GDPR · Updated May 13, 2026

GDPR-native, not GDPR-retrofitted.

Repify is built in Spain by EterSystem and GDPR-native by design. Our DPO is reachable by email. Our supervisory authority is the AEPD. The full commitment is below.

Who's the data controller?

Repify Tech S.L. is the data controller for personal data we collect about you (the account holder). For data about your customers' reviews, you are the controller and Repify is the processor — formalized in our Data Processing Agreement (available at dpo@repify.tech).

Data Processing Agreement

We offer a DPA covering Article 28 GDPR. Email dpo@repify.tech for a counter-signed copy.

Your rights

  • Right of access: request a copy of all data we hold about you. Email dpo@repify.tech.
  • Right to rectification: correct any inaccurate data. Self-service from your profile, or by email.
  • Right to erasure: delete your account and all associated data (excluding mandatory tax records). Email dpo@repify.tech.
  • Right to data portability: export your reviews as CSV (Growth plan) or request a full export by email.
  • Right to restrict processing: pause processing while disputes are resolved. Email dpo@repify.tech.
  • Right to object: stop us from processing your data for non-essential purposes (e.g. analytics).

We respond to GDPR requests within 30 days — usually within 2 business days.

  • Contract: processing necessary to operate the service you signed up for.
  • Legal obligation: invoice retention (Spanish tax law: 6 years).
  • Legitimate interest: service-quality analytics, security monitoring. Always anonymized; you can object.
  • Consent: for any non-essential marketing emails (always opt-in).

Our subprocessors

We list every subprocessor we use, what they do, and where they store data. Updated whenever we add or remove one. Subscribe to subprocessor change notifications at dpo@repify.tech.

  • Hosting provider — application infrastructure. Details in the DPA.
  • Google — Google Business Profile API (reviews and replies), via OAuth2.
  • Stripe (Ireland) — payment processing. Data: billing only.
  • OpenAI — AI draft generation. Data: review text + brand context; contractual no-training.
  • Plausible (Germany) — privacy-friendly analytics. Anonymous, no PII.
  • Postmark (Ireland) — transactional email delivery.

International transfers

Where customer data is transferred outside the EU — for example in the AI provider API calls described above — we use Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption in transit, no-training contracts).

Security

See our full security page. Highlights: GDPR-native by design, encrypted connections in transit, hashed passwords, scoped OAuth2 for Google access.

Breach notification

If a personal-data breach happens, we notify affected customers and the AEPD within 72 hours, as required by GDPR Article 33. Our internal incident response plan is tested quarterly.

Data Protection Officer

Our DPO is Inés D. — reachable at dpo@repify.tech. Mail can also be sent to the office at Calle de Atocha 21, 3ºA, 28012 Madrid, Spain.

Supervisory authority

Spain — Agencia Española de Protección de Datos (AEPD) — aepd.es. If you're not satisfied with our handling of your data, you have the right to lodge a complaint with them or with your local data protection authority.

Need a DPA signed?

Get the DPA in your inbox.

Email our DPO — we usually return a counter-signed copy within 1 business day.