Privacy Policy

replypool.com

How KeepFlow L.L.C-FZ gathers, handles, discloses, and safeguards personal data across replypool.com and the services delivered through it.

Provider: KeepFlow L.L.C-FZ · Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Licence / Formation No. 2646796.01 / 2646796 · Effective date: 19 March 2026
Website: https://replypool.com
Contact: support@replypool.com

This document is drafted and published on replypool.com in English only.

In this Privacy Policy, KeepFlow L.L.C-FZ — below “KeepFlow”, “we”, “us”, or “our” — describes what happens to personal data handled through the replypool.com website, the platform itself, its integrations, our support desk, and our marketing work — and sets out which rights data protection law gives you and how to use them.

Summary of key points

  • We wear two hats: for our own operations (accounts, billing, marketing) we decide how data is used; for support conversations and similar material our business customer decides, and we simply follow its instructions.
  • The data we hold falls into familiar groups — contact details, account records, billing history, device and usage telemetry, correspondence, and whatever content customers route through the platform.
  • Personal data is never sold. It reaches only our vendors, affiliates, advisers, authorities when the law demands it, and parties to a corporate deal — each under suitable safeguards.
  • Processing can take place in the U.A.E. and elsewhere; where the law calls for transfer safeguards, we put them in place.
  • We keep data only while a purpose or legal duty exists, and we protect it with proportionate security controls — though no online system is ever fully risk-free.
  • Depending on where you live, you can ask to see, fix, erase, restrict, export, or object to our use of your data — write to support@replypool.com.
  • Marketing email is optional and every message lets you unsubscribe; operational notices about your account keep arriving either way.

1. When this policy applies and our role

1.1 Coverage

The policy covers personal data gathered when you browse the Website, book a demo, open an account, sign a contract or pay an invoice, talk to our support team, or use the Services day to day. It equally covers newsletter subscriptions, webinars and events we host, and any other business dealing between you and us.

1.2 Controller or processor

Context determines whether we act independently as a controller, or instead as a processor (service provider) engaged by a business customer. When a customer runs support conversations, tickets, knowledge-base files, end-user messages, or comparable operational material through the platform, it is normally that customer who sets the purposes and means of processing. There, the customer is the controller of record, and we handle the data only as instructed and as our contract with that customer allows.

1.3 If you are an End User

Did you chat with a company that happens to use our platform? Questions about what was said in that conversation belong with that company in the first instance. Where it is appropriate, we help our customer answer such requests.

2. The data we hold

2.1 Data you hand to us

Who you are and how to reach you: name, the company you work for, your role there, email, phone, mailing address, and comparable professional contact details.

Your account: username, sign-in identifiers, authentication metadata, assigned role and permissions, organisation record, and saved preferences.

Money matters: billing address, plan details, invoices, payment status, tax information, and the limited payment data a payment processor passes back to us.

Conversations with us: emails, messages, notes from calls, feedback, survey answers, demo bookings, and support tickets.

Marketing choices: what you subscribed to, which consents you gave, and how you engaged with our mailings.

2.2 Data collected as you use the service

Device and connection details: IP address, browser, device identifiers, operating system, session identifiers, timestamps, a rough location derived from the IP, and diagnostic logs.

Behaviour inside the product: which pages and features you open, clicks, navigation routes, connection settings, consumption volumes, event logs, and aggregate service statistics.

Data written by cookies and kindred technologies — the Cookie Policy covers these in detail.

2.3 Customer Content

Whatever a customer feeds into or pushes through the platform: prompts and instructions, tickets, dialogue histories, attachments, knowledge sources, helpdesk metadata, and similar operational material.

2.4 Where it comes from

Straight from you — each time you register, ask for a demo, subscribe, write to us, join an event, fill in a form, wire up an integration, or upload something.

From the technology itself — cookies, server logs, APIs, device signals, and other telemetry generated while the Website and Services run.

From our customers and their users — say, when a colleague is invited onto an account, a data source is connected, an integration is configured, or a support request is filed.

From outside parties — payment processors, analytics vendors, cloud and infrastructure suppliers, communication tools, integration partners, resellers, identity providers, and public business registries or directories.

3. Why we process data, and on what legal footing

3.1 Legal grounds

Every processing operation rests on a legal basis recognised by the law that applies to it: fulfilling a contract with you, meeting a legal duty, pursuing our legitimate interest in running and developing the business, acting on your consent, or another ground the applicable law accepts.

3.2 Purposes

  1. creating and running accounts, verifying who signs in, enforcing access rules, and delivering the Services;
  2. taking in, storing, retrieving, and analysing Customer Content — and producing Outputs from it — so the platform works for our customers;
  3. charging payments, administering subscriptions, issuing invoices, keeping accounting records, and stopping payment fraud;
  4. watching performance, fixing faults, keeping the platform secure, spotting abuse, auditing usage, and raising quality and reliability;
  5. onboarding, training, technical help, and ongoing account management;
  6. messaging you about your account, your subscription, service updates, legal notices, and policy revisions;
  7. sending marketing where the law and your preferences allow it, and checking whether those campaigns work;
  8. meeting legal duties, enforcing our contracts, bringing or defending claims, guarding our rights, and answering lawful demands from courts, regulators, or public bodies;
  9. supporting corporate transactions, internal reporting, due diligence, or financing — lawfully and with fitting safeguards.

4. Who receives personal data

4.1 No selling

Personal data is not something we sell, in any ordinary sense of that word.

4.2 Categories of recipients

Disclosure happens only where a purpose named in this policy requires it, and always under fitting contractual and organisational protections, to:

  • companies in our own group, where service delivery, administration, compliance, finance, or support makes it relevant;
  • vendors and subprocessors behind our hosting, infrastructure, analytics, security, communications, support tooling, payment handling, identity management, model inference, and similar operations;
  • third-party services and integrations you decide to connect, at your own request;
  • lawyers, accountants, insurers, auditors, and financing counterparties, all bound by confidentiality;
  • state, regulatory, tax, or law-enforcement bodies when disclosure is legally required or permitted;
  • current or potential acquirers, investors, or merger parties during a corporate deal, under confidentiality arrangements.

5. Transfers across borders

Storage and processing can happen in the United Arab Emirates and in any other country where we or our suppliers run operations. Your data may therefore travel to jurisdictions whose privacy rules differ from those at home.

Wherever the applicable law demands it, we back such transfers with recognised safeguards — contractual clauses, adequacy mechanisms, or other lawful transfer instruments. By supplying data to us and using the Services, you accept that this kind of cross-border handling can occur.

6. Keeping data safe

6.1 Our controls

We run organisational, technical, and administrative controls proportionate to the risk: access restrictions and role-based permissions, activity logging, encryption on the wire and — where fitting — at rest, vetting of suppliers, incident-response routines, and internal confidentiality rules. Their aim is to stop unlawful or unauthorised access, loss, misuse, tampering, or exposure.

6.2 What we cannot promise — and your part

No internet transmission and no storage system is beyond compromise, so absolute security is not something anyone can guarantee. On your side: pick strong credentials, grant access sparingly, configure permissions with care, and keep your own security measures in order while using the Services.

6.3 If something goes wrong

Should a breach touch personal data under our responsibility, we act as applicable law and our contracts require — including sending notifications wherever the law makes them mandatory.

7. How long data is kept

Data stays with us no longer than reasonably needed for the purposes it was gathered for: running the Services, keeping business records, honouring legal duties, settling disputes, enforcing contracts, blocking fraud, and defending our rights and other people’s.

The exact period depends on the kind of data, the plan involved, technical and operational constraints, and legal or contractual requirements. Once the need ends, the data is erased, anonymised, or moved to secure archive, as the law and our retention practice dictate.

8. Rights you can exercise

8.1 The rights

Depending on the law that governs your situation and the context of the processing, you may be entitled to: a copy of your data; correction of anything wrong or incomplete; erasure; a freeze on further processing; a portable export; an objection to particular uses; and withdrawal of any consent you previously gave. A complaint to the competent supervisory authority is also open to you.

8.2 Making a request

Send requests to support@replypool.com or through the channels listed on the Website. Expect us to ask for whatever is needed to confirm your identity and pin down what exactly you want. Where our only role is processor for one of our customers, we may pass your request to that customer or help them handle it, as our contract provides.

8.3 Limits

Using your rights never triggers worse treatment from us. That said, none of these rights is unconditional: statutory exceptions, technical constraints, and duties that force us to keep certain records can all narrow them.

9. Marketing messages

Where the law lets us, we share product news, announcements, event invitations, and offers. Opting out of anything promotional takes one click on the unsubscribe link — or a note to us — at any moment.

An opt-out does not silence the messages we must send anyway: account administration, service delivery, replies to your support requests, and legally required notices.

10. Cookies

Cookies, local storage, pixels, SDKs, and similar tools — ours and our partners’ — keep the Website and Services running, remember your choices, power analytics, and, where relevant, assist marketing. The Cookie Policy lists the kinds of cookies involved and the ways to control them.

11. Other people’s services

Links to outside websites, documentation hubs, helpdesks, messaging channels, file-storage tools, and the like may appear in the Website and Services. How those third parties treat privacy, security, or content is theirs to answer for, not ours — so read their notices before you interact with them or switch on an integration.

12. Children

This is a product for businesses, not for children, and we do not knowingly gather children’s data in breach of the law. If you suspect a child has supplied data to us unlawfully, let us know and we will act on it.

13. Revisions to this policy

Legal, technical, or business developments may prompt updates to this text. A materially revised version goes up on the Website, sometimes accompanied by notice inside the Services or by email. The effective date shown at the top tells you when the current wording took effect.

14. Reaching us

Questions about this policy or our privacy practice go to KeepFlow L.L.C-FZ at support@replypool.com, or by post to Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.