Skip to content
RETRIDGE
Legal

Privacy Policy

Last updated: 04-09-2026

It also explains — separately, in Section 7 — how we handle the data inside your systems when you engage us for an audit, security assessment, build, or training. Those are two different relationships with two different sets of rules, and we keep them apart.

Who is responsible for your data: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. For any question about this policy, email hello@retridge.com.

1. Summary

  • We collect only what we need to answer your enquiry, run a consultation, send the material you asked for, and understand how the site is used.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
  • We do not use client data or the contents of your systems to train machine learning models — ours or anyone else’s.
  • We sign an NDA before we access any client system.
  • You can ask us to show you, correct, or delete what we hold. Email us and we will action it.

2. Information we collect

2.1 Information you give us

Contact and consultation form. When you use the enquiry form on the Contact page, we collect your name, work email address, company name, the service you are interested in, whether you have an AI system in production or development, and the description of the symptoms you write. That description is free text — please do not paste credentials, API keys, customer records, or other sensitive material into it. If you need to share system detail before an NDA is in place, tell us and we will arrange a secure channel.

Consultation booking. Booking a discovery call is handled by Calendly, a third-party scheduling service. When you book, Calendly collects your name, email address, chosen time slot, and timezone, and issues a calendar invitation. Calendly processes that information under its own privacy policy in addition to ours.

RAG Audit Checklist and RAG Engineering Notes. If you request the checklist or subscribe to our monthly technical note, we collect your work email address and use it to send the PDF and subsequent issues. Every email includes an unsubscribe link, and unsubscribing removes you from the list.

Direct correspondence. If you email us at hello@retridge.com or contact us via LinkedIn, we keep that correspondence and any information in it.

2.2 Information collected automatically

When you visit the site, our hosting provider and analytics tooling record technical information including your IP address, browser type and version, device and operating system, referring page, pages viewed, and approximate location derived from IP. This is used to keep the site available, secure it against abuse, and understand which content is read.

2.3 What we do not collect

We do not collect special category data (health, biometrics, political opinions, religious beliefs, and similar) through this website, and we ask that you do not send it to us. We do not take payment details through the site.

3. Why we use it, and our legal basis

What we doWhyLegal basis (UK/EU GDPR)
Respond to your enquiry and scope a proposalTo answer the question you askedSteps taken at your request prior to a contract
Schedule and hold a consultation callTo deliver the meeting you bookedSteps taken at your request prior to a contract
Deliver the RAG Audit ChecklistYou asked us to send itConsent
Send RAG Engineering NotesTo keep you informed as you requestedConsent, or legitimate interest for existing clients
Deliver contracted engagementsTo perform the workPerformance of a contract
Site analytics and securityTo keep the site working, secure, and usefulLegitimate interest, or consent where cookies require it
Keep records of contracts and invoicesTo meet accounting and legal obligationsLegal obligation

Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interest, you may object, and we will stop unless we have compelling grounds to continue.

4. Cookies

Strictly necessary cookies keep the site functioning and do not require consent. Any analytics or preference cookies are set only where you have agreed, and you can change or withdraw that choice at any time via [MECHANISM]. Pages that embed third-party content — such as the Calendly scheduler — may cause that provider to set its own cookies when the content loads.

Most browsers let you block or delete cookies. Blocking strictly necessary cookies may stop parts of the site from working.

5. Who we share information with

We share personal information only with service providers who process it on our behalf, under contract, and only for the purposes above:

  • Hosting and content delivery — [PROVIDER]
  • Scheduling — Calendly
  • Email and enquiry delivery — [PROVIDER]
  • Newsletter delivery — [PROVIDER]
  • Analytics — [PROVIDER]
  • Accounting and invoicing — [PROVIDER]

We also disclose information where we are legally required to, where necessary to establish or defend legal claims, or in connection with a merger or acquisition — in which case you would be notified.

We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We have not done so in the preceding twelve months.

6. International transfers

Some of the providers above are based outside the UK and EEA, including in the United States. Where personal information is transferred outside the UK or EEA, we rely on an adequacy decision or on Standard Contractual Clauses together with any additional safeguards required. You can request details of the mechanism used for a specific provider.

7. Client data and engagement confidentiality

This section governs information we encounter inside your systems during an audit, red-team assessment, build, or training engagement. It is distinct from the website data described above.

We act on your instructions. For any personal data contained in your documents, queries, logs, or systems, you are the controller and Retridge acts as a processor. We process it only to perform the engagement, only on your documented instructions, and under a written agreement that meets the requirements of Article 28 UK/EU GDPR where applicable.

NDA precedes access. We execute a non-disclosure agreement before receiving access to any client system, repository, dataset, or credential.

Least-privilege access. We request the narrowest access that allows the work to be done, prefer read-only and scoped credentials, and prefer redacted or synthetic data where an evaluation can be run without production records. Credentials issued to us are used only for the engagement and should be revoked by you on completion.

Evaluation datasets. The query-level evaluation dataset we build for you is your property and is delivered to you. Where real user queries contain personal information, we work with you to pseudonymise or redact them before they enter the dataset.

We do not train on your data. We do not use client systems, documents, queries, or engagement findings to train, fine-tune, or otherwise improve any machine learning model, ours or a third party’s. Where an engagement requires sending client content to a third-party model provider, we do so only with your approval, using configurations that exclude the content from provider training, and we will name the providers involved in the engagement agreement.

Findings stay confidential. Security findings, failure analyses, and audit results are shared only with the people you designate. We publish client names, quotes, results, and case studies only with your prior written permission. Any material published without permission would be a breach of our agreement with you, and we do not do it.

Retention after the engagement. We delete or return client data and revoke our access within [NUMBER] days of engagement completion, other than the minimum record we must keep for contractual and accounting purposes. You can ask for deletion sooner.

8. How long we keep information

  • Unconverted enquiries and consultation records — [12–24] months from last contact, then deleted.
  • Newsletter and checklist subscribers — until you unsubscribe, plus a suppression record so we do not email you again.
  • Client records, contracts, and invoices — as required by tax and accounting law in [JURISDICTION], typically [6–7] years.
  • Client system data — per Section 7.
  • Server logs and analytics — [PERIOD].

9. Security

We apply the practices we assess in other people’s systems: encryption in transit, access control on a least-privilege basis, multi-factor authentication on accounts holding client or contact data, and separation of client engagement material from general business systems. No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal information and presents a risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.

10. Your rights

Depending on where you live, you may have the right to:

  • Access — get a copy of the personal information we hold about you
  • Correct — have inaccurate information fixed
  • Delete — have your information erased
  • Restrict or object — limit how we use it, including objecting to processing based on legitimate interest
  • Portability — receive your information in a machine-readable format
  • Withdraw consent — at any time, without affecting what we did before you withdrew it
  • Opt out — of sale, sharing, or targeted advertising (we do none of these), and of profiling with legal or similarly significant effects (we do not do this either)
  • Non-discrimination — we will not treat you differently for exercising any of these rights

To exercise any of them, email hello@retridge.com. We will respond within one month (UK/EU) or 45 days (US state privacy laws), and will tell you if we need longer. We may need to verify your identity first. You may use an authorised agent where the law allows it.

If you are in the UK or EEA and are unhappy with our response, you can complain to your national data protection authority — in the UK, the Information Commissioner’s Office at ico.org.uk. We would prefer you raise it with us first.

11. Third-party links

The site links to external sites, including LinkedIn and Calendly. We are not responsible for their privacy practices, and this policy does not cover them.

13. Changes

We will post any changes to this policy on this page and update the date at the top. Material changes will be flagged to newsletter subscribers and active clients.

12. Children

The site is aimed at businesses and is not directed at anyone under 16. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.

14. Contact

Email: hello@retridge.com
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]