legal requirements evolve.
When changes are material, we provide notification as required by applicable law.
The effective date above indicates when this Statement was last updated.