How LocalReply applies the General Data Protection Regulation
📅 Last updated: March 2025 — Applicable to EU residents and Switzerland (nFADP)
This GDPR policy applies to:
LocalReply acts as data controller for subscriber data — meaning the people who create an account and use our platform. We determine the purposes and means of processing this data.
We decide why and how data is processed.
For end customer data that interacts with the chat widget, LocalReply acts as a data processor on behalf of subscribers. The subscriber is the data controller for this data and must:
We act on your instructions as a subscriber.
⚠️ As a LocalReply subscriber, you are the data controller for your end customers' data. You are responsible for informing them that they are interacting with an AI assistant, and for complying with your GDPR obligations towards them.
Obtain a complete copy of the personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Request restriction of the processing of your data in certain circumstances.
Receive your data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interest or for direct marketing.
Not be subject to a decision based solely on automated processing with significant effects.
Withdraw your consent at any time, without affecting the lawfulness of prior processing.
Send an email to support@localreply.ai specifying the right you wish to exercise and your identity.
We may ask you to confirm your identity to protect your data from unauthorized requests.
We commit to responding within 30 days. This may be extended to 60 days for complex requests.
Exercising your rights is free. Only manifestly unfounded or excessive requests may incur a fee.
Some of our sub-processors are located in the United States. These transfers are governed by:
| Provider | Transfer mechanism |
|---|---|
| OpenAI | Standard Contractual Clauses (SCCs) |
| Stripe | EU-US Data Privacy Framework + SCCs |
| Twilio / SendGrid | Standard Contractual Clauses (SCCs) |
| EU-US Data Privacy Framework + SCCs | |
| Render | Standard Contractual Clauses (SCCs) |
In the event of a personal data breach, LocalReply commits to:
LocalReply conducts Data Protection Impact Assessments when processing is likely to result in high risk, particularly:
DPIAs are reviewed annually or whenever significant changes are made to processing.
LocalReply does not have a formally designated DPO (not required at our scale). All GDPR-related requests are handled by our team: