Skip to main content
Back

ReplyOS Privacy Policy

Version 2026-08-20.1 · Last updated 20 August 2026

1. Introduction

This Privacy Policy explains how Reply Intelligence Group Ltd collects, uses, stores, and shares personal data in connection with the ReplyOS platform and related services.

2. Who we are

The contracting party and data controller or processor (as described below) is Reply Intelligence Group Ltd (Company No. 17040048), registered office Flat 14, 2, Stewart Court, Colnhurst Road, Watford, United Kingdom, WD17 4BW. ReplyOS is the Company’s product.

ICO registration number: ZC192287.

For privacy questions, contact: hello@replyos.co.uk

3. Scope

This policy covers:

  • account and user data relating to ReplyOS customers;
  • website and onboarding data;
  • support and billing data;
  • personal data processed through the platform in connection with customer enquiries, messages, contacts, and related workflows.

4. Roles

For customer account data collected directly by the Company for account creation, billing, support, and service administration, the Company generally acts as controller.

For customer enquiry data, patient/customer communications, and related data processed on behalf of a practice or business using ReplyOS, the Company generally acts as processor on behalf of that customer, as described in the Data Processing Addendum.

5. Data we collect

We may collect and process:

  • account owner and user details such as name, email, phone number, job title, and login identifiers;
  • billing and subscription information;
  • configuration data, integration settings, and service preferences;
  • customer enquiry data made available through the service, such as names, phone numbers, email addresses, conversation content, timestamps, channel data, and booking-related metadata;
  • technical and usage data such as log data, device/browser data, IP address, user agent, and service interaction events;
  • support communications and feedback.

6. Purposes of processing

We use personal data to:

  • provide and operate the ReplyOS platform;
  • authenticate users and secure accounts;
  • enable messaging, automation, workflow, analytics, and integrations;
  • provide support, maintenance, and troubleshooting;
  • manage billing, subscriptions, and service communications;
  • monitor performance, reliability, and security;
  • comply with legal obligations and enforce our terms.

7. Lawful bases

Where the Company acts as controller, our lawful bases may include:

  • performance of a contract;
  • legitimate interests in operating, securing, and improving the service;
  • compliance with legal obligations;
  • consent, where specifically obtained for a particular purpose.

Where the Company acts as processor, we process personal data on the documented instructions of our customer and under the applicable customer relationship with the data subject.

8. Sharing

We may share personal data with:

  • infrastructure, hosting, analytics, support, and communication providers;
  • payment providers such as Stripe;
  • integration providers connected by the customer, such as messaging, CRM, booking, and telephony platforms;
  • professional advisers, auditors, insurers, or regulators where necessary;
  • law enforcement or authorities where required by law.

9. International transfers

Where personal data is transferred outside the UK, we will use appropriate safeguards where required, such as adequacy regulations or appropriate contractual protections, including the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as set out in our DPA.

10. Retention

We retain personal data for as long as necessary for the purposes described in this policy, including to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Where exact retention periods vary by customer configuration, contract, or legal obligation, we may retain data according to documented retention criteria and service requirements.

11. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. No system can be guaranteed 100 percent secure, but we take security seriously and continually improve our controls.

12. Data subject rights

Where the Company acts as controller, individuals may have rights including access, rectification, erasure, restriction, objection, and, where applicable, portability. They may also have the right to complain to the ICO.

Where the Company acts as processor on behalf of a customer, requests relating to customer enquiry data should usually be directed to the relevant customer organisation first, though the Company may assist that customer where required.

13. Cookies and similar technologies

If applicable, website and product interfaces may use cookies or similar technologies for session handling, security, analytics, and product functionality. Additional cookie information may be provided separately.

14. Contact and complaints

For privacy queries, contact: hello@replyos.co.uk

If you are unhappy with how your personal data has been handled, you may have the right to complain to the Information Commissioner’s Office.

15. Changes to this Policy

We may update this Privacy Policy from time to time. Where appropriate, we will update the version number, effective date, and notify customers of material changes.