GDPR Policy

How LocalReply applies the General Data Protection Regulation

📅 Last updated: March 2025 — Applicable to EU residents and Switzerland (nFADP)

🌐 This is the original, legally binding version of this document, drafted in English.
✅ LocalReply is committed to full GDPR compliance. This page details concretely how we apply these obligations and how to exercise your rights.

1. Scope of Application

This GDPR policy applies to:

  • Any person residing in the European Union who uses or interacts with the LocalReply platform
  • Any person residing in Switzerland, covered by the Federal Act on Data Protection (nFADP, in force since September 2023)
  • LocalReply subscribers — businesses or freelancers using our services
  • End customers — people interacting with a subscriber's chat widget

2. Roles: Controller vs Processor

LocalReply as Data Controller

LocalReply acts as data controller for subscriber data — meaning the people who create an account and use our platform. We determine the purposes and means of processing this data.

Controller

We decide why and how data is processed.

  • Subscriber registration and account data
  • Billing and subscription data
  • Aggregated, anonymized analytics

LocalReply as Data Processor

For end customer data that interacts with the chat widget, LocalReply acts as a data processor on behalf of subscribers. The subscriber is the data controller for this data and must:

  • Inform end customers that they are interacting with an AI assistant
  • Have a valid legal basis for processing their data
  • Respond to end customers exercising their rights
Processor

We act on your instructions as a subscriber.

  • Conversation messages
  • Appointment data (name, phone, email)
  • Detected language and session identifier

⚠️ As a LocalReply subscriber, you are the data controller for your end customers' data. You are responsible for informing them that they are interacting with an AI assistant, and for complying with your GDPR obligations towards them.

3. Your 8 GDPR Rights

1

Right of Access

Obtain a complete copy of the personal data we hold about you.

Art. 15 GDPR
2

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Art. 16 GDPR
3

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Art. 17 GDPR
4

Right to Restriction

Request restriction of the processing of your data in certain circumstances.

Art. 18 GDPR
5

Right to Portability

Receive your data in a structured, commonly used, machine-readable format.

Art. 20 GDPR
6

Right to Object

Object to processing based on legitimate interest or for direct marketing.

Art. 21 GDPR
7

Rights re: Automated Decisions

Not be subject to a decision based solely on automated processing with significant effects.

Art. 22 GDPR
8

Right to Withdraw Consent

Withdraw your consent at any time, without affecting the lawfulness of prior processing.

Art. 7(3) GDPR

4. How to Exercise Your Rights

1

Submit your request

Send an email to support@localreply.ai specifying the right you wish to exercise and your identity.

2

Identity verification

We may ask you to confirm your identity to protect your data from unauthorized requests.

3

Processing within 30 days

We commit to responding within 30 days. This may be extended to 60 days for complex requests.

4

Free of charge

Exercising your rights is free. Only manifestly unfounded or excessive requests may incur a fee.

Right to Lodge a Complaint

If you believe your rights have been violated, you can contact:

5. International Data Transfers

Some of our sub-processors are located in the United States. These transfers are governed by:

ProviderTransfer mechanism
OpenAIStandard Contractual Clauses (SCCs)
StripeEU-US Data Privacy Framework + SCCs
Twilio / SendGridStandard Contractual Clauses (SCCs)
GoogleEU-US Data Privacy Framework + SCCs
RenderStandard Contractual Clauses (SCCs)

6. Data Breach Procedure

In the event of a personal data breach, LocalReply commits to:

  • Within 72 hours: notify the competent supervisory authority if the breach is likely to result in a risk to people's rights and freedoms
  • Without undue delay: notify affected individuals if the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches in an internal register, even those not requiring notification
  • Implement corrective measures as quickly as possible

7. Data Protection Impact Assessment (DPIA)

LocalReply conducts Data Protection Impact Assessments when processing is likely to result in high risk, particularly:

  • For AI processing of sensitive conversational data
  • For any new feature involving large-scale processing of personal data

DPIAs are reviewed annually or whenever significant changes are made to processing.

8. Contact

LocalReply does not have a formally designated DPO (not required at our scale). All GDPR-related requests are handled by our team:

GDPR request?

We respond to all requests within 30 days as required by law.

📧 Contact us