Privacy Policy

The Redesign Group Privacy Policy

The Drala Project, Inc. d/b/a The Redesign Group

Version Date: September 2026
Privacy Policy

1. Introduction

This Privacy Policy ("Policy") explains how The Drala Project, Inc. d/b/a The Redesign Group ("Redesign," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with our website, products, services, Unified Portal, Redesign Applications, Cloud Hosting Services, Marketplace Functionality, Asset Management Functionality, events, career opportunities, and related offerings.

This Policy applies to personal information Redesign processes as a controller or business for its own purposes, including account administration, billing, relationship management, website operations, event administration, recruitment, security, analytics, product improvement, and business operations.

Where Redesign processes personal information on behalf of a customer, that processing is governed by the applicable agreement and Data Processing Agreement ("DPA"), not this Policy. The DPA is available at https://www.redesign-group.com/legal.

2. Who We Are

FieldDetail
Legal EntityThe Drala Project, Inc. d/b/a The Redesign Group
Principal Office222 N Pacific Coast Hwy, Floor 10, El Segundo, CA 90245, United States
State of IncorporationCalifornia
Privacy Contactprivacy@redesign-group.com

Redesign is a global technology and cybersecurity solutions provider and consulting firm that provides modern data center infrastructure, cybersecurity, dedicated private cloud, managed IT and security services, artificial intelligence solutions, and business transformation consulting. Redesign also develops and offers proprietary software products and platforms, including the Unified Portal, OpenCloud, Redesign Exchange, Redesign Trust Portal, Redesign C7e Enterprise AI Platform, Redesign AI Chat, Redesign GRC, C7e Studio, Cloud Hosting Services, Asset Management Functionality, Marketplace Functionality, and related applications. Redesign's affiliate in France, THE (RE) DESIGN GROUP FR, develops certain Redesign software products.

3. Self-Hosted Deployments

Certain Redesign products, including Redesign AI Chat and other Redesign Applications, may be deployed within the customer's own infrastructure using private models that run within the customer's environment. In those deployments, customer content may be processed entirely within the customer's environment and may not be transmitted to, accessed by, hosted by, or stored by Redesign. In that configuration, the customer is the sole controller of such data, and the parts of this Policy that describe processing of customer content do not apply to the extent Redesign has no access to it.

Redesign accesses customer data in self-hosted deployments only where the customer explicitly requests it, such as hands-on support, troubleshooting, or professional services. Any such access is governed by the applicable agreement and DPA.

4. Personal Information We Collect

Information you provide

CategoryExamplesSource
Account and identityName, business email, phone number, job title, organization, authentication identifiers, administrator credentials, user identifiersCustomer, authorized users, account registration
Contractual and billingCompany details, billing contacts, contract terms, purchase records, order data, payment information, tax-exemption information, invoicing dataCustomer, orders, marketplace
Support dataCorrespondence, tickets, support requests, diagnostic information, and any information shared during support or professional servicesCustomer, authorized users
Marketing and communicationsContact information, communication preferences, content downloadsData subjects, website visitors
Event registration dataName, email, company, title, dietary preferences, accessibility requirements, and photo/video/likeness consentEvent registrants, Event Registration Terms
Career and applicant dataName, email, phone number, resume, cover letter, employment history, education, references, work authorization status, and any other information submitted during the application processJob applicants

Information we collect automatically

CategoryExamplesSource
Website and technical dataIP address, browser type, operating system, device information, referral source, pages visited, session data, cookies, and similar technologiesWebsite visitors
Usage and telemetry dataLogin activity, session activity, feature usage, entitlement data, configuration data, performance data, diagnostic data, error data, Marketplace activity, Asset Data, and system information relating to Redesign products, services, Unified Portal, Redesign Applications, Cloud Hosting Services, Marketplace Functionality, and Asset Management FunctionalityRedesign products and services
Client systems dataData collected through remote monitoring, support tools, managed services tools, or platform management tools under contractual agreementsCustomer systems, where authorized

Information from third-party sources

We may also receive personal information from third-party sources, including business partners, technology manufacturers, OEM partners, distributors, referral partners, marketing partners, applicant tracking systems, public databases, and social media platforms, to the extent permitted by applicable law.

Information we do not collect

We do not collect or access customer content processed within a customer's self-hosted environment unless the customer explicitly requests access for support, troubleshooting, or professional services.

We do not knowingly collect personal information from children. Our products and services are enterprise offerings intended for business use and are not directed to children.

We do not collect or process sensitive personal information for purposes beyond those permitted under applicable US state privacy laws. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you.

5. How We Use Personal Information

We use the personal information we control to:

  • Establish and manage customer relationships, including account administration, onboarding, and user provisioning.
  • Provide, deliver, support, maintain, secure, troubleshoot, and improve our products, services, Unified Portal, Redesign Applications, Cloud Hosting Services, Marketplace Functionality, Asset Management Functionality, Lifecycle Recommendations, and related offerings.
  • Process billing, invoicing, payments, taxes, and contractual obligations.
  • Respond to inquiries, support requests, and service communications.
  • Administer entitlements, subscriptions, licenses, renewals, and orders.
  • Generate Lifecycle Recommendations, asset reports, usage reports, and service reports.
  • Administer events, including registration, logistics, dietary and accessibility accommodations, and attendee communications.
  • Evaluate job applicants and manage the recruitment process.
  • Secure and maintain the integrity of our systems, products, services, and customer accounts, including security monitoring, fraud prevention, abuse detection, and incident response.
  • Process security event data, threat intelligence, network telemetry, and incident response data in connection with managed security services, including for threat detection, prevention, forensic analysis, and security improvement.
  • Comply with applicable laws, regulations, legal process, governmental requests, tax obligations, and contractual obligations.
  • Enforce our terms, agreements, and policies.
  • Conduct analytics, product improvement, service improvement, benchmarking, and product development using aggregated, de-identified, or anonymized data that does not identify any individual or customer.
  • Communicate updates, service notices, product announcements, and, where permitted, marketing communications.

What we do not do

We do not sell personal information. We do not sell or share personal information for cross-context behavioral advertising.

Redesign and its Affiliates do not use identifiable Customer Data, including AI Input or AI Output, to train or fine-tune machine-learning or artificial-intelligence models unless the customer expressly authorizes that use through an applicable agreement, Order, Customer-controlled administrator setting, or other documented instruction. We may use aggregated, de-identified, or anonymized data that does not identify a customer or individual, and non-content usage data and telemetry, to develop, train, test, evaluate, and improve our models, products, and services, where permitted by applicable law.

6. AI Processing and Automated Decision-Making

Redesign products, including the Redesign C7e Enterprise AI Platform, Redesign AI Chat, C7e Studio, and related Redesign Applications, may use artificial intelligence to generate outputs from customer content. Outputs are probabilistic and may be incomplete, inaccurate, biased, or not suitable for a particular purpose. Outputs do not constitute professional, legal, financial, regulatory, audit, tax, medical, or other regulated advice.

Customers are responsible for human review and validation of AI outputs before reliance or use. AI-generated content must undergo human review and must not be used as a final decision without human validation, nor represented as legally or contractually binding.

Redesign products are not designed to carry out automated decision-making producing legal or similarly significant effects on individuals. Where a customer configures a Redesign product in a way that could involve such effects, the customer is responsible for implementing the safeguards required by applicable law, including meaningful human involvement.

Redesign's and the customer's roles under applicable artificial-intelligence laws depend on the applicable product, deployment model, and use case. Where Redesign acts as a provider or developer of an artificial-intelligence system or model, Redesign is responsible for obligations applicable to that role. Customers are responsible for obligations arising from their deployment, configuration, and use of Redesign AI products, including required impact assessments, notices, human oversight, and consumer-rights processes.

7. Information Sharing

We do not sell personal information. We may share personal information we control with:

Affiliates. We may share personal information with our affiliates, including THE (RE) DESIGN GROUP FR, for the purposes described in this Policy.

Service providers. We may share personal information with trusted service providers that support our business operations, including hosting, billing, CRM, support tooling, analytics, security, marketing, applicant tracking, and communications providers, under appropriate contractual safeguards.

Third-party technology providers. Where customers use Third-Party Services, Marketplace Functionality, or third-party integrations through the Unified Portal, personal information may be shared with applicable third-party providers as necessary to fulfill the customer's instructions, orders, or integrations. Third-party providers are responsible for their own privacy practices.

Event sponsors and co-hosts. Where an Event is co-hosted with or sponsored by a third party, the registration process may offer you a separate choice to authorize Redesign to share specified contact information with an identified sponsor or co-host for its own communications and follow-up. Redesign will not make such a disclosure unless you affirmatively select that option or otherwise direct Redesign to make the disclosure. The sponsor or co-host is responsible for its subsequent processing and communications.

Professional advisers and authorities. We may share personal information with professional advisers, auditors, legal counsel, and governmental or regulatory authorities where required by law, legal process, or governmental request.

Corporate transactions. We may share personal information in connection with a merger, acquisition, reorganization, sale of assets, financing, or similar corporate transaction, subject to this Policy.

8. Cookies and Similar Technologies

Our website and commercial portals may use cookies, web beacons, pixels, and similar technologies. We may use the following categories of cookies:

Strictly Necessary. Required for website functionality, security, and authentication.

Performance and Analytics. Help us understand how visitors use our website and improve performance.

Functional. Remember preferences and settings to improve user experience.

Marketing. Support marketing communications and advertising relevance, where applicable.

You can manage cookie preferences through your browser settings. Some functionality may be limited if cookies are disabled.

We honor legally recognized browser-based opt-out preference signals, including Global Privacy Control signals, as required by applicable law. We do not otherwise respond to Do Not Track signals at this time.

9. Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this Policy, to comply with legal obligations, to resolve disputes, to enforce agreements, and to maintain business records, after which it is deleted or anonymized in accordance with our retention practices.

For customer content and other data within a customer's self-hosted environment, retention and deletion are managed entirely by the customer within its own environment.

Career and applicant data is retained for the duration of the recruitment process and for a reasonable period thereafter (generally no longer than 24 months) unless you consent to a longer retention period for consideration in future opportunities or applicable law requires otherwise.

10. International Transfers

Redesign is headquartered in the United States. Personal information may be transferred to and processed in the United States, France, the United Kingdom, Canada, and other countries. Where required by applicable law, we rely on adequacy decisions, Standard Contractual Clauses (including the UK International Data Transfer Agreement and Addendum), or other recognized transfer mechanisms. Redesign does not currently participate in the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework; if Redesign self-certifies under any Data Privacy Framework program in the future, this Policy will be updated accordingly.

11. Security

Redesign maintains an information security program with administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. Our program aligns with recognized industry standards, including SOC 2, ISO/IEC 27001, and NIST frameworks, as applicable. Details are available upon request.

For Redesign products deployed within a customer's environment, the customer is responsible for the security of its own infrastructure, including network security, identity and access management, endpoint protection, patching, backups, physical security, and environmental controls.

12. Your Privacy Rights

Under the GDPR, UK GDPR, and related laws

If the EU General Data Protection Regulation, the UK GDPR (as supplemented by the UK Data (Use and Access) Act 2025), or the Swiss Federal Act on Data Protection (FADP) applies, you may have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent. You may lodge a complaint with a supervisory authority, including the CNIL in France, the ICO in the United Kingdom, or your local supervisory authority.

Under US state privacy laws

Depending on your state of residence, including California (CCPA/CPRA), Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Maryland, Minnesota, New Jersey, Delaware, Iowa, Nebraska, New Hampshire, Tennessee, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws, you may have the right to know, access, correct, delete, and port your personal information, and to opt out of the sale or sharing of personal information for targeted advertising or cross-context behavioral advertising.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not discriminate against you for exercising your privacy rights.

CCPA disclosure table

Category of Personal InformationCollectedSourcesPurposesRecipients
Identifiers (name, email, phone, company)YesYou, customer, third-party sources, event registrationAccount, billing, support, communications, events, recruitmentService providers, affiliates, event sponsors (with consent)
Commercial information (orders, transactions, subscriptions)YesYou, customer, marketplaceBilling, fulfillment, entitlementsService providers, affiliates
Internet / electronic activity (IP, browser, usage data, telemetry)YesAutomatically collectedSecurity, analytics, product improvementService providers
Professional / employment information (job title, company, resume, work history)YesYou, customer, third-party sources, job applicantsAccount, relationship management, recruitmentService providers, affiliates
Inferences (usage patterns, preferences)YesDerived from aboveAnalytics, product improvementInternal use
Characteristics of protected classifications (dietary restrictions, accessibility needs)YesEvent registrantsEvent administration and accommodationService providers, venue partners

California Shine the Light. Under California Civil Code Section 1798.83, California residents with an established business relationship with Redesign may request information about personal information we have shared with third parties for their direct marketing purposes. To make such a request, contact privacy@redesign-group.com.

Under Canadian privacy laws

If PIPEDA, Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25), or other applicable provincial privacy legislation applies, you may have the right to access, correct, and withdraw consent for the use of your personal information.

How to exercise your rights

To exercise rights regarding data we control, contact: privacy@redesign-group.com

Where the data relates to processing within a customer's environment, please direct your request to the customer as controller. Redesign will assist the customer as required by the applicable agreement and DPA.

You may designate an authorized agent to submit a privacy request on your behalf. We may require verification of both the agent's authority and your identity before processing such request.

We will respond to verified requests within the timeframes required by applicable law.

13. Events

When you register for or attend an event hosted, organized, or sponsored by Redesign ("Event"), we collect personal information as described in Section 4 (Event registration data). Your attendance is also governed by the Event Registration Terms and Conditions, available at https://www.redesign-group.com/legal, which address assumption of risk, photo and video consent, indemnification, and other matters specific to Event participation.

Where an Event is co-hosted with or sponsored by a third party, the registration process will identify the applicable sponsor or co-host. Attendee information will be shared for the sponsor's or co-host's own communications only where the attendee affirmatively authorizes or directs that disclosure.

Photo and video consent under the Event Registration Terms is separate from data processing consent under this Policy and applicable data protection law. For Events subject to the GDPR, UK GDPR, or other data protection laws that require a lawful basis for processing, you may withdraw data processing consent by contacting privacy@redesign-group.com, though withdrawal will not affect the lawfulness of processing based on consent before withdrawal.

14. Career Opportunities

When you apply for a position with Redesign through our website or other channels, we collect career and applicant data as described in Section 4. We use this data to evaluate your application, communicate with you about the recruitment process, and comply with legal obligations.

We may share applicant data with service providers that support our recruitment process (such as applicant tracking systems and background check providers, where applicable and with your consent where required). We do not sell applicant data.

If you are a California resident, you may have additional rights under the California Consumer Privacy Act. If you are located in the European Economic Area, the United Kingdom, or Switzerland, the legal basis for processing your applicant data is our legitimate interest in evaluating candidates and, where required, your consent.

15. Children

Our products and services are enterprise offerings intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13 (or such other age as specified by applicable law). If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.

16. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated through our website or to customer administrators, and the effective date at the top will be updated.

17. Contact Us

The Drala Project, Inc. d/b/a The Redesign Group
222 N Pacific Coast Hwy, Floor 10
El Segundo, CA 90245, United States
Attention: Legal Department

Privacy inquiries: privacy@redesign-group.com
Website: https://www.redesign-group.com