How Primanza LLC handles personal data
Privacy Policy
- Effective:
- July 10, 2026
- Last updated:
- July 10, 2026
This Privacy Policy explains how Primanza LLC, doing business as ReplyTune ("we", "us" or "our"), collects, uses, discloses and protects personal data in connection with the ReplyTune websites and services (the "Service"). It applies to visitors, account holders and their authorized users.
We designed the Service for global use and this Policy is written to meet the requirements of the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and comparable laws worldwide. Capitalized terms not defined here have the meaning given in our Terms of Service.
Contents
- 01Who We Are and Our Two Roles
- 02Personal Data We Collect
- 03How We Use Personal Data and Legal Bases
- 04Artificial Intelligence Processing
- 05Google User Data and Limited Use
- 06How We Share Personal Data
- 07International Data Transfers
- 08Data Retention and Deletion
- 09Security
- 10Your Rights (EEA, UK and Similar Laws)
- 11United States State Privacy Rights (California and Others)
- 12Other Regions
- 13Children's Privacy
- 14Automated Decision-Making and Profiling
- 15Cookies
- 16Changes to This Policy
- 17Contact Us
01Who We Are and Our Two Roles
Primanza LLC is the entity responsible for the Service. Our registered details and data-protection contacts are in Section 18.
Controller data
For personal data about our account holders, their authorized users and website visitors (for example, your name, email, login and billing details), we act as a controller and determine how and why that data is processed. This Policy governs that processing.
Processor data
For the personal data contained in the reviews and profiles you connect to the Service (for example, the names, profile photos and review text of the people who write reviews of your business), we act as a processor on your behalf. You (our customer) are the controller of that data, and we process it only to provide the Service to you, under our Data Processing Agreement. If you are a reviewer and want to exercise rights over a review, please contact the business that owns the listing; we will support that business as its processor.
02Personal Data We Collect
Data you provide
- Account data: name, email address and a securely hashed password. If you sign in with Google, we receive your name, email and profile image from Google.
- Business and brand data: business name and type, locations and addresses, and the brand profile you configure (tagline, contact channels, service areas, tone, preferred and banned phrases, business facts and signature). Do not include special-category or unnecessary personal data in these free-text fields.
- Support and communications: the content of messages you send us and related metadata.
Data collected on your behalf from Connected Platforms
- Google Business Profile data: the OAuth authorization to your account, connected location details, and the reviews we synchronize, which include the reviewer's display name and photo, star rating, review text and language, and reply history. This is processor data as described in Section 1.
Payment data
Subscriptions are processed by Stripe. Stripe collects and processes your payment-card details directly; we receive limited billing information such as your billing name, country, the last four digits and card brand, and subscription status. We do not receive or store full card numbers.
Data collected automatically
- Technical and usage data: IP address, device and browser type, pages viewed, actions taken, timestamps and diagnostic logs, collected to operate and secure the Service.
- Cookies: strictly necessary cookies used for authentication and security. See our Cookie Policy.
Sensitive data
We do not intentionally collect special categories of personal data (such as health, religion or biometric data). Please do not submit such data in free-text fields. If reviewers include such information in their reviews, we process it only as your processor, at your instruction and under your responsibility as controller.
03How We Use Personal Data and Legal Bases
As controller, we use personal data for the purposes below. Where the GDPR applies, we rely on the legal bases indicated.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and administer your account; authenticate you | Account data | Performance of a contract (Art. 6(1)(b)) |
| Provide, operate and support the Service | Account, business/brand, usage data | Performance of a contract (Art. 6(1)(b)) |
| Process payments and prevent payment fraud | Billing data | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Secure the Service, prevent abuse and debug | Technical, usage, log data | Legitimate interests (Art. 6(1)(f)) |
| Improve and develop features (not by training generative models on your reviews or replies) | Aggregated / de-identified usage data | Legitimate interests (Art. 6(1)(f)) |
| Send service, security and transactional messages | Account data | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Send marketing (where permitted) | Account data | Consent (Art. 6(1)(a)) or legitimate interests, with opt-out |
| Comply with law and enforce our terms | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and will provide details on request. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
04Artificial Intelligence Processing
To generate reply drafts, sentiment classifications and insight reports, review content and the brand context you configure are sent to our AI sub-processor, OpenAI, through its business API. We do not use, and we instruct our AI sub-processor not to use, the content of your reviews or replies to train generative AI models. AI Output is generated solely to provide the Service to you.
AI Output is probabilistic and may be inaccurate. The Service does not make decisions that produce legal or similarly significant effects on the reviewers whose reviews are processed; it drafts and, at your election, publishes replies under your control. See Section 16 on automated decision-making, and our Terms of Service and Sub-processors list.
05Google User Data and Limited Use
When you connect Google, we request the minimum Google Business Profile scopes needed to read your reviews and locations and to publish replies on your behalf, and, if you use Google sign-in, basic profile information to authenticate you.
Google API Services Limited Use commitment
ReplyTune's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the Service's user-facing features, do not transfer it except as necessary to provide those features or as required by law, do not use it for advertising, and do not allow humans to read it except with your consent, for security or to comply with law, or in aggregated/anonymized form.
You can revoke our access at any time from your Google Account permissions or from the Locations page in your dashboard. Revoking access stops future synchronization; data already synchronized is handled as described in Section 10.
07International Data Transfers
We are based in the United States and use sub-processors located in the United States and other countries. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country not recognized as providing adequate protection, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses, supplemented for the United Kingdom by the UK International Data Transfer Addendum, together with any supplementary measures required. Where a sub-processor is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), we may rely on that certification. You may request a copy of the relevant safeguards by contacting us at privacy@primanza.com.
08Data Retention and Deletion
We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to comply with legal, tax and accounting obligations, resolve disputes and enforce agreements.
If you delete your account, or ask us to delete it, we will permanently delete or de-identify the synchronized reviews, drafts, brand settings and other Customer Data within 30 days, except for limited data we must retain by law (such as invoice records) or hold in routine backups until they expire on a rolling basis. Aggregated or de-identified data that no longer identifies you may be retained.
09Security
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit, hashing of passwords, access controls on a need-to-know basis, and logging and monitoring. Google refresh tokens and similar secrets are protected against unauthorized access. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and, where required, the relevant authorities, without undue delay. Report suspected vulnerabilities to security@primanza.com.
10Your Rights (EEA, UK and Similar Laws)
Subject to applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and, where processing is based on consent, withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact privacy@primanza.com. We will respond within the timeframe required by law (generally one month under the GDPR). We may need to verify your identity. There is no fee unless your request is manifestly unfounded or excessive. If you are in the EEA, you may complain to your local Data Protection Authority; in the UK, to the Information Commissioner's Office (ICO).
If your personal data is contained in a review (processor data), we will forward your request to the relevant business (the controller) and support them in responding.
11United States State Privacy Rights (California and Others)
If you are a California resident, the CCPA/CPRA gives you rights regarding your personal information. Over the preceding 12 months we may have collected the categories of personal information described in Section 2 (identifiers, customer records, commercial information, internet/network activity, and, from Google sign-in, an image). We collect it for the business purposes in Section 3 and disclose it to the recipients in Section 6.
Your California rights
- Right to know/access the personal information we collect, use and disclose.
- Right to delete personal information, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information and to limit use of sensitive personal information. We do not sell or share personal information and do not use sensitive personal information for purposes requiring a limitation right.
- Right to non-discrimination for exercising your rights.
To exercise these rights, contact privacy@primanza.com. You may use an authorized agent. We will verify your request as required by law. Similar rights may apply under the privacy laws of other US states (such as Virginia, Colorado, Connecticut, Utah and Texas), and we honor equivalent requests from residents of those states.
12Other Regions
- United Kingdom: the UK GDPR and Data Protection Act 2018 apply; the ICO is the supervisory authority.
- Brazil (LGPD): you have rights of access, correction, deletion, portability and information about sharing; the processing bases mirror those in Section 3.
- Canada (PIPEDA): we obtain consent as required and provide access and correction rights.
- Australia (Privacy Act / APPs): we handle personal information consistently with the Australian Privacy Principles.
- Residents of other jurisdictions with data-protection laws may have similar rights; contact us to exercise them.
Where required, we have appointed representatives for data subjects: EU representative — [EU representative — to be appointed under Art. 27 GDPR]; UK representative — [UK representative — to be appointed under UK GDPR].
13Children's Privacy
The Service is intended for businesses and users aged 18 or older. It is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@primanza.com and we will delete it.
14Automated Decision-Making and Profiling
The Service classifies review sentiment and drafts replies using AI. These are content-generation features under your control; they do not make decisions that produce legal or similarly significant effects on individuals within the meaning of Article 22 of the GDPR. You choose whether to publish replies automatically or after review. If we ever introduce features involving solely automated decisions with such effects, we will provide the disclosures and safeguards the law requires.
16Changes to This Policy
We may update this Policy from time to time. We will change the "Last updated" date and, for material changes, provide additional notice by email or in-product notice before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
17Contact Us
For privacy questions or to exercise your rights, contact our privacy team at privacy@primanza.com, or write to:
Primanza LLC, Primanza LLC, [Registered agent street address], [City], Wyoming [ZIP], United States.