Data processing
Draft, pending legal review. Last updated 2026-09-24. Bracketed items are still to be filled in.
A plain summary of the data processing terms that apply when your vault holds personal data. To sign a data processing agreement, email andres@redmage.cc.
Roles
The vault's owner (you) is the controller. Red Mage is the processor.
Reliquary is run by Red Mage (Andrés): [to be filled: legal name], [to be filled: legal form], registered in [to be filled: country] under [to be filled: registration number], VAT [to be filled: VAT ID], [to be filled: address]. Contact: andres@redmage.cc.
What we process, and why
| Subject matter | Hosting and serving your vaults: context, proposals, logs and environment variables |
|---|---|
| Duration | While you use Reliquary, until the data is erased or the vault deleted |
| Purpose | Only to provide the service to you and your team, on your instructions (what you and your members do in the product is the instruction) |
| Categories of data | Whatever you put in: typically names, email addresses and work details of your members and of people mentioned in your content; credentials in variables |
| Data subjects | Your members, and people your content is about (clients, contacts, colleagues) |
| Special categories | Not allowed: don't store health, biometric or similar data |
What we commit to
- Process your data only on your documented instructions, and tell you if we believe an instruction breaks the law.
- Keep it confidential: only Red Mage has operator access, and uses it only to run and support the service.
- Keep the security measures on the security page in place.
- Use only the listed sub-processors, with data protection terms at least as protective as these, and tell you [to be filled: notice period] before adding or replacing one, so you can object.
- Help you answer your data subjects' requests: export, erasure of a file, deletion of a vault.
- Tell you without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting your data, with what we know.
- At the end, let you export, then delete your data; backups age out after Supabase keeps daily backups for 7 days; the operator also keeps up to 14 off-site copies, in which variable values exist only as ciphertext.
- Give you the information you need to show compliance, and answer reasonable audit questions in writing.
Transfers outside the EU
The database and app run in the EU. Where a sub-processor may access data from outside the EU, the transfer relies on [to be filled: transfer safeguard, e.g. the provider's Standard Contractual Clauses]. The sub-processor list names each provider and its location.