Data processed
Merchant account data, support emails, tickets, Shopify order data, technical data, operational logs and integration settings.
This notice explains in a transparent way how Repliva collects, uses, stores and protects personal data when you visit the website, request access to the waitlist, create an account, or use the platform to connect Gmail, Shopify and other operational tools.
Merchant account data, support emails, tickets, Shopify order data, technical data, operational logs and integration settings.
AI prepares analysis and drafts; the merchant’s operator always reviews and approves the final reply, including through MCP.
Email, Shopify, AI providers and MCP clients can receive data needed for authorized functions. We do not promise zero retention.
We implement authentication, authorization, logical segregation, secret protection, logging, backup and recovery controls.
The controller for website data, business inquiries, professional accounts and management of the contractual relationship is Antonino Lombardo, owner of Repliva. Privacy contact: replivacustomer@gmail.com.
For emails, tickets, orders and other customer data processed on the merchant’s behalf, Repliva acts as processor on merchant instructions under the agreement required by GDPR Article 28. Processing conditions appear in section 18 of the Terms of Service, subject to any specifically and validly concluded DPA.
This notice covers processing carried out when you browse the website, fill in a form, create or use an account, connect integrations, import emails or tickets, use AI features, or communicate with the Repliva team.
Repliva may process personal data in different roles depending on the context.
Repliva acts as controller when processing data relating to website visitors, waitlist users, commercial leads, merchant accounts, authorized merchant users, commercial or administrative communications, security, abuse prevention and technical platform management.
When a merchant connects Gmail, Shopify or other operational systems and Repliva processes end-customer data contained in emails, tickets, orders or support conversations, the merchant normally remains the controller of its own customer data and Repliva acts as a processor, handling the data exclusively on the merchant’s behalf and according to documented instructions.
Repliva may process different categories of personal data depending on the integrations, tenant and features actually used.
The following lawful bases concern processing by Repliva as controller. For end-customer data, the merchant determines purposes and lawful basis: its contract with Repliva does not itself authorize processing of any customer data.
Account data and data necessary for requested integrations are needed to provide those functions; optional data and marketing consent are not necessary to use the service. Consent can be withdrawn without affecting earlier lawful processing.
With merchant authorization, Repliva accesses Google/Gmail data needed for requested functions: message import and display, classification, summaries, drafts, synchronization and sending operator-approved replies.
Data may include addresses, senders, recipients, subjects, content, metadata, threads, necessary attachments, labels and technical integration credentials.
Repliva’s use of information received from Google APIs and its transfer to other applications are subject to the Google API Services User Data Policy, including Limited Use requirements, and applicable Google Workspace policies.
Google data is not sold, used for advertising or advertising profiles, or used to train, improve or fine-tune general-purpose AI models. A simple agreement with the merchant does not create an exception. Transfers to providers and authorized clients are limited to requested functions and uses permitted by Google; MCP connections do not authorize further reuse.
Human access to Google data is limited to cases permitted by those policies, such as explicit consent for specific messages, security needs or legal requirements. Communications are not freely read for independent purposes.
When a merchant connects Shopify, Repliva may access the data necessary to provide operational context for support requests.
Repliva uses Shopify data to display order information within tickets, help operators respond more quickly, generate more contextual drafts, suggest actions consistent with order status and reduce the merchant’s manual workload.
Repliva does not use Shopify data for its own advertising purposes and does not sell such data to third parties.
Repliva is a semi-automatic service: AI classifies, summarizes and prepares suggestions. The merchant’s operator must always review and approve the final reply before sending. This is a workflow obligation, including through MCP, rather than a guarantee that Repliva can verify every approval inside external clients.
Processing may transmit necessary email and conversation content, order data, policies, FAQs and merchant instructions to AI providers. The setup chat can also transmit messages, proposed settings and imported page text to AI providers.
Requests can pass through intermediaries such as OpenRouter to the configured model provider, for example Google/Gemini or OpenAI. Intermediary retention and model-provider retention are separate. Diagnostics services such as Langfuse, if enabled, may receive metadata and processing content to investigate errors and performance.
We do not guarantee that providers collect or retain no data. They may process inputs, outputs and metadata to deliver services, manage security and abuse, retain logs or meet legal obligations under applicable terms, settings and agreements. No training does not mean zero retention; we do not promise anonymity, a complete absence of authorized human access or exclusively EU residency.
Repliva does not use merchant data, emails or tickets to train its own general-purpose AI models. Adapting replies to an individual merchant’s policies and corrections can involve storing rules and history in that merchant’s account; this is distinct from general model training.
This notice does not authorize providers to use data freely or release Repliva from its duties when selecting, instructing and overseeing subprocessors. DPAs, minimization and provider restrictions, particularly for Google data, remain binding. Incompatible uses require excluding the provider or stopping the transfer, rather than an exemption in this notice.
The service is intended to assist an operator, not to make solely automated decisions with legal or similarly significant effects on individuals. If the merchant changes workflows through external tools, it must assess lawfulness and safeguards without bypassing required human review.
Repliva does not intentionally request the input of special categories of personal data, such as data relating to health, political opinions, religious beliefs, trade union membership, sexual orientation or biometric data.
However, such data may accidentally appear in messages sent by end customers to merchants or in attachments imported into the platform.
In those cases, Repliva processes such data only on the merchant’s instructions, within the limits necessary to provide the service, subject to the applicable security measures and the agreement required under GDPR Article 28. The merchant must also assess the conditions of GDPR Articles 9 and 10 where applicable.
The merchant is responsible for avoiding the import or upload of data that is not necessary for customer support purposes.
Data is not publicly disclosed. It is accessible to authorized persons for the stated purposes, advisers bound by confidentiality and authorities where required by law.
Technical services involved depend on enabled features. The contractual subprocessor list, with legal entities, locations, services and safeguards, must be established and authorized under the DPA; request it at replivacustomer@gmail.com. The following description does not certify unverified locations or settings.
Infrastructure providers, AI intermediaries and models, or external clients may process data outside the European Economic Area. We do not promise that all data remains in the EU; routing depends on the service, provider and configuration.
For transfers under its responsibility, Repliva must establish a valid mechanism under GDPR Chapter V, such as an adequacy decision applicable to the recipient or standard contractual clauses with necessary assessments and supplementary safeguards. Merely accepting this page or enabling MCP does not replace these safeguards.
You can request information about recipients, processing countries and applicable safeguards, and a copy of safeguards as provided by law, from the privacy contact. The merchant separately assesses transfers by external clients it selects.
Account data is retained to manage the relationship; tax data, contractual evidence and records needed to protect rights follow relevant legal duties and limitation periods. Business inquiry and waitlist data remains only while needed for the request, or until consent withdrawal for consent-based communications.
Emails, tickets, analysis, drafts and history are retained to provide the merchant’s service and under deletion instructions and applicable agreements. Moving a ticket to trash or archiving it is not deletion: there is no general automatic expiry of all content after a fixed number of days.
Sending records, action evidence and accounting data may outlast content deletion to prevent duplicates, resolve pending operations, meet legal obligations or protect rights. Retention must be limited to data needed for these purposes; it does not authorize indefinite retention of all message copies.
Diagnostic logs, revoked credentials and backups can have different periods from tickets. Deletion does not mean immediate removal from every backup or provider; residual copies must be protected, excluded from ordinary use and removed under the documented schedule for the system. To learn or agree on applicable account periods and request deletion, contact replivacustomer@gmail.com.
The onboarding draft and conversation may remain in browser local storage for the account after refresh; closing the tab does not delete them. The conversation is not included in the final settings save, but messages submitted to the chat are processed by AI providers as described above.
A merchant may disconnect Gmail, Shopify or other integrated providers at any time from the Repliva dashboard, from the external provider settings or by contacting Repliva support.
After disconnection, Repliva stops synchronization with the disconnected integration, no longer accesses new data through that integration, and related tokens or technical credentials are revoked, disabled or removed according to applicable technical timing.
Data already imported may still be retained according to retention settings, legal obligations, technical backup needs or deletion requests.
The merchant may request deletion of tenant data according to the procedures available in the service or under applicable contractual arrangements. When Repliva acts as a processor, requests concerning end-customer data are handled according to the merchant’s instructions.
Repliva adopts technical and organizational measures that are reasonable and proportionate to the nature of the data processed.
No measure can guarantee absolute security, but Repliva implements controls aimed at reducing the risks of unauthorized access, loss, alteration, disclosure or misuse of data.
In the event of a security incident involving personal data, Repliva will take the measures required by applicable law and, where necessary, will inform merchants, users or competent authorities within the timeframes and using the methods required by law.
Where provided by law, you can request access, rectification, deletion, restriction and portability, object to legitimate-interest processing and withdraw consent. Withdrawal does not affect earlier lawful processing. You can complain to the Italian Garante per la protezione dei dati personali or the competent authority where you habitually live or work or where the alleged infringement occurred.
Send requests to replivacustomer@gmail.com. We respond within GDPR deadlines, normally one month; any extension for complexity or number of requests is explained within the first month. We request only necessary and proportionate identity-verification information.
If you are a merchant’s customer, contact that merchant as controller. If we receive a request concerning data processed on its behalf, we forward it and assist under applicable obligations.
The Repliva service is not directed to children under 16 and is not designed to knowingly collect personal data from children.
If you believe that a child has provided personal data to Repliva, you may contact us to request removal.
Data relating to minors may accidentally appear in support messages or data imported by merchants. In those cases, Repliva processes such data only on the merchant’s instructions and only to the extent necessary to provide the service.
Repliva may update this Privacy Policy to reflect legal, technical, organizational or functional changes to the service.
If relevant changes occur, Repliva will publish the updated version on this page together with the revised last-updated date.
Where necessary, Repliva may also provide an additional notice through the service, by email or through other appropriate channels.
For questions about this notice or the processing of personal data, you may contact Antonino Lombardo at replivacustomer@gmail.com.
If your organization has entered into a DPA, specific contractual terms or other additional agreements with Repliva, those documents also govern the allocation of privacy roles and responsibilities where applicable.
Connecting an MCP client authorizes access within granted scopes. The client can receive ticket content, customer and order data, drafts, results and operational data necessary for invoked tools. Keys, OAuth authorizations and call records are processed to manage access, security and operations.
An external client may forward results to its AI provider, retain them in logs or use them in merchant-configured workflows under its own terms. The merchant must assess this processing, inform individuals and limit data and permissions. Revocation prevents future access through the revoked credential but does not remove copies already held by the client.
Repliva provides the technical interface and can execute real sends on authorized calls; connecting alone does not start an autonomous sending workflow. Final replies remain subject to human review and approval under Terms section 17. The merchant is responsible for external workflows it configures, without releasing Repliva from its own privacy responsibilities.