Legal

The personal data Reponse processes, why, on what basis, for how long, with whom, and how to exercise your rights.

Privacy Policy

Last updated: 23 September 2026

This policy explains what personal data is processed in connection with the Reponse service, why, on what legal basis, for how long, and with whom it is shared. It is written to be read, not endured. It applies to the reponse.ai website, the Reponse application, the chat widget installed on our customers' sites, the APIs and the MCP server.

The service is sold to professionals. The website remains accessible to anyone, including consumers, and some data subjects are consumers, in particular the end customers of merchants who use Reponse. Rules that apply to consumers are flagged where they matter.

1. Who is the controller and how to reach us

The Reponse service is published by Shmore, a French simplified joint-stock company (SAS) with share capital of 1,000 euros, registered office at 26 Thubert, 44118 La Chevrolière, France, registered with the Nantes Trade and Companies Register under number 990 895 971.

Contact details:

  • General contact and exercise of rights: hello@reponse.ai
  • Support: support@reponse.ai
  • Postal address: 26 Thubert, 44118 La Chevrolière, France
  • Intra-EU VAT number: FR26990895971
  • Publication director: Vincent Redor
  • Data protection: Shmore has not appointed a data protection officer. The single point of contact for any question about your data is hello@reponse.ai, with the subject line "Data protection".

In this policy, "we", "Reponse" and "Shmore" refer to the same company. "You" refers to the person whose data is processed. "Customer" refers to the professional merchant using Reponse for its Shopify store: Reponse only contracts with professionals. "End customer" refers to a person who contacts one of our customers through Reponse tools.

2. Two distinct roles, not to be confused

The GDPR distinguishes the controller, who decides on purposes and means, from the processor, who acts on instructions. Reponse occupies both positions depending on the data concerned. The distinction determines who you should address to exercise your rights.

2.1 Reponse acts as controller for the account data of its merchant customers and their staff, for the data of visitors to the reponse.ai website and for its own marketing. This covers user accounts, workspaces, tracking of the subscriptions billed by Shopify, support provided to our customers, audience measurement on our website and product, commercial prospecting, demo requests and platform security. Sections 4 to 9 describe these processing activities, together with the part of section 11 that falls under this role.

2.2 Reponse acts as processor, on behalf of the merchant, for the data of its store's customers. This covers in particular chat conversations with end customers, tickets, customer and order data synced from Shopify, contact records, customer reviews, loyalty and referral data and transactional emails sent on the merchant's behalf. In that case the controller is the merchant, not Reponse. We do not use this data for our own purposes. This role is governed by our data processing agreement, and the list of our sub-processors is published on a dedicated page. Sections 10 to 12 describe this role.

2.3 If you are an end customer and you want to know how your data is used, or wish to exercise your rights, contact first the merchant whose customer service you reached out to. We will forward any request received directly to that merchant and help them respond.

3. How to read the sections below

For each purpose, we state the data processed, the legal basis under Article 6 GDPR, the source of the data where it does not come from you, whether providing the data is mandatory or optional, the retention period and the recipients.

4. Account creation and management, provision of the service

Data processed: email address, first and last name where provided, sign-in method (no password is created: you sign in with a one-time code sent to your email address, or through your Shopify admin session when you open Reponse from your store), identifiers of the Shopify store and of the Shopify staff member using it, workspace name, role within the workspace, language and interface preferences, configuration settings, connection logs and connection IP address, technical account identifier.

Purposes: create and secure your account, give you access to the features subscribed to (human live chat and AI agent, tickets and shared inbox, customer reviews, loyalty and referral, contact CRM, transactional emails, catalog and orders, APIs and MCP server), manage invitations and permissions within the workspace, ensure service continuity.

Legal basis: performance of the contract, Article 6(1)(b) GDPR, including pre-contractual steps when the app is installed. For technical security logs, legitimate interests, Article 6(1)(f), consisting in protecting the platform against unauthorised access.

Source: the data comes from you; from Shopify, when you install or open the app from your store's admin; or from the person who invited you into a workspace when a colleague creates your access, in which case the source is your organisation.

Provision of the data: providing an email address and an authentication method is a requirement for creating the account. It is contractual in nature: without this data we cannot open an account or provide the service. The other data in this paragraph, in particular your name and preferences, is optional and refusing to provide it has no consequence other than a less personalised experience.

Retention: for the duration of the contract, then 30 days after it ends, before deletion or anonymisation. Daily database backups are kept for 7 days; deleted data disappears from them as they rotate, no later than 30 days after deletion. Connection logs are kept for 12 months.

Recipients: Supabase, for the database, authentication and file storage. Netlify, for hosting the website and functions. Resend, for sending service emails, and Amazon SES, as backup provider. Shmore's director, the only person with access to this data on our side.

5. Subscriptions and billing

Reponse is billed exclusively through Shopify (Shopify App Pricing): the subscription is accepted in the Shopify admin, its charges appear on the merchant's Shopify invoice and are paid with the payment method on file with Shopify. Shmore receives no card number and no other payment data.

Data processed: the store and workspace concerned, subscribed plan, subscription status and subscription identifiers at Shopify, history of the charges billed, usage data required to apply the plan.

Purposes: activate and track subscriptions, apply the subscribed plan, track the charges billed, apply the refund policy, keep accounting records.

Legal basis: performance of the contract, Article 6(1)(b), for the subscription and its billing. Legal obligation, Article 6(1)(c), for the retention of accounting records.

Source: Shopify, which sends us the status of the subscription and of the charges billed.

Provision of the data: Reponse asks you for no billing data. A paid plan can only be activated if you accept the subscription in the Shopify admin.

Retention: accounting records are kept for 10 years from the close of the financial year, in accordance with Article L123-22 of the French Commercial Code. Other subscription data is kept for the duration of the contract, then 30 days after it ends.

Recipients: Shopify, Supabase, our chartered accountant, and the tax authorities upon a founded request.

Refunds: refund requests follow our refund policy. Data relating to a refund request is kept with the accounting records.

6. Support and assistance

Data processed: content of your requests, email address, account and workspace identifier, history of exchanges, technical information you send us (screenshots, logs, error messages), diagnostic data strictly necessary to resolve the incident.

Purposes: answer your requests, diagnose and fix incidents, improve documentation and the product based on the issues encountered.

Legal basis: performance of the contract for support relating to the subscribed service, Article 6(1)(b). Legitimate interests, Article 6(1)(f), for product improvement based on requests received, our interest being to fix defects and reduce the number of incidents.

Source: you. Where applicable, a colleague in your organisation who opens a request concerning you.

Provision of the data: providing the details describing your request is optional, but without them we cannot handle the request. No other consequence attaches to a refusal.

Retention: 3 years after the request is closed.

Recipients: Supabase, Resend and Amazon SES, and Shmore's director, who handles support requests. We only access your workspace if you ask us to, and only to handle your request.

7. Audience measurement and product improvement

Data processed: pages viewed, actions performed in the product, device and browser type, language, country inferred from the IP address, technical session or visitor identifier, date and time.

Purposes: understand how the website and the product are used, measure feature usage, detect friction points, guide the roadmap.

Legal basis: consent, Article 6(1)(a) GDPR and Article 82 of the French Data Protection Act, collected through our consent banner. You may refuse with no consequence on access to the service.

Tools: PostHog, on its European instance, for product usage measurement: it is disabled by default and no event is sent until you have accepted. Google Analytics 4, for website audience measurement: the tag is only loaded after you accept, with the audience measurement purpose alone (analytics_storage) and no advertising purpose. The choice expressed in the banner is stored in your browser under the key cookie_consent. You may change it at any time through the "Manage cookies" link in the website footer; if you refuse or withdraw, Google Analytics is not loaded and any _ga cookies already set are deleted.

Source: your browsing.

Provision of the data: audience measurement relies on your consent. You may refuse it or withdraw it, with no consequence whatsoever on access to the website or to the service.

Retention: audience data is kept for 13 months in Google Analytics and in PostHog alike. The Google Analytics ga cookies have a lifetime of 13 months; the PostHog tracker (cookie and local storage ph…_posthog), a lifetime of 12 months.

Recipients: PostHog, Google.

For details on trackers, see section 19 and our cookie policy.

8. Commercial prospecting and marketing

Data processed: first and last name, business email address, job title, company, website, country, history of commercial exchanges, interactions with our emails and content, information you enter in our forms, in particular contact forms, demo requests and our online tools.

Purposes: answer your commercial enquiries, send you information about the service, arrange demonstrations, maintain the relationship with our professional customers and prospects.

Demonstrations: booking a demonstration on the website goes through Cal.com, which receives your name, your email address and the slot you choose.

Legal basis: consent, Article 6(1)(a), where you sign up to a communication or fill in a form for that purpose. Legitimate interests, Article 6(1)(f), for prospecting addressed to professionals under the B2B regime accepted by the CNIL, our interest being to develop our business, provided the subject of the solicitation relates to the person's professional role. Pre-contractual steps, Article 6(1)(b), where you request an offer.

Source: you, when you contact us or fill in a form. For prospecting, your business contact details may also come from the business databases Apollo and Clay, which compile publicly accessible professional information (name, job title, company, business email address).

Provision of the data: providing this data is optional. A refusal only deprives you of an answer to your commercial enquiry or of our communications, and has no effect on access to the service or on its performance.

Retention: 3 years from your last contact for prospects. For customers, for the duration of the contractual relationship then the same period.

Objection: every prospecting email contains an unsubscribe link, in accordance with Article L34-5 of the French Postal and Electronic Communications Code. You may also write to hello@reponse.ai. Unsubscription is processed without undue delay and does not deprive you of any service feature.

Recipients: Apollo and Clay for building prospecting lists, Resend and Amazon SES for sending, Supabase for storage, Cal.com for booking, PostHog for measurement. Notion and Klaviyo where those integrations are enabled.

Data processed: technical logs, IP addresses, timestamps, session identifiers, security events, abuse reports.

Purposes: protect accounts, detect and block intrusion attempts, fraud and abusive use, ensure the availability and integrity of the service, respond to requests from competent authorities.

Legal basis: legitimate interests, Article 6(1)(f), our interest being the security of the platform and its users. Legal obligation, Article 6(1)(c), for founded requests from authorities.

Provision of the data: this data is generated automatically by the use of the service. It does not result from a voluntary disclosure on your part and its collection cannot be separated from access to the service.

Retention: 12 months.

Recipients: Supabase, Netlify, Shmore's director, and where applicable judicial or administrative authorities upon a founded request.

10. Data processed on behalf of our customers

When you use Reponse to manage the relationship with your store's customers, you remain the controller of their data. We act as processor, on your instructions.

Categories of data concerned: content of chat conversations and tickets, identifiers and contact details of end customers (name, email, phone where provided), customer and order data synced from Shopify, order and cart history, customer reviews, loyalty points and referrals, CRM contact records, content of transactional emails and delivery, open and click events for those emails, lasting information retained about a contact (see section 13), attachments uploaded in conversations, associated activity logs.

Data read from your Shopify store: at installation, the app requests the following access, and no other:

  • customers, read and write: identity, contact details and history of the store's customers;
  • orders, read and write, and fulfillments: order contents, shipping addresses, fulfillment status and tracking;
  • products, read and write (write access is used to publish review ratings on product pages), inventory, discount codes, shipping zones and rates, markets, languages and translations;
  • storefront: published catalog and creation of carts and checkouts for the store's customers.

Two optional accesses are only requested from within the app, never at installation: reading the published theme and reading the store's legal policies (refund, shipping, privacy).

Instructions: we process this data solely to provide the service, ensure it functions correctly, respond to your support requests and comply with our legal obligations. We do not sell it and do not use it for our own commercial purposes.

Contractual framework: this processing is governed by our data processing agreement, compliant with Article 28 GDPR, entered into between you and Shmore.

Sub-processors: we use the providers listed in section 14 and on the Sub-processors page. The dated list published on that page is authoritative; you may object under the terms of the data processing agreement.

Retention: data is kept for as long as your workspace is active and according to the retention settings you define. At the end of the contract it is deleted 30 days after the contract ends. Backups, kept for 7 days, are cleared of it as they rotate, no later than 30 days after deletion.

Reversibility and export: you can request an export of your workspace data at hello@reponse.ai, during the contract or within 30 days after it ends. The export is provided in CSV or JSON format, within 30 days.

Assistance: we help you respond to your end customers' rights requests, document security measures and handle any data breach. We notify you by email of any breach affecting your data within 72 hours after becoming aware of it, in accordance with Article 33(2) GDPR. This assistance is free of charge in ordinary cases; beyond that, it is subject to a quote.

GDPR requests forwarded by Shopify: Reponse handles the three compliance webhooks Shopify requires of apps:

  • customers/data_request: when a store customer asks for their data, you are notified in Reponse, together with the reviews and review requests concerning them, so that you can answer within the 30-day deadline;
  • customers/redact: when a customer asks for erasure, their record is anonymised (it stays attached to the orders to preserve accounting records), their identifiers are deleted, and their reviews and review requests are erased or anonymised;
  • shop/redact: received 48 hours after the app is uninstalled, it removes Reponse's access to the store and the Shopify staff identities, triggers the erasure of reviews and their photos, and marks the workspace for the purge of its data.

What remains your responsibility: the legal basis for your own processing, informing your end customers, obtaining their consent where required, and the content you choose to import into the service.

11. Chat widget installed on our customers' sites

The Reponse chat widget is installed by our customers on their own website. It lets a visitor talk to the merchant's customer service, whether human or assisted by an AI agent.

Data processed by the widget: content of the messages exchanged, technical conversation identifier, page and product viewed during the conversation, number of visits to the merchant's site, browser language, timestamps, email address where the visitor chooses to leave it, and, where the visitor is signed in to their customer account on the store, the identifier of that account as passed on by Shopify. The IP address is received by our servers with each request and is used to limit abuse. The widget does not compute a browser fingerprint.

Allocation of roles:

  • for the content of conversations and the visitor data used for customer relationship purposes, the controller is the merchant who installed the widget. Reponse acts as processor, under the conditions of section 10.
  • for the strictly technical data necessary to operate, secure and keep the widget available, Reponse acts as controller, on the basis of its legitimate interests, Article 6(1)(f), consisting in running and protecting the service.

Trackers set by the widget: the widget stores, on the merchant's site domain:

  • reponse_session_id_[identifier], as a cookie (lifetime of 12 months) and in local storage: the conversation identifier, which lets the visitor find the conversation again from one page to the next. Where it is absent, the widget may reuse the visitor identifier already set by Shopify on the store;
  • reponse_visit_count and reponse_last_seen, in local storage: number of visits and date of the last visit, used to adapt how the chat is displayed;
  • reponse_launcher_config_[identifier], in local storage: a copy of the widget's display configuration, with no personal data;
  • reponse_auto_dismiss_[identifier] in local storage, reponse_auto_count_[identifier] and reponse_unread_[identifier] in session storage: remembering that the chat was closed, the number of automatic openings and unread messages.

The conversation identifier and the display preferences serve to operate the chat the visitor asks for. The visit counter is not strictly necessary to that operation: it is only stored if the visitor has accepted analytics in the store's cookie banner (on Shopify, Shopify's Customer Privacy API). Without that consent nothing is stored and any existing counter is erased.

Informing the visitor: it is for the merchant to inform the visitors of its website of the processing carried out through the widget and, where applicable, to refer to its own privacy policy.

Retention: according to the retention settings defined by the merchant, under the conditions of section 10, and 12 months for the technical logs processed under our own responsibility.

12. Customer reviews

The feature to collect and publish customer reviews is not active at this time. Once it is, Reponse will provide the tool and the merchant will decide how it is used.

Personal data contained in a review (the author's declared identity, the content of the review, the order reference) is processed by Reponse as a processor, under the conditions of section 10. The name and email address carried by a review request are erased twelve months after it is sent.

13. Use of artificial intelligence models

The service includes conversational agents and AI-assisted features. The agents generate their answers automatically, from the store's data (catalog, orders, policies, help articles) and the merchant's instructions. This section explains what is sent, to whom, and within what limits.

Model providers used: OpenAI, Google and Mistral. The service uses multi-provider routing, meaning a request may be sent to one or another of these providers depending on the model selected for the feature concerned.

Informing individuals: where a person interacts with the conversational agent, that person must be clearly informed that they are interacting with an artificial intelligence system, in accordance with Article 50 of the European Artificial Intelligence Act. In the widget, the agent speaks under the name and role the merchant gives it; a "Talk to a human" button remains available while the agent is answering, and, when a member of the merchant's team takes over, the header shows their name with the label "Store advisor". While the artificial intelligence agent is answering, the header shows an "AI" label next to its name, whose full title states that replies are generated by artificial intelligence. The merchant, who chooses the agent's name, role and welcome message, makes sure its end customers know they are talking to an AI.

What is sent: the content necessary to generate the answer, that is the current message or request, previous messages in the conversation where context is needed, and business context made available by the customer, for example product catalog excerpts, order information, help articles or configuration instructions. Personal data contained in such content may therefore be transmitted. The store's content is also converted into numerical representations (embeddings), by an OpenAI model, so that the agent can find the relevant passages.

Contact memory: where the end customer is an identified contact, a model picks out a few lasting pieces of information from the conversation (for example a preferred category, a size or a preferred contact channel) and saves them on their record, to personalise later exchanges. This information is kept with the contact record, under the rules in section 10.

What we do not do: Reponse neither trains nor fine-tunes any model on its customers' data. We do not make our customers' data available to model providers for training their models. We rely for this on those providers' commercial terms and contractual commitments, in particular their no-training-on-data modes. We use the paid API offerings of OpenAI, Google (Gemini) and Mistral, whose terms provide that the data sent is not used to train the models. Those commitments are made by each provider, and we cannot guarantee more than what they guarantee to us.

Legal basis: performance of the contract, Article 6(1)(b), where the AI-assisted feature is part of the subscribed service. Where Reponse acts as processor, the model provider is a sub-processor and the customer remains the controller.

Automated decision-making: answers generated by the AI agents assist in handling requests. No decision producing legal effects concerning individuals, or similarly significant effects within the meaning of Article 22 GDPR, is taken by an agent. The merchant can hand a conversation to a human at any time, who then takes over from the agent.

Data protection impact assessment: Shmore does not carry out a data protection impact assessment for this processing, which it performs as a processor. It is for the merchant, as controller, to assess whether such an assessment is required and, where it is, to carry it out; Shmore assists by providing the necessary information.

Retention: content sent is retained by the provider according to its own policy, for 30 days at most. Within Reponse, the conversation is kept according to the rules in section 10.

Limits: an answer generated by a model may be inaccurate. The customer retains control over configuration, the instructions given to the agent and the scope of data made available to it.

14. Processors and recipients

We do not sell your data. We use the following providers, each for a defined function. We only use providers offering sufficient guarantees within the meaning of Article 28 GDPR, under their data processing terms.

ProviderFunction
SupabaseDatabase, authentication, file storage
NetlifyHosting of the website and functions
OpenAIArtificial intelligence models
GoogleArtificial intelligence models; website audience measurement (Google Analytics 4), after consent
MistralArtificial intelligence models
StripeMerchant order payments, where that feature is enabled
ResendEmail sending
Amazon SESEmail sending
SvixDelivery of the email event notifications sent by Resend (delivery, open, click, bounce)
PostHogProduct usage measurement (European instance), after consent
Cal.comDemo booking on the website
ApolloBusiness database used for commercial prospecting
ClayBusiness database used for commercial prospecting
KlaviyoIntegration enabled at the customer's request
NotionIntegration enabled at the customer's request
TikTok ShopIntegration enabled at the customer's request
ShopifyMerchant's store platform, app installation and subscription billing (Shopify App Pricing)

Klaviyo, Notion and TikTok Shop are only enabled if the customer decides so, and only the data necessary for the integration concerned is exchanged.

The detailed list of our sub-processors, their role and their location is published and kept up to date on the Sub-processors page.

The host of the website within the meaning of the French Act on confidence in the digital economy is Netlify, whose address appears in our legal notice.

Other recipients may receive data in limited cases: our advisers, our chartered accountant and our lawyer, bound by professional secrecy, and judicial or administrative authorities upon a founded request.

15. Transfers outside the European Union

Some of our providers are established outside the European Union or may process data from third countries, in particular the United States. This is the case for some of the providers listed in section 14.

The artificial intelligence model providers call for a separate analysis:

  • OpenAI: OpenAI Ireland Ltd (Ireland) and OpenAI, L.L.C. (United States); data may be processed in the United States;
  • Google (Gemini): Google Ireland Ltd (Ireland) and Google LLC (United States); data may be processed outside the European Union;
  • Mistral: Mistral AI SAS, established in Paris (France), within the European Union.

These transfers are governed by the mechanisms provided for in Chapter V GDPR:

  • for providers established in the United States and certified, the EU-US Data Privacy Framework, on the basis of the European Commission adequacy decision of 10 July 2023;
  • failing that, the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional technical and organisational measures.

The country of processing of each provider is shown on the Sub-processors page.

Data location: the database, authentication, file storage and backups are hosted by Supabase in the eu-west-1 region, in Ireland. The website is served by Netlify's global delivery network (Netlify, Inc., San Francisco, United States), and the Netlify server functions that handle requests may run in the United States.

You can obtain a copy of the safeguards in place by writing to hello@reponse.ai.

16. Requests from foreign authorities

Several of our providers are subject to extraterritorial laws, in particular United States laws, which may lead a foreign authority to send them a request for access to data.

Our position is as follows:

  • we disclose data to an authority only on the basis of a request that is valid under the applicable law, and only within the limits of what is requested;
  • where the law does not prohibit it, we inform the customer concerned before disclosing any data relating to them, so that they can exercise their own remedies;
  • where a request appears to us manifestly unfounded, excessive or contrary to European Union law, we challenge it through the available channels;
  • where the request is addressed directly to one of our providers, our ability to act is limited to the commitments that provider has made in its own terms.

17. Security

We implement technical and organisational measures appropriate to the risk, in particular:

  • encryption of communications in transit (TLS) and encryption of data at rest by Supabase;
  • data segregation per workspace at database level (Row Level Security);
  • role and permission management within workspaces;
  • passwordless account authentication, by a one-time code sent by email or through the Shopify admin session;
  • verification of the signature of webhooks sent by Shopify;
  • verification of the signature of email event notifications, to check their origin;
  • two-factor authentication on the administration accounts of our tools (Supabase, Netlify, GitHub, Shopify Partner);
  • access to customer data restricted to Shmore's director, from France.

We claim no security certification, no external audit, no guaranteed availability level and no end-to-end encryption. No online service can guarantee absolute security.

In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we notify the CNIL within 72 hours and inform the individuals concerned where the risk is high, in accordance with Articles 33 and 34 GDPR. Where we act as processor, we inform the customer by email within 72 hours after becoming aware of it, under the conditions of section 10.

18. Your rights and how to exercise them

Under the GDPR and the French Data Protection Act, you have the following rights:

  1. Right of access: obtain confirmation that data concerning you is processed and receive a copy of it.
  2. Right to rectification: have inaccurate or incomplete data corrected.
  3. Right to erasure: request deletion of your data in the cases set out in Article 17.
  4. Right to restriction: request that processing be frozen in the cases set out in Article 18.
  5. Right to object: object to processing based on legitimate interests, on grounds relating to your particular situation, and object without condition to commercial prospecting.
  6. Right to portability: receive the data you provided to us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible.
  7. Withdrawal of consent: withdraw your consent at any time where it is the basis of the processing, without affecting the lawfulness of processing carried out before the withdrawal.
  8. Post-mortem directives: define general or specific directives on the fate of your data after your death.

Procedure:

  • Send your request to hello@reponse.ai, or by post to Shmore, 26 Thubert, 44118 La Chevrolière, France.
  • State the right you wish to exercise, the service concerned and the email address linked to your account, so that we can identify your data.
  • We respond within one month of receiving the request. This period may be extended by two months where the request is complex or where we receive a high number of requests, in which case we inform you of the extension and its reasons within the first month.
  • If reasonable doubt remains about your identity, we may ask for additional information strictly necessary for verification. We do not systematically request identity documents.
  • Exercising these rights is free of charge. A manifestly unfounded or excessive request, in particular because of its repetitive character, may be refused with reasons given.

If you are an end customer of a merchant: see section 2.3. Contact the merchant concerned, who is the controller. If you write to us, we forward your request and inform you accordingly.

Complaint: if you consider that your rights are not respected, you may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, phone +33 1 53 73 22 22, website www.cnil.fr. You may contact the CNIL directly without contacting us first, though an exchange with us often resolves the situation faster.

19. Cookies and trackers

The website and the application use cookies and similar technologies. A consent banner lets you accept or refuse non-essential trackers on your first visit. Your choice is stored in your browser under the key cookie_consent.

Three categories are used:

  • Strictly necessary trackers: operation of the service, in particular authentication (Supabase session cookies sb-…-auth-token), session security and storage of your consent choice. They do not require your consent.
  • Audience measurement: PostHog, on its European instance, disabled by default, and Google Analytics 4, loaded only after you accept (analytics_storage purpose only, _ga cookies with a lifetime of 13 months, deleted on withdrawal). Both are subject to your consent.
  • Trackers linked to integrations enabled by a customer: only where the customer concerned enables them.

The inventory of trackers, with their name, purpose, issuer and lifetime, is published in our cookie policy.

Applicable durations: your choice is timestamped and stored in your browser together with the banner version (keys cookie_consent, cookie_consent_at and cookie_consent_version); it is valid for 6 months, after which the banner is shown to you again. The _ga cookies have a lifetime of 13 months, the PostHog tracker 12 months.

You may change your choice at any time through the "Manage cookies" link in the website footer: the banner is shown again, and a refusal deletes any audience measurement cookies already set. Refusing non-essential trackers does not limit access to the service.

20. Minors

The service is reserved for adult professionals and is not intended for minors. We do not knowingly collect data relating to minors for our own purposes. If data relating to minors appears in content processed on behalf of a customer, it is for that customer, as controller, to have a valid legal basis and to obtain the required consent where applicable.

21. Job applications and suppliers

If you send us a job application, or if you are the contact person of one of our suppliers, we process the data you give us (identity, contact details, content of the application or of the exchanges) to handle the application or the supplier relationship, on the basis of pre-contractual steps or the contract, Article 6(1)(b), and of our legitimate interests, Article 6(1)(f). An unsuccessful application is kept for 2 years; supplier contact data, for the duration of the relationship then 5 years.

22. Sale, merger or cessation of business

In the event of a merger, contribution, full or partial sale of the business, or any other transaction transferring all or part of the company, data may be transferred to the acquirer, within the limits necessary to continue the service and subject to maintaining the level of protection described in this policy. Data subjects are informed before the transfer and retain all their rights, in particular their right to object and their right to erasure.

In the event of cessation of business, data is deleted or returned to the customers acting as controllers, subject to retention periods imposed by law, in particular accounting and tax periods. Customers are informed by email at least 30 days in advance and may, during that period, request an export of their data under the conditions of section 10.

23. Relationship with the other documents

This policy is to be read together with the other contractual documents of the service: the terms of sale, which govern both the sale and the use of the service, and, for processing carried out on behalf of a customer, the data processing agreement referred to in section 10. In the event of a contradiction on the processing of personal data, this policy and the data processing agreement prevail.

24. Changes to this policy

We may amend this policy to reflect changes to the service, to our providers or to applicable law. The last updated date appears at the top of the document. Any change is announced by email and by the last updated date on this page. In the event of a substantial change, in particular a new purpose or a change of legal basis, we inform affected users by email before it takes effect.

This version 1.0 has been in force since 23 September 2026. Previous versions are available on request at hello@reponse.ai.

25. Language

This policy is published in French and English. In the event of any discrepancy between the two versions, the French version prevails.

26. Contact us

For any question about this policy or the processing of your data: