Red Palm · Decision Engine
Legal & Trust Center
Everything you need to know about how RED PALM protects customer data, operates DECISION ENGINE, and manages security, privacy, compliance, billing, and legal policies.
Quick answers
The questions buyers ask first
Short answers up front, full policies one click deeper. Items marked TODO are completed before launch — never guessed.
Is my data encrypted?
Yes. Traffic is encrypted in transit with TLS, and data is encrypted at rest where supported by the underlying infrastructure, following industry-standard security practices.
Learn more →Who can see my data?
Only authorized RED PALM personnel, on a least-privilege basis, and only when necessary for support, maintenance, troubleshooting, security, or legal compliance.
Learn more →Do you train AI models on my data?
This answer must accurately document our AI providers, prompt retention, model training, customer-data usage, and opt-outs before launch — we will not ship a vague answer here.
Learn more →Where is my data stored?
Depends on final infrastructure. To be documented: cloud provider(s), hosting regions, backup locations, and disaster recovery posture.
Learn more →Who are your subprocessors?
A small set of vetted vendors — hosting, payments, AI, call tracking, email — each under contract to protect your data. The full list is public and kept current.
Learn more →Can I sign a DPA?
Yes. Enterprise customers may request a countersigned Data Processing Addendum, including Standard Contractual Clauses where applicable.
Learn more →What’s your uptime?
Availability commitments are documented in our Service Level Agreement. A public status page is planned. status.redpalm.ai · [TODO]
Learn more →How do I report a security issue?
security@redpalm.ai is the official security contact. Good-faith research is protected by safe harbor.
Learn more →Legal resources
Every policy, in plain sight
The full library that governs DECISION ENGINE — written to be read, not buried.
Terms of Service
The agreement that governs your subscription, billing, and use of DECISION ENGINE.
Read the policy →Privacy Policy
What we collect, why, how it’s shared, and the rights you have over it.
Read the policy →Cookie Policy
The cookies we set, what each category does, and how to control them.
Read the policy →Acceptable Use Policy
The rules that keep the platform safe, lawful, and fair for every customer.
Read the policy →Security Overview
Encryption, access controls, monitoring, incident response, and secure development.
Read the policy →Data Processing Addendum
GDPR, UK GDPR, and CCPA terms for processing personal data on your behalf.
Read the policy →Subprocessor List
Every vendor we rely on, what it does, and the data it touches — searchable.
Read the policy →Refund & Cancellation Policy
Month to month. Cancel from your dashboard. Billing and refunds, in plain terms.
Read the policy →Service Level Agreement
Availability commitments, maintenance windows, incident priorities, service credits.
Read the policy →Responsible AI Policy
How AI is used, where humans stay in control, and our transparency commitments.
Read the policy →Vulnerability Disclosure Policy
How to report security issues — with safe harbor for good-faith research.
Read the policy →Copyright & DMCA Policy
Copyright claims, DMCA notices, counter-notices, and repeat-infringer policy.
Read the policy →Contact Legal
The right channel for legal, privacy, security, compliance, billing, and media.
Read the policy →Compliance
Compliance
Where we stand today, stated plainly: framework alignment now, formal certifications as we grow. Badges below are roadmap markers, not certification claims.
GDPR
Processor terms, SCC-based transfers, and data-subject rights support through our DPA and Privacy Policy.
CCPA / CPRA
Service-provider terms, no sale of personal information, and California rights handling.
SOC 2
A SOC 2 examination is on our roadmap. This card will link to the report when it is available.
ISO 27001
ISO 27001 certification is under evaluation as the company scales.
Privacy Frameworks
Standard Contractual Clauses and the UK Addendum are used for international transfers where required.
Need additional legal or security information?
Security questionnaires, signed DPAs, vendor reviews, or anything this page doesn’t answer — we respond fast.
*Encryption at rest where supported by the underlying infrastructure — see the Security Overview.