Privacy policy
This policy explains what personal data ReplyAIDesk collects, why, who it is shared with, how long it is kept, and the rights you have. It is written for both the businesses that use ReplyAIDesk and the visitors who talk to the assistant on their websites.
1. Who we are and who this policy covers
ReplyAIDesk is operated by [Company legal name], [Company address] (“we”, “us”). This policy explains how we handle personal data for three groups of people:
- Customers and team members: people who create an account, manage knowledge, or reply to conversations in the dashboard.
- Website visitors: people who talk to the assistant embedded on a customer’s website.
- Visitors to this marketing site: people reading these pages or using the contact form.
For conversations that happen on a customer’s website, the customer decides why the assistant is used and what knowledge it may use. In that situation the customer is the data controller and we process the data on their behalf as a processor or service provider. For our own accounts, billing, and this website, we are the controller.
2. What we collect
2.1 Through the website assistant (widget)
- Messages: what the visitor types and the replies shown to them, including AI-generated replies and replies from the customer’s team.
- Attachments: files a visitor chooses to upload during an enquiry, subject to size and type limits set by the customer and by us.
- Contact details: name, email address and optional phone number when a visitor submits an enquiry or asks for a person to follow up.
- Consent timestamp: the date and time the visitor accepted the assistant’s notice before starting a conversation.
- Page URL and technical data: the address of the page where the conversation took place, the referring page, browser type, approximate region derived from IP address, and a random visitor token stored in the browser’s localStorage so the conversation can continue across page views.
2.2 From customers and team members
- Account details: name, work email address, password (stored as a salted hash), role, and login activity.
- Knowledge content you add: website pages, documents, and written answers you approve for the assistant to use.
- Billing details: your PayPal subscription identifier and transaction history. We do not receive or store your full card number or PayPal password.
- Support and contact messages, including messages sent through the contact form on this site.
2.3 Automatically
Server logs (IP address, user agent, requested URL, timestamps) for security and troubleshooting, and a session cookie for logged-in users. See the cookie policy.
3. How we use personal data
- To provide the service: generate replies from approved knowledge, deliver enquiries to the customer’s team, and enable live handover.
- To operate accounts, bill subscriptions through PayPal, and send service emails (enquiry notifications, usage warnings, billing notices).
- To keep the service secure: detecting abuse, preventing spam, scanning uploaded files, and investigating incidents.
- To improve the product using aggregated, de-identified usage statistics.
- To comply with legal obligations and respond to lawful requests.
We do not use customer knowledge, visitor conversations, or attachments to train AI models, and we do not sell personal data.
Where the law requires a legal basis (for example under the GDPR or UK GDPR), we rely on: performance of a contract (providing the service to customers), legitimate interests (security, product improvement, responding to enquiries), consent (visitor conversations where the customer configures a consent notice; marketing emails), and legal obligation.
4. AI processing
To generate replies, the visitor’s message and relevant excerpts of the customer’s approved knowledge are sent to our AI provider (see section 5). The AI provider processes the data to return a reply and, under our agreement, does not use it to train their models. AI replies are limited to approved knowledge; when the knowledge does not cover a question the assistant says so rather than guessing. Customers remain responsible for reviewing the knowledge they approve.
5. Who we share data with (processors)
| Processor | Purpose | Data involved |
|---|---|---|
| [AI provider name] | Generating assistant replies and search embeddings | Visitor messages, approved knowledge excerpts |
| PayPal | Subscription billing and payment processing | Customer name, email, subscription and transaction identifiers |
| [Email provider name] | Sending transactional email | Recipient email address, notification content |
| [Hosting provider name] | Hosting the application, database and file storage | All service data |
We may also disclose data to professional advisers, to a successor in a merger or acquisition (with notice), or where required by law. Customers can see conversation and enquiry data for their own websites in the dashboard; we do not share one customer’s data with another.
6. Retention
- Conversations, enquiries and attachments: kept for as long as the customer’s retention setting specifies (default: [default retention period]), or until the customer deletes them. Customers can shorten this in their settings.
- AI request logs (used for troubleshooting and usage accounting): 90 days.
- Email delivery logs: 90 days.
- Account and billing records: for the life of the account and afterwards as required for tax and accounting purposes (typically [statutory period]).
- Server logs: [log retention period].
When a customer closes their account, we delete or de-identify their data within [deletion window] except where retention is required by law.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent. You may also have the right to complain to a supervisory authority.
- Website visitors: if you talked to an assistant on a customer’s website, please contact that business first; they control the conversation data. If you contact us instead, we will forward your request to the customer and help them respond.
- Customers and team members: you can export conversations, enquiries and knowledge from the dashboard, update account details in settings, and request account deletion through the contact form (mention “privacy request”).
We respond to verified requests within the period required by applicable law (for example 30 days under the GDPR and 45 days under the California Consumer Privacy Act).
California residents: we do not sell or share personal information for cross-context behavioural advertising. The categories of personal information we collect are described in section 2. [Add any additional CCPA/CPRA disclosures required]
8. Cookies and local storage
This site and the dashboard use a strictly necessary session cookie for logged-in users and CSRF protection. The embedded widget does not set cookies on the customer’s website; it stores a random visitor token in the browser’s localStorage so a conversation can continue between page views. Full details are in the cookie policy.
9. Security
We use encryption in transit (HTTPS), encryption of sensitive credentials at rest, salted password hashing, role-based access to customer data, rate limiting, and optional malware scanning of uploaded files. No system is perfectly secure; if we become aware of a breach affecting your data we will notify affected customers and authorities as required by law.
10. International transfers
We are based in [Country / state of establishment] and our processors may store or process data in the United States and other countries. Where data is transferred from the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. Contact us for a copy of the relevant safeguards.
11. Children
The service is intended for businesses and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided data to us, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email to customers or by a notice in the dashboard at least [notice period] before they take effect. The date at the top shows when it was last revised.
13. Contact
Privacy questions and requests: [privacy contact email], or by post to [Company legal name], [Company address]. You can also use the contact form. [If applicable: Data Protection Officer / EU or UK representative details]
Related: Privacy policy · Terms of service · Cookie policy · Refund & cancellation policy · Contact
