Back to home
Terms of Service

General terms governing the use of the Repliva platform

This page sets out the legal terms that apply to access to and use of the Repliva website, waitlist and SaaS platform by merchants, authorized team members and other users interacting with the service.

Last updated: September 14, 2026

Service usage

Semi-automatic service: AI prepares drafts; the operator always reviews and approves the final reply.

AI outputs

Every reply requires human review, including through MCP. Outputs may contain errors and do not guarantee results.

Merchant duties

The merchant remains responsible for imported content, authorized integrations, configured policies and the lawful processing of end-customer data.

Contract framework

These terms govern access, usage limits, suspension, termination, intellectual property and the general liability framework.

1. Acceptance and business use

Repliva is intended for merchants and professionals acting for their business. Anyone activating an account for an organization represents that they can bind it and authorize its operators.

These terms apply when validly accepted in the contractual relationship. Merely visiting the website, reading this page or generally accepting the terms does not replace any specific approvals required by law. If you do not accept the terms, do not activate or use the service.

Any applicable consumer protections remain unaffected; user status depends on actual use and applicable law.

Email registration includes a terms acceptance checkbox. For quick registration, the notice beside the Google button explains that continuing accepts the terms. We record version, language, choice wording and date, linked to the authenticated account. Existing accounts see a non-blocking dashboard notice: postponing it does not mean acceptance. General acceptance does not constitute specific approval of clauses where the law requires it. Analytics consent remains separate and optional.

2. Service provider identity

The Repliva service is provided by Antonino Lombardo, owner of the service and contractual counterparty in the relationship with the merchant, referred to below as “Repliva” or the “provider”.

Formal communications relating to these terms should be sent to the contact details listed on this page or in the applicable commercial agreement.

3. Semi-automatic service and human control

Repliva provides semi-automatic SaaS software for ecommerce customer support. It can synchronize and organize emails, analyze requests and order context, classify tickets and prepare drafts or suggestions using AI.

In the intended workflow, the final reply is always reviewed and approved by the merchant’s operator, who decides its content, recipient and sending. Generating a draft does not constitute approval, sending or completion of a commercial action.

Repliva does not independently activate customer messaging workflows merely because an inbox is connected, a draft is generated or MCP is enabled. Sending tools execute requests from the operator or systems authorized by the merchant. External clients and MCP automations are subject to section 17.

4. Eligibility and account requirements

Account details must be accurate and compatible with lawful use of the service; any suspension is governed by section 14.

  • You may use the service only if you have the legal capacity to enter into a binding agreement.
  • You are responsible for the accuracy of the information provided during onboarding, registration and configuration.
  • You must securely protect credentials, access rights and permissions assigned to your account or team members.
  • If you become aware of unauthorized access or compromise, you must notify Repliva without undue delay.

5. Merchant responsibilities

  • Connect only inboxes, stores and data for which the merchant has authorization; provide appropriate notices and lawful bases for customer data.
  • Check and maintain commercial policies, FAQs, instructions, recipients and permissions; do not put secrets or unnecessary personal data in prompts.
  • Have an authorized operator review and approve each final reply before sending, including bulk or MCP requests. The operator must check facts, tone, promises, amounts and the correct customer and order.
  • Separately authorize and verify refunds, cancellations, returns and other actions with financial or legal effects; a draft does not prove execution.
  • Train operators on AI limitations, oversee external tools, protect keys and promptly revoke unnecessary or compromised access.

6. AI features and output limitations

AI outputs are probabilistic and may contain errors, fabricated information, omissions, bias or outdated data. They are not professional advice or a guarantee of accuracy, economic results, legal compliance or acceptance of a request.

The merchant is responsible for final review and the operational decisions it makes using outputs. This allocation does not release Repliva from its own obligations, service defects attributable to it or liabilities that cannot be excluded under section 13.

Prompts, necessary content and outputs may be transmitted to AI providers and technical intermediaries. Repliva does not promise that they collect or retain no data: processing, logs, abuse monitoring, authorized human access where applicable and retention depend on the service and applicable contracts. Privacy obligations, merchant instructions and integration data restrictions remain binding.

7. Prohibited uses

  • Using Repliva or MCP for spam, marketing messages without a lawful basis, phishing, fraud, impersonation or violations of third-party rights.
  • Importing or disclosing data without authorization, using one merchant’s data for another customer or incompatible purposes, or bypassing provider restrictions, including Google data restrictions.
  • Allowing an agent or automation to send final replies without the human review and approval required by these terms.
  • Making solely automated decisions with legal or similarly significant effects on people without the conditions and safeguards required by law; using the service for purposes prohibited by AI legislation.
  • Bypassing security controls, scopes, permissions or technical limits; introducing malware or interfering with the service. Activities protected by mandatory law remain permitted.

8. Third-party services and integrations

Repliva uses infrastructure, email and AI providers and can connect to tools chosen by the merchant. Their terms, availability, quotas and APIs may affect the service.

The merchant assesses the terms, privacy settings and permissions of external clients it connects, including AI assistants and automation platforms. These parties may receive data and MCP call results and retain them in their own systems.

Repliva does not control every internal activity of third parties and does not guarantee the complete absence of collection, retention or incidents. This does not remove Repliva’s obligations when selecting and managing its own providers or its GDPR responsibilities, including Article 28(4) for subprocessors.

9. Plans, fees and renewals

Unless otherwise stated in an order form, quote, checkout or separate commercial agreement, access to paid platform features is subject to the pricing and limits published or communicated by Repliva at the time of activation.

Unless otherwise agreed in writing, any trials, renewals, suspension for non-payment, upgrades, downgrades, taxes, refunds, and other commercial conditions will follow the activation flow, checkout, selected plan, or other applicable commercial documentation.

  • Fees are net of applicable taxes unless expressly stated otherwise.
  • Non-payment may lead to limitation or suspension of access to paid functionality.
  • Order forms, quotes or enterprise agreements prevail over these terms in case of conflict for the specific commercial items they regulate.

10. Intellectual property

Repliva and its licensors retain all rights, title and interest in and to the platform, software, interface, proprietary content, know-how, logos, trademarks, documentation and related developments, except for rights expressly granted to the merchant.

Except as permitted by mandatory law or written authorization, you may not copy, modify, distribute, sublicense, decompile, create derivative works from or otherwise misuse Repliva proprietary assets.

  • The merchant retains rights in its own data, content and materials uploaded to the service.
  • The merchant grants Repliva the rights strictly necessary to host, process, transmit and use that content solely to provide the service and perform contractual obligations.

11. Data, confidentiality and processing agreement

The Privacy Policy describes processing and distinguishes account data from the merchant’s customer data. Processing personal data on behalf of the merchant requires an agreement under GDPR Article 28; general acceptance of a privacy notice is neither end-customer consent nor a substitute for that agreement.

The processing conditions in section 18 form part of these terms when validly concluded between the parties. A specifically signed DPA prevails in a conflict concerning processing, without prejudice to law and data subject rights.

Each party keeps the other’s information confidential and limits access to authorized persons for service delivery, legal obligations or protection of rights.

12. Service availability and changes

Repliva aims to keep the service reasonably available, but does not guarantee that the platform will always be error free, uninterrupted or immune from vulnerabilities.

We may modify, update, replace or discontinue features, interfaces, technical limits, integrations or parts of the service for technical, security, legal or product-evolution reasons.

  • Scheduled or emergency maintenance may cause temporary unavailability.
  • Beta, experimental or early-access features may be subject to additional limits and increased variability.

13. Warranties and limits of liability

Repliva does not guarantee that AI outputs are always correct or the service is uninterrupted. It remains responsible for performing its contractual duties and complying with mandatory obligations.

In business relationships, to the extent permitted by law and subject to valid specific approval where required, Repliva is not liable for consequences attributable to the merchant’s unlawful use or breach of these terms, incorrect instructions or content supplied by the merchant, or external workflows it configures. Consequences attributable to Repliva’s own breach are not excluded.

Under the same conditions, indirect damages and loss of profit are excluded and Repliva’s aggregate contractual liability for ordinary negligence is limited to the fees paid by the merchant for the service in the twelve months before the harmful event, unless otherwise agreed in writing.

No clause excludes or limits liability for intentional misconduct or gross negligence, breach of public-order obligations or other matters prohibited by Article 1229 of the Italian Civil Code or mandatory law. Data subject rights, compensation and allocation of liability under GDPR Article 82, obligations toward authorities and applicable consumer protections remain unaffected.

Limitations subject to Articles 1341 and 1342 of the Italian Civil Code require valid, separate and specific written approval. Publication of this page, MCP use or general acceptance of the terms does not constitute that approval.

14. Suspension and termination

Any data export period, post-termination retention window and account deactivation mechanics should be aligned with the relevant commercial and privacy documentation.

  • Repliva may suspend or restrict access in the event of a breach of these terms, risk to platform security or integrity, unlawful use, non-payment or a competent authority request.
  • The merchant may stop using the service subject to the active plan rules or any applicable commercial agreement.
  • Clauses that by their nature should survive termination will remain in effect, including those on accrued payments, intellectual property, liability, confidentiality and disputes.

15. Governing law and disputes

These terms are governed by Italian law, without prejudice to applicable mandatory rights and rules. Statutory jurisdiction rules apply to disputes unless otherwise validly agreed. Supervisory authorities retain their powers.

16. Changes and contact details

Updates are published with a date and version. Material contractual changes are communicated to the merchant before application, using the methods and notice required by law and contract; acceptance is obtained where necessary. Publication does not make new liability exclusions retroactive or replace specific approvals.

For contractual questions, DPA requests and reports of misuse: Antonino Lombardo, replivacustomer@gmail.com. Version: 2026-09-14.

17. MCP, external clients and automation policy

Repliva provides MCP (Model Context Protocol) connections and tools. Connecting does not by itself activate autonomous messaging to end customers. The merchant chooses external clients, agents, instructions, permissions and automations and is responsible for activities attributable to it.

MCP tools with write or send permissions can perform real operations, including single and bulk email replies, when they receive an authorized call. An API key or OAuth authorization enables the client within granted scopes; it does not prove that a person has read and approved every message.

The merchant must configure and enforce human review and approval of final content and recipients before every send, including each reply in a batch. Agents or workflows must not approve on the operator’s behalf. Repliva does not technically verify every approval step inside external clients.

The merchant must limit scopes, protect credentials and data, check results before repeating operations, retain necessary authorization evidence and stop or revoke clients in case of anomalies. Revoking a connection does not delete data already received by the client.

For use in the EU and other applicable territories, the merchant assesses privacy, electronic communications, consumer rights and AI transparency obligations based on the actual workflow. Human involvement or the MCP protocol does not provide a general exemption from GDPR or the AI Act and does not transfer Repliva’s own obligations to the merchant.

18. Processing on behalf of the merchant (DPA)

Subject and duration. For end-customer personal data, the merchant appoints Repliva as processor for the service duration and until agreed return or deletion. Purposes are customer support, ticket management, order consultation and reply preparation; operations include collection, consultation, organization, storage, AI analysis, transmission on instruction and deletion. Data subjects are the merchant’s customers, contacts and operators; data includes identifiers, contact details, communications, orders, deliveries, drafts and operational records.

Instructions and confidentiality. Repliva processes this data only on documented merchant instructions, including configurations and authorized requests, also for international transfers, unless legally required otherwise, in which case it informs the merchant beforehand where permitted. It promptly flags instructions it considers contrary to data protection law. Authorized persons are bound by confidentiality. Incompatible independent purposes or general-purpose model training on this data are not authorized.

Security and incidents. Repliva implements risk-appropriate measures under GDPR Article 32, including authentication, access control, tenant separation, credential protection and incident management. It notifies the merchant without undue delay after becoming aware of a personal data breach, providing available information and subsequent updates to support the merchant’s legal duties.

Subprocessors. Use of subprocessors requires specific or general written merchant authorization based on a list identifying entities, services and processing locations. Under general authorization, Repliva gives advance notice of additions or replacements to allow reasoned objections before processing. If an objection cannot be resolved, the parties agree on an alternative or termination of the affected function. Repliva imposes equivalent contractual obligations and remains responsible under Article 28(4). Categories and services described in the Privacy Policy do not replace the authorized list.

Assistance and audits. Taking account of the processing and available information, Repliva assists the merchant with rights requests, security, breach notifications, impact assessments and prior consultations. It provides information needed to demonstrate compliance and allows and contributes to audits and inspections by the merchant or its appointed auditor, using arrangements that protect other tenants without preventing required checks.

Transfers and termination. Transfers outside the EEA require a valid condition under GDPR Chapter V and supplementary safeguards where needed; choosing an integration alone is not a derogation. At termination, Repliva returns or deletes data and copies at the merchant’s choice, except where law requires retention. Residual backup copies are isolated from ordinary use and deleted in the applicable technical cycle; details and deadlines are documented in the operational agreement. Revoking a connection does not delete previously imported data.