RedditLab24 ← Back to site

Privacy Policy

Effective 3 September 2026 · Last updated 3 September 2026

This policy explains what personal data RedditLab24 processes, where it comes from, why we process it, and how you can object or ask us to delete it. It covers this website and any business email we send.

If you received an unsolicited email from us and want it to stop, reply with the word UNSUBSCRIBE, or write to alex@redditlab24.net. We remove the address and add it to a permanent suppression list. No explanation needed.

1. Who is responsible for your data

The data controller is:

Aleksandr Roganin, operating as RedditLab24, sole trader
12F, No. 32, Gongyuan Rd., Zhongzheng Dist.
Taipei City 100, Taiwan
Email: alex@redditlab24.net

RedditLab24 is a trading name, not a separate legal entity. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. For anything relating to your data, write to the address above — we handle these requests directly.

2. What data we process

CategoryExamples
Business contact dataName, job title, business email address, employer, company website, publicly listed professional profile
Brand mention dataPublic posts, comments and threads that mention a brand we are analysing: the text itself, the username or handle that wrote it, the community or subreddit, the date and the link
Analysis we generateSummaries, sentiment and volume figures, themes and short verbatim quotes drawn from the brand mention data above, produced with the help of automated language models
CorrespondenceEmails you send us and our replies, including any details you choose to share
Client dataFor clients: company details, billing information, project briefs and approvals
Technical dataServer logs generated when you visit this site: IP address, user agent, requested page, timestamp

We do not process special category data (health, beliefs, biometrics and similar) and we ask you not to send it to us. Our analysis produces no automated decision with legal or similarly significant effects on anyone, so Article 22 GDPR does not apply.

3. Where we get it, and how we contact you

Business contact data is collected from publicly available sources: company websites, published team and contact pages, business directories, public professional profiles and public posts. We do not buy contact lists, and we do not scrape private or login-protected areas of any platform.

Brand mention data is collected from publicly accessible discussion platforms, principally Reddit. We read what is already public. We do not log in to view restricted content, we do not contact the people who wrote the posts, and we do not attempt to identify them, resolve a username to a real name, or build a profile of any individual poster. Usernames appear only where they are already attached to the public post being quoted.

Each analysis is prepared for one brand and sent to that brand once. If the recipient asks for the full version, we send it. That is the whole sequence — we do not run follow-up campaigns and we do not re-contact people who did not reply.

This section is our notice under Article 14 GDPR, which applies when personal data is obtained from a source other than the individual. If you would like to know the specific source for your own record, ask and we will tell you.

3a. If you were quoted in one of our analyses

This part is for people whose public posts we quote, rather than the brands we write to. You did not ask to hear from us, and you may not know we exist, so here is the plain version.

Requests go to alex@redditlab24.net. If an analysis containing your words has already been delivered to a brand, tell us and we will pass the removal request on to them.

4. Why we process it, and on what legal basis

PurposeLegal basis
Sending business-to-business introductions about our serviceLegitimate interests — Article 6(1)(f) UK/EU GDPR
Collecting public brand mentions and preparing the analysis we sendLegitimate interests — Article 6(1)(f)
Replying to your enquiryLegitimate interests, or steps prior to a contract — Article 6(1)(b)
Delivering the service to clients and invoicingPerformance of a contract — Article 6(1)(b)
Keeping a suppression list of people who opted outLegal obligation and legitimate interests — Articles 6(1)(c) and 6(1)(f)
Keeping accounting recordsLegal obligation under Taiwanese tax law — Article 6(1)(c)
Operating and securing this websiteLegitimate interests — Article 6(1)(f)

Our legitimate interests assessment, in short

We contact people in a professional capacity, at business addresses, about a service relevant to their role. We send one message per brand, containing work we have actually done on that brand rather than a generic pitch, and we identify ourselves honestly. There is no sequence and no follow-up unless the recipient asks for one. We consider this a proportionate use of business contact data that a professional would reasonably expect. If you disagree in your own case, your objection wins — see section 7.

For the people quoted inside an analysis, the balancing test is set out in section 3a: public material, minimal extraction, a single private recipient, short retention, and removal on request.

Where the law of your country requires prior consent for unsolicited commercial email to individuals, we rely on consent instead and will not contact you without it.

5. How long we keep it

6. Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of processors to run the business:

These providers operate in the United States and elsewhere, so your data may be transferred outside the EEA, the UK or your home country. Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU–US Data Privacy Framework, depending on the provider.

7. Your rights

Subject to the conditions in the applicable law, you can ask us to:

Direct marketing is absolute. Under Article 21(2) GDPR you can object to marketing at any time, for any reason or none, and we must stop. There is no balancing test and we will not ask you to justify it.

To exercise any right, email alex@redditlab24.net. We respond within one month. Exercising your rights is free, and we will not treat you differently for it.

If you are unhappy with how we handled your request, you can complain to a supervisory authority: in the EU, the data protection authority of your country of residence; in the UK, the Information Commissioner's Office (ico.org.uk); in Taiwan, the Personal Data Protection Commission. You may complain without contacting us first, though we would rather have the chance to fix it.

8. Notice for recipients in the United States

Our commercial emails comply with the CAN-SPAM Act of 2003. Specifically: header and sender information is accurate and not misleading, subject lines reflect the content of the message, each message identifies itself as a commercial message and includes our valid physical postal address (section 1 above), and each message contains a working opt-out. Opt-out requests are processed within ten business days and at no cost to you. We do not transfer opted-out addresses to any third party for their own use.

If you are a California resident, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioural advertising.

9. Notice under Taiwan's Personal Data Protection Act

The purposes of collection are set out in section 4, corresponding to marketing (040), business administration (090) and contract management (069) under the PDPA classification. Data may be used within and outside Taiwan, for the periods in section 5, by us and by the processors in section 6. Under Article 3 of the PDPA you may request review, copies, correction, supplementation, suspension of processing or deletion, and you are free to decline to provide data — though we may then be unable to reply or deliver a service. Where we use your data for marketing, we will stop upon your first request.

10. Cookies and tracking

This site sets no cookies. There is no analytics, no advertising pixel, no session tracking and no cross-site profiling. Fonts are served from this domain rather than from a third-party font service, so loading this page does not disclose your IP address to a font provider. Our emails contain no tracking pixels, so we cannot tell whether you opened one.

Our host records standard server logs for security and abuse prevention, as described in sections 2 and 5. Cloudflare may set a strictly necessary security cookie to detect malicious traffic; it does not track you across sites.

11. Security

Data is held in access-controlled accounts protected by unique credentials and two-factor authentication, and all traffic to this site is encrypted in transit with TLS. No system is perfectly secure, but we keep the data footprint small on purpose: the less we hold, the less there is to lose.

12. Children

This is a business-to-business service. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe we hold a child's data, tell us and we will delete it.

13. Changes to this policy

If we change this policy we will update the effective date at the top of the page. Material changes affecting how we use data already collected will be communicated to affected people by email where we hold a valid address.

14. Contact

Questions, requests and complaints: alex@redditlab24.net, or by post to the address in section 1. We answer every message, including the ones telling us to go away.