Privacy Policy

Last Updated: 06-05-26

1. Who We Are

Replyy AI is an AI-powered Instagram and WhatsApp DM appointment-setting service operated by Girik Varma and Suyash Verma ("we", "us", "our"), trading under the name Replyy AI. Our website is located at https://tryreplyy.com.

We are not a registered legal entity at this time. We operate as a co-founded agency and will register as a partnership firm in India. All contractual and financial matters are currently handled by Girik Varma on behalf of the agency.

Contact: team@tryreplyy.com

2. Scope of This Policy

This Privacy Policy applies to:

  1. Website visitors — anyone visiting https://tryreplyy.com or any subdomain operated by us.
  2. Clients — coaches, consultants, and service businesses who engage Replyy AI to provide appointment-setting services under a signed agreement.
  3. Leads and prospects ("Leads") — individuals whose Instagram DM conversations are processed by Replyy AI on behalf of our clients.

We operate as:

3. Data We Collect

3.1 Website Visitors

When you visit our website, we may collect:

3.2 Clients

When you engage Replyy AI as a client, we collect:

3.3 Leads and Prospects (Processed on Behalf of Clients)

As part of delivering our service, our AI agent accesses and processes data belonging to your client's Instagram audience. This data is processed solely to perform the appointment-setting service and includes:

We do not sell, share, rent, or use Lead data for any purpose other than delivering the appointment-setting service to the relevant client.

4. How We Use Data

Data CategoryPurposeLegal Basis
Website visitor contact/form dataRespond to demo requests and sales enquiriesLegitimate interest (pre-contractual) / Consent
Server logsSecurity, abuse prevention, infrastructure monitoringLegitimate interest
Client identity and credentialsDeliver the appointment-setting serviceContract performance
Client payment informationInvoicing, commission tracking, financial recordsContract performance / Legal obligation
Lead conversation dataAI-powered DM qualification and appointment bookingContract performance (on behalf of client/controller)
Lead booking dataSyncing booked calls to client's calendarContract performance
Lead voice dataTranscription (inbound) and voice note delivery (outbound)Contract performance

We may use aggregated, non-personally-identifiable patterns observed across client engagements to improve our service methodology and conversation strategies. For example, we may learn that certain conversation approaches are more effective in specific industries and apply those insights across our client base. This aggregate operational learning does not involve sharing any individual lead's personal data between clients and is based on our legitimate interest in improving our service quality.

We do not use any data for automated decision-making that produces legal or similarly significant effects on individuals, except for the lead qualification scoring used solely for the purpose of prioritising appointment-setting conversations on behalf of clients.

5. Sub-Processors and Third Parties

We use the following third-party sub-processors to deliver our service. We have carried out good-faith due diligence on each. Where compliance documentation is limited (particularly for smaller vendors), we have noted this transparently.

Sub-processorPurposeData ProcessedLocationCompliance Notes
SupabaseDatabase (all structured data)All categoriesEU West (Paris) / ConfigurableGDPR compliant; DPA available on all plans; SOC 2 Type II
OpenAIAI language model (conversation generation, Whisper transcription)DM text, voice transcriptsUSDoes not train on API inputs/outputs by default; formal DPA requires enterprise contract; GDPR compliance limited for standard API plans
ElevenLabsVoice note synthesis (text-to-speech)Lead-directed audio scriptsUSGDPR compliant (EU-US Data Privacy Framework); voice/audio data may be used for model training unless opted out — we have opted out at account level; DPA available via enterprise plan only
ZernioInstagram/WhatsApp messaging API (DM sending/receiving) — one of two messaging providers, selected per clientDM content, platform profile dataEU (Spain)Claims GDPR compliance; governed by Spanish law; no formal DPA published; limited compliance documentation
Meta Platforms (Instagram/WhatsApp Graph API)Direct Instagram/WhatsApp messaging API — alternative messaging provider, selected per clientDM content, platform profile data, OAuth access tokensUS / GlobalGDPR compliant; subject to Meta's Platform Terms, Privacy Policy, and Data Processing Terms; DPA available via Meta's standard developer agreements
ManyChatFirst-contact outbound DM automation (agency tool, configured per client)Client Instagram account accessUSGDPR compliance documentation available; DPA availability dependent on plan tier
RailwayAgent deployment infrastructureAgent runtime environment, logsUS / EUGDPR compliant (EU-US Data Privacy Framework); DPA available on request
Coolify (self-hosted)Infrastructure orchestrationContainer and service configurationEU (Hetzner, Germany)Self-hosted; no data leaves our Hetzner VPS
Hetzner OnlineVPS hosting (all infrastructure)All data at rest and in transitGermany (EU)GDPR compliant; EU-based data centre; German data protection laws apply
AxiomInfrastructure log aggregationServer logs, error tracesUSGDPR compliant (EU-US Data Privacy Framework); DPA terms unclear; logs contain IP addresses and infrastructure metadata only
CalendlyBooking platform (client calendar integration)Lead name, email, booking timeUSGDPR compliant (EU-US Data Privacy Framework); DPA available
Cal.comBooking platform (alternative)Lead name, email, booking timeUS / Self-hostedOpen-source; GDPR compliance depends on deployment mode
Open Exchange Rates (openexchangerates.org)Daily currency exchange rate data for converting closed-deal revenue to USDNo personal data (public exchange rate data only — we query rates, we do not send PII)USStandard SaaS terms; queries are aggregate-level and contain no Lead or Client personal data
WisePayment processingTransaction amounts, client identityUK / EUFCA regulated; GDPR compliant

Honest compliance note: We are an early-stage agency operating under Indian law. We do not currently hold a formal Data Processing Agreement with every sub-processor listed above (notably Zernio and ElevenLabs for non-enterprise accounts). Full formal GDPR and CCPA compliance is a work in progress. If you are an EU or California resident and this matters for your engagement with us, please contact privacy@tryreplyy.com before engaging our services.

6. Data Retention

Data CategoryRetention Period
Website visitor logs90 days (infrastructure log rotation)
Contact/form submissionsUntil you request deletion, or 2 years of inactivity
Client data (active)Duration of the client agreement
Client data (post-termination)30 days after termination, then deleted or anonymised
Encrypted credentialsDeleted immediately upon client offboarding or account deletion
Lead conversation logsDuration of the client agreement; deleted within 30 days of client offboarding
Lead booking dataDuration of the client agreement; deleted within 30 days of client offboarding
Voice data (audio files)Deleted after transcription processing; transcripts retained for the duration of the client agreement
Financial/payment records7 years (Indian tax law requirements)

After the applicable retention period, data is either permanently deleted or irreversibly anonymised. Clients may request early deletion of their data and their leads' data by contacting us.

7. Data Security

We implement the following security measures:

Despite these measures, no system is completely secure. We cannot guarantee absolute security of data transmitted over the internet.

8. Your Rights

8.1 Indian Users — Digital Personal Data Protection Act 2023 (DPDPA)

As a data principal under the DPDPA 2023, you have the right to:

8.2 EU/EEA/UK Users — GDPR and UK GDPR

Where GDPR applies, you have the right to:

Limitation: As noted in Section 5, not all of our sub-processors have formal DPAs in place. We are working towards full GDPR compliance. If your request relates to data processed through a sub-processor without a formal DPA, we will make best efforts but cannot guarantee full GDPR-standard responses.

8.3 California Users — CCPA / CPRA

California residents have the right to:

Limitation: We do not meet the thresholds that trigger mandatory CCPA compliance for most businesses (we are below $25M annual gross revenue and below 100,000 consumers). We nonetheless honour these rights in good faith.

8.4 Exercising Your Rights

To exercise any of the above rights, contact us at:

If your request relates to Lead data (i.e., you are a prospect whose data was processed by our AI on a client's behalf), you should also contact the client directly, as they are the Data Controller for your personal data in that context.

9. Meta Platform Data (Instagram and WhatsApp)

Our service accesses Instagram and WhatsApp account data via one of two routes, selected per client during onboarding:

  1. Zernio API — a third-party integration layer that wraps Meta's Instagram Graph API and WhatsApp Business API.
  2. Meta Graph API (direct) — direct integration with Meta's Instagram Graph API and WhatsApp Business API using OAuth-issued access tokens.

Use of Instagram and WhatsApp data is subject to:

We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., Instagram, or WhatsApp. We do not access data beyond what is necessary to deliver the appointment-setting service.

10. International Data Transfers

We are based in India. Data may be transferred to and processed in the United States, European Union, and United Kingdom by our sub-processors listed in Section 5. Where such transfers occur, we rely on the sub-processor's applicable transfer mechanisms (EU-US Data Privacy Framework, Standard Contractual Clauses, or adequacy decisions).

11. Children's Privacy

Our service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, contact team@tryreplyy.com and we will delete it promptly.

12. Changes to This Policy

We may update this policy periodically. Material changes will be communicated to active clients by email. The "Last Updated" date at the top reflects the most recent revision. Continued use of our website or services after changes constitutes acceptance of the updated policy.

13. Contact

Replyy AI (operated by Girik Varma and Suyash Verma) Email: team@tryreplyy.com Website: https://tryreplyy.com