Legal

Privacy Policy

Last updated: 12 September 2026

This policy explains how ELAREN GROUP SL, which operates Dredo, handles personal data. It covers the marketing site at dredo.app and the Dredo help desk application. Dredo is built and operated in Spain, and your data is hosted in the European Union (Germany), with our infrastructure provider Hetzner.

1. Who is responsible

The data controller is ELAREN GROUP SL (“Dredo”), Calle Unión 7, 45100 Sonseca, Toledo, Spain. VAT/NIF: ESB75779777. For any question about privacy or to exercise your rights, write to hello@dredo.app.

We have not appointed a Data Protection Officer, because we are not legally required to. Privacy requests are handled directly by our team at hello@dredo.app.

Dredo is subject to the EU General Data Protection Regulation (GDPR). The supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), www.aepd.es.

2. Scope and our two roles

This policy applies to two different kinds of data, and our role changes depending on which one we mean.

We are the controller for the data of the people who sign up and run a workspace (account and staff data) and for billing data. For that data, this policy is the full picture: we decide why and how it is processed.

We are the processor for the content a workspace collects about its own end-users and requesters. There, the workspace (our customer) is the controller: it decides what to collect and why, and we only process that content on its instructions. A Data Processing Agreement (DPA) is available for business customers. If you are the end-user of a business that uses Dredo, see section 11.

3. What data we collect

Account and staff data (we are controller).

Billing data (we are controller).

Workspace content (we are processor, on behalf of the workspace). When a workspace uses Dredo to run support, we process on its behalf: requester email addresses; ticket subject, status and priority; messages, including public replies and internal notes; attachments; custom-field values; email thread identifiers; an immutable event timeline; CSAT ratings; and notifications.

Support communications. When you contact us at hello@dredo.app, we process your email, your message and anything you choose to include, so we can answer you.

4. Why we use it and our legal bases

We only process personal data where the law gives us a basis to do so.

For workspace content that we process as a processor, the legal basis is determined by the workspace (the controller), not by us.

5. Cookies

The marketing site at dredo.app uses no third-party analytics or tracking. Fonts are self-hosted, so no font request leaves our servers. We only store a small local preference to remember the language you choose.

The Dredo application uses only essential session cookies, which keep you signed in and secure your access. Without them the service cannot work.

You can read the full cookie detail on our cookie policy. Our terms of service are available here.

6. Who we share it with

We do not sell personal data. To run the service we rely on a small number of subprocessors, each bound to process data only on our instructions:

We use GitHub for our source code and continuous integration only; no customer content is processed there. We may also disclose data where we are legally required to do so.

7. International transfers

Your data is hosted in the European Union (Germany), with our infrastructure provider Hetzner. Some subprocessors (Stripe, Resend and Sentry) may process personal data in the United States. Where personal data is transferred outside the European Economic Area, the transfer is covered by the EU Standard Contractual Clauses (SCCs).

8. How long we keep it

We keep account data for as long as the account exists, and delete it on request within a reasonable period.

Analytics history is kept according to your plan:

Storage limits also depend on your plan. If you cancel, the workspace reverts to the Free plan and its data is kept unless you ask us to delete it. Billing records are retained for as long as tax and accounting law requires.

9. How we protect it

We apply technical and organisational measures to protect personal data:

10. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent where processing is based on it.

To exercise any of these rights, write to hello@dredo.app. We will respond within one month. If you believe we have not handled your request properly, you can lodge a complaint with the AEPD, www.aepd.es.

11. If you are an end-user of one of our customers

If a business or organisation uses Dredo to provide support to you, that business is the controller of your data, not Dredo. Dredo acts only as a processor and handles your data on the business’s instructions.

To access, correct or delete your data, or to exercise any other right, please contact the business you were in touch with. If you reach out to us, we will refer you to them, since they decide how your data is used.

12. Children

Dredo is a tool for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the “last updated” date at the top of this page and, where appropriate, give notice through the service. The current version always governs.

14. Contact

For any question about this policy or about how we handle your data, write to hello@dredo.app or by post to ELAREN GROUP SL, Calle Unión 7, 45100 Sonseca, Toledo, Spain.

15. Language

This policy is published in English and Spanish. In case of any discrepancy between the two versions, the Spanish version prevails.