Privacy Policy

Last updated: 19 July 2026

How ReplyEveryReview collects, uses and protects personal information.

1.1 About this policy

This Privacy Policy explains how ReplyEveryReview collects, uses, stores and shares personal information when a person visits the website, creates or uses an account, purchases or enquires about the service, uses a customer or agency workspace, communicates with ReplyEveryReview, or appears in a public online conversation processed through the service.

ReplyEveryReview is a managed public-conversation discovery, AI-scoring and reply-management service. It helps businesses identify relevant public discussions, including recommendation requests, buying-intent conversations, competitor complaints, public feedback and other discussions connected to a customer's products, services, industry or market. Relevant findings may be scored, summarised and organised using automated systems. Suggested replies may be prepared for human review. Replies are not automatically published by default.

1.2 Who we are

ReplyEveryReview is a trading name operated by Lewis Clarke, a sole trader. For the purposes of applicable UK data-protection law, Lewis Clarke trading as ReplyEveryReview is generally the data controller for the personal information described in this Privacy Policy. In some circumstances, ReplyEveryReview may process information on the documented instructions of a business customer. Where ReplyEveryReview acts as a processor, the Data Processing Addendum applies.

1.3 Information we collect

Account and identity information: name, business name and job role; email address and telephone number; account identifiers, user roles and authentication information; agency, customer, staff or administrator account type; information about authorised users connected to an account. Passwords are intended to be handled securely through the authentication provider and are not intended to be visible to ReplyEveryReview staff.

Business profile and onboarding information: business name, website, industry and description; products, services and target customers; locations served, keywords and search phrases; competitor names and common customer problems; tone of voice, reply preferences and approval requirements; topics, claims or phrases to avoid; examples of suitable and unsuitable replies. Customers should not submit unnecessary or sensitive personal information through the business profile.

Subscription and transaction information: selected plan and billing frequency; payment status, invoice details and transaction identifiers; purchased add-ons, top-ups, usage and plan allowances; renewal, cancellation and refund information; limited payment-related details received from the payment provider. Payments may be processed through Stripe or another authorised payment provider. ReplyEveryReview does not normally receive or store complete payment-card numbers.

Public-conversation information: public usernames, display names and limited public profile information; post, review, caption or comment text; conversation titles, summaries, source URLs and platform names; publication dates and publicly visible engagement information; keywords, services, products or competitor names mentioned; publicly stated or reasonably apparent general location information; relevance, intent, urgency, sentiment and reply-suitability indicators; AI-generated scores, classifications and workflow status. Information is not treated as exempt from data-protection requirements merely because it was posted publicly. ReplyEveryReview aims to collect only the information reasonably necessary to identify, assess and present a relevant public conversation.

Reply, approval and workflow information: AI-assisted reply drafts and summaries; customer or staff edits; approval, rejection, publication and completion status; internal notes and feedback; the identity of the authorised user taking an action; audit information showing when an action occurred.

Technical, usage and communication information: IP address, browser, device and operating-system information; login history, session information and security logs; pages and dashboard functions used; error, diagnostic and performance information; cookie and consent preferences; support enquiries, complaints, survey responses and other communications.

1.4 Where information comes from

  • directly from the person using or contacting ReplyEveryReview
  • from an employer, agency, customer or account administrator
  • from publicly accessible websites, platforms and online discussions
  • through authorised search, monitoring and public-data providers
  • from authentication, hosting, payment, email and security providers
  • from cookies and similar technologies
  • from publicly available business sources

Third-party platforms remain responsible for their own privacy practices and for how they originally collected or published information.

1.5 Why we use information and our lawful bases

Providing and administering the service. ReplyEveryReview uses information to create accounts, authenticate users, complete onboarding, configure monitoring campaigns, run searches, organise findings, produce AI-assisted scores and summaries, prepare suggested replies, operate approval workflows, generate reports, process payments, manage subscriptions and provide support. The lawful basis will normally be performance of a contract or taking steps requested before entering into a contract.

Discovering and assessing public conversations. ReplyEveryReview may process limited public-conversation information to identify conversations matching customer criteria, detect recommendation requests and buying intent, identify competitor complaints and alternative requests, assess relevance and suitability, remove duplicates and display useful findings. The lawful basis will generally be the legitimate interests of ReplyEveryReview and its business customers. Before relying on legitimate interests, ReplyEveryReview considers whether the processing is necessary and proportionate, what a person may reasonably expect, and whether the person's rights override those interests.

Security, legal compliance and service improvement. Information may be processed to prevent unauthorised access, investigate misuse, protect systems, maintain audit records, comply with legal duties, establish or defend legal claims, diagnose errors, evaluate search quality and improve the service. The lawful basis may be legitimate interests or compliance with a legal obligation. Where consent is required for analytics or similar technologies, ReplyEveryReview relies on consent.

Marketing. ReplyEveryReview may use business contact information to send relevant service information. Where required, consent will be obtained; otherwise ReplyEveryReview may rely on legitimate interests for proportionate business-to-business communications. Every electronic marketing message will provide an unsubscribe method. Marketing opt-outs may also be sent to support@replyeveryreview.co.uk.

1.6 AI scoring and automated processing

ReplyEveryReview uses automated and AI-assisted systems to categorise public conversations, calculate relevance or opportunity scores, identify possible sentiment or buying intent, summarise findings, prioritise results, detect unsuitable content and generate suggested replies. Scores, summaries and suggested replies are indicators and drafting aids rather than verified statements of fact. They support human review and are not intended to make decisions producing legal or similarly significant effects on the person who wrote the public content.

ReplyEveryReview does not use these scores to determine whether a person receives employment, credit, insurance, healthcare, legal action or another significant outcome. An authorised customer or staff user must review the original source and decide whether a reply is suitable. A person may contact privacy@replyeveryreview.co.uk to ask about processing involving their information or to object to a relevant classification.

1.7 Sensitive information and children

ReplyEveryReview is not designed to deliberately collect or profile people based on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic information, biometric identification, health information, sex life or sexual orientation. Public conversations may occasionally contain sensitive information; ReplyEveryReview aims to minimise, restrict or delete it where it is not necessary. Customers must not configure campaigns designed to target, discriminate against or exploit people based on protected or sensitive characteristics.

The service is intended for business users aged 18 or over and is not directed at children. Where a finding appears to have been posted by or substantially concerns a child, ReplyEveryReview may remove or restrict the finding where the information is not necessary.

1.8 Information obtained indirectly from public sources

ReplyEveryReview cannot normally provide an individual privacy notice to every person whose public post appears in a search result. Instead, ReplyEveryReview publishes this Privacy Policy, limits processing to publicly accessible information, does not access private messages or restricted accounts without authority, minimises the data retained, provides an accessible rights-request process, applies defined retention periods, restricts sensitive-information processing and keeps replies under human approval. Where direct notification is reasonably possible and proportionate, or legally required, ReplyEveryReview will take appropriate steps to provide it.

1.9 Who we share information with

  • hosting, cloud, database and authentication providers, including Supabase where used
  • payment providers, including Stripe where used
  • AI and language-model providers, including OpenAI where used
  • authorised public-source search or collection providers
  • email, support, analytics, performance and security providers
  • professional advisers, insurers, regulators, courts or public authorities where required

Information may also be shared with an agency managing a customer account, authorised users belonging to the same customer workspace, or a buyer or successor as part of a genuine business restructuring or sale. Service providers are required to use information only for authorised purposes and subject to appropriate contractual and security requirements. ReplyEveryReview does not sell personal information to data brokers.

1.10 Customer and agency responsibilities

Customers and agencies are responsible for ensuring they have authority to provide information, that account users are authorised, that monitoring instructions are lawful and proportionate, that replies are reviewed before use, that public engagement complies with law and platform rules, and that their own privacy information accurately explains how they use findings. An agency must have appropriate authority from every client it manages. Customers must not instruct ReplyEveryReview to collect private or unlawfully obtained information, target people using sensitive characteristics, create discriminatory profiles, identify anonymous users unnecessarily, monitor people for personal disputes, or use findings for legal or similarly significant decisions.

1.11 International transfers

Some providers may process information outside the United Kingdom. Where a restricted international transfer takes place, ReplyEveryReview will use an appropriate safeguard where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful transfer mechanism.

1.12 Retention

ReplyEveryReview retains personal information only for as long as reasonably necessary. Unless a longer period is required by law, an active dispute, fraud investigation or legal claim, the following periods apply:

InformationTypical retention period
Account and business-profile informationWhile the account is active and up to 24 months after closure.
Unreviewed public findingsUp to 90 days from collection.
Rejected, irrelevant or duplicate findingsNormally deleted or anonymised within 90 days after the decision. A minimal fingerprint may be retained to prevent repeated collection.
Relevant finding metadataUp to 12 months from discovery.
Copied public text or screenshotsNormally deleted within 90 days after review. A source URL and limited summary may be retained for the applicable finding period.
AI scores, summaries and rejected draftsUp to 12 months.
Approved replies and completed workflowsUp to 24 months after completion.
Customer reportsWhile the account is active and up to 24 months after closure.
Payment, tax and accounting recordsUp to six years, or longer where required by law.
General support recordsUp to 24 months after closure of the matter.
Formal complaints and disputesUp to six years after resolution where reasonably necessary.
Security and access logsUp to 12 months, or longer where connected to an incident or claim.
Cookie-consent recordsUp to 24 months or until a newer choice replaces them.
BackupsDeleted information may remain in protected backups for up to 35 days before automatic overwrite.

Information may be deleted or anonymised earlier where it is no longer necessary, a valid objection or deletion request applies, it was collected in error, or continued retention creates disproportionate privacy risks. Marketing suppression records may be retained for as long as needed to respect an opt-out.

1.13 Security and personal-data incidents

ReplyEveryReview uses reasonable technical and organisational measures intended to protect personal information, which may include role-based access controls, secure authentication, encrypted transmission, restricted production access, logging, supplier assessment, backup procedures and incident-response processes. Where a confirmed personal-data breach affects information processed for a customer, ReplyEveryReview will notify the affected customer without undue delay. Where ReplyEveryReview acts as controller, it will assess whether notification to the Information Commissioner's Office or affected individuals is legally required. Suspected privacy or security incidents should be reported to privacy@replyeveryreview.co.uk. No online system can guarantee complete security; customers must protect login credentials and promptly report suspected unauthorised access.

1.14 Your data-protection rights

Depending on the circumstances, a person may have the right to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and a review of relevant automated processing. Some rights are subject to legal conditions and exemptions. Requests should be sent to privacy@replyeveryreview.co.uk. Where a request concerns public online content, it helps to provide the public username, relevant platform, source URL, description of the content and requested action. Identity may need to be verified before a request is completed.

1.15 Complaints

Please contact privacy@replyeveryreview.co.uk first so that ReplyEveryReview can investigate. A person also has the right to complain to the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.

1.16 Third-party websites and platforms

The service may link to public posts, social platforms and third-party websites. Those third parties operate under their own terms and privacy policies. ReplyEveryReview does not control their independent privacy practices.

1.17 Changes to this policy

ReplyEveryReview may update this Privacy Policy to reflect legal, technical or service changes. The latest version will be published with an updated revision date. Where a material change affects how personal information is used, reasonable steps will be taken to notify affected users.

1.18 Contact