Legal & Compliance Room Updated 19 September 2026 Ask a question

Répondia Legal & Compliance Room

Final texts, version 2.0 of 19 September 2026

Document register published at legal.repondia.com.

Reading convention. The documents below describe how the service operates and the standing commitments of Répondia. The terms negotiated with each customer (plan, conversation cap, price, discount, options, payment term, trial duration and commitment duration) appear exclusively in the Order Form signed by the customer. No amount, threshold or commercial duration appears in this register. In the event of any discrepancy, the Order Form and the signed contract prevail.

Courtesy translation. Only the French version is binding.

01 CORPORATE & WEBSITE

1. Legal Notice

Courtesy translation. Only the French version is binding.

Publisher

The website repondia.com and the Répondia platform are published by Répondia SAS, a French simplified joint-stock company (société par actions simplifiée) with a share capital of EUR 1,000, registered with the Nice Trade and Companies Register under number 983 585 290, whose registered office is at 16 bis boulevard de Montréal, 06200 Nice, France.

Intra-Community VAT number: FR 71 983 585 290. APE code: 62.02A, computer systems and software consultancy.

Publication director

Publication director: Natan Darhi, President. Contact: natan.darhi@repondia.com

Hosting

The marketing website repondia.com is hosted by Framer B.V., Amsterdam, the Netherlands.

The application platform is hosted by Google Cloud EMEA Limited, in the europe-west1 region (Saint-Ghislain, Belgium), and by Supabase Inc. on Amazon Web Services infrastructure in the eu-west-3 region (Paris, France).

Intellectual property

All content of the website and the platform (the Répondia trade mark, logos, texts, interfaces, source code, documentation) is the exclusive property of Répondia SAS or is licensed to it. Any reproduction or representation, in whole or in part, without prior written authorisation is prohibited.

Consumer mediation

As Répondia deals exclusively with business customers, the consumer mediation scheme does not apply.

2. General Terms of Service

Courtesy translation. Only the French version is binding.

Version in force, published at legal.repondia.com. The customer acknowledges having read these terms and having accepted them without reservation by the sole fact of signing the Order Form.

Article 1Purpose

These general terms govern the provision by Répondia SAS of the Répondia solution, a software service delivered in SaaS mode that enables the missed calls of a hotel or restaurant establishment to be taken up by a conversational agent operating on WhatsApp and on the other subscribed channels, together with the associated configuration, integration and support services.

They apply to every business customer and prevail over the customer's own purchasing terms, unless an express derogation has been accepted in writing.

Article 2Definitions

Order Form: document signed by the customer, specifying the establishments equipped, the plans subscribed, the options, the financial terms and the duration.

Establishment: point of sale or site operated by the customer and equipped with the solution.

Organisation: all the establishments of a single customer within the platform.

Conversation: continuous exchange with one and the same person on a given channel, counted against the plan.

Request: inbox item grouping a missed call and the exchanges that follow from it.

Assistant: automated conversational agent provided by Répondia.

Article 3Formation of the contract

The contract is formed upon signature of the Order Form sent to the customer by e-mail. It consists, in decreasing order of priority, of the Order Form, these general terms and their annexes, including the Data Processing Agreement, the service levels policy and the Acceptable Use Policy.

Each establishment is the subject of a separate line in the Order Form, including within the same organisation.

Article 4Description of the service

The service relies on conditional call forwarding, activated by the customer with its telephone operator, to a number provided by Répondia. Répondia does not sit on the establishment's line and receives only the calls that are not answered.

The caller is informed of the automated nature of the exchange, then invited to continue by message. The assistant handles the request solely on the basis of the information entered by the establishment and of the booking tools it has connected.

The channels, modules and integrations actually opened to the establishment are those set out in the Order Form.

Article 5Obligations of Répondia

Répondia is bound by a best-efforts obligation (obligation de moyens). It undertakes to provide the service in accordance with the documentation in force, to keep the platform in operational condition, to provide support under the conditions laid down in the service levels policy, and to process personal data in accordance with the Data Processing Agreement.

Article 6Obligations of the customer

The customer warrants that it holds the necessary rights and legal bases over the data it entrusts to Répondia.

It enters and keeps up to date the establishment information that feeds the assistant: opening hours, closures, booking rules, modification and cancellation conditions, allergens, frequently asked questions.

It activates and maintains call forwarding with its operator, appoints a reachable operational contact, and ensures that use complies with the Acceptable Use Policy and with the rules laid down by Meta for the WhatsApp Business platform.

The customer remains responsible for the replies given by its staff and for the accuracy of the information passed to the assistant.

Article 7Plans and conversation cap

7.1 Each establishment is equipped according to the plan set out in the Order Form. The plan determines the monthly conversation cap and the modules included.

7.2 A conversation is counted per person and per channel, over a calendar month. Successive messages from the same person within the same request constitute a single conversation.

7.3 Consumption may be consulted by the customer at any time in the statistics of its establishment. Répondia informs the customer when the cap is being approached.

7.4 Beyond the monthly cap, conversations continue to be handled without interruption of the service. The next plan up then applies, under the conditions set out in the Order Form. The customer is informed without delay and may, if it so wishes, return to the previous plan for the following month.

Article 8Price and payment

8.1 The prices, discounts and options are those set out in the Order Form. They are stated exclusive of tax.

8.2 Invoices are issued according to the frequency and payment method chosen in the Order Form, and are payable within the term stipulated therein.

8.3 Any late payment gives rise automatically, without prior formal notice, to penalties calculated at the European Central Bank's key interest rate plus ten points, together with the fixed compensation of EUR 40 for recovery costs provided for in Article L.441-10 of the French Commercial Code.

8.4 Where an invoice remains unpaid after a period of sixty days following its due date, and has gone unanswered despite the reminders sent to the customer, Répondia may suspend access to the service after written notification. Suspension does not release the customer from payment of the sums due. The service is restored as soon as possible once the situation has been regularised.

8.5 The messaging rates applied by Meta for the delivery of messages are liable to change independently of Répondia's will. Any passing-on of an operator rate change is notified to the customer with sixty days' notice. A customer that does not accept it may terminate the scope concerned without penalty, by written notification received before the date on which the new pricing takes effect.

Article 9Term, trial, renewal and termination

9.1 The contract begins with a trial period, the duration and pricing conditions of which are set out in the Order Form. During this period, the customer may terminate at any time by simple e-mail, without notice or penalty.

9.2 Unless termination is notified before the end of the trial period, the contract continues for the commitment period set out in the Order Form, on the plan determined by mutual agreement between the parties.

9.3 At the end of the commitment period, the contract is subject to automatic renewal for periods of the same duration, unless either party gives notice of non-renewal within the notice period stipulated in the Order Form.

9.4 Either party may terminate the contract for serious breach by the other, after formal notice has remained without effect for thirty days.

9.5 Termination entails the closure of access, the return of data under the conditions laid down in the deletion policy, and payment of the sums remaining due for the current commitment period.

Article 10Service levels

The availability and support commitments are set out in the service levels policy, annexed hereto and published at legal.repondia.com.

Article 11Personal data

The processing of personal data is governed by the Data Processing Agreement annexed hereto. The customer acts as controller, Répondia as processor.

Article 12Intellectual property and data

The customer retains ownership of its data and of the content relating to its establishments. Répondia retains ownership of the platform, its code, its interfaces and its developments, including enhancements arising from the customer's suggestions.

A non-exclusive, non-transferable licence to use is granted to the customer for the term of the contract and solely for the needs of its business.

Article 13Confidentiality

Each party undertakes not to disclose the other's confidential information, for the term of the contract and for three years after its end. Confidential information includes in particular the financial terms, operating data and information relating to customers.

Article 14Liability

Répondia's total liability, on all grounds combined, is capped at the sums actually paid by the customer during the twelve months preceding the event giving rise to liability.

Indirect damage, loss of revenue, loss of bookings and reputational harm are excluded.

Répondia is not liable for unavailability attributable to Meta, to the WhatsApp Business Solution Provider, to the customer's telephone operator or to the connected booking software, nor for an incorrect configuration supplied by the customer.

The following are not subject to any limitation: gross negligence or wilful misconduct, personal injury, and the obligations of confidentiality and of personal data protection.

Article 15Commercial reference

Répondia may cite the customer's name and logo as a commercial reference, unless the customer expresses its disagreement clearly and in writing, at any time. Such refusal takes effect within thirty days across all of Répondia's materials.

Article 16Force majeure

Neither party may be held liable for a breach resulting from an event of force majeure within the meaning of Article 1218 of the French Civil Code. If the event continues beyond sixty days, either party may terminate the contract without compensation.

Article 17Assignment

The contract may not be assigned without the prior written consent of the other party. By way of exception, Répondia may assign it to a company of its group or in the context of a restructuring operation, by informing the customer.

Article 18Amendment of the general terms

Répondia may amend these terms. Any substantial amendment is notified to the customer thirty days before it takes effect. A customer that does not accept it may terminate without penalty within that period.

Article 19Governing law and jurisdiction

These terms are governed by French law. Any dispute falls within the exclusive jurisdiction of the Commercial Court of Nice (Tribunal de commerce de Nice).

3. Terms of Use

Courtesy translation. Only the French version is binding.

Access

Access to the Répondia platform is reserved for the users designated by the customer. Each account is strictly personal; sharing credentials is prohibited and constitutes a breach of contract.

The customer is responsible for managing its users, the rights it grants them and the actions carried out from their accounts.

Roles and rights

The platform distinguishes two statuses.

Organisation owner, one per organisation. The owner holds all rights over every establishment of the organisation, including access to the conversations of each of them.

Establishment member, a member has access only to the establishments to which they have been invited. Their rights are granted individually from among seventeen distinct permissions covering the handling of requests, replying on each channel, channel configuration, reviews, statistics, the establishment profile, connection to booking software, member management, automations and upselling rules. Where no permission has been granted, access is read-only.

A user is either an owner or a member; never both within the same organisation. Any attempt to access an establishment outside the assigned scope is rejected by the platform.

Access to billing data is read-only on the customer side; changes are made by Répondia.

Authentication

Authentication is performed by identifier and password, or by Google sign-in. The password contains at least eight characters, including one upper-case letter, one lower-case letter, one digit and one special character.

Two-factor authentication is available to customer users and mandatory for Répondia's internal accounts holding extended rights.

The session token is valid for one hour and renewed automatically. The session is closed after thirty days of inactivity, and in any event at the end of ninety days.

Expected use

The user undertakes not to circumvent the technical protection measures, not to carry out bulk extraction of data by automated means outside the interfaces provided, not to use the service for unsolicited mass marketing, and to report without delay any suspicion that an account has been compromised.

Availability and changes

The service is provided on a continuous-improvement basis. Répondia may change the features, provided that it does not remove any substantial function during the subscription. Planned interruptions are notified in accordance with the service levels policy.

Suspension

Répondia may suspend an access in the event of a proven threat to the security of the platform or of other customers, of use contrary to the Acceptable Use Policy, or of non-payment under the conditions laid down in Article 8.4 of the general terms. Suspension is preceded by written notification, except where there is an immediate security risk.

4. Privacy Policy

Courtesy translation. Only the French version is binding.

This policy covers the processing operations for which Répondia acts as controller: website visitors, prospects, job applicants and platform users. The data of the establishments' end customers are processed by Répondia as processor, on behalf of the establishment and under its responsibility; they fall under the Data Processing Agreement and the privacy policy of that establishment.

Controller

Répondia SAS, RCS Nice 983 585 290, 16 bis boulevard de Montréal, 06200 Nice, France. Data protection contact: legal@repondia.com

Répondia does not fall within the cases in which the appointment of a data protection officer is mandatory. A data protection lead is appointed internally and can be reached at that address.

Processing operations, purposes and legal bases

Purpose Data processed Legal basis Retention
Reply to a demonstration or contact request Identity, company, position, business contact details Pre-contractual measures 3 years from the last contact
Commercial prospecting of business professionals Business contact details, company identified during a visit to the website Legitimate interest 3 years from the last contact
Management of platform user accounts Name, business e-mail address, role, permissions Performance of the contract Term of the contract, then 30 days
Logging of access and of sensitive actions User identifier, action, target, IP address, timestamp Legitimate interest : security 1 year
Technical logging of requests IP address, method, path, status, duration Legitimate interest : security 30 days
Invoicing and accounting Billing data Legal obligation 10 years
Audience measurement of the website and the application Browsing identifiers, usage events Consent 13 months
Management of job applications Data in the application file Pre-contractual measures 2 years from the last contact
Personnel management and payroll HR data Legal obligation Statutory periods

Recipients

The data are accessible to Répondia's authorised staff and to its processors, which are contractually bound by equivalent confidentiality and security obligations. The list of processors is published in this register.

No data are sold, rented or transferred to third parties for commercial purposes.

Location

Hosting and production processing are located in the European Union. Residual transfers are described in the international transfer policy.

Your rights

Every person has the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set directives regarding what happens to their data after their death.

These rights are exercised at legal@repondia.com. A reply is given within one month.

Any person may lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

5. Cookie Policy

Courtesy translation. Only the French version is binding.

This policy describes the trackers placed when browsing repondia.com, the application app.repondia.com and via the conversation widget installed on the websites of customer establishments.

No tracker that is not strictly necessary is placed before consent has been obtained.

Website repondia.com

Tracker Issuer Purpose Duration Consent
_ga Google Analytics 4, via Google Tag Manager Audience measurement 13 months Required
_fbp Meta Pixel, via Google Tag Manager Measurement of advertising campaigns 3 months Required
Company identification tracker Lemlist (lemlist SAS, France) Identification of the companies visiting the website, for business prospecting purposes Session Required
Framer audience measurement Framer B.V. Cookieless traffic statistics - Exempt
Calendly cookies Calendly LLC Appointment scheduling, placed when the module is opened Variable Required

Application app.repondia.com

Tracker Issuer Purpose Duration Consent
ph_* PostHog (European Union instance) Product usage analytics 1 year Required
Session token Répondia / Supabase Keeping the authenticated session alive Session Exempt
Facebook SDK Meta Connection of the WhatsApp Business account, loaded only on the dedicated screen Session Necessary for the service requested

Conversation widget

Tracker Issuer Purpose Duration Consent
repondia_wc_session Répondia (first party) Continuity of the conversation started by the visitor 365 days Exempt
Turnstile Cloudflare Protection against bots Session Exempt

Consent may be withdrawn at any time, as simply as it was given, through the cookie management link in the footer.

6. Cookie Consent Management Policy

Courtesy translation. Only the French version is binding.

Principles applied

  • Refusing is as simple as accepting: both actions are accessible at the same level, from the first screen.
  • No tracker subject to consent is placed before a positive action by the user.
  • Continuing to browse does not amount to consent.
  • The choice is kept for six months, then requested again. A refusal is not requested again before that period has expired.

Mechanisms

On the website repondia.com, consent is collected through Framer's built-in banner, linked to Google's consent mode via Google Tag Manager. The Google Analytics, Meta Pixel and Lemlist tags fire only after acceptance.

On the application app.repondia.com, a banner offers acceptance or refusal. PostHog is loaded only after agreement, and proof of consent is recorded server-side.

Proof of consent

For the application, each choice is recorded with the user's identifier, the decision, the banner version and the timestamp.

For the marketing website, the visitor's choice is kept by their browser. A timestamped server-side register, hosted in the European Union, is being rolled out in order to provide enforceable proof.

Review

The list of trackers is reviewed at every production release affecting the website or the application, and at least once a year. Person responsible: Natan Darhi.

02 GDPR / DATA PRIVACY

7. Data Processing Agreement

Courtesy translation. Only the French version is binding.

Status of the parties

The customer (an establishment or hotel group) acts as controller. Répondia acts as processor within the meaning of Article 28 of the General Data Protection Regulation (GDPR), and processes the data only on documented instructions from the customer, acceptance of the contract and its annexes constituting the initial instruction.

This status also applies vis-à-vis Meta: the WhatsApp Business account is created in the business space of the establishment, which remains its holder. Répondia and the Business Solution Provider have technical access to it, which the establishment may revoke at any time.

Annex 1Description of the processing

Item Content
Subject matter Taking up missed calls and managing the customer relationship through messaging assisted by artificial intelligence
Duration Term of the contract, followed by the return and deletion period
Nature of the operations Collection, recording, organisation, consultation, transcription, disclosure, storage, erasure
Purposes Making and modifying bookings, replying to information requests, handover to the establishment, requesting and replying to reviews, supporting the customer journey, improving the quality of the assistant's replies
Data subjects Customers and prospects of the establishment who have called or exchanged messages; platform users designated by the establishment
Categories of data Telephone number, name, e-mail address, social messaging identifier, content of messages, voice recordings and their transcriptions, booking history and preferences, timestamps, call metadata, allergies and diets volunteered spontaneously
Special categories No special category of data is requested, required or inferred

Processing of dietary information

Where a person spontaneously communicates an allergy or a diet in the context of a booking, that information is processed as a simple item of service-performance data, passed to the establishment for the purposes of welcoming the guest. It is not subject to any enrichment, any profiling or any reuse for other purposes.

Improvement of service quality

The customer expressly authorises Répondia to consult conversations for the sole purposes of improving the quality of the assistant's replies and the performance of the service.

This activity is strictly regulated: it is reserved for Répondia's two chief technical officers, is carried out within the internal tools and the monitoring traces, and may involve replaying a conversation in a test environment without any message being sent to the data subject. It involves no export outside Répondia's tools and no model training or fine-tuning. Only the assistant's instructions and configuration rules are modified.

Questions the assistant was unable to answer are proposed to the establishment to enrich its knowledge base; the establishment validates them.

Commitments of Répondia

Confidentiality. Staff with access to the data are bound by a contractual obligation of confidentiality.

Security. Répondia implements the measures described in the technical and organisational measures, annexed to this agreement.

Sub-processing. The customer gives a general authorisation to engage sub-processors, an up-to-date list of which is published. Any addition or replacement is notified thirty days before it takes effect. The customer has a right of reasoned objection; failing agreement, it may terminate the scope concerned without penalty.

Assistance. Répondia assists the customer with the exercise of data subjects' rights, with carrying out impact assessments and with the notification of personal data breaches.

Personal data breach. Répondia notifies the customer of any breach affecting its scope within forty-eight hours of the incident being classified, and provides it with the information needed for its own notification to the supervisory authority.

Audit. Répondia makes its compliance documentation available to the customer. An on-site audit may be organised once a year, on thirty days' notice, at the customer's expense.

Fate of the data. At the end of the contract, an export of contacts is available on a self-service basis in the application; the extraction of requests, conversations and bookings is carried out by Répondia at the customer's request and delivered before deletion. The data are deleted within thirty days following the end of the contract. Residual copies disappear through the automatic rotation of backups within seven days and of monitoring traces within fourteen days. A certificate of deletion is issued on request.

8. Record of Processing Activities, Répondia as controller

Courtesy translation. Only the French version is binding.

Record kept under Article 30(1) of the GDPR. Location of processing: European Union. Person responsible for the record: Natan Darhi, natan.darhi@repondia.com.

No. Processing Purpose Legal basis Data subjects Retention
R1 Prospecting and commercial relationship Business development Legitimate interest Business contacts 3 years without contact
R2 Customer management and invoicing Performance of the contract Contract and legal obligation Customer contacts Term of the contract, then 10 years for accounting
R3 Platform user accounts Provision of access Performance of the contract Staff of the establishments Term of the contract, then 30 days
R4 Audit log of access and sensitive actions Security and traceability Legitimate interest Platform users 1 year
R5 Technical logs of the platform Security and operations Legitimate interest Users and visitors 30 days
R6 Audience measurement of the website and the application Improvement of the interfaces Consent Visitors and users 13 months
R7 Management of job applications Recruitment Pre-contractual measures Applicants 2 years after the last contact
R8 Personnel management and payroll Employer obligations Legal obligation Employees and contractors Statutory periods

9. Record of Processing Activities, Répondia as processor

Courtesy translation. Only the French version is binding.

Record kept under Article 30(2) of the GDPR, on behalf of each customer establishment acting as controller.

No. Processing Categories of data Sub-processors Location
S1 Receipt of the missed call, announcement and recording of the voice message Calling number, timestamp, voice recording Twilio Ireland Limited French numbers; call logs in the United States
S2 Transcription and analysis of the voice message Voice recording, transcription Microsoft Ireland Operations Limited (Azure OpenAI) European Union
S3 Conversation assisted by artificial intelligence Content of messages, name, e-mail address, telephone, establishment context Google Cloud EMEA Limited (Vertex AI), Microsoft Ireland Operations Limited European Union
S4 Delivery of WhatsApp and Instagram messages Number, social identifier, content of messages Meta Platforms Ireland Limited, Twilio Ireland Limited Ireland, United States
S5 Creation and modification of bookings Name, telephone, date, party size, notes Booking software connected by the establishment Depending on the vendor
S6 Establishment profile and knowledge base Establishment data Google Cloud EMEA Limited, Supabase Inc. European Union
S7 Inbox, statistics and dashboard History of requests and bookings Google Cloud EMEA Limited, Supabase Inc. European Union
S8 Google reviews and Instagram comments Name or pseudonym of the author, text of the review Zernio Software SL, Google, Meta European Union, United States
S9 Mobile application notifications Excerpt of the message, without name or number Google (Firebase), Apple (APNs) International delivery
S10 Monitoring and improvement of reply quality Conversation traces LangChain Inc. (European Union instance) European Union
S11 Voicemail received by e-mail Voice recording, calling number Google (Workspace) European Union

10. List of Sub-processors

Courtesy translation. Only the French version is binding.

List published at legal.repondia.com. Any change is notified to customers thirty days before it takes effect, by e-mail to the designated compliance contact. The customer has a right of reasoned objection.

Provider Contracting entity Role Location Framework
Google Cloud Google Cloud EMEA Limited (Ireland) Application hosting, internal messaging, logs, secrets, Vertex AI models europe-west1 (Belgium) Cloud Data Processing Addendum accepted
Supabase Supabase Inc. (United States) Database, file storage, authentication eu-west-3 (Paris) DPA incorporated into the terms, Standard Contractual Clauses
Microsoft Microsoft Ireland Operations Limited Transcription, analysis and generation of replies (Azure OpenAI) European Union Products and Services DPA
Meta Meta Platforms Ireland Limited WhatsApp and Instagram delivery Ireland, United States Data Processing Terms, Standard Contractual Clauses
Twilio Twilio Ireland Limited Numbers, calls, voicemail, WhatsApp gateway French numbers, logs in the United States DPA and Standard Contractual Clauses
LangSmith LangChain Inc. (United States) Agent monitoring traces European Union instance Signed DPA, Standard Contractual Clauses
PostHog PostHog Inc. (United States) Application usage analytics European Union instance DPA being signed
Brevo Sendinblue SAS (France) Transactional e-mails France DPA incorporated into the terms
Cloudflare Cloudflare Inc. (United States) Anti-bot protection of the widget Global network DPA incorporated into the terms, Standard Contractual Clauses
Zernio Zernio Software SL (Spain) Google reviews management European Union, logs in the United States DPA being obtained
Apple Apple Distribution International (Ireland) Notifications for iOS devices International delivery Apple developer terms
Google Workspace Google Cloud EMEA Limited (Ireland) Receipt of voice messages forwarded by e-mail European Union Cloud Data Processing Addendum
GitLab GitLab Inc. (United States) Source code hosting and continuous integration United States No end-customer data
Discord Discord Inc. (United States) Technical alerts intended for the team United States No conversation content transmitted

The booking software connected by the establishment (Zenchef, TheFork, SevenRooms, Overfull) are not processors of Répondia. They are contracted directly by the establishment, which remains responsible for them.

11. Data Retention Policy

Courtesy translation. Only the French version is binding.

Principle

Each category of data has a defined retention period, applied automatically by a daily scheduled task and not by manual intervention. Each run records its date and the number of items deleted per type; this trace contains no deleted data.

Periods applied

Category Period Starting point Outcome at expiry
Content of messages, transcriptions, summaries 24 months Receipt of the message Deletion
Voice recordings and attached media 24 months Receipt Deletion
Request without content (date, channel, status) Term of the contract - Deletion
Bookings and aggregated statistics Term of the contract - Deletion
Contacts (name, number, social identifier) Term of the contract, then 30 days End of the contract Deletion
User accounts Term of the contract, then 30 days End of the contract Deletion
Access audit log 1 year Event Deletion
Technical request logs 30 days Request Deletion
Authentication logs 7 days Sign-in Deletion
Agent monitoring traces 14 days Execution Deletion
Database backups 7 days Creation Automatic rotation
Voice messages received by e-mail Deleted after processing, within 30 days at the latest Receipt Deletion
Billing data 10 years Close of the financial year Statutory archiving

Justification for the twenty-four-month period

This period corresponds to the loyalty cycle observed in the hotel and restaurant sector. It makes it possible to recognise a customer from one season to the next and to retrieve the history of a disputed booking, without keeping exchanges beyond their operational usefulness.

A customer may contractually request a shorter period, applied to its entire scope.

12. Data Deletion Policy

Courtesy translation. Only the French version is binding.

End of contract

An export of contacts is available on a self-service basis in the application. The extraction of requests, conversations and bookings is carried out by Répondia at the customer's request and delivered before deletion.

The establishment's data (contacts, user accounts, conversations, files) are deleted within thirty days following the end of the contract.

Erasure request from an individual

The deletion of a person is carried out from the application, by a member holding the corresponding right. It is final and cascades to the associated requests, conversations, messages, bookings and logs, as well as to audio and media files, including the recordings held by the telephony provider. The audit log keeps a trace of the operation.

Where a request is addressed directly to Répondia, it is forwarded without delay to the establishment, as controller, and the person is informed accordingly.

Residual copies

After deletion, residual copies disappear through automatic rotation: database backups within seven days, monitoring traces within fourteen days. Test environments contain anonymised data only.

Limits

Deletion does not cover the data passed to the establishment's booking software, which remain under its sole control, nor the data kept under a legal obligation, in particular an accounting obligation.

13. Data Subject Rights Handling Procedure

Courtesy translation. Only the French version is binding.

Allocation of roles

The data subjects of the service are the customers of the establishments. Their legitimate point of contact is the establishment, as controller. Répondia makes no assessment of the merits of a request: it provides the technical assistance needed to carry it out.

Request received by the customer

  1. The customer forwards the request to Répondia's compliance channel, identifying the person by their telephone number and the establishment concerned.
  2. Répondia acknowledges receipt within one working day.
  3. Répondia carries out the extraction, rectification or deletion within five working days, and returns the result in a readable and reusable format.
  4. The customer notifies the data subject. The operation is traced in the audit log.

The establishment may also carry out the deletion of a person itself from the application, without going through Répondia.

Request received directly by Répondia

The request is forwarded without delay to the establishment concerned, and the person is informed of this in the same reply. No data are disclosed directly without an instruction from the controller, except where Répondia is itself the controller (website, prospecting, user accounts) in which case it replies within one month.

Objection to messages

Any person may ask for solicitations to stop by replying STOP in the conversation. The block is immediate, automatic, and binding on all outbound sending modules.

Traceability

Each request is recorded with its date of receipt, its channel, the establishment concerned, its nature, its reply date and the operations carried out. This register is made available during customer audits.

14. Personal Data Breach Handling Procedure

Courtesy translation. Only the French version is binding.

Definition adopted

A breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

This covers in particular: the large-scale sending of messages to the wrong recipients, the exposure of an export, the compromise of an account holding extended rights, and any leak occurring at a processor.

Steps and time limits

Step Time limit Person responsible
Internal reporting Immediate Any person who notices the incident
Classification: security incident or personal data breach 4 hours Natan Darhi, data protection lead
Containment and preservation of evidence Ongoing Chief technical officers
Notification to the customers acting as controllers 48 hours after classification Management
Assistance to the customer with its notification to the authority Within the 72-hour time limit binding on it Management
Post-incident report and corrective action plan 15 days Management and technical team

Content of the notification

The notification specifies the nature of the breach, the categories and approximate number of persons and records concerned, the likely consequences, the measures taken or proposed, and the contact point from which further information can be obtained.

An incomplete initial notification is sent rather than delayed, then supplemented as the investigation progresses.

Escalation

Natan Darhi is the permanent escalation contact point, reachable including at weekends.

Register of breaches

All breaches, including those not giving rise to notification to the authority, are recorded with the facts, their effects and the corrective measures adopted. This register is kept at the disposal of the CNIL.

15. Data Protection Impact Assessment

Courtesy translation. Only the French version is binding.

The impact assessment is the responsibility of the controller, and therefore of the establishment. Répondia makes a template impact assessment available to its customers, which the establishment adopts and completes in the light of its own organisation.

Applicable triggering criteria

Innovative use of an artificial intelligence technology, large-scale processing, collection of data relating to booking behaviour. Where two criteria are met, the assessment is mandatory.

Structure of the template

1. Description of the processing. Reference to the data flow map in this register, supplemented by the channels and integrations actually subscribed by the establishment.

2. Necessity and proportionality. Minimisation of the data passed to the assistant, retention periods, information given to individuals from the first message, arrangements for exercising rights, legal basis chosen by the establishment for call take-up.

3. Risks identified.

Risk Severity Measures
Illegitimate access to the content of conversations High Segregation by establishment, two-level access control, audit log, encryption
Unwanted modification or cancellation of a booking Moderate Writing only through the connected tools, booking held pending where no software is connected, human takeover
Incorrect reply from the assistant causing harm Moderate Replies limited to the information entered by the establishment, automatic escalation where information is missing
Disappearance of data Moderate Daily backups, tested restoration
Excessive transmission of data to the model Moderate History limited to the current request, defined and documented context scope
Re-identification by cross-referencing history Low Limited retention period, no cross-referencing between establishments

4. Opinion of the data protection lead and position of the controller.

16. Data Flow Map

Courtesy translation. Only the French version is binding.

Reference journey

  1. Unanswered call. The establishment has activated conditional call forwarding with its operator to a Répondia number. Répondia does not sit on the line and receives only the calls that are not answered. Data captured: calling number, timestamp, destination line.
  2. Announcement and voice message. The telephony provider picks up, plays the announcement informing the caller of the automated nature of the service, and records any message left. It calls Répondia's interface with a signed request.
  3. Retrieval of the recording. The recording is copied into Répondia's storage in Paris, then deleted at the telephony provider as soon as the copy is confirmed. Only the call metadata remain with the provider.
  4. Transcription. The recording is transcribed by the transcription service hosted in the European Union, then analysed to determine the language and the nature of the request.
  5. Outbound message. The take-up message is sent from the establishment's WhatsApp Business account, via the Business Solution Provider, then delivered by Meta.
  6. Reply from the person. The message passes through Meta and then the Business Solution Provider, and reaches Répondia's interface, which verifies the signature of the request and identifies the destination establishment by the number called.
  7. Building the context. Current message, last twenty messages of the current request, establishment profile and associated rules, the person's upcoming bookings, results from the booking tools.
  8. Generation of the reply. The context is passed to the language model, hosted in the European Union. The provider uses neither the requests nor the replies to train its models.
  9. Action. Where applicable, creation, modification or cancellation of a booking in the software connected by the establishment. Where no software is connected, the booking is created pending human validation.
  10. Rendering. Real-time display in the establishment's inbox, mobile application notification, and the possibility for staff to take over at any time.
  11. Persistence. Conversation, status, booking and statistics recorded in the database hosted in Paris. Execution trace kept for fourteen days in the European monitoring tool.

03 INTERNATIONAL DATA TRANSFERS

17. International Data Transfer Policy

Courtesy translation. Only the French version is binding.

Principle

Répondia's hosting and production processing are located in the European Union: application and internal services in Belgium, database and files in France, artificial intelligence processing in the European Union.

Any transfer outside the European Economic Area is either based on an adequacy decision, or governed by the European Commission's Standard Contractual Clauses of 4 June 2021, accompanied by a transfer impact assessment.

Residual transfers identified

Flow Destination Necessity Framework
Delivery of WhatsApp and Instagram messages Meta Platforms Ireland, with possible processing in the United States Inherent in the channel chosen by the establishment Data Processing Terms and Standard Contractual Clauses
Call and messaging logs of the telephony provider United States Configuration of the operator account DPA and Standard Contractual Clauses
Database and storage Paris, vendor governed by US law Provision of the service DPA and Standard Contractual Clauses
Agent monitoring European instance, vendor governed by US law Quality and debugging Signed DPA and Standard Contractual Clauses
Application usage analytics European instance, vendor governed by US law Product improvement DPA and Standard Contractual Clauses
Mobile application notifications International delivery Operation of notifications Provider terms, limited excerpt that can be disabled

Establishments located outside the European Union

The data of customer establishments located outside the European Union (in particular in Saint-Barthélemy, Switzerland, Belgium, Morocco, the United Arab Emirates, Singapore and Australia) are processed and hosted in the European Union. They are therefore not outbound transfers within the meaning of Chapter V of the Regulation.

Local law remains applicable to the establishment in its capacity as controller: Law 09-08 and the CNDP framework in Morocco, the Federal Personal Data Protection Law in the United Arab Emirates, the Personal Data Protection Act in Singapore, the Privacy Act in Australia, the new Federal Act on Data Protection in Switzerland. Répondia provides these customers with the same documentation and the same contractual commitments as its European customers.

Internal rule

No new provider processing personal data outside the European Economic Area is put into production without a signed Data Processing Agreement, applicable Standard Contractual Clauses and a documented transfer impact assessment.

18. Standard Contractual Clauses

Courtesy translation. Only the French version is binding.

Répondia relies on the European Commission's Standard Contractual Clauses 2021/914, in the following configuration.

Module 3, processor to sub-processor. Main configuration, applicable to flows to hosting, telephony, messaging and monitoring providers whose contracting entity or parent company is established outside the European Economic Area.

Module 2, controller to processor. Applicable where the contractual structure with a customer so requires.

UK Addendum. Applicable to establishments located in the United Kingdom, in the form of the International Data Transfer Addendum.

Switzerland. Adaptation of the references to the new Federal Act on Data Protection and to the competent supervisory authority.

Annexes kept up to date

Annex I, identification of the parties, description of the transfer, competent supervisory authority. Annex II, technical and organisational measures, by reference to the corresponding document in this register. Annex III, list of sub-processors, by reference to the published list.

The Data Processing Agreements and clauses entered into with each provider are kept by Répondia and disclosed to the customer on request, within the limits set by the providers concerned.

19. Transfer Impact Assessments

Courtesy translation. Only the French version is binding.

An assessment is drawn up for each destination outside the European Economic Area, following the structure recommended by the European Data Protection Board.

Structure applied

  1. Precise mapping of the transfer: data concerned, volume, frequency, format, recipient.
  2. Transfer tool used.
  3. Assessment of the law and practices of the destination country, in particular the possibilities of access by public authorities.
  4. Supplementary measures implemented.
  5. Conclusion as to whether an essentially equivalent level of protection is achieved.
  6. Annual review, or review upon any significant change.

Common supplementary measures

Encryption of data in transit and at rest; limitation of the content transmitted to what is strictly necessary; no administrator access from a third country; restricted and logged access control; contractual commitment to challenge access requests from authorities and to inform the customer to the extent permitted by law.

Assessments drawn up

Meta, for the delivery of messages. Telephony provider, for call logs. Database vendor, whose hosting is European but whose company is governed by US law. Monitoring tool, on a European instance. Usage analytics tool, on a European instance. Mobile application notification services.

20. Countries of Processing and Hosting

Courtesy translation. Only the French version is binding.

Country Role Data concerned Status
Belgium Application, internal processing, logs, artificial intelligence processing All service data European Union
France Database, file storage, backups, telephone numbers, transactional e-mails All service data European Union
Ireland Contracting entities of the main providers, message delivery, anonymised pre-production environment Messages, anonymised data European Union
Spain Online reviews management Name of the author and text of the review European Union
United States Call logs of the telephony provider, head offices of certain vendors, source code hosting, internal technical alerts Metadata, no end-customer data for the code and the alerts Standard Contractual Clauses
Outside the European Union (Switzerland, Saint-Barthélemy, Morocco, United Arab Emirates, Singapore, Australia) Customer establishments only No local processing or storage Not applicable

04 SECURITY

21. Information Security Policy

Courtesy translation. Only the French version is binding.

Scope

This policy covers all of Répondia's information systems: production platform, development and pre-production environments, internal tools, workstations and provider accounts.

Governance

Natan Darhi, President, is the data protection lead and compliance contact point. Nicolas Patron and Fabio Palumbo, chief technical officers, are responsible for implementing and maintaining the technical measures.

The policy is reviewed annually, and at every major change to the architecture.

Classification of information

Four levels: public, internal, confidential, and end-customer data. This last level requires encryption, access restricted to named individuals and logging of every consultation.

Personnel security

Staff and contractors are bound by a contractual obligation of confidentiality. Access is granted on a strict need-to-have basis, reviewed quarterly and revoked within twenty-four hours in the event of departure.

Development security

The source code is hosted in private repositories to which access is limited to the chief technical officers. Every change is reviewed by a chief technical officer before merging. Production releases are preceded by a deployment to pre-production, and the infrastructure is described as code, versioned and reviewed.

Secrets are stored in a dedicated vault and injected when services start. No secret is versioned. The continuous integration pipeline authenticates with the cloud provider without a static key, through identity federation.

Vulnerability management

Dependencies are monitored continuously and security patches are proposed automatically. Every integration pipeline runs a search for known vulnerabilities in the application dependencies. Static code analysis and secret detection are enabled on the administration interfaces.

Compliance and audits

Répondia aligns its practices with the requirements of the ISO/IEC 27001 standard without holding the certification to date. The launch of a certification process is planned for the second half of 2027.

The first external penetration test is scheduled for the first quarter of 2027.

Supplier management

Any provider that will process data is subject to a prior assessment according to the grid in this register, and to a Data Processing Agreement signed before going into production.

22. Technical and Organisational Measures

Courtesy translation. Only the French version is binding.

Annex II to the Standard Contractual Clauses and attachment to the Data Processing Agreement.

Area Measure in place
Encryption in transit HTTPS on all interfaces, TLS 1.2 minimum, TLS 1.3 by default. Encrypted connections to the databases. Strict transport security header on the administration interfaces.
Encryption at rest AES-256 on the database, file storage, backups, logs, internal messaging and the secrets vault. Keys managed by the infrastructure providers.
Additional application-level encryption Symmetric encryption of the API keys and telephony tokens entrusted by customers, with the master key stored in a vault.
Customer access control Two statuses, seventeen individually assignable permissions, scope limited to the authorised establishments, rejection of any out-of-scope request.
Authentication Two-factor authentication available to customer users and mandatory for internal accounts with extended rights. Google sign-in available. Password policy enforced by the platform. One-hour token, session closed after thirty days of inactivity and ninety days at most.
Customer segregation Establishment identifier carried by every record; systematic filtering at the application interface level; row-level security enabled on all tables of the database; separate WhatsApp Business account and telephony sub-account per organisation; routing of inbound messages by destination number with signature verification.
Segregation of artificial intelligence processing Each call to the model relates to a single conversation of a single establishment. No cross-referencing between establishments.
Logging Named audit log covering the consultation of conversations, the export of contacts and administration actions, kept for one year. Append-only log of request and booking events. Technical request logs kept for thirty days.
Backup Automatic daily backup of the production database, seven-day retention, hosted in Paris, encrypted, accessible to two people holding two-factor authentication. Audio and media files are not backed up separately from their replicated storage.
Environments The pre-production environment contains anonymised data only, regenerated after each copy. No real end-customer data outside production.
Monitoring Real-time error alerts sent to the chief technical officers; tracking of application errors on the interface side; centralised logs.
Development Private repositories with restricted access, mandatory code review, secrets in a vault, authentication of the deployment pipeline without a static key.
Workstations Disk encryption, password manager, two-factor authentication on all professional tools.
Minimisation Context passed to the model limited to the current request; messaging identifiers, internal notes and labels excluded; notification preview can be disabled per establishment.

23. Incident Response Plan

Courtesy translation. Only the French version is binding.

Classification

Level Definition Handling Customer information
P1 Service unavailable, or suspected compromise Immediate during staffed hours, best effort outside them Within 1 hour
P2 Major function degraded for several establishments During staffed hours Within 4 hours
P3 Incident confined to one establishment During staffed hours Within 1 day
P4 Anomaly with no operational impact Product backlog Release note

Phases

Detection, classification, containment, eradication, recovery, lessons learned. Any incident classified P1 or P2 gives rise to a written report sent to the customers concerned within fifteen days.

Detection and escalation

Server errors are reported in real time, with an automatic summary, on the devices of the two chief technical officers, including in the evening, at weekends and on public holidays. They intervene on a best-effort basis outside staffed hours, with no guaranteed handling time outside them.

Natan Darhi is the permanent escalation contact point.

Link with the personal data breach procedure

Every P1 or P2 incident is classified in the light of the personal data breach procedure within four hours of its detection.

24. Business Continuity Plan

Courtesy translation. Only the French version is binding.

Outage of the messaging platform (Meta)

Messages sent by end customers are kept by Meta and delivered when the service is restored. The assistant's failed replies are not resent automatically; the team is alerted.

Outage of the Répondia platform

Inbound WhatsApp messages. A catch-up task re-reads the messages from the Business Solution Provider and imports the missing ones, without duplicates. No message is lost.

Inbound Instagram messages. Meta resends failed notifications for a period that allows a short interruption to be caught up.

Missed calls. A fallback address configured at the telephony provider takes over: the caller hears the announcement and leaves their message, which is recorded and then imported when the platform is restored.

Voice messages already received. Queued and replayed automatically every fifteen minutes.

Outage of the conversational engine alone

The inbox continues to receive and display messages. Pending processing is retried for approximately forty minutes, then placed in an error queue that is replayed automatically upon recovery.

Outage of a model provider

After two unsuccessful attempts, the assistant switches automatically to the second provider. If both are unavailable, the message remains in the inbox for human handling and an alert is raised. The review and comment modules switch to human handling.

If the configuration interface is unavailable, the assistant relies on the last cached configuration.

Suspension of a WhatsApp Business account by Meta

The scope is limited to one organisation: each organisation has its own account. Meta alerts by e-mail and in the management interface. Répondia requests a review and, in parallel, opens a ticket with the Business Solution Provider.

During the suspension, missed calls continue to feed the inbox through voicemail and its transcription, and the establishment calls its customers back. The other channels remain operational. If the review fails, a new account or a new number is connected according to the internal migration procedure, the history being kept.

Human unavailability

Critical access is held by at least two people, the credentials being kept in a shared vault. No operational function depends on a single person.

25. Disaster Recovery Plan

Courtesy translation. Only the French version is binding.

Item Value
Recovery time objective (RTO) 4 hours during staffed hours; no guaranteed time outside them
Recovery point objective (RPO) 24 hours
Backup frequency Daily, automatic
Retention 7 rolling days
Location France, same region as the production database
Encryption AES-256 at rest
Access to backups Two people, mandatory two-factor authentication
Application redundancy Single region, automatic distribution across several zones, permanent minimum instance
Database redundancy Single zone, without replica or automatic failover
Last restoration test June 2026, full restoration of the database in approximately one hour

Accepted limits

Audio and media files are not backed up separately from their replicated storage. Point-in-time recovery is not enabled: the maximum loss corresponds to the last daily backup. No multi-region recovery plan is in place.

These limits are documented and brought to the attention of customers rather than offset by unverifiable claims.

26. Access Control Policy

Courtesy translation. Only the French version is binding.

Access by customer users

Two statuses and seventeen permissions, described in the Terms of Use. Reading conversations, requests, bookings and contacts is open to every active member of the establishment; reviews and statistics require a dedicated permission.

The organisation owner has access to the conversations of all of its establishments. A member sees only their own; any out-of-scope request is rejected.

Répondia's internal access

Three people have access to the production environment: the two chief technical officers and the President.

Access to the database and to the backups, as well as to the code repositories, is restricted to the two chief technical officers, with mandatory two-factor authentication.

The platform administration right is granted outside the application, in a dedicated table: no user can grant it to themselves. It requires a session authenticated with two factors.

Every consultation of a conversation, every export of contacts and every administration action is entered in the audit log with the author's identifier, the target, the IP address and the timestamp. This log is kept for one year and can be consulted.

Development assistance tools have no access to the production environment.

Life cycle

Creation at the request of the customer's contact person, quarterly access review, revocation within twenty-four hours in the event of departure, deletion of accounts thirty days after the end of the contract.

27. Backup and Restoration Policy

Courtesy translation. Only the French version is binding.

Scope and arrangements

The production database is backed up automatically every day, the backup being kept for seven rolling days, hosted in the same region as the database, in France, and encrypted at rest.

Audio and media files rely on the provider's replicated storage and are not backed up separately.

Access

Backups are accessible to two people only, through the provider's console, with two-factor authentication enforced across the whole organisation.

Restoration tests

A full restoration of the database was carried out in June 2026 during an infrastructure migration, in approximately one hour. No periodic test is scheduled at a fixed interval to date.

Link with deletion

Data deleted in production may remain for up to seven days in the backups, and up to fourteen days in the monitoring traces. This period is explicitly brought to the attention of customers and data subjects rather than presented as instant deletion.

05 AI

28. Policy on the Processing of Data by Artificial Intelligence

Courtesy translation. Only the French version is binding.

Providers and uses

Répondia trains no model. It calls, through an application programming interface, models supplied by two vendors, each agent having its own versioned configuration stored in the database.

Google, via Vertex AI in a European region, main conversational agent across all channels and booking integrations, agents specialised by type of establishment, replies to reviews and comments, reputation analyses, context summaries.

Microsoft, via Azure OpenAI in a European region, transcription of voice messages, analysis of the voice message, classification of requests, language detection, call analysis, new-generation conversational agents for some establishments, internal configuration and support tools.

A third provider is used for an internal configuration recommendation tool, which processes no end-customer data and is not called by production.

Content passed to the model

For each message received, the assistant receives:

  • the current message in full, including attached images;
  • the last twenty messages of the current request only, closed requests are never passed on;
  • the person's name, e-mail address and telephone number, needed to greet them and to create or retrieve their booking;
  • the establishment profile: name, type, description, opening hours, closures, booking, modification and cancellation rules, upselling partners, questions already escalated;
  • the person's upcoming bookings, up to a limit of ten;
  • the results from the booking tools queried;
  • for a voice message, its transcription.

Data excluded from the context

The person's WhatsApp or Instagram identifier, the staff's internal notes, internal labels, and the history of closed requests are never passed to the model.

No data from another establishment are passed on: each call relates to a single conversation of a single establishment.

No pseudonymisation

The name, e-mail address and number are passed in clear text, this information being necessary to perform the service requested by the person. The providers do not use these data to train their models, and the processing is located in the European Union.

Automated decision-making

The assistant may create, modify or cancel a booking. These actions produce neither a legal effect nor a similarly significant effect within the meaning of Article 22 of the Regulation, and therefore do not constitute automated decision-making within the meaning of that provision.

Where no booking software is connected, no booking can be made final by the assistant: it is created pending validation by staff.

A human takeover is possible at any time.

29. Artificial Intelligence Transparency Notice

Courtesy translation. Only the French version is binding.

Obligation

A person who interacts with an artificial intelligence system must be informed of it. The European regulation on artificial intelligence makes this information explicit for conversational systems. Répondia applies it to all of its conversations and all of its calls.

Information provided

The announcement played upon the missed call informs the caller of the automated nature of the service before any recording.

The first message of each conversation carries the following notice, in the language of the exchange:

Hello, this is [Establishment]. We saw your call and are replying by message. You are talking to our automated assistant; a member of the team can take over the conversation at any time. Reply STOP to stop receiving messages.

This notice cannot be disabled by the establishment.

Scope

The information covers the automated nature of the interlocutor, the possibility of reaching a human, the identity of the responsible establishment, the means of objecting to receiving messages, and the reference to the establishment's privacy policy.

Classification under the European regulation

The system falls under the transparency obligations and not under the category of high-risk systems: it is not involved in access to employment, credit or education, nor in the provision of essential services, and carries out no scoring of individuals.

This classification is reviewed at every major functional change.

30. Assessment of Model Providers

Courtesy translation. Only the French version is binding.

Criterion Google : Vertex AI Microsoft : Azure OpenAI
Contracting entity Google Cloud EMEA Limited, Ireland Microsoft Ireland Operations Limited
Use Main conversational agent, reviews, analyses Transcription, analysis, new-generation agents, internal tools
Processing region European Union European Union
Contractual framework Cloud Data Processing Addendum accepted Products and Services Data Protection Addendum
Training on the data transmitted Contractually excluded Contractually excluded, for Microsoft's models as well as OpenAI's
Retention by the provider In line with the European contractual framework Retention of requests and replies limited to abuse monitoring, up to thirty days, in the region of the resource
Zero retention - Request for exemption from abuse monitoring pending with the provider
Provider certifications ISO 27001, SOC 2 ISO 27001, SOC 2
Fallback solution Automatic switch to the second provider Automatic switch to the second provider

A third provider is used for an internal tool that processes no end-customer data.

Admission criteria for a new provider

Processing in the European Union, contractual exclusion of training, signed Data Processing Agreement, recognised security certification, and existence of an alternative in the event of failure.

31. Retention and Training, Commitments relating to Artificial Intelligence

Courtesy translation. Only the French version is binding.

Commitments

  • Customers' conversations are not used to train or fine-tune any language model, either by Répondia or by its providers. This exclusion is contractual with both providers used.
  • The data of one establishment are never used to improve the service of another establishment.
  • Artificial intelligence processing is located in the European Union.
  • An establishment's knowledge base belongs to it. It can be returned and deleted on request.
  • Any change to these commitments is notified to customers before it is applied.

Retention by the providers

The requests sent to the transcription and analysis provider may be kept for up to thirty days for abuse monitoring, in the European region of the resource, and are reviewed only in the event of an alert. A request for exemption from this monitoring is pending.

The internal monitoring traces, which contain the content of conversations for debugging purposes, are hosted in the European Union and kept for fourteen days.

Improvement of service quality

Real conversations are consulted for the purpose of improving the quality of the replies and the performance of the assistant, within the framework declared in the Data Processing Agreement: an activity reserved for the two chief technical officers, carried out in the internal tools, with the possibility of replay in a test environment without any message being sent to the data subject, without export outside Répondia's tools and without model training.

06 CUSTOMER COMPLIANCE

32. Security Questionnaire, Reference Answers

Courtesy translation. Only the French version is binding.

Identity. Répondia SAS, RCS Nice 983 585 290, 16 bis boulevard de Montréal, 06200 Nice, France. Compliance contact point: legal@repondia.com.

Certifications. Practices aligned with the requirements of the ISO/IEC 27001 standard, without certification to date. Certification process planned for the second half of 2027.

Penetration tests. First external test scheduled for the first quarter of 2027.

Hosting. Application and artificial intelligence processing in Belgium; database, files and backups in France. No production data outside the European Union, with the exception of the residual flows documented in the international transfer policy.

Segregation. Single database with establishment identifier, filtering at application level, row-level security enabled on all tables, separate WhatsApp Business account and telephony sub-account per organisation, signature verification of inbound messages.

Encryption. TLS 1.2 minimum in transit, AES-256 at rest on the database, files and backups. Keys managed by the infrastructure providers; no customer-managed keys to date.

Authentication. Two-factor authentication available to customers, mandatory for internal accounts with extended rights. Google sign-in available. No SAML enterprise identity federation to date.

Logging. Named audit log of conversation consultations, exports and administration actions, kept for one year.

Internal access. Three people in production, two for the database and the code, mandatory two-factor authentication, full logging.

Backups. Daily, seven-day retention, France, encrypted. Full restoration tested in June 2026 in approximately one hour.

Continuity. RTO of four hours during staffed hours, RPO of twenty-four hours. Database in a single zone without replica. Automatic catch-up mechanisms on all inbound channels.

Incidents. Real-time alerts, classification into four levels, customer notification within one hour for a major incident, personal data breach notification within forty-eight hours after classification.

Sub-processors. List published and notified thirty days before any change.

Artificial intelligence. Two providers, processing in the European Union, contractual exclusion of training, context limited to the current conversation of a single establishment.

Development. Private repositories, mandatory code review, secrets in a vault, authentication without a static key, continuous monitoring of dependencies.

33. GDPR Questionnaire, Reference Answers

Courtesy translation. Only the French version is binding.

Question Answer
Role of the parties The customer is the controller, Répondia the processor within the meaning of Article 28.
Data protection officer No mandatory appointment. Data protection lead appointed: Natan Darhi, natan.darhi@repondia.com.
Record of processing activities Kept under Articles 30(1) and 30(2), published in this register.
Data Processing Agreement Annexed to the general terms, signed with each customer.
Retention periods Content of exchanges twenty-four months; contacts and accounts thirty days after the end of the contract; audit log one year.
Location European Union for hosting and processing. Residual flows documented and governed.
Sub-processors Published list, thirty days' notice, right of reasoned objection.
Transfers outside the European Union Standard Contractual Clauses 2021/914, mainly Module 3, with impact assessments.
Data subjects' rights Documented procedure, execution within five working days, deletion also achievable by the establishment from the application.
Personal data breaches Documented procedure, customer notification within forty-eight hours after classification, register kept.
Impact assessment Template made available to customers acting as controllers.
Audit Documentation made available; on-site audit once a year, thirty days' notice, at the customer's expense.
Reversibility Self-service export of contacts, extraction of the rest on request before deletion.
Artificial intelligence Transparency from the first contact, European processing, contractual exclusion of training.

34. Processor Assessment Grid

Courtesy translation. Only the French version is binding.

Grid applied before any provider that will process personal data is put into production. A provider cannot be onboarded if the first six points are not met.

  1. Company name, country of establishment and contracting entity.
  2. Exact nature of the data processed and limited purpose.
  3. Signed Data Processing Agreement compliant with Article 28.
  4. Location of processing and storage; Standard Contractual Clauses where processing takes place outside the European Economic Area.
  5. Retention period and deletion procedure at the end of the relationship.
  6. Documented security measures; certification or audit report available.
  7. List of its own sub-processors.
  8. Commitment to notify breaches and applicable time limit.
  9. Reversibility: export format, time frame, any cost.
  10. Dependency: existence of an alternative solution in the event of failure.

The result is recorded per provider and reviewed annually.

35. Contractual Security Annex

Courtesy translation. Only the French version is binding.

Contractual extract annexed to the contract, restating the following commitments in the form of firm obligations.

Location. Hosting and production processing, including artificial intelligence processing, are located in the European Union. Any change of location is notified thirty days in advance.

Encryption. Data encrypted in transit by TLS 1.2 at minimum and at rest with AES-256, backups included.

Segregation. The data of each establishment are isolated by a dual control at application and database level, and by a messaging account dedicated to each organisation. No data of one establishment are accessible to another or passed to a model for the benefit of another.

Access. Internal access restricted to three named people, with two-factor authentication and named logging of every consultation of a conversation, kept for one year and open to consultation by the customer.

Artificial intelligence. No model training or fine-tuning on the customer's data. Processing in the European Union. Consultation of conversations for the sole purpose of quality improvement, within the framework defined in the Data Processing Agreement.

Incidents. Notification of any breach affecting the customer's scope within forty-eight hours of its classification, with the information needed for notification to the supervisory authority.

Sub-processors. Published list, thirty days' notice, right of reasoned objection and option to terminate the scope concerned.

Audit. Documentation made available; annual on-site audit on thirty days' notice.

Reversibility and deletion. Export made available before deletion; deletion within thirty days after the end of the contract; disappearance of residual copies within seven days for backups and fourteen days for monitoring traces; certificate on request.

Measures in progress. The first external penetration test is scheduled for the first quarter of 2027 and the launch of a certification process for the second half of 2027. Audio and media files are not backed up separately from their replicated storage. The database is not replicated across zones. No intervention time is guaranteed outside staffed hours.

36. Service Levels and Support Policy

Courtesy translation. Only the French version is binding.

Availability

Répondia commits to a monthly availability rate of 99.5%, measured on the availability of the message processing interface.

The measurement is based on the platform's technical logs. An availability statement is provided to the customer at its request, at any time.

The following are excluded from the calculation:

  • planned maintenance, notified forty-eight hours in advance;
  • unavailability attributable to Meta, to the WhatsApp Business Solution Provider, to the customer's telephone operator or to the connected booking software;
  • unavailability resulting from an incorrect configuration supplied by the customer;
  • cases of force majeure.

Support hours and channel

The assistant built into the Répondia application is accessible twenty-four hours a day, seven days a week to log a request, which is timestamped as soon as it is submitted.

The Répondia teams handle requests seven days a week, from 9 a.m. to 8 p.m., weekends and public holidays included.

Outside these hours, major technical alerts are reported in real time to the chief technical officers, who intervene on a best-effort basis, with no guaranteed handling time.

The single channel for opening a ticket is the assistant built into the application. This single channel guarantees the traceability and timestamping of every request.

Priority levels

Priority Definition Handling Workaround or resolution
P1 No message is being processed for the establishment 1 hour during staffed hours 4 hours
P2 Degraded function, service partially delivered 4 hours 1 day
P3 Minor anomaly or configuration question 1 day 5 days
P4 Feature request Assessment within 5 days Product roadmap

Continuity during an incident

Inbound channels have catch-up mechanisms described in the business continuity plan: messages received during an interruption are imported when the service is restored.

Penalties

No financial penalty is attached to these commitments. In the event of serious and repeated breach, the customer has the right of termination provided for in Article 9.4 of the general terms.

37. Acceptable Use Policy

Courtesy translation. Only the French version is binding.

This policy protects Répondia, its customers and the compliance of the numbers and messaging accounts used. A breach may lead to suspension of the channel concerned, over which Meta remains the sole master.

Prohibited uses

  • Importing contact lists that have never interacted with the establishment, or that were acquired from third parties.
  • Sending mass promotional messages to people who have not given their agreement.
  • Continuing to send to a person who has asked for solicitations to stop.
  • Passing the assistant off as a human being, or removing the transparency notice.
  • Collecting payment data, identity documents or health-related information through the conversational channel.
  • Using the service for purposes that are unlawful, defamatory, discriminatory or misleading.
  • Attempting to access another establishment's data, testing the security of the platform without prior written authorisation, or carrying out automated extraction outside the interfaces provided.
  • Reselling the service or making it available to a third party without written agreement.

Consequences

Warning, then suspension of the channel concerned, then termination for serious breach. Where there is an immediate risk to the compliance of the accounts or to the security of the platform, suspension may take place without notice, the customer being informed without delay.

Responsibility for content

The customer is solely responsible for the accuracy of the establishment information it provides (in particular prices, opening hours, cancellation conditions and allergens) and for the messages it triggers from the platform.