Who's the data controller?
Repify Tech S.L. is the data controller for personal data we collect about you (the account holder). For data about your customers' reviews, you are the controller and Repify is the processor — formalized in our Data Processing Agreement (available at dpo@repify.tech).
Data Processing Agreement
We offer a DPA covering Article 28 GDPR. Email dpo@repify.tech for a counter-signed copy.
Your rights
- Right of access: request a copy of all data we hold about you. Email dpo@repify.tech.
- Right to rectification: correct any inaccurate data. Self-service from your profile, or by email.
- Right to erasure: delete your account and all associated data (excluding mandatory tax records). Email dpo@repify.tech.
- Right to data portability: export your reviews as CSV (Growth plan) or request a full export by email.
- Right to restrict processing: pause processing while disputes are resolved. Email dpo@repify.tech.
- Right to object: stop us from processing your data for non-essential purposes (e.g. analytics).
We respond to GDPR requests within 30 days — usually within 2 business days.
Legal bases for processing
- Contract: processing necessary to operate the service you signed up for.
- Legal obligation: invoice retention (Spanish tax law: 6 years).
- Legitimate interest: service-quality analytics, security monitoring. Always anonymized; you can object.
- Consent: for any non-essential marketing emails (always opt-in).
Our subprocessors
We list every subprocessor we use, what they do, and where they store data. Updated whenever we add or remove one. Subscribe to subprocessor change notifications at dpo@repify.tech.
- Hosting provider — application infrastructure. Details in the DPA.
- Google — Google Business Profile API (reviews and replies), via OAuth2.
- Stripe (Ireland) — payment processing. Data: billing only.
- OpenAI — AI draft generation. Data: review text + brand context; contractual no-training.
- Plausible (Germany) — privacy-friendly analytics. Anonymous, no PII.
- Postmark (Ireland) — transactional email delivery.
International transfers
Where customer data is transferred outside the EU — for example in the AI provider API calls described above — we use Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption in transit, no-training contracts).
Security
See our full security page. Highlights: GDPR-native by design, encrypted connections in transit, hashed passwords, scoped OAuth2 for Google access.
Breach notification
If a personal-data breach happens, we notify affected customers and the AEPD within 72 hours, as required by GDPR Article 33. Our internal incident response plan is tested quarterly.
Data Protection Officer
Our DPO is Inés D. — reachable at dpo@repify.tech. Mail can also be sent to the office at Calle de Atocha 21, 3ºA, 28012 Madrid, Spain.
Supervisory authority
Spain — Agencia Española de Protección de Datos (AEPD) — aepd.es. If you're not satisfied with our handling of your data, you have the right to lodge a complaint with them or with your local data protection authority.