Privacy

Privacy Policy

Last updated: 28 June 2026
Draft — pending legal review. Not yet binding.

Who we are (controller)

Replyo is operated by [Company name, to be confirmed by counsel], a company registered in Romania (EU). We act as the data controller for account and contact data, and as a data processor for the customer-conversation content you instruct us to handle on your behalf. Contact: privacy@replyo.app

What data we collect

We collect and process the following categories of data: • Account data: name, work email address, company name, and billing information provided at registration. • Customer-conversation content: messages sent through your connected WhatsApp Business number or web-chat widget, including text and attachments. This data is provided by you (the subscriber) acting as the controller toward your end customers. • Catalog and knowledge-base content: product records, documents, and prices you upload. • Usage data: feature interactions, request timestamps, error logs, and aggregated analytics.

Why we process it and legal basis

• Performance of contract (Art. 6(1)(b) GDPR): account management, service delivery, billing, and support. • Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, service security, aggregated analytics to improve the product. • Legal obligation (Art. 6(1)(c) GDPR): tax records and regulatory requirements. We do not use your data for advertising or sell it to third parties.

Processors and sub-processors

We share data only with processors who are contractually bound to protect it under GDPR-compliant data-processing agreements. Current categories: • EU cloud infrastructure provider (compute and storage). • Transactional email provider (operational emails only). • Payment processor (billing data; PCI-DSS compliant). An up-to-date list of named sub-processors is available on request at privacy@replyo.app.

Where data is stored

All data is hosted and processed within the European Union. We do not transfer personal data outside the EEA. When your customer conversations are processed by our AI inference layer, we pass only pseudonymised content — no raw personally identifiable information (names, contact details, or account identifiers) is sent to the AI provider.

Retention

• Active accounts: data is retained for the duration of your subscription plus a 30-day grace period after cancellation. • Conversation data: anonymised at 12 months of inactivity; hard-deleted at 24 months. • 'Forget me' requests: actioned within 30 days. Account data deleted; conversation content anonymised immediately. • Billing records: retained for 7 years to comply with Romanian and EU tax law.

Your GDPR rights

As a data subject, you have the right to: • Access: request a copy of the personal data we hold about you. • Rectification: correct inaccurate data. • Erasure: request deletion of your data ('right to be forgotten'). • Portability: receive your data in a machine-readable format. • Objection: object to processing based on legitimate interests. • Restriction: request that we limit how we use your data while a dispute is resolved. To exercise any of these rights, email privacy@replyo.app. We respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority. In Romania: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro.

Cookies

We use strictly necessary cookies to maintain your session and prevent cross-site request forgery. We do not use third-party tracking or advertising cookies. Anonymised analytics may use a first-party cookie to count unique visits; no cross-site tracking is performed. You can disable cookies in your browser settings, but the application will not function without the session cookie.

How to contact us

Privacy inquiries: privacy@replyo.app Postal address: [To be added by counsel before publication]

Privacy Policy — Replyo