Legal

PRIVACY POLICY

pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)

Last updated: July 21, 2026

1. Data Controller

The Data Controller is:

  • Name: Michele Bogoni
  • VAT ID: 04555040239
  • Registered office: Via Novella, 5/E – 37032 Monteforte d'Alpone (VR), Italy
  • Email: info@truereply.it

For any request regarding the processing of personal data, the user may contact the Data Controller at the email address above.

2. Categories of data collected

2.1 Data of registered users (TrueReply customers)

Upon registration and during use of the service, we collect:

  • Identification data: first name, last name, email address
  • Authentication data: password (cryptographic hash via Firebase Authentication)
  • Billing data: processed and stored by Stripe Inc. TrueReply neither stores nor has access to credit card data
  • Usage data: number of conversations, messages, voice minutes consumed, chatbot configuration
  • Uploaded content: documents, URLs, and texts uploaded to the chatbot knowledge base

2.2 Data of visitors of customers' websites (chatbot end users)

When a visitor interacts with a TrueReply chatbot installed on a customer's website, we collect:

  • Chat messages: the content of the conversation with the chatbot
  • Anonymous visitor identifier: a random ID generated by the browser and stored locally (localStorage) to ensure session continuity
  • Session identifier: a random UUID generated for each chat session
  • Page URL: the web page the visitor is on at the time of the interaction
  • Device type: mobile or desktop
  • Contact data voluntarily provided: name, email, phone number, or other information the visitor chooses to share during the conversation (lead capture)
  • Voice call data, inbound and outbound (if active): caller or recipient number, date, duration, talk-time, conversation transcript, outcome. Audio recording is processed only where active, that is for the Provider's demonstration number (demo bot); for customers' calls only transcripts and metadata are processed
  • Outbound campaign data (if active): contact lists uploaded by the customer, consent attestations and their source, account-wide opt-out and suppression lists
  • WhatsApp messages (if active): message content, media, and metadata such as sender and recipient numbers, date and time, delivery and read status
  • Email correspondence of the connected mailbox (if active): when the customer connects their own mailbox to the service, we process the messages that arrive in it from the moment of connection and the replies sent or drafted through the service: sender and recipients, subject, date and time, technical message and thread identifiers, message body, and any attachments in PDF or image format. The data subjects of this processing are the customer's third-party correspondents, that is, anyone who writes to the connected mailbox: they have no direct relationship with TrueReply, which neither contacts nor informs them directly. Informing them remains the responsibility of the customer, who is the Data Controller (see section 9)
  • Unified contact record: on behalf of the customer, the service links to a single contact the interactions that the same person has across different channels (website chat, WhatsApp, phone), using the normalized phone number and email address as keys. The contact holds first and last name, contact details (up to five phone numbers and five email addresses, with an indication of how they were acquired), the company where available, the tags and variables configured by the customer, and the state of each channel; it does not hold conversation content
  • Automation execution data: when the customer configures an automation, we record the event that triggers it (channel, session identifier, associated contact, and any lead data or message preview), the resulting execution with its outcome, the individual steps performed with a truncated summary of the parameters used and of the response received, and any waits for a reply from the data subject

2.3 Data collected on truereply.it

When browsing truereply.it, we collect data via:

  • Google Analytics 4: anonymized browsing data (pages visited, session duration, traffic source, device type)
  • Meta Pixel (Facebook): browsing data for remarketing and advertising conversion analysis
  • Server-side conversion measurement (Meta Conversions API and equivalent Google measurement): for those who leave a contact (form, chat) or activate a plan, we transmit to Meta and Google identifiers in hashed form (email address, phone number) and any advertising click parameters (fbc/fbp), for the sole purpose of measuring and optimizing advertising campaigns. The legal basis is the consent given when submitting the contact or activating the plan, by accepting this privacy policy, which is separate from and independent of the cookie consent expressed through the banner
  • Microsoft Clarity: anonymous session recordings, heatmaps, and page interaction data to improve user experience
  • Brevo (Sendinblue): email address, in case of voluntary subscription to the newsletter

3. Purpose and legal basis of processing

Purpose Data processed Legal basis
Provision of the SaaS service and account management Identification, authentication, usage data Performance of a contract (Art. 6.1.b GDPR)
Payment processing and invoicing Billing data (via Stripe) Performance of a contract (Art. 6.1.b GDPR)
Operation of the AI chatbot Chat messages, session data, page URL, device type Legitimate interest of the Controller and customers (Art. 6.1.f GDPR)
Lead capture on behalf of customers Contact data voluntarily provided by the visitor Consent of the data subject (Art. 6.1.a GDPR)
Inbound AI voice service Caller number, date, duration, talk-time, transcript, outcome Processing on behalf of the customer, on a legal basis determined by the customer as Controller; for the Provider's own technical purposes, legitimate interest (Art. 6.1.f GDPR)
Outbound AI voice calls on behalf of the customer Recipient number, date, duration, talk-time, transcript, outcome, consent attestations, opt-out lists Consent collected by the customer as Controller (Art. 6.1.a GDPR and Art. 130 Italian Privacy Code); TrueReply acts as Data Processor
WhatsApp messaging on behalf of the customer WhatsApp message content and metadata Legal basis determined by the customer as Controller; TrueReply acts as Data Processor
Conversational email channel on the customer's mailbox (if active): reading incoming messages, generating the reply or the draft reply, managing the thread Content and metadata of the connected mailbox's email correspondence, attachments in PDF and image format, mailbox access credentials Legal basis determined by the customer as Controller, who remains responsible for informing their correspondents; TrueReply acts as Data Processor
Unified contact record: recognizing the same person across the customer's channels and managing the relationship Name, phone and email contact details, company, tags, variables configured by the customer, state of each channel Legal basis determined by the customer as Controller; TrueReply acts as Data Processor
Execution of automations configured by the customer, including the transmission of data to the third-party systems the customer designates Event triggering the automation, contact and conversation data used in the steps, parameters and outcomes of the actions performed Documented instruction of the customer as Controller pursuant to Art. 28(3)(a) GDPR, on a legal basis determined by the customer; TrueReply acts as Data Processor
Logging of relevant operations (audit) and proof of opt-out Operator identifier, action, recipient in masked form, date and time; phone number subject to opt-out Obligation of the Processor (Arts. 28(3)(h) and 32 GDPR) and accountability (Art. 5(2) GDPR); for opt-outs, Art. 130 of the Italian Privacy Code
Website traffic analysis and site improvement Browsing data (GA4, Clarity) Consent (Art. 6.1.a GDPR)
Remarketing and advertising Browsing data (Meta Pixel) Consent (Art. 6.1.a GDPR)
Newsletter delivery Email address Consent of the data subject (Art. 6.1.a GDPR)
Development of custom commissioned solutions Identification data, project data Performance of a contract (Art. 6.1.b GDPR)
Compliance with legal and tax obligations Identification data, billing data Legal obligation (Art. 6.1.c GDPR)

4. Methods of processing

Personal data are processed using IT and electronic tools, with logic strictly related to the purposes stated above and, in any case, in such a way as to ensure the security and confidentiality of the data.

Processing via artificial intelligence: messages sent by end users to the chatbot are processed by third-party AI models (Anthropic Claude for text chat, Google Gemini for voice) to generate relevant answers. Messages are sent to AI providers exclusively for real-time processing and are not used to train models. Conversations are stored in a Firestore database to allow the customer to monitor interactions.

Processing via embeddings: documents uploaded to the knowledge base are transformed into numerical representations (embeddings) via Google (Vertex AI), in the EU region, to enable semantic search. Content is sent to Google exclusively for real-time processing, is not used to train its models, and is not subject to permanent retention.

Processing of WhatsApp messages: messages exchanged on the customer's WhatsApp Business number are processed by TrueReply as a Data Processor, exclusively to provide the AI assistance service, transiting through Meta's WhatsApp Business Platform. Content is processed by AI models to generate answers and stored in a database to allow the customer to monitor conversations.

Processing of email correspondence (if active): when the customer connects their own mailbox to the service, TrueReply reads the messages that arrive in it from the moment of connection and prepares, on behalf of the customer, the reply or the draft reply, which always leaves from the customer's mailbox and under the customer's identity. The mailbox history is not imported, and mail already classified as junk by the mailbox provider is not processed. The mailbox provider (the customer's email provider or corporate mail administrator) remains a supplier of the customer and not a sub-processor of TrueReply. Because a business mailbox receives correspondence of every kind, the processing is bounded by the following measures:

  • Automatic filter before the artificial intelligence: before any processing by the AI models, a deterministic filter discards non-conversational messages (delivery failure notices, automatic replies and system messages, newsletters and list communications, notification-only addresses). Only the metadata of such messages is retained, that is sender, subject, and date: the content is not transmitted to any AI provider
  • Messages that do not require a reply: when the assistant recognizes that a message does not require a reply, only its metadata and the reason are retained, not the message body
  • Limiting the senders processed: the customer can restrict processing to the domains they specify and exclude specific domains; by default, messages coming from the customer's own domain are excluded
  • AI processing: the content of the messages that pass the filter is processed by Anthropic Claude solely to generate the reply or the draft, under the same conditions stated above for chat (real-time processing, no use for model training)
  • Sending limits and transparency: the service sends to one recipient per message, has no bulk-sending capability, and the assistant never initiates new email conversations on its own; the reply is addressed exclusively to the sender of the original message and states that it was prepared by an AI assistant. Messages whose sender is not authenticated by the standard technical checks of the protocol never result in an automatic send
  • Attachments: only attachments in PDF or image format and within the size limits provided will be processed; other formats will be neither downloaded nor retained. The files processed will be stored in a dedicated archive, segregated per customer and not publicly accessible, with download allowed only through short-lived signed links issued after authentication. The content of permitted attachments may be read by the AI models in order to reply within the context of the conversation the attachment arrived in
  • Certified email (PEC) mailboxes: excluded from the channel, the connection is refused by the service

Attachments on the other channels: outside the email channel the service neither downloads nor retains any attachment. Of the media received on WhatsApp (images, videos, audio, documents) only a textual placeholder with the caption, where present, remains in the conversation; the file is never fetched from Meta's servers.

Unified contact record: on behalf of the customer, the service links to a single contact the interactions that the same person has across different channels, using the normalized phone number and email address as keys. The contact record is the customer's own register of contacts, has a purpose of its own, distinct from conversation content, and does not retain conversation text. For the assistants the customer has declared as intended for the processing of special categories of data, the identifying fields of the contact record are encrypted at field level with a dedicated Google Cloud KMS key.

Execution of automations configured by the customer: based on rules the customer configures, an event in the conversation (a message, a lead, a call outcome, an appointment, a request received on a webhook address dedicated to the flow, or a time schedule) can start the execution of an automation. Five actions are available today: sending an email notification to the account holder (the recipient is always derived from the account profile, never from the parameters of the rule); sending a WhatsApp message based on a Meta-approved template; appending a row to the Google Sheet connected by the customer; updating the extracted variables and tags of the ongoing conversation; and an HTTP call to a public endpoint the customer configures. The notification transits through the SMTP provider listed in section 5, the WhatsApp message through Meta's WhatsApp Business Platform, the spreadsheet row through Google's services, while the HTTP call reaches the endpoint chosen by the customer; updating the conversation's variables entails no transmission outside the platform. TrueReply performs these actions as a documented instruction of the customer as Controller and determines neither their content nor their recipient. For each execution we retain the triggering event, the steps performed with a truncated summary of parameters and outcome, and any waits for a reply, for the periods stated in section 7. This processing concerns the identity of the contact and the state of the channels: it does not produce automated decisions producing legal effects or similarly significantly affecting the data subject within the meaning of Art. 22 GDPR.

Processing of outbound calls: outbound AI voice calls on behalf of the customer are delivered with compliance safeguards that the customer cannot disable: AI disclosure as the first sentence of every call, permitted time windows, use of the customer's real +39 number as caller ID (without spoofing), opt-out handling with an account-wide suppression list, and consent attestation at the time each list is imported.

AI classification and summarization: the transcribed text of calls and conversations may be processed by artificial intelligence models (Anthropic Claude) to classify opt-out requests and to generate summaries, solely for the purpose of providing the service.

5. Data processors and recipients

To provide the service, the Controller relies on the following sub-processors:

Provider Service Location Privacy Policy
Google Cloud / Firebase Hosting (including truereply.it), database, authentication, cloud functions, semantic search / embeddings (Vertex AI), encryption key management (Cloud KMS), writing to the Google Sheets connected by the customer and, where the email channel is activated, attachment storage EU (eur3) privacy.google.com
Stripe Inc. Payment processing, invoicing USA (SCC) stripe.com/privacy
Anthropic PBC Conversational AI processing (Claude): website chat, WhatsApp, and, if active, the email channel USA (SCC) anthropic.com/privacy
Telnyx LLC Telephony and voice calls USA (SCC) telnyx.com/privacy
Meta Platforms Ireland Ltd (WhatsApp Business Platform) WhatsApp messaging on the customer's number EU (Ireland) with US transfers (SCC) whatsapp.com/legal
Google (Vertex AI – Gemini) AI voice processing (call audio) EU (europe-west1) cloud.google.com/terms/data-processing-addendum
Google (Calendar API) Google Calendar integration (availability read and event creation, after OAuth consent) USA (SCC) policies.google.com/privacy
Brevo (Sendinblue) Email marketing and newsletter EU (France) brevo.com/privacy
Google (Analytics) Web traffic analysis USA (SCC) policies.google.com/privacy
Meta Platforms Remarketing and conversion analysis USA (SCC) facebook.com/privacy
Microsoft (Clarity) User behavior analysis USA (SCC) privacy.microsoft.com
SiteGround (SMTP server) Transactional email and system notifications (lead alerts, welcome, billing) EU siteground.com/privacy.htm

6. Data transfers outside the EU

Some of the sub-processors listed above are based in the United States. Data transfers to such parties take place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Art. 46.2.c GDPR, as well as the EU-US Data Privacy Framework where applicable.

The main database (Firestore) is hosted in the EU region (eur3 – europe-west) and data resides there permanently. Transmission to US-based AI providers occurs exclusively for the real-time processing of requests and does not entail the permanent retention of data by such providers.

7. Data retention period

  • Account data: retained for the entire duration of the contractual relationship and for 10 years thereafter, for tax and legal compliance
  • Chatbot conversations, including text chats, WhatsApp messages, email-channel conversations, and voice-call transcripts/metadata: retained for a maximum of 6 months from the last activity, after which they are automatically deleted. The customer (Controller) can connect their own Google Sheet to keep the full history without time limits in their own file. They are in any case removed upon account deletion
  • Email messages discarded by the automatic filter or recognized as non-conversational (if active): retained for the same period of 6 months as metadata only (sender, subject, date, and reason for discarding), without the message body
  • Email correspondence attachments (if active): they will be retained in the dedicated archive for a maximum of 6 months, aligned with the conversation they belong to, and removed together with it or upon account deletion
  • Access credentials of the connected email mailbox (if active): retained encrypted for as long as the connection remains active; deleted immediately upon disconnection of the mailbox and upon account deletion
  • Lead capture data: retained for the duration of the customer's subscription and accessible through the dashboard or Google Sheets
  • Call audio recordings: audio recording is active only for the Provider's demonstration number (demo bot) and is automatically deleted within a maximum of 90 days. For customers' calls (inbound and outbound) TrueReply processes and retains only transcripts and metadata, not the audio recording
  • Outbound campaign contact lists: retained for the duration of the customer's subscription and removed upon account deletion. Consent attestations (art. 130) are retained as proof of the legal basis, for as long as necessary to demonstrate its lawfulness
  • Opt-out and suppression lists: the voice-call suppression list is retained for the duration of the customer's subscription and is removed upon account deletion. The WhatsApp channel suppression list, which collects the opt-outs expressed by data subjects, is instead retained with no expiry and survives the deletion of the customer's account: retaining it ensures that a person who has asked not to be contacted again is not contacted again, not even following the closure of that account (Art. 130 of the Italian Privacy Code). The phone number is not retained in clear text: the list only records a non-reversible cryptographic digest of the contact detail, sufficient to recognise it if anyone attempted to contact that person again and unsuitable for recovering the number
  • Register of WhatsApp threads authorized by an advertisement: where an assistant is configured to answer only the WhatsApp conversations opened through a Click-to-WhatsApp advertisement, the service records every thread so authorized. This register is not an opt-out list: it is written for every authorized conversation, even where no opt-out has ever been expressed, and it serves to establish which conversations the assistant is authorized to answer and to give effect to any subsequent opt-out. It contains the data subject's phone number, the advertisement click identifier, and the headline and the URL of the advertisement the conversation originated from. It has no automatic expiry, but it is removed upon account deletion: before removal, any opt-outs expressed on those threads are carried over to the WhatsApp suppression list described in the previous point, so that deleting the register cannot cause the wish not to be contacted again to be lost. As of the date of this privacy policy, this configuration cannot be enabled by customers and is in use only on TrueReply's own WhatsApp number
  • Unified contact record: it has no automatic expiry and remains available for as long as the customer's account exists, the customer being its Controller; it is deleted upon account deletion. This is a deliberate choice: the contact record is the customer's own register of contacts, with a purpose of its own, distinct from conversation content, which remains subject to the 6-month limit. The register of proactive messages received by an individual contact is deleted together with the contact it refers to. The customer may also delete an individual contact at any time, in order to act upon a data subject's request: the deletion removes the contact, the contact details identifying them and the register of messages received, and removes the link to the contact record from the conversations and automation executions that referred to it (conversations remain subject to their own 6-month term and are deleted with the dedicated tool)
  • Automation execution data: the events that trigger them are retained for 30 days; executions, their steps, and waits for a reply for 90 days. The flow definitions configured by the customer and their versions have no automatic expiry and remain for as long as the customer keeps the account: deleting them from the dashboard archives them, retaining their versions as evidence of the configuration applied. Upon account deletion the definitions, their versions, the executions with their steps, the waits for a reply and the secrets registered for automations calling third-party APIs are removed by the automatic deletion procedure; the events that trigger the automations do not fall within it and delete themselves within 30 days by virtue of their own expiry
  • Log of relevant operations (audit): 24 months. It records the operator who performed the operation, their IP address, the action, the date and time, and details specific to each operation. It also records every transmission of data to the outside performed by the automations configured by the customer, with the destination and the outcome only and never the content transmitted: the address of the system called and the method of the HTTP call, without path, query parameters, headers, or request body; the Google Sheet and the destination tab, without the values of the row written; the recipient of the email notification. The recipients of WhatsApp sends and of email notifications appear in masked form; other data appear in full, in particular the phone number manually added to an opt-out list, the phone numbers the customer activates, deactivates, sets as call forwarding or uses as caller ID in campaigns, and the description of the consent source declared when importing campaign lists. The log survives account deletion because it is the evidence of compliance
  • Browsing data (GA4, Clarity, Meta Pixel): according to the retention policies of the respective providers (typically 14–26 months)
  • Newsletter data (Brevo): until consent is revoked by the data subject
  • Widget session data (localStorage): 30 minutes of inactivity (session); the visitor ID persists until the user manually clears browser data

8. Rights of the data subject

Pursuant to Articles 15–22 of the GDPR, the data subject has the right to:

  • Access: obtain confirmation of the existence of personal data concerning them and to receive it in an intelligible form
  • Rectification: obtain the correction of inaccurate data or the integration of incomplete data
  • Erasure: obtain the erasure of their personal data in the cases provided for by the GDPR
  • Restriction: obtain the restriction of processing in the cases provided for by the GDPR
  • Portability: receive their data in a structured, commonly used, and machine-readable format
  • Objection: object to the processing of their data for reasons related to their particular situation
  • Withdrawal of consent: withdraw at any time any consent given, without affecting the lawfulness of processing based on consent prior to withdrawal

To exercise their rights, the data subject may send a request to info@truereply.it. The Controller will respond within 30 days of receipt of the request. TrueReply account holders can also exercise, on a self-service basis from the dashboard (Settings section), the right to data portability and account deletion, with a 30-day grace period before permanent erasure. The self-service export produces a structured JSON file covering account data, the configuration of the assistants and their conversations (up to 5,000 per assistant, with an explicit indication of any truncation) and the unified contact record (up to 5,000 contacts, with the same truncation indication, in intelligible form even where it is stored encrypted). It does not cover the flow definitions and automation execution data, outbound campaigns with their lists and attestations, the opt-out lists, and the log of relevant operations: these data are provided upon written request to info@truereply.it, within the statutory time limits. Integration credentials and secrets are never included in the export.

The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

9. TrueReply's role in the processing of end users' data

TrueReply acts as a Data Processor on behalf of its customers (Data Controllers) with respect to the data of end users interacting with the chatbots, the inbound and outbound voice assistant, the WhatsApp channel and, where activated, the email channel, as well as with respect to the unified contact record and to the execution of the automations configured by the customer, including the transmission of data to the third-party systems the customer designates. The customer who installs the TrueReply chatbot on their website is responsible for informing their visitors about the processing of personal data via the chatbot, in compliance with the GDPR.

Likewise, the customer who connects their own mailbox to the service remains the Data Controller of the correspondence received in it and is required to inform their correspondents, pursuant to Articles 13 and 14 GDPR, that incoming messages are processed with the assistance of an artificial intelligence assistant and of an external data processor. TrueReply neither contacts nor informs such correspondents directly.

The relationship between the customer (Controller) and TrueReply (Processor) is governed by the Data Processing Addendum pursuant to Art. 28 GDPR, available at /dpa, which forms an integral part of the Terms and Conditions.

10. Google User Data (Google API Services)

TrueReply integrates with Google Calendar via the Google API Services, after the user's explicit consent through an OAuth 2.0 flow. This section describes which data we receive, how we use it, how we protect it, and how the user can revoke access at any time.

10.1 Scopes requested

Google scope Why we request it
openid Uniquely identify the Google account that authorized the connection.
https://www.googleapis.com/auth/userinfo.email Display the connected Google account's email in the TrueReply dashboard, so the user always knows which account is in use.
https://www.googleapis.com/auth/calendar.readonly List the user's calendars so the customer can pick which calendar to enable for bookings. We do not read events with this scope.
https://www.googleapis.com/auth/calendar.events Read free/busy availability of the selected calendar to propose open slots to end users via the chatbot, and create new events when a booking is confirmed. We only read event details when the chatbot needs to confirm a previously booked appointment.

We only request the minimum scope strictly necessary for the functionality. We do not request the full calendar scope nor calendar.settings.

10.2 How we use Google data

  • Availability lookup: when a website visitor chats with the customer's bot and asks for an appointment, TrueReply queries the selected calendar's freeBusy endpoint in real time to compute open slots consistent with the customer's configured working hours. We do not persist free/busy data.
  • Event creation: upon appointment confirmation, TrueReply creates an event on the customer's calendar via events.insert. The event's content (title, description, attendees) is derived exclusively from the visitor's input and from the customer's configured template.
  • Event read-back: if the chatbot needs to confirm a previously booked appointment, we call events.get with the event ID.

We do not use Google data for advertising purposes, we do not sell it, we do not share it with third parties, and we do not use it to train machine-learning models.

10.3 Google data retention and protection

  • OAuth refresh tokens are encrypted at rest via envelope encryption: AES-256-GCM with a random Data Encryption Key per token, itself wrapped with Google Cloud KMS (keyring truereply-secrets, key oauth-tokens, 90-day rotation). Only our backend Cloud Function holds the IAM permission to decrypt the DEK.
  • Access tokens are cached only for their validity window (typically one hour) and never persisted longer than necessary.
  • All Google data in transit travels over TLS 1.2+ (HTTPS) only.
  • Events we create and slots we read are not persisted in our database: they live only in the user's Google Calendar.
  • Access to Google data is restricted to TrueReply's backend Cloud Function (europe-west1). The voice service (Cloud Run) never holds tokens nor decrypts them: it calls authenticated internal endpoints that return only the aggregated operation result.

10.4 Limited Use disclosure

TrueReply's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

10.5 Revocation and deletion

The user can revoke access to their Google data at any time:

  • from the TrueReply dashboard: Integrations → Google Calendar → Disconnect (revokes the refresh token on Google's side and deletes the calendarConnector record from Firestore).
  • directly from Google: myaccount.google.com/permissions.

Upon disconnection, the encrypted refresh token is removed from our Firestore within seconds. Residual access tokens expire automatically within one hour.

10.6 Contact for Google data

Questions about Google data handling: info@truereply.it.

11. Security measures

The Controller adopts technical and organizational measures appropriate to ensure a level of security commensurate with the risk, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest (Firebase/Google Cloud encryption)
  • Authentication via Firebase Authentication with cryptographic hashing of passwords
  • Payment processing via Stripe (PCI DSS Level 1 certified), with no transit or storage of card data on TrueReply servers
  • Tenant data isolation: each customer accesses only their own data through Firestore security rules
  • Application-level encryption, via envelope encryption with a dedicated Google Cloud KMS key, of the highest-impact secrets entrusted by the customer for the operation of integrations: the Google Calendar OAuth refresh token, the WhatsApp Business access token, and the secrets the customer registers for automations towards third-party APIs. The cleartext value of such secrets is never returned by any interface of the service; automation secrets are additionally bound to the hosts the customer authorizes at registration time
  • Field-level encryption of conversation content, of the identifying fields of the contact record and of automation execution data (execution context, truncated summary of each step's parameters and outcome, error message), on a separate Google Cloud KMS key, for the assistants the customer has declared as intended for the processing of special categories of data
  • Controls on the destinations of the HTTP calls the customer configures in automations: internal, private, and reserved network addresses are blocked, and the connection is made only to the verified IP address
  • Rate limiting on public endpoints to protect against abuse
  • Widget in Shadow DOM for isolation from the hosting page context

12. Changes to this policy

The Controller reserves the right to make changes to this policy at any time. Changes will be published on this page with an indication of the last update date. Users are encouraged to consult this page periodically.

13. Contact

For any questions regarding this policy or the processing of personal data, you can contact the Controller by writing to: info@truereply.it