Privacy Policy
Last updated: 13/01/2026
This privacy policy aims to inform client establishments of Répondia how their personal data are collected and processed in connection with the provision of the Répondia solution.
Répondia provides a solution enabling establishments to manage missed calls and, depending on their configuration, to contact their customers via WhatsApp, qualify requests, provide information, and assist with the management of reservations and related requests.
In accordance with the GDPR, information relating to data processing must be provided in a concise, transparent, intelligible and easily accessible manner.
1. Identity of the data controller
The controller of personal data processed in the context of the commercial relationship between Répondia and its client establishments is:
REPONDIA SAS
16 Bis boulevard de Montréal, 06200 Nice, France
Confidentiality contact / DPO
Natan Darhi
natan.darhi@repondia.com
2. Scope
This policy covers the processing of personal data carried out by Répondia:
to manage the relationship with client establishments;
to administer accounts, access, contracts, exchanges and billing;
to provide support, maintenance, security and operation of the solution;
to enable the configuration and use of the solution by establishments.
It does not, on its own, constitute the information that establishments must provide to their own end customers. Indeed, when Répondia processes end-customer data on behalf of the establishment, the establishment generally acts as the data controller and Répondia as the processor, according to the instructions and parameters defined by the establishment. This division of roles must be expressly formalised.
3. Personal data processed concerning establishments
Répondia may process the following categories of data concerning representatives, authorised users or contacts of the establishments:
professional identity;
service login and access data;
contractual information;
billing information;
customer support data;
technical logs relating to the use of the service;
account configuration information, including certain settings linked to the WhatsApp Business account used in connection with the service.
4. Purposes of processing
The data of establishments are processed for the following purposes:
creation and management of the client account;
provision of the Répondia solution;
service configuration in accordance with the parameters defined by the establishment;
management of access rights and authorisations;
performance of the contractual relationship;
support, assistance and maintenance;
security, monitoring and incident prevention;
billing, accounting and administrative management;
improvement of the service’s operation and quality monitoring.
5. Legal bases
The processing carried out by Répondia in relation to establishments is based mainly on:
performance of the contract or pre-contractual measures;
Répondia’s legitimate interest in ensuring the security, support, maintenance, technical traceability and improvement of its services;
compliance with legal obligations, in particular accounting, tax and evidential obligations.
6. Retention periods
Unless a contrary legal obligation or a specific evidential need applies:
operational, support and service data are retained for 3 months;
data relating to missed calls, conversations and associated operational items are retained for 3 months, unless an extraction is provided to the client before deletion;
contractual and billing data are retained for 5 years, or longer if required by applicable regulations.
The data are then deleted or, where applicable, retained in archived form where this is legally required. The principle of storage limitation is expressly provided for by the GDPR, and the CNIL reminds organisations that a retention period must be defined according to the purpose pursued.
7. Recipients of the data
The following may access the data, within the scope of their responsibilities:
authorised Répondia teams;
technical service providers acting on behalf of Répondia;
administrative or judicial authorities where required by law.
8. Processors and technical tools
Répondia relies on certain technical service providers to deliver its service, in particular:
Twilio, for sending messages via the WhatsApp API according to the deployed architecture;
Meta / WhatsApp, in the context of using the WhatsApp Business platform;
Google Cloud Platform, notably via Cloud Run and Firestore, with principal hosting declared in the EEA;
Firebase, notably for application functions including authentication and Firestore;
FlutterFlow, as a front-end development tool.
Depending on the establishment’s configuration, Répondia may also interact with third-party booking tools such as Zenchef or TheFork.
The GDPR requires that any use of a processor be contractually governed, and that the use of further processors be authorised and transparent.
9. Hosting and transfers
Répondia states a principal hosting arrangement within the EEA.
However, certain technical providers used in the service chain, particularly within the WhatsApp Business ecosystem, may involve processing or access outside the EEA. Where such a transfer occurs, it must be governed by an appropriate mechanism within the meaning of the GDPR, in particular an adequacy decision or standard contractual clauses where required.
10. Security
Répondia implements security measures appropriate to the nature of the processing, including in particular:
encryption in transit;
encryption at rest;
segregation by establishment;
internal access rights management;
restriction of support access;
incident management procedures;
security reviews and testing.
The CNIL reminds organisations that processors and controllers must implement appropriate technical and organisational measures in light of the risk.
11. End-customer data of establishments
Within the scope of the service, Répondia may process certain data of the establishments’ end customers on their behalf, in particular:
telephone number;
surname or first name;
message content;
preferences and requests relating to the reservation;
date, time and number of covers;
call transcription;
exchange history;
technical data necessary for the operation of the service.
Some more sensitive information may be provided by end customers in the free text of exchanges, such as allergies, accessibility needs or special requests. This information is processed solely to fulfil the request made to the establishment and is transmitted to the establishment as part of the service.
Répondia specifies that end-customer data are not used to train general-purpose models.
12. Artificial intelligence
Répondia uses automated assistance mechanisms to:
qualify requests;
generate responses;
suggest reservations;
extract certain useful information;
produce summaries;
direct or route certain requests.
To Répondia’s knowledge, these automations do not, on their own, lead to a decision producing legal effects or similarly significant effects on the data subject. Human intervention on the establishment’s side remains possible.
13. Rights of individuals
Representatives of establishments have, as applicable, the rights of access, rectification, erasure, restriction, objection and, where applicable, portability.
These rights may be exercised with Répondia at the following address:
If they experience any difficulty, data subjects may also lodge a complaint with the CNIL.
14. Update
Répondia may amend this policy to reflect any legal, technical or operational developments. The version in force is the version published on the medium communicated to establishments.
This privacy policy aims to inform client establishments of Répondia how their personal data are collected and processed in connection with the provision of the Répondia solution.
Répondia provides a solution enabling establishments to manage missed calls and, depending on their configuration, to contact their customers via WhatsApp, qualify requests, provide information, and assist with the management of reservations and related requests.
In accordance with the GDPR, information relating to data processing must be provided in a concise, transparent, intelligible and easily accessible manner.
1. Identity of the data controller
The controller of personal data processed in the context of the commercial relationship between Répondia and its client establishments is:
REPONDIA SAS
16 Bis boulevard de Montréal, 06200 Nice, France
Confidentiality contact / DPO
Natan Darhi
natan.darhi@repondia.com
2. Scope
This policy covers the processing of personal data carried out by Répondia:
to manage the relationship with client establishments;
to administer accounts, access, contracts, exchanges and billing;
to provide support, maintenance, security and operation of the solution;
to enable the configuration and use of the solution by establishments.
It does not, on its own, constitute the information that establishments must provide to their own end customers. Indeed, when Répondia processes end-customer data on behalf of the establishment, the establishment generally acts as the data controller and Répondia as the processor, according to the instructions and parameters defined by the establishment. This division of roles must be expressly formalised.
3. Personal data processed concerning establishments
Répondia may process the following categories of data concerning representatives, authorised users or contacts of the establishments:
professional identity;
service login and access data;
contractual information;
billing information;
customer support data;
technical logs relating to the use of the service;
account configuration information, including certain settings linked to the WhatsApp Business account used in connection with the service.
4. Purposes of processing
The data of establishments are processed for the following purposes:
creation and management of the client account;
provision of the Répondia solution;
service configuration in accordance with the parameters defined by the establishment;
management of access rights and authorisations;
performance of the contractual relationship;
support, assistance and maintenance;
security, monitoring and incident prevention;
billing, accounting and administrative management;
improvement of the service’s operation and quality monitoring.
5. Legal bases
The processing carried out by Répondia in relation to establishments is based mainly on:
performance of the contract or pre-contractual measures;
Répondia’s legitimate interest in ensuring the security, support, maintenance, technical traceability and improvement of its services;
compliance with legal obligations, in particular accounting, tax and evidential obligations.
6. Retention periods
Unless a contrary legal obligation or a specific evidential need applies:
operational, support and service data are retained for 3 months;
data relating to missed calls, conversations and associated operational items are retained for 3 months, unless an extraction is provided to the client before deletion;
contractual and billing data are retained for 5 years, or longer if required by applicable regulations.
The data are then deleted or, where applicable, retained in archived form where this is legally required. The principle of storage limitation is expressly provided for by the GDPR, and the CNIL reminds organisations that a retention period must be defined according to the purpose pursued.
7. Recipients of the data
The following may access the data, within the scope of their responsibilities:
authorised Répondia teams;
technical service providers acting on behalf of Répondia;
administrative or judicial authorities where required by law.
8. Processors and technical tools
Répondia relies on certain technical service providers to deliver its service, in particular:
Twilio, for sending messages via the WhatsApp API according to the deployed architecture;
Meta / WhatsApp, in the context of using the WhatsApp Business platform;
Google Cloud Platform, notably via Cloud Run and Firestore, with principal hosting declared in the EEA;
Firebase, notably for application functions including authentication and Firestore;
FlutterFlow, as a front-end development tool.
Depending on the establishment’s configuration, Répondia may also interact with third-party booking tools such as Zenchef or TheFork.
The GDPR requires that any use of a processor be contractually governed, and that the use of further processors be authorised and transparent.
9. Hosting and transfers
Répondia states a principal hosting arrangement within the EEA.
However, certain technical providers used in the service chain, particularly within the WhatsApp Business ecosystem, may involve processing or access outside the EEA. Where such a transfer occurs, it must be governed by an appropriate mechanism within the meaning of the GDPR, in particular an adequacy decision or standard contractual clauses where required.
10. Security
Répondia implements security measures appropriate to the nature of the processing, including in particular:
encryption in transit;
encryption at rest;
segregation by establishment;
internal access rights management;
restriction of support access;
incident management procedures;
security reviews and testing.
The CNIL reminds organisations that processors and controllers must implement appropriate technical and organisational measures in light of the risk.
11. End-customer data of establishments
Within the scope of the service, Répondia may process certain data of the establishments’ end customers on their behalf, in particular:
telephone number;
surname or first name;
message content;
preferences and requests relating to the reservation;
date, time and number of covers;
call transcription;
exchange history;
technical data necessary for the operation of the service.
Some more sensitive information may be provided by end customers in the free text of exchanges, such as allergies, accessibility needs or special requests. This information is processed solely to fulfil the request made to the establishment and is transmitted to the establishment as part of the service.
Répondia specifies that end-customer data are not used to train general-purpose models.
12. Artificial intelligence
Répondia uses automated assistance mechanisms to:
qualify requests;
generate responses;
suggest reservations;
extract certain useful information;
produce summaries;
direct or route certain requests.
To Répondia’s knowledge, these automations do not, on their own, lead to a decision producing legal effects or similarly significant effects on the data subject. Human intervention on the establishment’s side remains possible.
13. Rights of individuals
Representatives of establishments have, as applicable, the rights of access, rectification, erasure, restriction, objection and, where applicable, portability.
These rights may be exercised with Répondia at the following address:
If they experience any difficulty, data subjects may also lodge a complaint with the CNIL.
14. Update
Répondia may amend this policy to reflect any legal, technical or operational developments. The version in force is the version published on the medium communicated to establishments.
This privacy policy aims to inform client establishments of Répondia how their personal data are collected and processed in connection with the provision of the Répondia solution.
Répondia provides a solution enabling establishments to manage missed calls and, depending on their configuration, to contact their customers via WhatsApp, qualify requests, provide information, and assist with the management of reservations and related requests.
In accordance with the GDPR, information relating to data processing must be provided in a concise, transparent, intelligible and easily accessible manner.
1. Identity of the data controller
The controller of personal data processed in the context of the commercial relationship between Répondia and its client establishments is:
REPONDIA SAS
16 Bis boulevard de Montréal, 06200 Nice, France
Confidentiality contact / DPO
Natan Darhi
natan.darhi@repondia.com
2. Scope
This policy covers the processing of personal data carried out by Répondia:
to manage the relationship with client establishments;
to administer accounts, access, contracts, exchanges and billing;
to provide support, maintenance, security and operation of the solution;
to enable the configuration and use of the solution by establishments.
It does not, on its own, constitute the information that establishments must provide to their own end customers. Indeed, when Répondia processes end-customer data on behalf of the establishment, the establishment generally acts as the data controller and Répondia as the processor, according to the instructions and parameters defined by the establishment. This division of roles must be expressly formalised.
3. Personal data processed concerning establishments
Répondia may process the following categories of data concerning representatives, authorised users or contacts of the establishments:
professional identity;
service login and access data;
contractual information;
billing information;
customer support data;
technical logs relating to the use of the service;
account configuration information, including certain settings linked to the WhatsApp Business account used in connection with the service.
4. Purposes of processing
The data of establishments are processed for the following purposes:
creation and management of the client account;
provision of the Répondia solution;
service configuration in accordance with the parameters defined by the establishment;
management of access rights and authorisations;
performance of the contractual relationship;
support, assistance and maintenance;
security, monitoring and incident prevention;
billing, accounting and administrative management;
improvement of the service’s operation and quality monitoring.
5. Legal bases
The processing carried out by Répondia in relation to establishments is based mainly on:
performance of the contract or pre-contractual measures;
Répondia’s legitimate interest in ensuring the security, support, maintenance, technical traceability and improvement of its services;
compliance with legal obligations, in particular accounting, tax and evidential obligations.
6. Retention periods
Unless a contrary legal obligation or a specific evidential need applies:
operational, support and service data are retained for 3 months;
data relating to missed calls, conversations and associated operational items are retained for 3 months, unless an extraction is provided to the client before deletion;
contractual and billing data are retained for 5 years, or longer if required by applicable regulations.
The data are then deleted or, where applicable, retained in archived form where this is legally required. The principle of storage limitation is expressly provided for by the GDPR, and the CNIL reminds organisations that a retention period must be defined according to the purpose pursued.
7. Recipients of the data
The following may access the data, within the scope of their responsibilities:
authorised Répondia teams;
technical service providers acting on behalf of Répondia;
administrative or judicial authorities where required by law.
8. Processors and technical tools
Répondia relies on certain technical service providers to deliver its service, in particular:
Twilio, for sending messages via the WhatsApp API according to the deployed architecture;
Meta / WhatsApp, in the context of using the WhatsApp Business platform;
Google Cloud Platform, notably via Cloud Run and Firestore, with principal hosting declared in the EEA;
Firebase, notably for application functions including authentication and Firestore;
FlutterFlow, as a front-end development tool.
Depending on the establishment’s configuration, Répondia may also interact with third-party booking tools such as Zenchef or TheFork.
The GDPR requires that any use of a processor be contractually governed, and that the use of further processors be authorised and transparent.
9. Hosting and transfers
Répondia states a principal hosting arrangement within the EEA.
However, certain technical providers used in the service chain, particularly within the WhatsApp Business ecosystem, may involve processing or access outside the EEA. Where such a transfer occurs, it must be governed by an appropriate mechanism within the meaning of the GDPR, in particular an adequacy decision or standard contractual clauses where required.
10. Security
Répondia implements security measures appropriate to the nature of the processing, including in particular:
encryption in transit;
encryption at rest;
segregation by establishment;
internal access rights management;
restriction of support access;
incident management procedures;
security reviews and testing.
The CNIL reminds organisations that processors and controllers must implement appropriate technical and organisational measures in light of the risk.
11. End-customer data of establishments
Within the scope of the service, Répondia may process certain data of the establishments’ end customers on their behalf, in particular:
telephone number;
surname or first name;
message content;
preferences and requests relating to the reservation;
date, time and number of covers;
call transcription;
exchange history;
technical data necessary for the operation of the service.
Some more sensitive information may be provided by end customers in the free text of exchanges, such as allergies, accessibility needs or special requests. This information is processed solely to fulfil the request made to the establishment and is transmitted to the establishment as part of the service.
Répondia specifies that end-customer data are not used to train general-purpose models.
12. Artificial intelligence
Répondia uses automated assistance mechanisms to:
qualify requests;
generate responses;
suggest reservations;
extract certain useful information;
produce summaries;
direct or route certain requests.
To Répondia’s knowledge, these automations do not, on their own, lead to a decision producing legal effects or similarly significant effects on the data subject. Human intervention on the establishment’s side remains possible.
13. Rights of individuals
Representatives of establishments have, as applicable, the rights of access, rectification, erasure, restriction, objection and, where applicable, portability.
These rights may be exercised with Répondia at the following address:
If they experience any difficulty, data subjects may also lodge a complaint with the CNIL.
14. Update
Répondia may amend this policy to reflect any legal, technical or operational developments. The version in force is the version published on the medium communicated to establishments.
This privacy policy aims to inform the client establishments of Répondia of how their personal data is collected and processed in connection with the provision of the Répondia solution.
Répondia provides a solution that operationalises missed call management and, based on your system configuration, enables establishments to engage with their clients via WhatsApp, qualify enquiries, supply information, and support the management of bookings and associated requests.
In compliance with GDPR, information regarding data processing must be provided in a concise, transparent, intelligible and easily accessible format.
1. Identity of the Data Controller
The data controller for personal data processed within the context of the commercial relationship between Répondia and its client establishments is:
REPONDIA SAS
16 Bis boulevard de Montréal, 06200 Nice, France
Privacy Contact / DPO
Natan Darhi
natan.darhi@repondia.com
2. Scope of Application
This policy covers personal data processing carried out by Répondia:
to manage relationships with client establishments;
to administer accounts, access credentials, agreements, communication, and billing;
to ensure technical support, maintenance, system security, and solution operations;
to facilitate configuration and system use of the solution by establishments.
This document does not, in isolation, constitute the complete information notice that establishments must provide to their own end customers. Indeed, when Répondia processes end-customer data on behalf of an establishment, the establishment primarily acts as the Data Controller and Répondia acts as the Data Processor, in accordance with the instructions and parameters defined by the establishment. This distinction of roles must be explicitly formalised.
3. Personal Data Processed Concerning Establishments
Répondia may process the following categories of data concerning representatives, authorised users or contacts of the establishments:
professional identity;
login and service access credentials;
contractual details;
billing information;
customer support interactions;
technical logs linked to system usage;
account configuration data, including certain parameters linked to the WhatsApp Business account deployed for the service.
4. Purposes of Processing
Establishment data is processed for the following purposes:
customer account creation and management;
provision of the Répondia solution;
service configurations in accordance with parameters set by the establishment;
access and permission management;
execution of contractual obligations;
technical support, assistance, and maintenance;
security monitoring, supervision, and incident prevention;
billing, accountancy, and administrative management;
service performance optimization and quality control monitoring.
5. Legal Basis
Processing operations carried out by Répondia in relation to establishments are based primarily on:
the performance of a contract or pre-contractual measures;
legitimate interests of Répondia in securing, supporting, maintaining, ensuring technical traceability of, and improving its services;
compliance with legal obligations, in particular statutory compliance, taxation, and evidentiary requirements.
6. Data Retention Periods
Unless subject to a contrary legal obligation or specific evidentiary requirement:
operations, operational support, and system usage data is retained for 3 months;
data linked to missed calls, conversations, and associated operational elements is retained for 3 months, unless extracted and delivered to the client prior to deletion;
contractual and billing records are retained for 5 years, or longer where required by applicable regulations.
Thereafter, data is permanently deleted or, where applicable, archived in accordance with statutory requirements. The principle of storage limitation is explicitly mandated by GDPR, and the CNIL reiterates that retention periods must be defined in relation to the specific purpose pursued.
7. Recipients of the Data
Access to data is restricted, within the limits of their respective duties, to:
authorised Répondia personnel;
technical service providers acting on behalf of Répondia;
administrative or judicial authorities where mandated by law.
8. Processors and Technical Instruments
Répondia utilises select technical service providers to deliver its services, notably:
Twilio, for system-dispatched messaging via the WhatsApp API depending on the architecture deployed;
Meta / WhatsApp, within the framework of utilizing the WhatsApp Business Platform;
Google Cloud Platform, specifically via Cloud Run and Firestore, with primary hosting declared within the EEA;
Firebase, notably for operational application functionality including authentication and Firestore;
FlutterFlow, as a front-end development environment.
Depending on the specific configuration of the establishment, Répondia can also interface with third-party reservation software such as Zenchef or TheFork.
GDPR mandates that any engagement of a processor must be governed by a contract, and that the recruitment of sub-processors must be authorised and handled transparently.
9. Hosting and Transfers
Répondia declares its primary data hosting is located within the EEA.
Nevertheless, certain technical service providers utilized within the service supply chain, specifically within the WhatsApp Business ecosystem, may require processing or technical access from outside the EEA. Where such a transfer arises, it must be governed by an appropriate mechanism under GDPR, specifically an adequacy decision or standard contractual clauses where required.
10. Security
Répondia implements rigorous security measures aligned with the nature of the processing operations, including:
encryption in transit;
encryption at rest;
data isolation segregated by establishment;
internal access rights management;
restricted technical support access;
incident management protocols;
security audits and testing reviews.
The CNIL emphasizes that controllers and processors must configure appropriate technical and organisational measures commensurate with the level of risk.
11. End-Customer Data from Establishments
As part of the service, Répondia may process certain end-customer data on behalf of establishments, including:
telephone number;
first and last name;
free-text message content;
booking preferences and requests;
date, time, and table cover count;
call transcriptions;
communication histories;
technical identifiers required for system performance.
More sensitive information may be shared by end-customers within free-text communication fields, such as allergen warnings, accessibility requirements, or specific requests. This information is processed uniquely to fulfil the request submitted to the establishment and is shared with the latter as part of the service provision.
Répondia explicitly clarifies that end-customer data is not used for training generalist AI models.
12. Artificial Intelligence
Répondia operates automated assistant features to:
qualify user enquiries;
generate automated replies;
suggest reservations;
extract operational insights;
produce text summaries;
route or delegate enquiries.
To the best of Répondia's knowledge, these automated sequences do not, in isolation, lead to automated decision-making that produces legal effects or similarly significant impacts on the data subject. Human intervention from the establishment's team remains possible at any time.
13. Data Subject Rights
Establishment representatives have, where applicable, the right to access, rectify, erase, restrict, object to processing, and, where technically viable, request data portability.
These rights may be exercised directly with Répondia at the following address:
If a resolution is not achieved, data subjects have the right to lodge a complaint with the competent supervisory authority (such as the CNIL).
14. Updates
Répondia reserves the right to amend this policy to reflect any legal, technical, or operational adjustments. The applicable version is that which is currently published on the support media provided to establishments.
Customer Service
Frequently Asked Questions
How does automated reservation work with your solution?
When a guest leaves a voicemail, our AI analyses their request (date, time, number of guests) and responds directly on WhatsApp. If any details are missing, it asks the necessary questions. It then forwards the reservation to your teams for approval.

