Privacy Policy
How Replygate collects, uses, shares, and protects personal data.
Version September 24, 2026
For processing on your organisation’s behalf, see our Data Processing Agreement.
Introduction
This Privacy Policy explains how TKM Group FZE ("TKM," "Replygate," "we," "us" or "our") collects, uses, discloses and protects personal data when you visit replygate.io, create or administer a Replygate account, use our applications and services, contact support, or otherwise interact with us (collectively, the "Service"). It also explains the choices and rights available to individuals.
1. Scope and Our Data-Protection Roles
1.1 This Policy applies to personal data for which TKM determines the purposes and means of processing, including website, account, authentication, billing and business-contact records, and administrative records used for security, support and fraud prevention. For those activities, TKM acts as a controller or equivalent responsible organization under applicable law. Customer Content accessed for instructed support or service security remains subject to the processor arrangements below.
1.2 Customers may submit emails, contacts, messages, files, CRM records and other content to the Service ("Customer Content"). When we process personal data in Customer Content on a customer's documented instructions, the customer is the controller and TKM acts as its processor or service provider. The customer's own privacy notice governs its collection and use of that data.
1.3 Our Data Processing Agreement (DPA), including its completed schedules and applicable Standard Contractual Clauses (SCCs), governs personal data processed on a customer's behalf. Applicable mandatory law and SCCs prevail over conflicting provisions, followed by the DPA and then commercial terms or Order Forms. This Policy does not grant additional rights to use Customer Content.
2. Personal Data We Collect
2.1 Account and business information may include your name, business name, work email, telephone number, job role, country, time zone, account identifiers, authentication status and user permissions.
2.2 Billing and transaction information may include billing address, tax identifiers, subscription and plan selections, invoice details, payment status, purchased products, transaction history and limited payment-method details such as card brand, expiration date and last four digits.
2.3 Service and device information may include IP address, browser and device type, operating system, referring pages, timestamps, session and authentication events, feature usage, diagnostic logs, error reports and security events.
2.4 Communications may include support requests, feedback, survey responses, emails and other communications you send to us.
2.5 Customer Content may include personal data about your employees, prospects, customers and other contacts. Customers decide what Customer Content to submit and are responsible for having a lawful basis to provide it to the Service.
3. How We Obtain Personal Data
3.1 We obtain personal data directly from you, from the organization that provides your account, through your use of the Service, from systems and integrations you connect, from payment and authentication providers, and from service providers that help us prevent fraud, secure accounts and operate the Service.
3.2 If you provide personal data about another person, you represent that you are authorized to do so and have provided any notice required by applicable law.
4. How and Why We Use Personal Data
4.1 We use personal data to create and administer accounts; provide, personalize and maintain the Service; process transactions; calculate taxes; issue invoices; deliver support; communicate operational information; secure accounts and infrastructure; prevent abuse and fraud; diagnose errors; enforce our agreements; comply with law; and establish, exercise or defend legal claims.
4.2 Where applicable law requires a legal basis, we rely on performance of a contract, steps requested before entering a contract, compliance with legal obligations, our legitimate interests in operating and protecting a business-to-business service, and consent where required.
4.3 We may use information that has been rendered genuinely anonymous, so that individuals cannot be identified by means reasonably likely to be used, to understand usage and improve the Service. Removing direct identifiers alone does not make data anonymous. Any processing of Customer Content to produce anonymous information must first be permitted by the customer's documented instructions and the DPA; this paragraph does not authorize independent reuse of personal data.
5. Customer Content and AI Features
5.1 We process Customer Content to provide the features selected and configured by the customer, including message handling, CRM workflows, search, automation and AI-assisted drafting. This processing may include transmitting relevant content and instructions to contracted infrastructure, search, communications and AI service providers.
5.2 We use Customer Content only within the agreed purposes, documented customer instructions and lawful obligations permitted by the DPA. We do not sell Customer Content, use it for advertising or train our own general-purpose AI models on it. Applicable provider processing, including security and abuse monitoring, is described in the DPA's subprocessor schedule and does not authorize unrelated provider use.
5.3 AI-generated output may be inaccurate and can contain personal data derived from submitted content. Customers are responsible for reviewing output before using or sending it and for configuring the Service consistently with their privacy obligations.
6. How We Share Personal Data
6.1 We may share personal data with contracted service providers that support cloud hosting, data storage, communications, authentication, analytics, customer support, security, tax calculation, payment processing and AI-enabled features. They may process data only for the contracted services and subject to appropriate confidentiality and data-protection obligations.
6.2 We may share data with integrations or third-party services at a customer's direction; with professional advisers and authorities when reasonably necessary to comply with law or protect rights and safety; and in connection with a merger, financing, acquisition, reorganization or sale of assets, subject to appropriate safeguards.
6.3 We do not sell personal data for money. If an applicable law treats certain analytics or advertising disclosures as a "sale" or "sharing," we will provide any notice and choice required by that law.
7. Payments
7.1 Payment details are collected and processed by Stripe and its affiliates under Stripe's own privacy terms. Replygate generally does not receive or store your full card number or security code. We receive limited payment-method and transaction information needed to manage subscriptions, invoices, refunds, disputes, fraud prevention and accounting.
7.2 When you authorize us to retain and reuse a payment method, we and Stripe process the related identifiers and consent records for the purposes disclosed at checkout, including subscription renewals and other charges you separately authorize.
8. International Data Transfers
8.1 TKM is established in the United Arab Emirates, and our providers may process data in other countries. Those countries may have data-protection laws different from those where you live.
8.2 Where required, we use recognized safeguards for restricted international transfers, such as adequacy decisions, standard contractual clauses, contractual protections and supplementary technical or organizational measures.
9. Data Retention
9.1 We retain personal data for as long as reasonably necessary to provide the Service, administer the business relationship, meet contractual and legal obligations, resolve disputes, enforce agreements and maintain security and fraud-prevention records. Retention periods depend on the data type, processing purpose, account status and applicable legal requirements.
9.2 Personal data in Customer Content is returned, retained and deleted according to the DPA, including documented customer instructions, applicable SCC duties and permitted preservation exceptions. Its retention schedule addresses active content, derived data, backups and provider copies. Backup copies are restricted from ordinary use and expire within the applicable schedule; outstanding deletion instructions are reapplied following restoration before ordinary use resumes. General business-record retention does not override these limits.
10. Security
10.1 We maintain administrative, technical and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration and disclosure. No system is completely secure, and we cannot guarantee absolute security.
10.2 You are responsible for protecting account credentials, maintaining appropriate user permissions and promptly notifying us if you suspect unauthorized access.
11. Your Privacy Rights
11.1 Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about how personal data is processed. You may also have the right to complain to a data-protection authority.
11.2 To exercise a right concerning data for which TKM is controller, contact info@replygate.io. We may need to verify your identity and authority. If your request concerns Customer Content controlled by a Replygate customer, contact that customer first; we will assist the customer as required by contract and law.
11.3 You may unsubscribe from non-essential marketing email using the link in the message or by contacting us. You will continue to receive transactional, security, billing and other service-related communications when necessary.
12. Cookies and Similar Technologies
12.1 We use cookies and similar technologies that are necessary for authentication, security, preferences and Service operation. We may also use measurement technologies to understand website and product performance. Where required, non-essential technologies are used only after the applicable consent or choice is provided.
12.2 Browser controls can block or delete cookies, but disabling necessary cookies may prevent parts of the Service from functioning.
13. Children
13.1 Replygate is a business service and is not directed to children. We do not knowingly collect personal data directly from anyone under sixteen (16), or a higher minimum age required by local law, through account signup.
14. Changes to This Policy
14.1 We may update this Policy to reflect changes in the Service, our practices or applicable law. We identify the published version and provide any additional notice required by law or our agreements. An update does not retroactively authorize processing or amend an accepted DPA or SCCs contrary to their change requirements.
15. Contact Us
15.1 Questions, requests and complaints may be sent to info@replygate.io or to TKM Group FZE, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates; trade licence 4203780.01.
