Repply

Privacy Policy

Effective: October 2, 2025

This Privacy Policy explains how HYPERPLAN (“we”, “us”) collects and processes personal data when businesses use our product to connect their Instagram and WhatsApp accounts, submit menus and opening hours, and have AI-generated replies sent to their incoming messages. It also covers our website and analytics.

Who we are

Controller: HYPERPLAN. For most website analytics and our direct customer account data, we act as an independent controller.

Processor: For messages received by our customers via Instagram/WhatsApp, we act as a processor on behalf of the business that connected the account. The business remains the controller for its end customers’ data.

Contact: contact+privacy_policy@hyperplan.net

What we process

Purposes and legal bases

Where we process and store data

Our application runs on Cloudflare in the closest region possible to users. Persistent data is stored in the European Union on Supabase, and analytics are stored in the EU with PostHog.

Processors and sub-processors

Each provider processes data under a data processing agreement and appropriate safeguards. We only share data with processors necessary to provide the service, under documented instructions.

International transfers

We use recognized safeguards for transfers outside your jurisdiction:

For AI inference and model improvement, OpenAI may process data in the United States. Conversation content may include personal data provided by users in messages. We rely on the safeguards above for these transfers.

AI model improvement (OpenAI)

To generate replies, we send conversation data to OpenAI. Under its terms, OpenAI may use this data to train and improve its models. This section provides transparency on that practice.

Analytics and cookies

We use PostHog in a cookieless mode for product and website analytics. We do not use third-party advertising cookies or cross-site tracking via PostHog. Our legal basis is legitimate interests (Art. 6(1)(f) GDPR). Where local law requires consent for analytics, we will honor that requirement.

Retention

We keep personal data only as long as necessary for the purposes above. Typical periods:

Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit, network protections via Cloudflare, access controls, and least‑privilege principles. Access to end‑customer messages is restricted and audited.

Your rights

Under GDPR, you (or your end customers via the controller) may have the right to access, rectify, erase, restrict processing, object, and data portability. Where we act as a processor, please contact the relevant business/controller first; we will support their request. For matters where we are the controller (e.g., your repp.ly account or website analytics), contact us at contact+privacy_policy@hyperplan.net.

You can lodge a complaint with your local authority. Our lead authority is the CNIL (France): cnil.fr.

Children

Our service is for businesses and not directed to children. We do not knowingly collect children’s data.

Changes

We may update this Privacy Policy from time to time. When we do, we will publish an updated version and effective date on this page, unless another type of notice is required by applicable law.

Contact

HYPERPLAN – Privacy inquiries: contact+privacy_policy@hyperplan.net