Privacy Policy
Last updated: 2026-07-22
1. Introduction — who we are
Replyion SL (in formation), Spain (“Replyion”, “we”, “us”) provides an AI patient coordinator for fertility clinics. The service runs on the clinic’s own WhatsApp Business number: it answers patient inquiries, helps schedule consultations, and escalates clinical questions to the clinic’s team. This policy explains what personal data we process, why, and what rights you have.
Questions about this policy or about your data: hello@replyion.com.
2. The two roles we play
In plain English, Replyion handles two very different kinds of data:
- Clinic data— operator accounts, billing details, and the clinic’s service configuration. For this data, Replyion is the data controller: we decide how and why it is processed.
- Patient data — WhatsApp conversations and appointment details. For this data, the clinic is the data controller and Replyion is a data processoracting on the clinic’s documented instructions under a Data Processing Agreement (DPA).
If you are a patient, you exercise your GDPR rights through your clinic first — it is the controller of your conversation and appointment data. If you cannot reach your clinic, contact us at hello@replyion.com and we will help route your request.
3. Information we process
Clinic-provided information
The clinic configures the service with its own information: services offered, prices, opening hours, staff names and roles, frequently asked questions, and operator contact details.
Patient data (processed on the clinic’s behalf)
WhatsApp messages exchanged between the patient and the clinic’s number, including any health information a patient chooses to share. Health information is a special category of personal data under Article 9 GDPR. It is processed under the clinic’s legal basis — the patient’s explicit consent (Art. 9(2)(a)) or the provision of healthcare (Art. 9(2)(h)) — as determined by the clinic as controller.
Appointment data
Consultation requests and bookings: requested times, confirmed slots, and related scheduling details.
Technical and operational metadata
Message timestamps, delivery status, and operational logs needed to run the service reliably and securely.
4. Google user data
When a clinic authorizes it via Google OAuth, Replyion accesses the clinic’s Google Calendar solely to check availability and to create, update, or cancel consultation appointments. We do not access any other Google data.
- Google OAuth tokens are encrypted at rest using AES-256-GCM.
- Google user data is not shared with third parties except the sub-processors necessary to operate the service, is not used for advertising, and is not sold.
- The clinic can revoke Replyion’s access at any time from its Google account settings. Stored tokens are deleted when the clinic disconnects the integration.
Replyion’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. WhatsApp
Patient–clinic messages travel over WhatsApp Business (operated by Meta) through our Business Solution Provider, 360dialog GmbH (Germany). WhatsApp’s own end-to-end transport encryption applies between the patient’s device and WhatsApp.
6. AI processing
Messages are processed by Anthropic’s Claude models to generate responses. The AI never diagnoses and never gives medical advice — this is technically enforced, not just a policy statement. Clinical questions are escalated to the clinic’s medical team. Patient data is not used to train AI models.
7. Cookies and analytics
This website uses almost no cookies. Analytics (Plausible, EU-hosted, cookieless) load only with your consent, and only if analytics is enabled for the site. Full details in our Cookie Policy.
8. Legal bases (where Replyion is the controller)
| Processing | Legal basis |
|---|---|
| Providing the service to clinics (accounts, configuration, support) | Contract — Art. 6(1)(b) |
| Invoicing, tax, and commercial record-keeping | Legal obligation — Art. 6(1)(c) |
| Service security, abuse prevention, and product improvement | Legitimate interests — Art. 6(1)(f) |
9. Retention
These retention periods are enforced in the platform, not aspirational:
| Data | Retention |
|---|---|
| Conversation messages | 90 days active, then archived encrypted; hard-deleted within 365 days of last activity (clinic-configurable between 30 and 365 days) |
| Human-takeover contact details | Encrypted and purged within 24 hours |
| Appointment records | Retained per Spanish tax and medical record obligations (up to 7 years) |
| Billing records | 7 years (Spanish tax law) |
| Security audit records | Retained for legal record-keeping (minimum 7 years) |
10. Sub-processors
We use a short list of sub-processors to operate the service. The maintained list, with purpose, location, and status, is published at /legal/sub-processors. In summary:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database | EU (Frankfurt) |
| Anthropic | AI processing | USA |
| Vercel | Hosting | EU regions preferred |
| 360dialog | WhatsApp Business API | Germany |
| Meta (WhatsApp) | Messaging transport | Clinic-owned WhatsApp Business Account |
| Calendar (when the clinic connects it) | Per Google infrastructure | |
| Upstash | Infrastructure metadata | EU |
11. International transfers
Data is stored at rest in the EU (Frankfurt). Where a sub-processor processes data outside the EEA — Anthropic, in the USA — transfers are protected by appropriate safeguards under GDPR Chapter V, including Standard Contractual Clauses.
12. Security
In summary: TLS 1.2+ in transit (TLS 1.3 preferred), AES-256 encryption at rest, per-clinic tenant isolation enforced with PostgreSQL row-level security, encrypted OAuth tokens, append-only audit logging, and least-privilege access. Full details on our Security page.
13. Your GDPR rights
Under Articles 15–22 GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to its processing. Patients should exercise these rights through their clinic (the controller of patient data); clinics and anyone else can write to hello@replyion.com.
You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or with your local data protection authority.
The AI coordinator makes no decisions producing legal or similarly significant effects about you within the meaning of Article 22 GDPR.
14. Children
The service is not directed at individuals under 18.
15. Changes and contact
We may update this policy; the “Last updated” date above always reflects the current version. Material changes affecting clinics are notified to clinic operators. Contact: hello@replyion.com — Replyion SL (in formation), Spain.