SoftReply is live in beta — email, chat and phone carry real traffic today.Try it out →
Legal

Privacy Policy

Last updated 20 June 2026
i

Working template — plain-language scaffolding that reflects how SoftReply actually handles data. Have counsel review and adapt it before you publish or rely on it.

This policy explains what personal data Skiwo AS processes, why, and the choices you have. It covers our website and the SoftReply application.

1. Who we are

For your account and website data, Skiwo AS is the data controller. For the customer data you bring into the app, you are the controller and SoftReply is your processor under the Data Processing Addendum.

2. Data we process

Account data: names, work email, workspace settings and billing details.

Customer communications: to provide the inbox and analytics, we store a copy of the messages, drafts and review history in your workspace. We need this copy to display conversations and generate reports — we do not re-fetch them from your storage on demand.

Usage data: logs, device and diagnostic information used to operate and secure the service.

3. How we use data

To provide the service: routing messages, drafting replies, recording review provenance, and producing reports.

To secure and improve the service, to handle support, and to meet legal and billing obligations. We do not sell personal data.

4. Legal bases (GDPR)

We rely on performance of a contract, our legitimate interests in operating and securing the service, your consent where required (for example, marketing cookies), and compliance with legal obligations.

5. Where data is stored

The platform and the copies we store are hosted in the European Union. Outbound mail and its associated storage run in your own AWS account, in the region you choose.

Where any transfer outside the EEA occurs, we rely on appropriate safeguards such as Standard Contractual Clauses.

6. Subprocessors

AWS — core infrastructure and hosting (EU).

Your AWS account — outbound email (SES), delivery events (SNS) and storage (S3), in your region.

An AI model provider — draft generation, region-routed within the EU.

Stripe — subscription billing only; it does not receive your customer communications.

7. Retention

We keep customer data for as long as your workspace is active and according to the retention settings you choose. After termination you have 30 days to export, then we delete or anonymise the data.

8. Your rights

Subject to applicable law, you may access, correct, export, restrict or delete personal data, and object to certain processing.

For data you control as a controller, we will help you respond to your customers’ requests. To exercise your own rights, contact privacy@softreply.com.

9. Security

We use encryption in transit and at rest, role-based access, tenant isolation and audit logging. See the Security page for detail. We are transparent that we are not SOC 2 or ISO 27001 certified today.

10. Cookies

Our website uses essential cookies and, with consent, limited analytics. You can manage preferences in your browser and our cookie banner.

11. Children

SoftReply is a business tool not directed to children, and we do not knowingly collect data from them.

12. Changes & contact

We will post updates here and date them. Privacy questions and our Data Protection contact: privacy@softreply.com.

Questions about this document? Write to legal@softreply.com.