Introduction
At Repusurance, we believe that trust is built through transparency, responsible technology, and respect for personal data.
This GDPR & Data Protection Notice explains how Repusurance handles personal data when the EU General Data Protection Regulation (GDPR) applies to our processing activities.
This notice should be read together with our Privacy Policy, Terms of Service, and Cookies Policy.
Our Commitment to Data Protection
Repusurance is an AI-powered reputation management platform that helps businesses and individuals monitor, understand, and improve their digital reputation.
Because our Services may process information relating to identifiable individuals, we take data protection seriously.
Where the GDPR applies, we aim to process personal data in accordance with its principles, including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
When Does GDPR Apply?
The GDPR may apply to Repusurance where:
- Repusurance has an establishment in the EU/EEA and processes personal data in connection with its activities; or
- Repusurance is established outside the EU/EEA but offers goods or services to individuals in the EU/EEA; or
- Repusurance monitors the behaviour of individuals in the EU/EEA where the GDPR's territorial requirements are met.
Whether GDPR applies to a particular processing activity depends on the circumstances.
Who Is Responsible for Your Data?
For personal information collected directly through the Repusurance website and Services, Repusurance may act as a Data Controller where we determine why and how the personal data is processed.
When Repusurance processes personal data on behalf of a business customer according to that customer's instructions, Repusurance may act as a Data Processor.
The GDPR distinguishes between controllers, who determine the purposes and means of processing, and processors, who process personal data on behalf of a controller.
Repusurance
Legal Entity: [Full Legal Company Name]
Registered Address: [Registered Address]
Email: [privacy@repusurance.com]
Website: [https://repusurance.com]
Data Protection Officer
If Repusurance is required to appoint a Data Protection Officer under applicable law:
DPO: [Name / DPO Service Provider]
Email: [dpo@repusurance.com]
A DPO may be required in certain circumstances, including where an organization's core activities involve large-scale regular and systematic monitoring of individuals or large-scale processing of sensitive data.
What Personal Data May We Process?
Depending on how you use Repusurance, we may process:
Account Information
- Name
- Email address
- Phone number
- Company name
- Job title
- Account credentials
- Account preferences
Business Information
- Company information
- Brand information
- Website URLs
- Business profiles
- Reputation-related information
- Information submitted by customers
Technical Information
- IP address
- Device information
- Browser information
- Operating system
- Log information
- Usage information
- Approximate location
- Authentication information
Reputation Information
Repusurance may process reputation-related information obtained from:
- Search engines
- Public websites
- Reviews
- News publications
- Public social media
- Public forums
- Other publicly accessible online sources
Some information obtained from public sources may relate to identifiable individuals and therefore may constitute personal data under the GDPR.
Our Legal Bases for Processing
Where GDPR applies, we process personal data only where we have an appropriate legal basis.
Depending on the circumstances, these may include:
Performance of a Contract
We may process information necessary to:
- Create and manage your account
- Provide Repusurance Services
- Process subscriptions
- Provide customer support
- Deliver reports and alerts
- Perform obligations under an agreement
Legitimate Interests
We may process information where necessary for legitimate interests, provided those interests are not overridden by your fundamental rights and freedoms.
Examples may include:
- Maintaining platform security
- Preventing fraud
- Improving our Services
- Understanding platform usage
- Protecting our systems
- Managing business relationships
- Monitoring service performance
Consent
Where required, we may request your consent for certain activities, such as:
- Certain marketing communications
- Non-essential cookies
- Certain optional analytics technologies
- Other processing where consent is required
You may withdraw consent at any time.
Legal Obligations
We may process information where necessary to comply with applicable laws, regulations, legal processes, or lawful requests.
Reputation Monitoring and Public Information
Reputation management is a core part of Repusurance.
Our Services may identify and analyze publicly available information across the digital ecosystem.
This can include:
- Reviews
- News articles
- Search results
- Public social media posts
- Public forums
- Websites
- Public business profiles
- Online mentions
The fact that information is publicly available does not automatically make every use of that information lawful under the GDPR.
Accordingly, where GDPR applies, Repusurance considers applicable requirements relating to lawful processing, transparency, purpose limitation, data minimization, accuracy, and individual rights.
AI and Automated Processing
Repusurance uses AI and automated technologies to analyze reputation-related information.
These technologies may generate:
- Sentiment analysis
- Reputation scores
- Risk indicators
- Summaries
- Trends
- Alerts
- Recommendations
- Reputation insights
AI-generated outputs may be based on large amounts of information and automated analysis.
They may not always be accurate or complete.
Automated Decision-Making
Repusurance does not intend for its reputation insights to independently make legally binding or similarly significant decisions about individuals.
Where applicable GDPR requirements relating to automated decision-making or profiling apply, we will provide the information and rights required by law.
GDPR transparency requirements can include information about automated decision-making, the logic involved, and the potential consequences where applicable.
Your GDPR Rights
If the GDPR applies to your personal data, you may have the right to:
Right to Be Informed
You have the right to understand how your personal data is collected and used.
Right of Access
You may request a copy of personal data we hold about you.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
In certain circumstances, you may request deletion of your personal data.
Right to Restriction
You may request that we restrict processing in certain circumstances.
Right to Data Portability
Where applicable, you may request your personal data in a structured, commonly used, machine-readable format.
Right to Object
You may object to certain processing, including processing based on legitimate interests and direct marketing.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time.
These rights are subject to the conditions and exceptions provided under the GDPR.
How to Submit a GDPR Request
You can submit a privacy request by contacting:
Email: [privacy@repusurance.com]
Please include:
- Your name
- Email address associated with your account, where applicable
- The nature of your request
- Any relevant information that helps us identify the data involved
We may request additional information where reasonably necessary to verify your identity and protect your personal information.
Under GDPR guidance, organizations generally need to respond to valid data-subject requests without undue delay and, in principle, within one month.
Data Processors
Repusurance may use third-party service providers to process personal data on our behalf.
These may include providers supporting:
- Cloud infrastructure
- Hosting
- Data storage
- Analytics
- Customer support
- Authentication
- Payments
- Security
- Monitoring
- AI infrastructure
Where Repusurance acts as a processor for a customer, our processing should be governed by an appropriate data processing agreement or other legally binding arrangement.
Under GDPR Article 28 principles, processors should process personal data according to the controller's documented instructions and implement appropriate technical and organizational measures.
Data Processing Agreements
Where Repusurance acts as a Data Processor for an eligible business customer, the parties may enter into a Data Processing Agreement (DPA).
The DPA may address:
- Processing instructions
- Categories of personal data
- Categories of data subjects
- Security measures
- Confidentiality
- Sub-processors
- Data-subject requests
- Security incidents
- Data deletion or return
- International data transfers
- Audit and compliance obligations
Sub-Processors
Repusurance may use approved sub-processors to provide certain infrastructure or services.
Where required by GDPR, Repusurance will implement appropriate contractual and organizational safeguards for sub-processors.
A current sub-processor list may be made available here:
[View Repusurance Sub-Processors]
International Data Transfers
Repusurance may use service providers or infrastructure located outside the EU/EEA.
Where personal data is transferred outside the EU/EEA, Repusurance will use an appropriate GDPR transfer mechanism where required.
Depending on the circumstances, these mechanisms may include:
- European Commission adequacy decisions
- Standard Contractual Clauses
- Other legally recognized transfer mechanisms
The European Commission recognizes Standard Contractual Clauses as a mechanism for appropriate safeguards when transferring personal data to certain third countries.
Data Security
Repusurance uses reasonable technical and organizational measures designed to protect personal data.
Depending on the service and information involved, these measures may include:
- Encryption in transit
- Access controls
- Authentication
- Role-based access
- Security monitoring
- Logging
- Backup systems
- Infrastructure security
- Restricted internal access
- Security reviews
No system can guarantee absolute security.
We continuously evaluate and improve our security practices as our Services evolve.
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected or as required by law.
Retention may depend on:
- The type of information
- The purpose of processing
- The customer relationship
- Contractual requirements
- Legal obligations
- Security requirements
- Dispute-resolution requirements
When information is no longer required, it may be deleted, anonymized, or securely disposed of.
Data Breaches
Repusurance maintains procedures designed to identify, investigate, contain, and respond to personal-data security incidents.
Where GDPR requires notification of a personal data breach to a supervisory authority, the applicable notification requirements will be followed.
Where required, affected individuals may also be notified.
Children's Data
Repusurance is not intended for children below the applicable minimum age.
We do not knowingly collect children's personal data without an appropriate legal basis and required authorization.
If you believe that we have inadvertently collected personal data relating to a child, please contact us.
Marketing
Where GDPR applies, Repusurance will process personal data for direct marketing only where we have an appropriate legal basis.
You may object to direct marketing at any time.
You can unsubscribe using the link provided in marketing communications or contact:
[privacy@repusurance.com]
Changes to This GDPR Notice
We may update this GDPR & Data Protection Notice from time to time.
When material changes are made, we may provide additional notice where required by applicable law.
The latest version will always be published on this page.
Contact Repusurance
For GDPR, privacy, or data protection questions:
Repusurance
Legal Entity: [Full Legal Company Name]
Address: [Registered Address]
Privacy: [privacy@repusurance.com]
DPO: [dpo@repusurance.com]
Website: [https://repusurance.com]
Our Data Protection Promise
Reputation is built on trust. So is technology.
At Repusurance, we aim to make reputation intelligence more transparent, responsible, and secure — while respecting the rights and choices of the people whose information we process.
Protect. Manage. Elevate.