Privacy

Privacy notice

Draft. Needs a lawyer's review before the first paying customer.

Last updated: 08 October 2026. This notice explains what personal data ReplyRain holds, why, and what you can do about it. The controller is the operator of ReplyRain; its legal name and address are stated on every invoice and will be added here after legal review. Contact: support@example.com.

1. If your company's contact address is in the base

This section is the information Art. 14 GDPR asks us to give to people whose data we did not collect from them. The shared base holds companies and their general inboxes. It holds no named person and no private mailbox; should that ever change, this notice changes first.

  • What we hold: the company's name, country and line of business as an official register publishes them, and - where the law of the company's country allows a stranger to write to it - the general address the company publishes on its own website for being written to (such as info@), with the page it stood on and the day it was read.
  • Where it comes from: official company registers and other public sources whose licence allows the reuse, listed on the Data sources page, and the company's own website, read by our reader, which names itself and obeys the site's robots file (about our reader). Every letter sent through the product says where the recipient's address came from. We never build an address from a name and never take one that was written so that programs would not read it.
  • Why, and on what basis: so that businesses can write to other businesses about business matters - our and our customers' legitimate interest (Art. 6(1)(f) GDPR), within the rules on unsolicited e-mail of the recipient's country. Countries whose law asks for consent first are closed in the product.
  • Who receives it: nobody receives a list. A customer whose search matches a company may have letters sent to its address through the product; the address itself is shown to that customer only when somebody at that address has answered. One address is given to one customer at a time, with a pause of 30 days before the next.
  • How long: an address read from a company's site that no customer was given is deleted 365 days after it was read and is not collected again by itself. Otherwise: until the source withdraws the record, the record is found to be out of date, a letter to the address is returned, or you ask us to remove it.
  • How to stop it: every letter carries a one-click link. For an address of the shared base it stops every sender who writes through ReplyRain, at once - not only the one who wrote.
  • Your rights: you may ask for a copy, have the record corrected or erased, and object to its use — for direct marketing the objection is absolute and needs no reason. Use the data-request form; it needs no account. After erasure a keyed hash of your address stays on a do-not-contact list so the record is not imported again; the list cannot be read back into addresses. You may also complain to the data-protection authority of your country.

2. If you have an account

  • What we hold: your name and e-mail address, a hash of your password (argon2id, never the password), the numeric id and user name of the Telegram account you linked, your language, the browsers you are signed in from (a hash of the session token, the browser's name, a keyed hash of the network address), and a history of actions in your workspace as ids and counts.
  • Why: to provide the service you asked for (Art. 6(1)(b)), to keep it secure and to answer for what happened in it (Art. 6(1)(f)), and to issue invoices (Art. 6(1)(c)).
  • How long: for as long as the account exists; sessions and one-time codes for days; invoices for as long as accounting law requires.

3. Lists a customer uploads

For contacts a customer uploads, the customer is the controller and we are its processor. If you were contacted by a customer of ours, the unsubscribe link in the letter stops that sender at once; for anything else about that data, the customer named in the letter's footer is the one to ask — or ask us and we will pass it on.

4. Cookies

Only cookies the site cannot work without, all first-party and none for tracking: the session cookie, a token that protects forms, your language, a one-time message shown after a form is sent, and short-lived cookies during sign-in. There is no analytics, no advertising and nothing loaded from another site.

5. Where the data is and who helps us

The service runs at a hosting provider in [region — to be completed at deployment], which processes the data on our behalf under a data-processing agreement. Sign-in codes are delivered through Telegram, which receives the code and your Telegram id and nothing else. A list of processors will be kept here.

6. Security

Workspaces are separated in the database itself; passwords and tokens are stored as hashes only; connections are encrypted; exported files are marked. If a breach affects your data we will tell you and the authority as the law requires.

7. Changes

We will post changes here and, when they matter, tell account holders in the product.