Service security

Where your data lives, what the platform collects, who can see it, and how long it is kept.

Last reviewed:

This page answers, without hedging, the four questions anyone should ask before putting company information into a platform: where the data lives, what is collected, who can see it, and how long it is kept.

Where your data lives

Red Cricket Cloud is a cloud service. Red Cricket runs the platform on infrastructure from specialized providers that process data on our behalf, under our instructions and not for their own purposes. Those providers may process data on servers outside Mexico, mainly in the United States.

Red Cricket is a Mexican company and processing is governed by Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). The list of providers, what each one does and which data it reaches, lives in the Privacy Notice, which is where it is kept up to date.

What the platform collects

Two things are worth separating: your account data, which Red Cricket answers for, and the data you upload about third parties — your vendors, your domains, your people — which your organization answers for and which Red Cricket processes only on your instructions.

WhatIncludesWhy
Account and usersName, work email, organization, role, language, encrypted credentials, and multi-factor authentication factorsCreating and running your organization, and giving you access
Usage and securityIP address, session and device identifiers, access and action logsRunning the service securely and keeping an audit trail
BillingTax details, billing email, and charge history. Card data is received and stored by the payment processor: Red Cricket does not store itCharging the subscription and invoicing
AdvisorScheduling, attendees, and session notesDelivering the advisory and counting the cycle's hours
SupportThe content of what you write to usHelping you
What you uploadVendors and their contacts, domains, work emails, and assets you register in the modulesRunning the modules you subscribed to

We do not request sensitive personal data. Free-text fields — notes, descriptions, questionnaire answers — are yours: whatever you write there travels with the rest of the module's content, so it is worth keeping out of them anything you would rather not have processed.

Who can see it

  • Your organization, isolated from every other one. Access is enforced at the database level: one organization cannot reach another's data.
  • The people you invite, with the role you give them.
  • Red Cricket staff, only as needed to operate the platform and handle support, on infrastructure that logs activity.
  • The providers that run the service, each with only the data its function requires.
  • Competent authorities, only under a legally grounded and substantiated request.

What is sent to an artificial intelligence provider

Some modules use an external artificial intelligence service to classify alerts, summarize questionnaires, and explain findings in plain language. That provider is given no access to your account or to the database: it receives only the specific fragment the module sends it — an alert's content, a finding's text, a domain — and returns the result. That provider is identified in the Privacy Notice, along with the data it reaches.

How long it is kept

SituationWhat happens
Your 30-day trial ends and you don't subscribeAccess is suspended, but what you configured is kept for 60 calendar days and comes back as it was if you subscribe within that window. After 60 days, the organization and its data may be deleted
You end your subscriptionYou can request an export of your data for up to 30 calendar days after termination
Once the export window closesWe delete or anonymize your data, except what we must keep by legal obligation
Security logs (access and actions)12 months
Billing dataThe period required by tax law
Your cookie preference12 months, in a first-party cookie

Backups follow their own cycle: data deleted from the service remains in the database backups until they rotate, within a maximum of 7 days. Files you upload — compliance evidence, profile pictures — are stored separately and are not part of those backups: once you delete them, no copy remains.

What is in your hands

  • Turn on multi-factor authentication, for your account and as a requirement for your team.
  • Define roles: who views, who configures, and who administers.
  • Request an export of your data during the subscription and for up to 30 days after ending it.
  • Cancel whenever you want, effective at the end of the paid period.
  • Exercise your ARCO rights — access, rectification, cancellation, objection — by writing to privacy@redcricket.net. Much of your account data you can correct yourself from the platform.

What we don't promise