Privacy Policy
Last updated: 12 September 2026
This policy explains how ELAREN GROUP SL, which operates Dredo, handles personal data. It covers the marketing site at dredo.app and the Dredo help desk application. Dredo is built and operated in Spain, and your data is hosted in the European Union (Germany), with our infrastructure provider Hetzner.
1. Who is responsible
The data controller is ELAREN GROUP SL (“Dredo”), Calle Unión 7, 45100 Sonseca, Toledo, Spain. VAT/NIF: ESB75779777. For any question about privacy or to exercise your rights, write to hello@dredo.app.
We have not appointed a Data Protection Officer, because we are not legally required to. Privacy requests are handled directly by our team at hello@dredo.app.
Dredo is subject to the EU General Data Protection Regulation (GDPR). The supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), www.aepd.es.
2. Scope and our two roles
This policy applies to two different kinds of data, and our role changes depending on which one we mean.
We are the controller for the data of the people who sign up and run a workspace (account and staff data) and for billing data. For that data, this policy is the full picture: we decide why and how it is processed.
We are the processor for the content a workspace collects about its own end-users and requesters. There, the workspace (our customer) is the controller: it decides what to collect and why, and we only process that content on its instructions. A Data Processing Agreement (DPA) is available for business customers. If you are the end-user of a business that uses Dredo, see section 11.
3. What data we collect
Account and staff data (we are controller).
- Your name, email address and a hashed password (we never store your password in plain text).
- Your interface language, avatar and email-verified flag.
- Session data, including your IP address, browser user-agent and session expiry, which we keep to secure your account.
Billing data (we are controller).
- Company name, billing country and VAT ID, which we validate through the EU VIES service.
- Your Stripe customer and subscription identifiers.
- Card details are entered with and handled by Stripe. Dredo does not store your card number.
Workspace content (we are processor, on behalf of the workspace). When a workspace uses Dredo to run support, we process on its behalf: requester email addresses; ticket subject, status and priority; messages, including public replies and internal notes; attachments; custom-field values; email thread identifiers; an immutable event timeline; CSAT ratings; and notifications.
Support communications. When you contact us at hello@dredo.app, we process your email, your message and anything you choose to include, so we can answer you.
4. Why we use it and our legal bases
We only process personal data where the law gives us a basis to do so.
- To perform our contract with you: creating and running your account, providing the service and supporting you. Legal basis: performance of a contract.
- To comply with legal and tax obligations: issuing invoices, applying VAT rules and keeping accounting records. Legal basis: legal obligation.
- Our legitimate interests: keeping accounts and workspaces secure, preventing fraud and abuse, and improving the product. We balance these against your rights, and you can object (see section 10). Legal basis: legitimate interests.
- Consent: where the law requires it, for example any future non-essential cookies or optional communications. You can withdraw consent at any time. Legal basis: consent.
For workspace content that we process as a processor, the legal basis is determined by the workspace (the controller), not by us.
5. Cookies
The marketing site at dredo.app uses no third-party analytics or tracking. Fonts are self-hosted, so no font request leaves our servers. We only store a small local preference to remember the language you choose.
The Dredo application uses only essential session cookies, which keep you signed in and secure your access. Without them the service cannot work.
You can read the full cookie detail on our cookie policy. Our terms of service are available here.
6. Who we share it with
We do not sell personal data. To run the service we rely on a small number of subprocessors, each bound to process data only on our instructions:
- Stripe Payments Europe / Stripe, Inc. · payments and tax · EU/US · SCCs
- Resend · transactional and authentication email (verification, password reset, notifications) · US · SCCs
- Sentry · error monitoring and diagnostics · EU/US · SCCs
- Hetzner Online GmbH · hosting and infrastructure (servers, database, file storage) · Germany (EU) · EU hosting
We use GitHub for our source code and continuous integration only; no customer content is processed there. We may also disclose data where we are legally required to do so.
7. International transfers
Your data is hosted in the European Union (Germany), with our infrastructure provider Hetzner. Some subprocessors (Stripe, Resend and Sentry) may process personal data in the United States. Where personal data is transferred outside the European Economic Area, the transfer is covered by the EU Standard Contractual Clauses (SCCs).
8. How long we keep it
We keep account data for as long as the account exists, and delete it on request within a reasonable period.
Analytics history is kept according to your plan:
- Free: 7 days.
- Starter: 90 days.
- Pro: 365 days.
- Business: unlimited.
Storage limits also depend on your plan. If you cancel, the workspace reverts to the Free plan and its data is kept unless you ask us to delete it. Billing records are retained for as long as tax and accounting law requires.
9. How we protect it
We apply technical and organisational measures to protect personal data:
- Each workspace’s data is isolated from every other workspace.
- Passwords and invitation tokens are stored hashed, never in plain text.
- Data is encrypted in transit using TLS.
- Access is controlled through roles and permissions.
- Secrets are redacted from our logs.
10. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on it.
To exercise any of these rights, write to hello@dredo.app. We will respond within one month. If you believe we have not handled your request properly, you can lodge a complaint with the AEPD, www.aepd.es.
11. If you are an end-user of one of our customers
If a business or organisation uses Dredo to provide support to you, that business is the controller of your data, not Dredo. Dredo acts only as a processor and handles your data on the business’s instructions.
To access, correct or delete your data, or to exercise any other right, please contact the business you were in touch with. If you reach out to us, we will refer you to them, since they decide how your data is used.
12. Children
Dredo is a tool for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the “last updated” date at the top of this page and, where appropriate, give notice through the service. The current version always governs.
14. Contact
For any question about this policy or about how we handle your data, write to hello@dredo.app or by post to ELAREN GROUP SL, Calle Unión 7, 45100 Sonseca, Toledo, Spain.
15. Language
This policy is published in English and Spanish. In case of any discrepancy between the two versions, the Spanish version prevails.