Hanif Developments (002647287-X) operates Roidio. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use our website, applications, subscriptions, trials, support channels, and related services.
We are based in Malaysia and make the service available worldwide. Depending on where you live, local privacy rights may also apply.
1. Who Is Responsible for Your Personal Data
Hanif Developments is responsible for personal data we process for our own service operations, account administration, billing, analytics, marketing, security, and support.
You can contact us at [email protected] or by post at P/35 Block B, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.
2. Personal Data We Collect
We collect personal data that you provide directly, data generated through your use of the service, and data received from third-party services you choose to connect to Roidio.
- Account data, such as name, email address, password authentication data, organization or team details, role, settings, and profile information.
- Authentication data from Google Auth, such as email address, name, profile image, OAuth subject identifier, and sign-in metadata.
- Billing data handled through Stripe, such as checkout details, subscription status, invoice history, payment method metadata, tax details, fraud signals, and transaction identifiers.
- Usage and device data, such as IP address, browser, device type, pages viewed, events, referral URLs, approximate location, session data, cookies, pixels, and similar technologies.
- Client Profile data, such as business name, industry, audience, voice, offerings, positioning, and other business knowledge you enter or import to ground AI-assisted work.
- Knowledge connector content, such as the text content of Google Drive documents and Notion pages you explicitly select and sync to use as AI context within the service.
- Connected account credentials, such as encrypted OAuth tokens, Application Passwords, and API keys for supported platforms you link to Roidio, including Google Drive, Notion, and WordPress.
- Operation and approval data, such as bounded inputs, status, step output, exact change plans, approval decisions, external-action receipts, verification results, AI-generated content, safe error details, and internal usage records.
- AI Search evidence and website content data, such as audited URLs, prompts, engine observations, coverage limitations, citations, supported WordPress fields, immutable snapshots, proposed diffs, deployment receipts, and remeasurement results.
- Customer content, such as prompts, website materials, generated outputs, saved workflows, notes, and other materials submitted to the service.
- Support and communications data, such as messages, requests, feedback, survey responses, and email metadata.
- Marketing and advertising data, such as campaign interactions, conversion events, audience or attribution signals, and ad measurement data where legally permitted.
3. How We Use Personal Data
We use personal data to operate, secure, improve, and market the service, and to comply with legal obligations.
- Provide accounts, dashboards, subscriptions, trials, AI features, analytics, support, and team workflows.
- Process payments, invoices, subscription changes, cancellations, renewals, fraud prevention, and tax or accounting records.
- Authenticate users, protect accounts, monitor security, prevent abuse, detect bots via Cloudflare Turnstile, troubleshoot errors, and enforce our Terms.
- Generate evidence-backed AI Search proposals using Client Profile data, measured evidence, connected website content, and selected knowledge-source content as bounded AI context.
- Retrieve and process content from connected knowledge sources (Google Drive, Notion) you authorize, for use as context in AI features.
- Read supported content from a WordPress site you connect, prepare an exact proposed change, and deploy or restore that change only after the required human approval.
- Analyze product usage, measure performance, improve features, and understand how users interact with the service.
- Send service messages, security notices, billing notices, product updates, and marketing communications where permitted via Elastic Email.
- Measure product acquisition and conversions through Google Ads and related analytics tools where enabled.
- Comply with legal, regulatory, tax, accounting, dispute, and enforcement obligations.
4. Legal Bases and Consent
Where a legal basis is required, we rely on contract performance, legitimate interests, consent, compliance with legal obligations, and protection of rights and security, depending on the activity and jurisdiction.
Where consent is required for cookies, analytics, advertising, marketing emails, or cross-border transfers, we will request or respect consent through the product, browser settings, platform controls, unsubscribe links, or other legally recognized mechanisms.
6. AI Processing
When you use AI-assisted features, prompts, Client Profile data, knowledge connector content, connected website data, uploaded materials, generated outputs, metadata, and related usage information may be processed by OpenAI to provide, secure, monitor, and support those features.
OpenAI is used for Client Profile extraction and evidence-backed AI Search proposals.
Do not submit sensitive personal data, regulated data, confidential third-party data, or data you are not authorized to process unless the product expressly supports that use and you have all required rights, notices, and consents.
8. Connected Accounts and Third-Party Integrations
Roidio allows you to connect supported third-party platforms for customer-authorized reads and narrowly scoped actions. When a connection requires credentials or OAuth tokens, we store them encrypted at rest.
The following integrations are available and involve storing or processing data from those platforms:
- WordPress — Application Password credentials stored to read supported website content and, only after exact human approval, deploy or restore a reviewed change.
- Google Drive — OAuth token stored to allow you to select and sync Google Drive documents as knowledge sources for AI context.
- Notion — OAuth token stored to allow you to select and sync Notion pages as knowledge sources for AI context.
- You may disconnect supported accounts from the applicable dashboard connection surface. Disconnecting removes stored credentials. Synced content may be retained for a limited period before deletion unless you request earlier deletion.
9. International Transfers
Because Roidio is available worldwide and uses global cloud, payment, analytics, authentication, AI, and storage providers, personal data may be processed in Malaysia and other countries, including the United States, where our providers operate.
Where required, we use appropriate safeguards such as contractual protections, data processing terms, vendor assessments, consent, or other mechanisms recognized by applicable data protection laws.
10. Retention
We retain personal data for as long as needed to provide the service, maintain accounts, process subscriptions, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and keep business records.
Typical retention periods by data type: account data is kept while the account is active and for a reasonable period after closure; billing and tax records are kept as required by applicable law (typically 7 years); security and access logs are kept for a limited operational period; support messages are kept while needed for service and recordkeeping; operation records and AI outputs are retained while your account is active; synced website and knowledge-source content is retained until you disconnect the source or delete your account; media files in Cloudflare R2 are retained while your account is active; and deleted account data is removed or anonymized within 90 days unless longer retention is legally required.
11. Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These include encryption at rest for connected account credentials, encrypted transport (TLS), access controls, and bot protection via Cloudflare Turnstile on public-facing forms. No online service can guarantee absolute security.
If you believe your account or data has been compromised, contact us immediately at [email protected].
12. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing is based on consent.
To exercise privacy rights, contact [email protected]. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.
13. Data Deletion and Account Closure
You have the right to request deletion of your personal data. We provide the following options:
- Delete specific data — You may request deletion of specific data categories (such as synced website or knowledge-source content, operation records, AI outputs, or media files) by emailing [email protected] with the subject line "Data Deletion Request". Please specify the data you want deleted and the account email address.
- Close your account and delete all data — To permanently close your account and request deletion of all associated personal data, email [email protected] with the subject line "Account Closure and Data Deletion". We will verify your identity, terminate your subscription (if active), and initiate deletion of your account data.
- Disconnect connected accounts — You may revoke Roidio's access to supported connected accounts, including Google Drive, Notion, and WordPress, from the applicable dashboard surface. This removes stored credentials. Residual synced content will be queued for deletion.
- We will action deletion requests within 30 days of verified identity confirmation. Certain data may be retained beyond this period where required by applicable law (for example, billing records for tax compliance), where data is part of an ongoing dispute or legal obligation, or where immediate technical deletion is not feasible, in which case the data will be securely isolated and deleted as soon as practicable.
- Note that deletion is irreversible. Deleting your account will permanently remove access to your subscription, Client Profiles, operation history, and associated data.
14. Children
The service is intended for business and professional users and is not directed to children. Do not use the service if you are not legally able to form a binding agreement or if your use would require parental consent that has not been provided.
15. Marketing Communications
We may send product updates, newsletters, offers, and service-related communications via Elastic Email. You can unsubscribe from marketing emails using the unsubscribe link in any email or by contacting [email protected]. We may still send transactional or security messages regardless of marketing preferences.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as updating the effective date, posting a notice, or sending account email where appropriate. Continued use of the service after changes become effective means you accept the updated Policy.
17. Contact
For privacy questions, data access requests, or deletion requests, contact Hanif Developments at [email protected] or by post at P/35 Block B, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.