Who's the data controller?
UNQ Systems & Solutions S.L. is the data controller for personal data we collect about you (the account holder). For data about your customers' reviews, you are the controller and Repify is the processor — formalized in our Data Processing Agreement (available at hi@repify.tech).
Data Processing Agreement
We offer a DPA covering Article 28 GDPR. Email hi@repify.tech for a counter-signed copy.
Your rights
- Right of access: request a copy of all data we hold about you. Email hi@repify.tech.
- Right to rectification: correct any inaccurate data. Self-service from your profile, or by email.
- Right to erasure: delete your account and all associated data (excluding mandatory tax records). Email hi@repify.tech.
- Right to data portability: export your reviews as CSV (Growth plan) or request a full export by email.
- Right to restrict processing: pause processing while disputes are resolved. Email hi@repify.tech.
- Right to object: stop us from processing your data for non-essential purposes (e.g. analytics).
We respond to GDPR requests within 30 days — usually within 2 business days.
Legal bases for processing
- Contract: processing necessary to operate the service you signed up for.
- Legal obligation: invoice retention (Spanish tax law: 6 years).
- Legitimate interest: service-quality analytics, security monitoring. Always anonymized; you can object.
- Consent: for any non-essential marketing emails (always opt-in).
Our subprocessors
We list every subprocessor we use, what they do, and where they store data. Updated whenever we add or remove one. Subscribe to subprocessor change notifications at hi@repify.tech.
- Hosting provider — application infrastructure. Details in the DPA.
- Google — Google Business Profile API (reviews and replies), via OAuth2.
- Stripe (Ireland) — payment processing. Data: billing only.
- OpenAI — AI draft generation. Data: review text + brand context; contractual no-training.
- Postmark (Ireland) — transactional email delivery.
International transfers
Where customer data is transferred outside the EU — for example in the AI provider API calls described above — we use Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption in transit, no-training contracts).
Security
See our full security page. Highlights: GDPR-native by design, encrypted connections in transit, hashed passwords, scoped OAuth2 for Google access.
Breach notification
If a personal-data breach happens, we notify affected customers and the AEPD within 72 hours, as required by GDPR Article 33. Our internal incident response plan is tested quarterly.
Data Protection Officer
Our DPO is Inés D. — reachable at hi@repify.tech.
Supervisory authority
Spain — Agencia Española de Protección de Datos (AEPD) — aepd.es. If you're not satisfied with our handling of your data, you have the right to lodge a complaint with them or with your local data protection authority.