How RedSec LTD processes data on behalf of customers in delivering SpyPhone products and services.
Effective: July 6, 2026
This Data Processing Agreement (DPA) applies where RedSec LTD processes personal data on behalf of a customer controller in the course of providing services.
This DPA is between RedSec LTD (processor) and the customer (controller), and supplements the Terms of Service. It applies to personal data processed to deliver contracted services.
The customer is the data controller and determines the purposes and means of processing. RedSec LTD acts as processor and processes data only on documented instructions from the customer.
Categories may include device identifiers, communications metadata, and location data necessary to provide the contracted monitoring capabilities. The customer is responsible for lawfulness of collection.
RedSec LTD applies encryption in transit and at rest, access controls, hardware-level isolation, and documented operational-security procedures consistent with recognized frameworks.
RedSec LTD engages subprocessors only with customer authorization and under written agreements imposing equivalent data-protection obligations. A current list is available on request.
On contract end, RedSec LTD returns or deletes customer data at the customer's choice, save where retention is required by law.
SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.