Legal · Updated May 13, 2026

Privacy Policy

We collect the minimum we need to run the product. We never train AI on customer data. We're GDPR-native, built in Spain by EterSystem. Plain-language version below; lawyer-language version on request.

1. Who we are

Repify Tech S.L. (CIF: B12345678) operates this product. Our office is at Calle de Atocha 21, 3ºA, 28012 Madrid, Spain. The data controller for personal data is Repify Tech S.L. Reach our data protection officer at dpo@repify.tech.

2. What we collect

Account data: name, email, company name, role, password (hashed with bcrypt + salt).

Billing data: billing name, billing address, VAT ID, payment method token (Stripe — we never see your card number).

Google Business Profile data: via OAuth2, scoped to read reviews and post replies. We store reviews, your replies, ratings, dates and review authors as Google exposes them.

Usage data: standard product analytics — pages viewed, features used, error logs. Anonymous beyond your account ID.

What we don't collect: we don't read your other Google data (Gmail, Drive, Calendar, etc). We don't fingerprint your visitors. We don't sell anything to anyone.

3. Why we collect it

  • To operate the product (reading and replying to reviews).
  • To bill you accurately.
  • To send service emails (alerts, billing, important changes).
  • To improve the product (anonymous usage analytics).
  • To comply with EU and Spanish tax law (invoice retention).

4. AI and your data

When Repify generates a reply draft, the review text and your brand-voice document are sent to OpenAI models via the OpenAI API. OpenAI contractually does not train on API data. We don't train on your data either. Drafts are stored in your Repify workspace.

5. Where your data lives

Production data and backups are stored with our hosting provider under the protections described in our DPA. Where customer data is transferred outside the EU — for example in the AI API calls described above — the transfer is covered by Standard Contractual Clauses (SCCs).

6. Your rights under GDPR

You can: access your data, correct it, delete it, export it, restrict processing, or object to processing. Most of this is self-service from your account settings; for the rest, email dpo@repify.tech and we respond within 30 days (usually within 2 business days).

7. How long we keep it

  • Active accounts: as long as your account is open.
  • Closed accounts: all personal data deleted within 30 days of closure, except invoicing data we're legally required to retain (Spanish tax law: 6 years).
  • Backups: rolling 30-day window. Deleted data is fully gone after the backup window expires.

8. Cookies

We use one session cookie (for authentication) and one analytics cookie (anonymous, EU-hosted analytics via Plausible). No tracking cookies, no third-party ad cookies, no Facebook pixels.

9. Changes to this policy

If we change anything material, we email all active customers at least 14 days before the change takes effect. The previous version is always available on request.

10. Contact

DPO: dpo@repify.tech
Office: Calle de Atocha 21, 3ºA, 28012 Madrid, Spain
Supervisory authority: Agencia Española de Protección de Datos — aepd.es