Skip to content
Replyion
Legal · Privacy Policy

Privacy Policy

Last updated: 2026-07-22

1. Introduction — who we are

Replyion SL (in formation), Spain (“Replyion”, “we”, “us”) provides an AI patient coordinator for fertility clinics. The service runs on the clinic’s own WhatsApp Business number: it answers patient inquiries, helps schedule consultations, and escalates clinical questions to the clinic’s team. This policy explains what personal data we process, why, and what rights you have.

Questions about this policy or about your data: hello@replyion.com.

2. The two roles we play

In plain English, Replyion handles two very different kinds of data:

If you are a patient, you exercise your GDPR rights through your clinic first — it is the controller of your conversation and appointment data. If you cannot reach your clinic, contact us at hello@replyion.com and we will help route your request.

3. Information we process

Clinic-provided information

The clinic configures the service with its own information: services offered, prices, opening hours, staff names and roles, frequently asked questions, and operator contact details.

Patient data (processed on the clinic’s behalf)

WhatsApp messages exchanged between the patient and the clinic’s number, including any health information a patient chooses to share. Health information is a special category of personal data under Article 9 GDPR. It is processed under the clinic’s legal basis — the patient’s explicit consent (Art. 9(2)(a)) or the provision of healthcare (Art. 9(2)(h)) — as determined by the clinic as controller.

Appointment data

Consultation requests and bookings: requested times, confirmed slots, and related scheduling details.

Technical and operational metadata

Message timestamps, delivery status, and operational logs needed to run the service reliably and securely.

4. Google user data

When a clinic authorizes it via Google OAuth, Replyion accesses the clinic’s Google Calendar solely to check availability and to create, update, or cancel consultation appointments. We do not access any other Google data.

Replyion’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. WhatsApp

Patient–clinic messages travel over WhatsApp Business (operated by Meta) through our Business Solution Provider, 360dialog GmbH (Germany). WhatsApp’s own end-to-end transport encryption applies between the patient’s device and WhatsApp.

6. AI processing

Messages are processed by Anthropic’s Claude models to generate responses. The AI never diagnoses and never gives medical advice — this is technically enforced, not just a policy statement. Clinical questions are escalated to the clinic’s medical team. Patient data is not used to train AI models.

7. Cookies and analytics

This website uses almost no cookies. Analytics (Plausible, EU-hosted, cookieless) load only with your consent, and only if analytics is enabled for the site. Full details in our Cookie Policy.

8. Legal bases (where Replyion is the controller)

ProcessingLegal basis
Providing the service to clinics (accounts, configuration, support)Contract — Art. 6(1)(b)
Invoicing, tax, and commercial record-keepingLegal obligation — Art. 6(1)(c)
Service security, abuse prevention, and product improvementLegitimate interests — Art. 6(1)(f)

9. Retention

These retention periods are enforced in the platform, not aspirational:

DataRetention
Conversation messages90 days active, then archived encrypted; hard-deleted within 365 days of last activity (clinic-configurable between 30 and 365 days)
Human-takeover contact detailsEncrypted and purged within 24 hours
Appointment recordsRetained per Spanish tax and medical record obligations (up to 7 years)
Billing records7 years (Spanish tax law)
Security audit recordsRetained for legal record-keeping (minimum 7 years)

10. Sub-processors

We use a short list of sub-processors to operate the service. The maintained list, with purpose, location, and status, is published at /legal/sub-processors. In summary:

Sub-processorPurposeLocation
SupabaseDatabaseEU (Frankfurt)
AnthropicAI processingUSA
VercelHostingEU regions preferred
360dialogWhatsApp Business APIGermany
Meta (WhatsApp)Messaging transportClinic-owned WhatsApp Business Account
GoogleCalendar (when the clinic connects it)Per Google infrastructure
UpstashInfrastructure metadataEU

11. International transfers

Data is stored at rest in the EU (Frankfurt). Where a sub-processor processes data outside the EEA — Anthropic, in the USA — transfers are protected by appropriate safeguards under GDPR Chapter V, including Standard Contractual Clauses.

12. Security

In summary: TLS 1.2+ in transit (TLS 1.3 preferred), AES-256 encryption at rest, per-clinic tenant isolation enforced with PostgreSQL row-level security, encrypted OAuth tokens, append-only audit logging, and least-privilege access. Full details on our Security page.

13. Your GDPR rights

Under Articles 15–22 GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to its processing. Patients should exercise these rights through their clinic (the controller of patient data); clinics and anyone else can write to hello@replyion.com.

You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or with your local data protection authority.

The AI coordinator makes no decisions producing legal or similarly significant effects about you within the meaning of Article 22 GDPR.

14. Children

The service is not directed at individuals under 18.

15. Changes and contact

We may update this policy; the “Last updated” date above always reflects the current version. Material changes affecting clinics are notified to clinic operators. Contact: hello@replyion.com — Replyion SL (in formation), Spain.