Service usage
Semi-automatic service: AI prepares drafts; the operator always reviews and approves the final reply.
This page sets out the legal terms that apply to access to and use of the Repliva website, waitlist and SaaS platform by merchants, authorized team members and other users interacting with the service.
Semi-automatic service: AI prepares drafts; the operator always reviews and approves the final reply.
Every reply requires human review, including through MCP. Outputs may contain errors and do not guarantee results.
The merchant remains responsible for imported content, authorized integrations, configured policies and the lawful processing of end-customer data.
These terms govern access, usage limits, suspension, termination, intellectual property and the general liability framework.
Repliva is intended for merchants and professionals acting for their business. Anyone activating an account for an organization represents that they can bind it and authorize its operators.
These terms apply when validly accepted in the contractual relationship. Merely visiting the website, reading this page or generally accepting the terms does not replace any specific approvals required by law. If you do not accept the terms, do not activate or use the service.
Any applicable consumer protections remain unaffected; user status depends on actual use and applicable law.
Email registration includes a terms acceptance checkbox. For quick registration, the notice beside the Google button explains that continuing accepts the terms. We record version, language, choice wording and date, linked to the authenticated account. Existing accounts see a non-blocking dashboard notice: postponing it does not mean acceptance. General acceptance does not constitute specific approval of clauses where the law requires it. Analytics consent remains separate and optional.
The Repliva service is provided by Antonino Lombardo, owner of the service and contractual counterparty in the relationship with the merchant, referred to below as “Repliva” or the “provider”.
Formal communications relating to these terms should be sent to the contact details listed on this page or in the applicable commercial agreement.
Repliva provides semi-automatic SaaS software for ecommerce customer support. It can synchronize and organize emails, analyze requests and order context, classify tickets and prepare drafts or suggestions using AI.
In the intended workflow, the final reply is always reviewed and approved by the merchant’s operator, who decides its content, recipient and sending. Generating a draft does not constitute approval, sending or completion of a commercial action.
Repliva does not independently activate customer messaging workflows merely because an inbox is connected, a draft is generated or MCP is enabled. Sending tools execute requests from the operator or systems authorized by the merchant. External clients and MCP automations are subject to section 17.
Account details must be accurate and compatible with lawful use of the service; any suspension is governed by section 14.
AI outputs are probabilistic and may contain errors, fabricated information, omissions, bias or outdated data. They are not professional advice or a guarantee of accuracy, economic results, legal compliance or acceptance of a request.
The merchant is responsible for final review and the operational decisions it makes using outputs. This allocation does not release Repliva from its own obligations, service defects attributable to it or liabilities that cannot be excluded under section 13.
Prompts, necessary content and outputs may be transmitted to AI providers and technical intermediaries. Repliva does not promise that they collect or retain no data: processing, logs, abuse monitoring, authorized human access where applicable and retention depend on the service and applicable contracts. Privacy obligations, merchant instructions and integration data restrictions remain binding.
Repliva uses infrastructure, email and AI providers and can connect to tools chosen by the merchant. Their terms, availability, quotas and APIs may affect the service.
The merchant assesses the terms, privacy settings and permissions of external clients it connects, including AI assistants and automation platforms. These parties may receive data and MCP call results and retain them in their own systems.
Repliva does not control every internal activity of third parties and does not guarantee the complete absence of collection, retention or incidents. This does not remove Repliva’s obligations when selecting and managing its own providers or its GDPR responsibilities, including Article 28(4) for subprocessors.
Unless otherwise stated in an order form, quote, checkout or separate commercial agreement, access to paid platform features is subject to the pricing and limits published or communicated by Repliva at the time of activation.
Unless otherwise agreed in writing, any trials, renewals, suspension for non-payment, upgrades, downgrades, taxes, refunds, and other commercial conditions will follow the activation flow, checkout, selected plan, or other applicable commercial documentation.
Repliva and its licensors retain all rights, title and interest in and to the platform, software, interface, proprietary content, know-how, logos, trademarks, documentation and related developments, except for rights expressly granted to the merchant.
Except as permitted by mandatory law or written authorization, you may not copy, modify, distribute, sublicense, decompile, create derivative works from or otherwise misuse Repliva proprietary assets.
The Privacy Policy describes processing and distinguishes account data from the merchant’s customer data. Processing personal data on behalf of the merchant requires an agreement under GDPR Article 28; general acceptance of a privacy notice is neither end-customer consent nor a substitute for that agreement.
The processing conditions in section 18 form part of these terms when validly concluded between the parties. A specifically signed DPA prevails in a conflict concerning processing, without prejudice to law and data subject rights.
Each party keeps the other’s information confidential and limits access to authorized persons for service delivery, legal obligations or protection of rights.
Repliva aims to keep the service reasonably available, but does not guarantee that the platform will always be error free, uninterrupted or immune from vulnerabilities.
We may modify, update, replace or discontinue features, interfaces, technical limits, integrations or parts of the service for technical, security, legal or product-evolution reasons.
Repliva does not guarantee that AI outputs are always correct or the service is uninterrupted. It remains responsible for performing its contractual duties and complying with mandatory obligations.
In business relationships, to the extent permitted by law and subject to valid specific approval where required, Repliva is not liable for consequences attributable to the merchant’s unlawful use or breach of these terms, incorrect instructions or content supplied by the merchant, or external workflows it configures. Consequences attributable to Repliva’s own breach are not excluded.
Under the same conditions, indirect damages and loss of profit are excluded and Repliva’s aggregate contractual liability for ordinary negligence is limited to the fees paid by the merchant for the service in the twelve months before the harmful event, unless otherwise agreed in writing.
No clause excludes or limits liability for intentional misconduct or gross negligence, breach of public-order obligations or other matters prohibited by Article 1229 of the Italian Civil Code or mandatory law. Data subject rights, compensation and allocation of liability under GDPR Article 82, obligations toward authorities and applicable consumer protections remain unaffected.
Limitations subject to Articles 1341 and 1342 of the Italian Civil Code require valid, separate and specific written approval. Publication of this page, MCP use or general acceptance of the terms does not constitute that approval.
Any data export period, post-termination retention window and account deactivation mechanics should be aligned with the relevant commercial and privacy documentation.
These terms are governed by Italian law, without prejudice to applicable mandatory rights and rules. Statutory jurisdiction rules apply to disputes unless otherwise validly agreed. Supervisory authorities retain their powers.
Updates are published with a date and version. Material contractual changes are communicated to the merchant before application, using the methods and notice required by law and contract; acceptance is obtained where necessary. Publication does not make new liability exclusions retroactive or replace specific approvals.
For contractual questions, DPA requests and reports of misuse: Antonino Lombardo, replivacustomer@gmail.com. Version: 2026-09-14.
Repliva provides MCP (Model Context Protocol) connections and tools. Connecting does not by itself activate autonomous messaging to end customers. The merchant chooses external clients, agents, instructions, permissions and automations and is responsible for activities attributable to it.
MCP tools with write or send permissions can perform real operations, including single and bulk email replies, when they receive an authorized call. An API key or OAuth authorization enables the client within granted scopes; it does not prove that a person has read and approved every message.
The merchant must configure and enforce human review and approval of final content and recipients before every send, including each reply in a batch. Agents or workflows must not approve on the operator’s behalf. Repliva does not technically verify every approval step inside external clients.
The merchant must limit scopes, protect credentials and data, check results before repeating operations, retain necessary authorization evidence and stop or revoke clients in case of anomalies. Revoking a connection does not delete data already received by the client.
For use in the EU and other applicable territories, the merchant assesses privacy, electronic communications, consumer rights and AI transparency obligations based on the actual workflow. Human involvement or the MCP protocol does not provide a general exemption from GDPR or the AI Act and does not transfer Repliva’s own obligations to the merchant.
Subject and duration. For end-customer personal data, the merchant appoints Repliva as processor for the service duration and until agreed return or deletion. Purposes are customer support, ticket management, order consultation and reply preparation; operations include collection, consultation, organization, storage, AI analysis, transmission on instruction and deletion. Data subjects are the merchant’s customers, contacts and operators; data includes identifiers, contact details, communications, orders, deliveries, drafts and operational records.
Instructions and confidentiality. Repliva processes this data only on documented merchant instructions, including configurations and authorized requests, also for international transfers, unless legally required otherwise, in which case it informs the merchant beforehand where permitted. It promptly flags instructions it considers contrary to data protection law. Authorized persons are bound by confidentiality. Incompatible independent purposes or general-purpose model training on this data are not authorized.
Security and incidents. Repliva implements risk-appropriate measures under GDPR Article 32, including authentication, access control, tenant separation, credential protection and incident management. It notifies the merchant without undue delay after becoming aware of a personal data breach, providing available information and subsequent updates to support the merchant’s legal duties.
Subprocessors. Use of subprocessors requires specific or general written merchant authorization based on a list identifying entities, services and processing locations. Under general authorization, Repliva gives advance notice of additions or replacements to allow reasoned objections before processing. If an objection cannot be resolved, the parties agree on an alternative or termination of the affected function. Repliva imposes equivalent contractual obligations and remains responsible under Article 28(4). Categories and services described in the Privacy Policy do not replace the authorized list.
Assistance and audits. Taking account of the processing and available information, Repliva assists the merchant with rights requests, security, breach notifications, impact assessments and prior consultations. It provides information needed to demonstrate compliance and allows and contributes to audits and inspections by the merchant or its appointed auditor, using arrangements that protect other tenants without preventing required checks.
Transfers and termination. Transfers outside the EEA require a valid condition under GDPR Chapter V and supplementary safeguards where needed; choosing an integration alone is not a derogation. At termination, Repliva returns or deletes data and copies at the merchant’s choice, except where law requires retention. Residual backup copies are isolated from ordinary use and deleted in the applicable technical cycle; details and deadlines are documented in the operational agreement. Revoking a connection does not delete previously imported data.