Privacy Policy

How we collect, use, and protect your data

📅 Last updated: March 2025 — Subject to Swiss law and the European GDPR

🌐 This is the original, legally binding version of this document, drafted in English.

1. Data Controller

Data Controller
LocalReply
Independent operator — Switzerland

2. Data Collected

2.1 Business customer data (LocalReply subscribers)

DataSourceRequired
First and last nameRegistration formYes
Professional email addressRegistration formYes
Phone numberAccount configurationNo
Business name and addressAccount configurationYes
Payment informationStripe (never stored by us)Yes
Google Calendar tokensGoogle OAuth authorizationNo
Usage data (logins, actions)AutomaticAutomatic

2.2 End customer data (chat widget visitors)

DataSourceRequired
Conversation messagesChat widgetYes
Name (if provided for an appointment)ConversationNo
Phone (if provided for an appointment)ConversationNo
Email (if provided for an appointment)ConversationNo
Detected languageAutomaticAutomatic
Anonymized IP addressAutomaticAutomatic
Session identifier (hash)AutomaticAutomatic

3. Purposes and Legal Bases

PurposeLegal basis (GDPR)
Service delivery (AI, appointments, dashboard)Contract performance — Art. 6(1)(b)
Billing and subscription managementContract performance — Art. 6(1)(b)
Transactional emails (confirmations, alerts)Contract performance — Art. 6(1)(b)
Service improvement and anomaly detectionLegitimate interest — Art. 6(1)(f)
Compliance with legal obligationsLegal obligation — Art. 6(1)(c)
Marketing emails (if consent given)Consent — Art. 6(1)(a)

Conversation data is processed to provide AI responses. It is not used to train our AI models without explicit consent.

4. Sub-processors and Third Parties

LocalReply uses the following providers, each with their own privacy policy:

ProviderRoleLocationPolicy
StripePayment processingUS / EUstripe.com/privacy
SendGrid (Twilio)Email deliveryUSsendgrid.com
Google Calendar APICalendar syncUS / EUpolicies.google.com
OpenAIAI conversation processingUSopenai.com/privacy
TwilioSMS delivery (Pro plan)UStwilio.com/legal
RenderBackend hostingUSrender.com/privacy

Transfers to countries outside the EU/Switzerland are carried out on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission, or other adequate transfer mechanisms.

4b. Data Processing Agreement (DPA)

As a LocalReply subscriber deploying the chat widget to your end customers, you act as a data controller and LocalReply acts as a data processor on your behalf for end customer data.

By accepting these Terms of Service, you also enter into a Data Processing Agreement (DPA) with LocalReply. Under this DPA:

  • LocalReply processes end customer data solely on your documented instructions and for the purpose of providing the Service
  • LocalReply implements appropriate technical and organizational security measures (Art. 32 GDPR)
  • LocalReply assists you in responding to data subject requests from your end customers
  • LocalReply notifies you of any data breach affecting your end customers' data within 72 hours of becoming aware
  • LocalReply deletes or returns all personal data upon termination of the Service
  • LocalReply makes available all information necessary to demonstrate compliance with Art. 28 GDPR

A full copy of our DPA is available upon request at support@localreply.ai.

ℹ️ Note on OpenAI: Data sent to OpenAI via the API is not used to train OpenAI models by default, pursuant to OpenAI's API data usage policy. LocalReply does not enable training on your data.

5. Retention Periods

Data typeRetention period
Account data (subscriber)Duration of subscription + 3 years
Billing data10 years (legal accounting obligation)
Conversations and messages12 months after last activity
Appointment data24 months after appointment date
Technical logs90 days
End customer data (visitors)6 months after the conversation

Upon expiry of these periods, data is irreversibly deleted or anonymized.

6. Your Rights

Under GDPR (EU 2016/679) and the Swiss Federal Act on Data Protection (nFADP), you have the following rights:

  • Right of access (Art. 15 GDPR) — obtain a copy of your personal data
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data
  • Right to erasure (Art. 17) — request deletion of your data ("right to be forgotten")
  • Right to restriction (Art. 18) — restrict processing in certain cases
  • Right to data portability (Art. 20) — receive your data in a structured format
  • Right to object (Art. 21) — object to processing based on legitimate interest
  • Right to withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact us at support@localreply.ai. We will respond within 30 days.

You also have the right to lodge a complaint with the competent data protection authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).

7. Data Security

LocalReply implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, or destruction:

  • Data in transit encrypted via TLS/HTTPS
  • Sensitive tokens (Google Calendar) encrypted in the database
  • Authentication via time-limited JWT tokens
  • Data access restricted to the strict minimum
  • Automatic daily backups
  • Access and anomaly monitoring

In the event of a data breach likely to result in a high risk to your rights and freedoms, we will notify you within 72 hours in accordance with Art. 33 GDPR.

8. Cookies

LocalReply uses a limited number of strictly necessary cookies for the service to function:

CookiePurposeDuration
auth_tokenAuthentication of logged-in userSession / 30 days
business_idIdentification of active businessSession

We do not use advertising or third-party tracking cookies. No data is shared with advertising networks.

9. Minors

LocalReply is a service intended for professionals and adults. We do not knowingly collect personal data from children under 16. If you believe a minor has provided us with data, contact us for immediate deletion.

10. Policy Changes

We reserve the right to modify this privacy policy at any time. In case of a material change, you will be notified by email at least 30 days before the new provisions come into effect.

The current version is always accessible on this page. The date of last update appears at the top of this document.

11. Contact

For any questions regarding this policy or to exercise your rights:

Questions about your data?

We commit to responding within 30 days.

📧 Contact us