Ridgital

Privacy Policy

Last updated: 14 July 2026

Ridgital LLC (“Ridgital”, “we”, “us”, or “our”) provides websites, customer portals, software, SaaS products, hosted tools, APIs, infrastructure software, professional services, and other digital products and services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, protect, retain, export, and delete personal data in connection with the Services.

This Policy is intended to comply with the laws of the Republic of Armenia, including the Law on Protection of Personal Data, and with other applicable data-protection laws, including the EU General Data Protection Regulation (“GDPR”) where it applies.

1. Scope and our data-protection roles

This Policy applies to website visitors, prospective customers, Customers, account users, organization administrators, support contacts, and other persons who interact with Ridgital or the Services.

For website, account, commercial, billing, security, support, and business-administration data, Ridgital generally determines why and how personal data is processed and therefore acts as a data controller or equivalent responsible party under applicable law.

Customers may submit, connect, store, or generate personal data through a Service (“Customer Content”). Where the Customer determines the purpose, data, users, instructions, and legal basis, the Customer generally acts as controller and Ridgital processes the data on the Customer’s behalf. A data processing agreement and product-specific privacy terms may apply where required.

This Policy does not replace a Customer’s privacy notice to its employees, users, recipients, end customers, or other data subjects.

2. Personal data we may collect

2.1 Account and organization data

  • name, business email address, telephone number, country, company name, role, and contact details;
  • account, user, workspace, organization, tenant, project, and application identifiers;
  • invitations, permissions, role assignments, account status, preferences, and language settings;
  • login, logout, password-reset, session, multi-session, and authentication activity; and
  • information supplied during registration, onboarding, verification, account administration, or support.

2.2 Customer Content and Service data

The data processed depends on the Service selected and the Customer’s configuration. Examples may include:

  • files, documents, text, messages, email addresses, sender and recipient information, user information, and communications;
  • message subjects, text and HTML bodies, technical headers, reply-to addresses, tags, custom metadata, application identifiers, and delivery instructions where an email service is used;
  • delivery attempts and outcomes, deferrals, bounces, suppressions, open and click outcomes, message and event timelines, and related timestamps;
  • API requests and responses, SMTP activity, webhook configurations and payloads, endpoint URLs, response codes, retry history, usage records, reports, exports, deletion requests, and audit information; and
  • other data that the Customer chooses to upload, connect, generate, or process through a Service.

A Service Schedule or product notice may describe more precisely which fields and events a particular Service processes.

2.3 Credentials, integrations, and connected services

  • credential name, type, status, owner, creator, creation time, last-use time, rotation or revocation activity, and access scope;
  • encrypted or otherwise protected access tokens, service credentials, API keys, certificates, webhook secrets, or connection strings where required to operate an enabled integration;
  • hosting, storage, database, messaging, email, payment, monitoring, communication, and other provider account or endpoint information; and
  • integration configuration, subscribed events, permissions, synchronization history, delivery results, errors, and retry activity.

Secrets are subject to appropriate technical controls. Some complete keys or secrets may be shown only when created and may not be recoverable later.

2.4 Package, subscription, and payment data

  • selected Service, package, feature entitlements, limits, retention period, support level, subscription status, renewal date, usage, credits, and overages;
  • order, proposal, contract, statement of work, invoice, tax, billing-contact, and billing-correspondence information; and
  • payment status, amount, currency, transaction reference, invoice reference, payment time, and reconciliation information received from a bank, VPOS gateway, or payment provider.

Ridgital does not store full payment-card numbers, CVV/CVC codes, or PINs. These are handled by the relevant authorized payment provider.

2.5 Automatically collected technical, usage, and security data

  • IP address, user agent, browser, device, operating system, approximate request location where lawfully derived, and network information;
  • pages, features, buttons, and documentation accessed; referring page; timestamps; session and cookie identifiers; and interface preferences;
  • API, SMTP, storage, data-transfer, message, request, concurrency, performance, and capacity measurements;
  • authentication attempts, authorization results, validation failures, rate-limit or quota events, errors, support diagnostics, and security alerts; and
  • service name, severity, correlation ID, tenant or organization ID, project or resource ID, actor, action, target, result, and timestamp where applicable.

3. How we collect data

We collect personal data:

  • directly from you when you register, purchase, configure, upload, connect, communicate, request support, or use a Service;
  • from Customer administrators and authorized users who invite, manage, or provide information about other users;
  • from Customer applications, systems, configured providers, infrastructure, and enabled integrations;
  • automatically from our websites, applications, APIs, infrastructure, cookies, logs, monitoring, security controls, and usage meters; and
  • from banks, payment providers, hosting and cloud providers, communication networks, identity providers, support providers, and other vendors involved in operating a Service.

4. Why we process personal data

We process personal data to:

  • create, authenticate, secure, and administer accounts, organizations, tenants, projects, users, roles, sessions, and credentials;
  • provide, configure, operate, maintain, support, and troubleshoot the Services and Customer-enabled integrations;
  • receive, store, validate, technically transform, transmit, deliver, monitor, and return Customer Content according to Customer instructions;
  • provide packages, subscriptions, checkout, invoicing, payment reconciliation, credits, quotas, metering, usage visibility, and support entitlements;
  • generate dashboards, events, logs, reports, exports, retention workflows, and authorized deletion processes;
  • monitor reliability, capacity, performance, availability, integration health, and Service quality;
  • provide support, investigate failures, communicate about accounts or Services, and maintain operational and audit records;
  • detect and prevent fraud, spam, abuse, credential misuse, unauthorized access, security incidents, prohibited use, and violations of our Terms;
  • improve the functionality, usability, security, and efficiency of our Services using account, usage, diagnostic, aggregated, or de-identified information where appropriate; and
  • comply with legal, regulatory, tax, accounting, judicial, contractual, and compliance obligations and establish or defend legal claims.

We do not sell personal data. We do not use Customer Content for targeted advertising or disclose it to advertising networks.

5. Legal bases where GDPR or similar law applies

Depending on the data and context, we rely on:

  • Contract: processing necessary to provide requested Services, accounts, subscriptions, billing, support, and integrations;
  • Legal obligation: processing necessary for tax, accounting, regulatory, judicial, or other legal duties;
  • Legitimate interests: securing and operating the Services, preventing abuse, enforcing agreements, supporting Customers, improving reliability, and protecting legal rights, where those interests are not overridden by individual rights; and
  • Consent: where we expressly request consent and applicable law requires or permits reliance on it.

For Customer-submitted personal data, the Customer is responsible for identifying and documenting the appropriate legal basis unless Ridgital independently determines the processing purpose.

6. Customer responsibilities

Customers must:

  • collect, connect, and submit personal data lawfully and only for legitimate, disclosed purposes;
  • provide required privacy notices and obtain any required consent or authorization;
  • configure access, retention, integrations, and security appropriately;
  • respond to data-subject requests for Customer-controlled data and use available export, correction, deletion, or restriction tools;
  • avoid submitting unnecessary personal data or data prohibited by the applicable Service Schedule; and
  • ensure that instructions, Customer Content, and use of the Services comply with applicable law and third-party rights.

7. Service communications and marketing

We may send operational communications needed to administer an account or provide a Service, including verification, password-reset, security, billing, renewal, payment-failure, quota, incident, support, export, deletion, and material Service-change notices. These messages are part of the Service and generally cannot be opted out of while the relevant account or Service remains active.

We may send product news, event information, or marketing communications where permitted by law. You may unsubscribe using the link in the message or by contacting us. Unsubscribing from marketing does not stop necessary account, security, billing, or Service communications.

8. Disclosure and recipients of data

We disclose personal data only as reasonably necessary to:

  • authorized users and administrators within the relevant Customer account, organization, workspace, or tenant;
  • Customer-configured integrations, endpoints, outbound email or SMTP providers, connected provider accounts, infrastructure, and service providers;
  • hosting, infrastructure, storage, database, queue, networking, monitoring, security, identity, support, email, and communication providers acting under appropriate obligations;
  • banks, VPOS gateways, payment processors, accounting providers, and fraud-prevention providers, including Ameriabank where it is the provider shown for the applicable checkout or payment flow;
  • professional advisers, auditors, insurers, and prospective parties to a corporate transaction, subject to appropriate confidentiality; and
  • courts, regulators, tax authorities, law-enforcement bodies, or other authorities where required by law or necessary to protect rights, safety, security, and the integrity of the Services.

Where a Service is multi-tenant, Customer-facing access is restricted to the relevant tenant or organization. We do not intentionally disclose one Customer’s Customer Content to another Customer.

9. Third-party services and subprocessors

Customers may enable third-party integrations or instruct us to use particular providers. Data sent to those providers is also subject to their terms and privacy practices. Ridgital may use subprocessors to operate the Services and remains responsible for managing them as required by applicable law and contractual commitments.

Product documentation, a Service Schedule, or a separate data processing agreement may identify categories of subprocessors, data locations, additional safeguards, or notification procedures.

10. International processing and transfers

Ridgital is established in Armenia. Depending on the Service, Customer configuration, users, connected systems, and providers, personal data may be processed in Armenia and other countries. Where applicable law requires safeguards for an international transfer, we will use an appropriate legal mechanism, contractual protection, adequacy basis, or other permitted safeguard.

11. Retention and deletion

Retention depends on the Service, package, Customer configuration, data category, contract, and legal requirements. Product documentation or a Service Schedule may specify retention for Customer Content, logs, events, artifacts, backups, or other Service data. Where Customer-controlled retention is available, Customer is responsible for configuring it appropriately.

We retain data only for as long as reasonably necessary for the purposes described in this Policy, including:

  • Customer Content and Service records for the active Service and applicable retention or transition period;
  • security, authentication, audit, operational, abuse-prevention, and compliance records according to platform policy;
  • invoice, payment, tax, accounting, dispute, and legal records for the period required or permitted by law; and
  • account and support information for as long as needed to administer the relationship, resolve issues, and protect legal rights.

Deletion may be delayed or limited where data must be retained for security, backup integrity, legal obligations, fraud prevention, audit integrity, third-party provider processing, or the establishment or defense of claims. Data in backups may remain until the relevant backup is securely overwritten or expires under the applicable cycle.

12. Security, isolation, and administrative access

We use technical and organizational measures designed to protect personal data, including authentication, role-based authorization, access controls, secure transport, credential protection, encryption where appropriate, tenant or organization isolation where applicable, logging, monitoring, rate limiting, session controls, vulnerability management, and audit trails.

Administrative access is restricted according to role and operational need and is subject to logging or audit controls where appropriate. Personnel and contractors with access are subject to confidentiality obligations.

If a personal-data incident occurs, we will investigate, contain, document, and provide notifications to Customers, affected persons, or authorities where required by applicable law or a binding agreement.

No system can be guaranteed completely secure. Customers must protect their users, devices, networks, accounts, credentials, integrations, endpoints, connected provider accounts, and configurations and notify us promptly of suspected compromise.

13. Aggregated and de-identified information

We may aggregate or de-identify information so that it no longer reasonably identifies an individual or Customer. We may use such information for statistics, capacity planning, security, benchmarking, Service improvement, and business analysis, and may disclose it where lawful. We do not attempt to re-identify data treated as de-identified unless necessary to test our safeguards or permitted by law.

14. Cookies and similar technologies

Our websites and portals may use cookies or similar technologies for login sessions, secure forms, CSRF protection, account security, load balancing, preferences, language, checkout continuity, support, analytics, and performance. Where required, we request consent before using non-essential analytics, advertising, or marketing technologies.

Third-party resources such as fonts, icons, payment interfaces, support tools, analytics, or technical assets may receive ordinary web-request information, including an IP address, when loaded. Available browser or consent controls may be used to manage optional cookies.

Our websites and portals may use cookies or similar technologies for login sessions, secure forms, CSRF protection, account security, load balancing, preferences, language, checkout continuity, support, analytics, and performance. Where required, we request consent before using non-essential analytics, advertising, or marketing technologies. Further detail, including the specific cookies we use and how to manage your choice, is available in our Cookie Policy.

15. Your rights and how to exercise them

Subject to applicable law, you may have rights to:

  • obtain information about and access to your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing in certain circumstances;
  • object to certain processing;
  • receive certain data in a portable format;
  • withdraw consent where processing is based on consent, without affecting earlier lawful processing; and
  • submit a complaint to the competent data-protection authority.

If a Ridgital Customer submitted or controls your data, contact that Customer first because it generally determines the relevant processing. We will assist the Customer with verified requests as required. You may also contact Ridgital below. We may verify identity, authority, account, and request scope before acting.

16. Children

The Services are intended for businesses and persons legally able to enter into the applicable agreement. They are not directed to children. Customers must not submit children’s personal data unless they have a lawful basis, provide required notices, obtain required authorization, and use a Service that permits such processing.

17. Product-specific privacy information

A Service Schedule, product notice, documentation, or data processing agreement may provide additional information about data fields, tracking, subprocessors, security, retention, deletion, regional processing, or Customer controls for a particular Service. Those materials supplement this Policy and control for their more specific subject matter.

18. Changes to this Policy

We may update this Policy to reflect changes in the Services, law, security requirements, subprocessors, or business practices. We will publish the revised version and update the “Last updated” date. Where required, we will provide additional notice of material changes.

19. Contact

For privacy questions, rights requests, or data-protection concerns, contact:

Ridgital LLC
9/1 Halabyan Street, Ajapnyak, Yerevan, Republic of Armenia
Email: info@ridgital.com
Phone: +374 93 949 121