Eridian
← Back to Home

Privacy Policy

Last updated: August 12, 2026

Eridian is a product of RENEDOR LLC. These documents are the current published policies for Eridian, operated by RENEDOR LLC. Viewing this page does not create an order form, DPA, or other contract. Send legal and data-subject requests to the addresses listed in each document.

1. Who We Are

Eridian is a product of RENEDOR LLC. Eridian is operated by RENEDOR LLC, a limited liability company organized under the laws of the United Arab Emirates, with its registered office at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates (the "Company", "we", "us", or "our"). This Privacy Policy explains how the Company collects, uses, stores, and discloses personal data in connection with Eridian and the public website.

For Customer Data processed through the Service on a customer's instructions, the customer is the controller (or equivalent under applicable law) and the Company is the processor. That processing is governed by the Data Processing Addendum at /legal/dpa and the customer's own privacy notice. This Policy describes the Company's own processing as a controller of account, billing, website, and support data, and summarizes processor practices for transparency.

2. Scope and Applicable Law

The Company's primary privacy law is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data of the United Arab Emirates and its executive regulations (the "UAE PDPL"), together with decisions of the UAE Data Office. Because the registered office is in Dubai Silicon Oasis, the DIFC Data Protection Law is not the Company's default regime.

Where the Company processes personal data of individuals in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation and the UK GDPR apply to that processing to the extent required. Where another country's law applies, the Company will comply with that law in addition to this Policy.

3. Personal Data We Collect

We collect the following categories, depending on how the Service and website are used:

  • Account and billing data: name, business email, job title, employer, workspace identifiers, billing address, VAT or tax registration numbers, payment-method tokens (processed by Stripe; the Company does not store full card numbers), and invoice history.
  • Customer Data: prompts, documents, retrieved context, Output, project metadata, and related logs that a customer or its users submit to the Service. The customer determines the content of Customer Data.
  • Usage and security data: API call metadata, model and region selected, token counts, latency, error codes, IP address, user-agent, authentication events, and audit-log entries.
  • Website data: pages viewed, referrer, approximate location derived from IP, cookie identifiers as described in the Cookie Policy, and form inputs entered on this site.
  • Support and communications: the content of emails and tickets sent to the addresses published on the website.

4. How We Use Personal Data and Lawful Bases

Under the UAE PDPL, the Company processes personal data where a lawful basis applies, including: (a) the data subject's consent; (b) processing necessary to perform a contract with the data subject or to take steps at the data subject's request; (c) processing necessary to comply with a legal obligation; and (d) processing necessary for the Company's legitimate interests, provided those interests do not override the data subject's rights. GDPR lawful bases, where applicable, are the counterparts of the above (Articles 6(1)(a)-(f) GDPR).

We use personal data to: provide and secure the Service; create and administer accounts; process payments; provide support; monitor performance and detect abuse; comply with accounting, tax, and regulatory duties; and improve the Service using aggregated or de-identified telemetry that does not include Customer Data used for model training.

5. No Training on Customer Data Without Consent

The Company does not use Customer Data to train, fine-tune, or otherwise improve foundation models without the customer's prior explicit written consent. Consent must be documented in an Order Form or other written instrument. Website use, account creation, or payment is not consent to training.

Model providers process prompts for inference when the customer selects a provider. The Company contracts with those providers as subprocessors and requires that Customer Data not be used for provider training except where the customer has separately consented under the DPA and the provider's terms.

6. How We Share Personal Data

We do not sell personal data. We share personal data only:

  • With subprocessors that host, route, bill, monitor, or secure the Service, as listed at /legal/subprocessors, under written contracts that impose confidentiality and data-protection obligations.
  • With model providers solely to perform the inference the customer requested.
  • With professional advisers (legal, audit, insurance) under confidentiality.
  • With a buyer or successor in a merger, acquisition, or asset sale, subject to this Policy.
  • When required by UAE or other applicable law, a competent court or regulator, or to protect the rights, safety, or property of the Company, customers, or the public.

7. International Transfers

The Company is established in the United Arab Emirates. Personal data may be transferred to subprocessors in the United States, the European Union, and other regions listed on the Subprocessors page.

For transfers subject to the UAE PDPL, the Company uses a permitted transfer mechanism, including an adequacy decision where one exists, a contract that includes appropriate protection measures, or another mechanism recognized by the UAE Data Office.

For transfers subject to GDPR or UK GDPR, the Company uses the European Commission's Standard Contractual Clauses (Module 2 for controller-to-processor transfers of Customer Data, and Module 1 where the Company is controller), the UK International Data Transfer Addendum, and the Swiss addendum where applicable.

8. Data Residency

Enterprise customers may pin Customer Data at rest to a residency region: United Arab Emirates, European Union, United States, or Asia-Pacific, as made available in the workspace and Order Form. Pinning controls storage location for Customer Data at rest and, where offered, primary processing.

Inference may still occur in the model provider's region. Account, billing, email, and security telemetry may be processed outside the pinned region. Zero-Data-Retention (ZDR) with selected providers is available on Enterprise tiers where the provider supports it.

9. Retention

Customer Data is retained for the subscription term plus thirty (30) days, unless a longer period is required by the Order Form, a legal hold, or law. Inference logs are retained for ninety (90) days by default and are configurable on Enterprise. Billing and tax records are retained for at least seven (7) years, or longer if UAE accounting rules require. Website logs are retained for up to thirteen (13) months. Backups rotate on a limited cycle after deletion from production systems.

10. Your Rights under the UAE PDPL

If the UAE PDPL applies to you, you may have the right to: (a) obtain information about processing; (b) request access to your personal data; (c) request rectification of inaccurate data; (d) request erasure where the PDPL permits; (e) request restriction of processing; (f) object to processing in the cases the PDPL allows; (g) withdraw consent where processing is based on consent, without affecting prior lawful processing; and (h) data portability where the PDPL provides it.

Requests should be sent to contact@geteridian.com. The Company may need to verify identity and, where the Company is processor, will redirect the request to the customer controller. You may also lodge a complaint with the UAE Data Office.

11. Additional Rights for EEA and UK Individuals

If GDPR or UK GDPR applies, you additionally have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to lodge a complaint with a supervisory authority in your place of residence or work. Contact the Data Protection Officer at contact@geteridian.com. The Company has not appointed an EU or UK representative unless an Order Form states otherwise.

12. Cookies

The website uses cookies and similar technologies as described in the Cookie Policy at /legal/cookies. Essential cookies are required to operate the site. Non-essential cookies, if any, are used only with a lawful basis, including consent where required.

13. Security

The Company implements technical and organizational measures appropriate to the risk, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, multi-factor authentication, network segmentation, logging, and vendor review. No method of transmission or storage is perfectly secure. Additional detail appears on the Security page and in the DPA.

14. Children

The Service is not directed to children. The Company does not knowingly collect personal data from anyone under 21. If the Company learns that it has collected such data, it will delete it except where retention is required by law.

15. Changes

The Company will post updates to this Policy with a new effective date. Material changes will be notified at least thirty (30) days in advance by email or in-product notice to workspace administrators.

16. Contact

Privacy and data-subject requests: contact@geteridian.com. Data Protection Officer: contact@geteridian.com. Legal notices: contact@geteridian.com. RENEDOR LLC, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates.