ReDist
Privacy framework

Privacy framework for organization trust workflows.

This page summarizes the ReDist privacy framework for public review. It is not a final privacy policy and must be reviewed by qualified UAE privacy or legal counsel before commercial use.

Verified Redistribution Operating SystemSurplus to impact, governed by trust.
SurplusDiscoveryApprovalTransferVerifyImpact
UAELaunch market
QRCertificate validation
GCCExpansion ready

Controlled pilot access. Public impact claims wait for completed, approved real Transfers.

Review notice

Framework pending formal UAE privacy review.

ReDist collects only the information needed to operate founder-guided redistribution, lead review, verification, evidence, and pilot workflows. Final privacy obligations require professional review.

Data ReDist may process

  • Organization data such as legal name, trade name, organization type, location, contact details, verification status, trust context, listings, requests, transfers, certificates, and impact summaries.
  • User data such as name, email, role, organization membership, support requests, feedback submissions, and authorized workflow actions.
  • Lead inquiry data submitted through the public contact form, including name, organization, email, phone, inquiry type, city, timeline, and message.
  • Operational records such as verification documents, transfer certificates, handover evidence, audit actions, permission decisions, and support notes where required for platform operation.

Why data is used

  • Operate supplier, recipient, transfer, verification, certificate, impact, and founder review workflows.
  • Review organization eligibility and pilot suitability.
  • Support trust, safety, dispute review, auditability, and platform security.
  • Respond to inquiries, schedule founder conversations, and manage pilot or partnership follow-up.

Protection principles

  • Sensitive documents should not be submitted through the public contact form.
  • Founder and platform review areas are intended to be protected from public access.
  • Public certificate verification should expose only public-safe transfer facts, not sensitive documents, contact details, or internal audit notes.
  • Service role keys, private credentials, and sensitive environment variables must never be exposed in the browser or committed to the repository.

Professional review required

  • UAE Personal Data Protection Law applicability.
  • Free zone or sector-specific data obligations.
  • Consent, notice, retention, deletion, and correction rights.
  • Cross-border processing disclosures for hosting, database, analytics, and support providers.
  • Incident notification, audit log retention, and certificate evidence retention periods.
Controlled pilot

Questions about data handling?

Contact the founder before submitting sensitive information, requesting pilot access, or using ReDist evidence in external reporting.

Ask a privacy question