Legal
Privacy Policy
Last updated 15 August 2026 · Applies to Replio (replio.talivio.com)
1. Who we are
Replio is operated by Talivio Technology OÜ, a company registered in Estonia. Because we are established in the European Union, our processing is governed by the General Data Protection Regulation (GDPR).
Contact: [email protected]
2. Our role
Replio is a tool that businesses use to answer their own customers on WhatsApp. That creates two distinct relationships, and they matter for your rights:
- For our customers' end-customers — the people who send WhatsApp messages to a business using Replio — we act as a processor. The business is the controller and decides what happens to those conversations. If you are one of these people, please direct requests to the business you messaged; we will support them in answering you.
- For our own account holders — the businesses that sign up for Replio — we act as a controller for their account and billing data.
3. What we process
WhatsApp conversation data, received from and sent through the WhatsApp Business Platform:
- message content (text and, where used, attached media)
- the phone numbers on both sides of the conversation
- WhatsApp message identifiers, timestamps, and delivery/read status
- the raw webhook payload as received, for troubleshooting and to prevent duplicate processing
Account data for the businesses using Replio: name, email address, a hashed password, workspace membership and role.
Billing data: subscription plan, usage counts, and payment status. Card details are entered directly with Stripe and never reach our servers.
We do not sell personal data, we do not use it for advertising, and we do not use conversation content to train our own models.
4. Why we process it
- Contract — delivering the service the business signed up for: receiving, storing, displaying and sending WhatsApp messages on their behalf.
- Legitimate interests — keeping the service secure, preventing abuse, and diagnosing faults.
- Legal obligation — retaining invoicing records for the period Estonian law requires.
5. Who else is involved
We use a small number of subprocessors. Each receives only what it needs:
- Meta Platforms Ireland Ltd. — the WhatsApp Business Platform (Cloud API) carries every message in and out. This is unavoidable: it is the messaging network itself.
- Anthropic, reached through the Talivio AI Gateway — used only when a business turns AI mode on. In that case the recent conversation is sent to generate a suggested reply. With AI mode off, no message content leaves our infrastructure for this purpose.
- Stripe — subscription payments and card processing.
- Our hosting and infrastructure providers — servers located in the European Union.
6. How long we keep it
Conversation data is kept for as long as the business keeps its Replio account, because the conversation history is the product. When an account is closed, its data is deleted. A business can also have any individual customer's data erased at any time — see below.
7. Access and erasure
Replio implements the GDPR rights of access and erasure at the level of an individual customer: everything held about one phone number can be exported, or erased, on request.
We want to be precise about what erasure does, because "we delete everything" would be the easy sentence and it would not be true. On erasure, the message content is permanently overwritten — the text, the media and the raw payload are gone and cannot be recovered. What remains is an empty record of the message identifier. That record exists for one reason: WhatsApp can re-deliver a webhook for a message we have already seen, and without it a delayed re-delivery would silently recreate the very data that was just erased. It holds no content.
You also have the rights to rectification, restriction, objection, and data portability, and the right to lodge a complaint with a supervisory authority — in our case the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
To exercise any of these, write to [email protected]. If you messaged a business that uses Replio, contact that business first — they decide what happens to your conversation.
8. Security
Traffic is encrypted in transit. Access tokens are encrypted at rest. Every incoming webhook is verified by cryptographic signature before it is accepted, and each business's data is isolated from every other business's data at the database query level.
9. Changes
If this policy changes materially, we will update the date at the top of this page and notify account holders by email.
This policy covers Replio specifically. For Talivio Technology OÜ as a company, see the Talivio privacy policy.