Service security
Where your data lives, what the platform collects, who can see it, and how long it is kept.
Last reviewed:
This page answers, without hedging, the four questions anyone should ask before putting company information into a platform: where the data lives, what is collected, who can see it, and how long it is kept.
Where your data lives
Red Cricket Cloud is a cloud service. Red Cricket runs the platform on infrastructure from specialized providers that process data on our behalf, under our instructions and not for their own purposes. Those providers may process data on servers outside Mexico, mainly in the United States.
Red Cricket is a Mexican company and processing is governed by Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). The list of providers, what each one does and which data it reaches, lives in the Privacy Notice, which is where it is kept up to date.
What the platform collects
Two things are worth separating: your account data, which Red Cricket answers for, and the data you upload about third parties — your vendors, your domains, your people — which your organization answers for and which Red Cricket processes only on your instructions.
| What | Includes | Why |
|---|---|---|
| Account and users | Name, work email, organization, role, language, encrypted credentials, and multi-factor authentication factors | Creating and running your organization, and giving you access |
| Usage and security | IP address, session and device identifiers, access and action logs | Running the service securely and keeping an audit trail |
| Billing | Tax details, billing email, and charge history. Card data is received and stored by the payment processor: Red Cricket does not store it | Charging the subscription and invoicing |
| Advisor | Scheduling, attendees, and session notes | Delivering the advisory and counting the cycle's hours |
| Support | The content of what you write to us | Helping you |
| What you upload | Vendors and their contacts, domains, work emails, and assets you register in the modules | Running the modules you subscribed to |
We do not request sensitive personal data. Free-text fields — notes, descriptions, questionnaire answers — are yours: whatever you write there travels with the rest of the module's content, so it is worth keeping out of them anything you would rather not have processed.
Who can see it
- Your organization, isolated from every other one. Access is enforced at the database level: one organization cannot reach another's data.
- The people you invite, with the role you give them.
- Red Cricket staff, only as needed to operate the platform and handle support, on infrastructure that logs activity.
- The providers that run the service, each with only the data its function requires.
- Competent authorities, only under a legally grounded and substantiated request.
What is sent to an artificial intelligence provider
Some modules use an external artificial intelligence service to classify alerts, summarize questionnaires, and explain findings in plain language. That provider is given no access to your account or to the database: it receives only the specific fragment the module sends it — an alert's content, a finding's text, a domain — and returns the result. That provider is identified in the Privacy Notice, along with the data it reaches.
How long it is kept
| Situation | What happens |
|---|---|
| Your 30-day trial ends and you don't subscribe | Access is suspended, but what you configured is kept for 60 calendar days and comes back as it was if you subscribe within that window. After 60 days, the organization and its data may be deleted |
| You end your subscription | You can request an export of your data for up to 30 calendar days after termination |
| Once the export window closes | We delete or anonymize your data, except what we must keep by legal obligation |
| Security logs (access and actions) | 12 months |
| Billing data | The period required by tax law |
| Your cookie preference | 12 months, in a first-party cookie |
Backups follow their own cycle: data deleted from the service remains in the database backups until they rotate, within a maximum of 7 days. Files you upload — compliance evidence, profile pictures — are stored separately and are not part of those backups: once you delete them, no copy remains.
What is in your hands
- Turn on multi-factor authentication, for your account and as a requirement for your team.
- Define roles: who views, who configures, and who administers.
- Request an export of your data during the subscription and for up to 30 days after ending it.
- Cancel whenever you want, effective at the end of the paid period.
- Exercise your ARCO rights — access, rectification, cancellation, objection — by writing to
privacy@redcricket.net. Much of your account data you can correct yourself from the platform.