Introduction
Vital (“the Service”) is operated by Red One Corporation (“Red One”, “we”, “us”). This policy explains what data the Service processes on behalf of the organizations that subscribe to it (“Customers”), and how we protect it. For Customer mailbox data, Red One acts as a data processor; the Customer is the data controller.
Data we process
We access mailboxes only after a Customer administrator grants explicit Microsoft 365 admin consent. To avoid requiring customers to re-consent later, the Service requests both read and management (read/write) permissions for the enrolled mailboxes at the time of consent; write permissions are exercised only for features the Customer enables.
Sub-processors
We share the minimum data necessary with the following sub-processors:
Our marketing site and app use Google Analytics. Analytics cookies are set only after you accept them via the on-site consent banner (analytics defaults to denied under Google Consent Mode until then). Within the app we strip URLs of query parameters before they reach Google, so mailbox identifiers and session tokens are never shared. You can change your choice anytime via the “Cookie settings” link.
AI processing & training
Email content is sent to our AI sub-processor solely to classify and draft replies for that message. We do not use Customer data to train AI models, and our AI sub-processor does not train its models on data submitted through its commercial API.
Storage & retention
Service data is stored in Microsoft Azure in the East US region. Compliance-tier Customers may be provisioned dedicated, geo-redundant storage and a dedicated key vault. We retain processed-message and action-item records for 12 months, and delete Customer data within 30 days of account termination on request.
Security
Data is encrypted in transit (TLS) and at rest. Each Customer’s data is logically isolated by tenant, and platform secrets are held in Azure Key Vault accessed via managed identity. Access to production systems is restricted to authorized Red One personnel.
Your rights
Depending on your jurisdiction (e.g., GDPR, CCPA), individuals may have rights to access, correct, delete, or export their personal data, and to object to or restrict processing. Because we process mailbox data on behalf of Customers, such requests are generally directed to the Customer (controller); we assist Customers in fulfilling them. Contact privacy@red.one.
Text messaging (SMS)
If you provide a mobile number, you consent to receive recurring automated text alerts from Vital — inbox monitoring notifications and account messages — at that number. Consent is not a condition of purchase, and you can opt out at any time by replying STOP (reply HELP for help). Message frequency varies, and message and data rates may apply. We use your mobile number and SMS opt-in solely to deliver these messages. We do not sell your personal information, and mobile opt-in information — your phone number and consent — is never shared with third parties or affiliates for their own marketing or promotional purposes. Your number is shared only with our SMS delivery sub-processor (Twilio) to send the messages you requested.
Changes
We will post material changes here and update the effective date. Continued use of the Service after changes constitutes acceptance.
Contact
Red One Corporation
3200 Highlands Pkwy SE, Smyrna, GA 30082
privacy@red.one