Privacy Policy
Version dated September 20, 2026. This is a legal draft pending completion of the controller details and final legal review.
1. General provisions
This document describes the intended principles for processing information in MPReply. It does not replace documents required from the actual controller and does not confirm that every process described here is already used in the commercial service.
2. Who is the data controller
Details of the legal entity or individual entrepreneur acting as controller must be added before commercial launch, including name, address, contact channel, and any other legally required information.
3. Data that may be processed
- account data such as email address, user identifier, and settings;
- company workspace and team membership data;
- marketplace access credentials required for connected integrations;
- reviews, questions, customer messages, and related data received from connected marketplaces;
- service data about AI usage needed for operation, diagnostics, and accounting;
- technical logs and security events with personal-data minimization.
4. Purposes of processing
- providing service functionality and account access;
- receiving customer messages and sending replies through marketplace connections;
- preparing AI-assisted reply drafts and controlling automation;
- detecting errors, maintaining security, and recording significant actions;
- supporting users and developing the product.
5. AI and context sharing
Only the context needed to process a customer message should be sent to an external generation service. Unnecessary personal data, secrets, access keys, and other credentials should not be included.
6. Marketplace access credentials
Marketplace access keys and related credentials are processed inside the service and are not shown in the normal user interface or ordinary logs. MPReply is designed to encrypt such data at rest and support safe replacement of compromised credentials.
7. Retention and deletion
Specific retention periods must be defined before commercial launch for each data category. The architecture should support data minimization, deletion, and export to the extent required by applicable obligations.
8. User rights
A legally valid procedure for requests concerning access, correction, deletion, and restriction of processing must be approved together with the controller details. Until this document is finalized, public questions about the service may be sent to support@mpreply.ru.
9. Security
Baseline measures include separation of data between organizations, access controls, encryption of marketplace credentials, protection against excessive requests, secure secret storage, recording of significant actions, backups, and personal-data minimization.
10. Changes to this document
The date and substance of changes should be recorded. Material changes should be published before a new version takes effect where required by applicable rules or contractual obligations.
