Skip to content

Privacy Policy

Last updated: March 2026

1. Controller

The controller responsible for data processing is:

Predivo GmbH
Bahnhofstrasse 55
6403 Küssnacht am Rigi, Switzerland
UID: CHE-374.611.592
Email: hello@replyflow.help
Representative: Roger Müller

2. Scope

This privacy policy applies to the ReplyFlow application and website (collectively, the "Service"). It explains how we collect, use, store, and protect your personal data in accordance with the Swiss Federal Act on Data Protection (DSG/FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

3. Data We Collect

We collect and process the following categories of personal data:

  • Account data: email address, full name, and hashed password when you create an account.
  • Business data: Google Business Profile information, customer reviews, and AI-generated reply drafts.
  • Usage data: feature usage patterns, timestamps, and session information necessary for providing the Service.
  • Payment data: billing information processed by Stripe. We do not store credit card numbers.

4. Purpose of Processing

We process your data for the following purposes:

  • Providing and operating the ReplyFlow Service
  • Generating AI-powered reply suggestions for your reviews
  • Authenticating your identity and securing your account
  • Processing payments and managing subscriptions
  • Communicating service updates and important notices
  • Improving the Service based on aggregated, anonymised usage patterns

5. Legal Basis

We process your personal data on the following legal bases:

  • Contract performance: processing necessary to provide the Service you subscribed to.
  • Legitimate interest: improving our Service and ensuring security.
  • Consent: where required, such as for optional communications.

6. Third-Party Processors

We use the following third-party service providers to operate ReplyFlow:

  • Supabase (EU region) — authentication and database hosting.
  • Anthropic Claude (USA) — AI language model for generating review reply suggestions. Review text is sent to Anthropic for processing; no personal customer data beyond the review content is transmitted.
  • Google Business Profile API — fetching and publishing reviews on your behalf, authorised via your Google account.
  • Metanet AG (Josefstrasse 218, 8005 Zürich, Switzerland) — website and application hosting.
  • Stripe (USA, with EU data processing) — payment processing. Stripe's privacy policy applies to payment data.
  • Metanet AG SMTP (Josefstrasse 218, 8005 Zürich, Switzerland) — transactional email delivery for account verification, password resets, and review alert notifications. Only your email address and message content are transmitted. Email is processed entirely within Switzerland.

7. Cookies

ReplyFlow uses only essential cookies required for the Service to function. Specifically, we use a Supabase authentication session cookie to keep you signed in. We do not use tracking cookies, advertising cookies, or analytics services such as Google Analytics.

8. Data Transfers

Some of our processors (Anthropic, Stripe) are based in the United States. Where personal data is transferred outside Switzerland or the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) and the processors' compliance with recognised data protection frameworks.

9. Data Retention

We retain your account data for as long as your account is active. If you delete your account, all personal data will be permanently removed within 30 days, except where retention is required by law (e.g., financial records under Swiss commercial law).

10. Your Rights

Under Swiss data protection law (DSG/FADP) and, where applicable, the GDPR, you have the following rights:

  • Right of access: request information about what personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to deletion: request erasure of your personal data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at hello@replyflow.help. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), encrypted storage, access controls, and regular security reviews.

12. Governing Law

This privacy policy is governed by Swiss law. The exclusive place of jurisdiction is Küssnacht am Rigi, Switzerland.

Questions about this policy? Contact us at hello@replyflow.help

Terms of Service · Impressum