GDPR Compliance Summary

Last Updated: January 25, 2026

1. DATA CONTROLLER

Data Controller:

  • Name: David Tsoifn
  • Business Registration Number (IČO): 57265224
  • Tax Identification Number (DIČ): 3122353432
  • VAT Number: SK3122353432
  • Address: Vlčie hrdlo 1887/81, 821 07 Bratislava - Ružinov, Slovakia
  • Email: support@replaysenseai.com

2. YOUR GDPR RIGHTS

2.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether your personal data is being processed and to receive a copy of the data we hold about you.

How to exercise: Email support@replaysenseai.com with your request. We will respond within 30 days.

2.2 Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data.

How to exercise: Contact us with the corrected information, and we will update our records within 30 days.

2.3 Right to Erasure (Article 17) - 'Right to be Forgotten'

You have the right to request deletion of your personal data under certain circumstances.

When applicable:

  • Data is no longer necessary for the original purpose
  • You withdraw your consent
  • You object to processing
  • Data was unlawfully processed

How to exercise: Email support@replaysenseai.com requesting erasure. We will delete your data within 24 hours of account disconnection.

Exceptions: We may retain data if required by law (tax, accounting records up to 7 years).

2.4 Right to Restrict Processing (Article 18)

You have the right to request that we limit how we process your data.

How to exercise: Email support@replaysenseai.com with details of what processing you want restricted. We will comply within 30 days.

2.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly-used, machine-readable format and to transmit it to another controller.

How to exercise: Email support@replaysenseai.com requesting your data in portable format (CSV, JSON, etc.). We will provide it within 30 days.

2.6 Right to Object (Article 21)

You have the right to object to processing of your data on grounds relating to your particular situation.

How to exercise: Email support@replaysenseai.com with your objection. We will stop processing within 30 days unless we have compelling legitimate grounds.

2.7 Right to Withdraw Consent (Article 7)

If we are processing your data based on consent, you have the right to withdraw that consent at any time.

How to exercise: Email support@replaysenseai.com to withdraw consent. Withdrawal does not affect the lawfulness of processing before withdrawal.

2.8 Right to Lodge a Complaint

If you believe we are violating your GDPR rights, you have the right to lodge a complaint with a supervisory authority (data protection authority) in your country.

Slovakia Data Protection Authority: https://www.dataprotection.sk/

3. LEGAL BASIS FOR DATA PROCESSING

We process your data based on the following legal bases under GDPR Article 6:

3.1 Contract (Article 6(1)(b))

Processing is necessary to provide the Service and fulfill our contractual obligations to you.

Data processed: Email, connected account credentials, conversation extracts

3.2 Consent (Article 6(1)(a))

Processing is based on your explicit consent.

Data processed: Analytics data (PostHog, Google Analytics), marketing communications

3.3 Legal Obligation (Article 6(1)(c))

Processing is necessary to comply with legal obligations.

Data processed: Payment records (tax/accounting purposes for 7 years)

3.4 Legitimate Interest (Article 6(1)(f))

Processing is necessary for our legitimate interests.

Data processed: Service improvement, security, fraud prevention

4. DATA RETENTION & DELETION

4.1 Retention Policy

  • Social Media Credentials & Conversation Data: Deleted within 24 hours of account disconnection
  • Email & Account Settings: Retained until you request deletion
  • Analytics Data: Retained for 90 days, then anonymized
  • Payment Records: Retained for 7 years (legal requirement)
  • No backups: Deleted data is not retained in backups

4.2 Automatic Deletion

Your connected account data and conversation extracts are automatically deleted within 24 hours of:

  • Disconnecting your social media account from our Service
  • Deleting your ReplaySense AI account

5. DATA TRANSFERS OUTSIDE EU

If you access ReplaySense AI from outside the EU, your data may be transferred to and processed in the EU.

Safeguards: We implement appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) where applicable
  • Encrypted transmission (HTTPS/TLS)
  • Secure API authentication

6. DATA PROCESSORS

We use the following data processors (third parties that process data on our behalf):

ProcessorPurposeLocationPrivacy Policy
StripePayment processingUS/EUhttps://stripe.com/privacy
PostHogAnalyticsUS/EUhttps://posthog.com/privacy
OpenAIAI processingUShttps://openai.com/privacy-policy
DeepSeekAI processingChinahttps://www.deepseek.com/privacy
MetaAPI accessUS/EUhttps://www.facebook.com/privacy/explanation
GoogleAnalyticsUShttps://policies.google.com/privacy

7. DATA SUBJECT RIGHTS REQUESTS

7.1 How to Submit a Request

All GDPR rights requests should be sent to:

Email: support@replaysenseai.com
Subject: "GDPR Rights Request - [Your Name]"

Include:

  • Your full name
  • Email address used for account
  • Specific right you are exercising (access, deletion, portability, etc.)
  • Any supporting documents

7.2 Response Timeline

  • Confirmation: We will acknowledge your request within 3 business days
  • Response: We will fulfill your request within 30 days (extendable by 60 additional days for complex requests)
  • Proof of Identity: We may request proof of identity to verify your request

7.3 Verification

We will verify your identity before fulfilling data subject requests to ensure we are releasing data to the rightful data subject.

8. CHILDREN'S DATA (Article 8)

ReplaySense AI is not intended for children under 16 (or the age of digital consent in your country). We do not knowingly collect data from children.

If we discover we have collected data from someone under 16, we will delete it immediately.

9. PRIVACY BY DESIGN & DEFAULT (Article 25)

We implement privacy by design and default by:

  • Collecting only necessary data
  • Automatic deletion of data upon account disconnection
  • Encrypted transmission (HTTPS/TLS)
  • Secure API authentication
  • No sharing with third parties (except as specified)

10. DATA PROTECTION IMPACT ASSESSMENT (DPIA)

We have conducted a Data Protection Impact Assessment for our Service and determined that we implement appropriate technical and organizational measures.

11. INTERNATIONAL DATA AGREEMENTS

For data transfers outside the EU, we rely on:

  • Standard Contractual Clauses (SCCs) where applicable
  • Adequacy decisions recognized by the EU
  • Your explicit consent

12. COMPLAINTS & DISPUTE RESOLUTION

12.1 Internal Complaint Process

If you have a complaint about our data processing:

  1. Contact us: Email support@replaysenseai.com with details
  2. Investigation: We will investigate within 30 days
  3. Response: We will provide our findings and any remedial actions

12.2 Supervisory Authority

If we cannot resolve your complaint, you have the right to lodge a complaint with your national data protection authority:

Slovakia Data Protection Authority
- Website: https://www.dataprotection.sk/
- Email: uoou@uoou.sk
- Phone: +421 2 5098 5600

13. UPDATES TO THIS GDPR SUMMARY

This GDPR summary may be updated periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes via email.

14. QUESTIONS & CONTACT

For GDPR-related questions:

Email: support@replaysenseai.com
Response time: Within 10 business days for GDPR-related inquiries