Legal
Privacy Policy
Last updated: June 2026 · Compliant with the GDPR (EU) 2016/679 and Spain's LOPDGDD 3/2018
1. Data controller
Controller: the controller’s full legal identity, tax ID and registered address must be verified before this policy is used as definitive legal information. The service operates under the trade name Repliq (“Repliq” or “we”).
Data protection contact: dsbusiness.global@gmail.com
Repliq is not required to appoint a Data Protection Officer (DPO) under GDPR art. 37, as it does not carry out large-scale personal data processing or systematically process special categories of data. Requests to exercise rights or privacy inquiries should be sent to the email address above.
2. Data we collect
- —Account data: email, name and password (encrypted by Supabase Auth using bcrypt).
- —Business data: business name, address, timezone and category.
- —Google OAuth tokens: encrypted at rest with AES-256-GCM; accessible only from the server.
- —Google Maps reviews: imported via the official Google Business Profile API.
- —Billing data: managed entirely by Stripe Inc. and Stripe Payments Europe Ltd. We do not store card data on our servers.
- —AI logs: prompt, response, model and tokens consumed for each processed review (for auditing and improvement).
- —Technical logs: IP address, user agent, access timestamps (kept for 30 days for security purposes).
3. Purpose and legal basis
We process your data for the following purposes and legal bases:
- — Provision of the contracted service (GDPR art. 6.1.b, contract performance): account management, AI draft generation, publishing responses on Google.
- — Invoicing and tax obligations (GDPR art. 6.1.c, legal obligation): issuing and retaining invoices.
- — Service improvement and security (GDPR art. 6.1.f, legitimate interest): aggregate usage analysis, fraud prevention, auditing.
- — Transactional communications (GDPR art. 6.1.b): operational service notifications (not marketing).
We do not sell data to third parties. We do not use it for advertising profiling. We do not carry out international transfers outside the EEA except as described in section 5.
4. Data retention
We keep your data for as long as you maintain an active account. When you delete your account, personal data is erased within a maximum of 30 days, except where retention is required by law:
- — Billing data: 6 years (art. 30 of the Commercial Code and art. 70 of the General Tax Law).
- — Technical access and security logs: 90 days, unless needed for a security incident investigation or requested by a competent authority.
- — AI logs (audit trail): 12 months for auditing and compliance.
- — Google OAuth tokens: deleted immediately upon revoking authorization or deleting the account.
5. Data processors and international transfers
We share strictly necessary data with the following data processors. All of them have signed the corresponding data processing agreement (DPA) and provide sufficient guarantees under GDPR art. 28:
- Supabase Inc. (database and authentication) — Servers in the EU (eu-west-1 region). DPA signed. No transfer outside the EEA.
- Vercel Inc. (application hosting and cookieless aggregate usage analytics via Vercel Web Analytics, no tracking cookies and no persistent per-visitor identifier) — Infrastructure in the EU/EEA. DPA signed. No transfer of personal data outside the EEA.
- Resend (transactional and alert emails: account confirmation, password recovery, critical review alerts) — Based in the US. International transfer covered by the Standard Contractual Clauses (SCC) adopted by European Commission Decision 2021/914.
- Stripe Payments Europe Ltd. (payment processing) — European entity based in Ireland. PCI-DSS Level 1 compliant. Transfers to the US under the European Commission's Standard Contractual Clauses (SCC).
- OpenAI, LLC (language models used to generate response drafts) — Based in the US. International transfer covered by the Standard Contractual Clauses (SCC) adopted by European Commission Decision 2021/914. OpenAI does not use data processed via the API to train its models (API Data Usage Policy, business configuration). Only review text and the generation prompt are transferred; no end-user identifying data is transferred beyond what is strictly necessary.
- Google LLC (Business Profile API) — Access exclusively via official OAuth 2.0 and only for the purpose authorized by the user. Google acts as an independent controller for its own services. Access can be revoked at any time from myaccount.google.com/permissions.
You can request a copy of the data processing agreements signed with the above providers by writing to our contact email.
6. Security
We implement technical and organizational measures under GDPR art. 32: TLS 1.3 encryption in transit, AES-256-GCM for OAuth tokens at rest, Row-Level Security (RLS) in the database, least-privilege role-based access, bcrypt password hashing, HMAC validation on webhooks, monitoring and auditing. Google tokens can be revoked at any time from your Google account. The current database plan does not include point-in-time recovery (PITR) backups; we are evaluating enabling this as the volume of managed data grows.
7. Your rights
As the data subject, you can exercise the following rights recognized by the GDPR and the LOPDGDD at any time:
- — Access, rectification, erasure, objection, restriction and portability.
- — Withdrawal of consent without retroactive effect.
- — Not to be subject to automated decisions with significant legal effects.
Write to us at dsbusiness.global@gmail.com to exercise these rights. If you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (AEPD) (aepd.es) or your local data protection authority.
8. Cookies
We use only cookies strictly necessary for authentication and application functionality (session, CSRF). We do not use tracking or advertising cookies. We use Vercel Web Analytics to measure aggregate product usage (see section 5); it is cookieless. It does not install cookies or generate a persistent per-visitor identifier. For this reason we do not require a consent banner under art. 22.2 of the LSSI-CE (the applicable EU ePrivacy standard for cookieless, non-tracking analytics).
9. Minors
The service is aimed at professionals and businesses. We do not knowingly collect data from minors under 14. If we detect any, we will delete it immediately.
10. Changes to this policy
We may update this policy for legal or operational reasons. Material changes will be notified by email at least 15 days in advance. The last-updated date appears at the top of this document.