Privacy Policy
Last updated: June 28, 2026
AI Response 365 S.R.L ("Response365", "we", "us", or "our") operates the Response365 Enterprise Resource Planning & Business Management Platform, available at app.response365.ai (the "Service"), together with our marketing website at response365.fi.
This Privacy Policy explains how we collect, use, disclose, and protect Personal Data. It is written to comply with the EU General Data Protection Regulation (GDPR) and equivalent data-protection laws.
Please read the section "Our two roles: Controller and Processor" carefully, because it determines which parts of this Policy apply to you and who you should contact about your Personal Data.
1. Our two roles: Controller and Processor
Response365 is a multi-tenant platform. Each customer organisation that subscribes to the Service (a "Tenant") maintains its own isolated workspace. Depending on the data involved, we act in one of two distinct roles under the GDPR.
1.1 When we are a Processor (most data inside a Tenant's account)
The business records and personal data that a Tenant and its Authorized Users enter into, upload to, or generate within the platform — for example customer and contact records, employee and payroll files, patient/clinical records, invoices, communications, and similar content ("Customer Data") — are processed by us only as a data Processor, acting on the documented instructions of the Tenant. In this relationship the Tenant is the data Controller and is responsible for the lawfulness of that data, including for establishing a legal basis, providing notices, and handling the rights of the individuals concerned.
This processing is governed by our Data Processing Agreement (DPA), not primarily by this Privacy Policy.
If your personal data is held in a Tenant's Response365 account (for example, because you are an employee, patient, customer, or contact of a business that uses Response365), that business — not Response365 — is the Controller of your data. To exercise your rights or ask how your data is used, please contact that organisation directly. We will refer requests we receive about Customer Data to the relevant Tenant and assist them as required by the DPA.
1.2 When we are a Controller (this Policy's main subject)
We act as the data Controller for the Personal Data we collect to provide, secure, bill, support, and improve the Service itself. This includes data about:
- the people who register for, administer, or use a Tenant account (account holders and Authorized Users);
- billing and subscription contacts;
- visitors to our marketing website and people who contact us.
This Privacy Policy primarily describes our processing in this Controller role. The remaining sections below apply to that processing.
2. Who we are (Controller identity)
- Controller: AI Response 365 S.R.L
- Legal form: Società a responsabilità limitata (S.R.L)
- Registered address: [PLACEHOLDER: registered office address]
- Company / registration number: [PLACEHOLDER: company registration number]
- VAT number: [PLACEHOLDER: VAT number]
- Governing jurisdiction: [PLACEHOLDER: home jurisdiction — Romania or Italy]
- Privacy contact: privacy@response365.ai
- Data Protection Officer: [PLACEHOLDER: DPO name / contact, if appointed]
- Lead supervisory authority: [PLACEHOLDER: competent data protection supervisory authority in the home jurisdiction]
3. Personal Data we collect as Controller
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, username, job title, organisation, role, password (hashed), account preferences, UI language | You / your Tenant administrator |
| Contact | Email address, phone number, business address | You |
| OAuth / sign-in profile | Profile details returned when you sign in or connect via Microsoft / Office 365, Google, LinkedIn, or Facebook (e.g. name, email, profile identifier) | The identity provider you choose |
| Billing & subscription | Stripe customer and subscription IDs, plan/tier, billing email, payment-method metadata such as card brand and last 4 digits — we never receive or store full card numbers | You, via Stripe |
| Usage & technical | IP address, device and browser type, pages and features used, timestamps, session and diagnostic logs | Automatically |
| Support communications | Messages, attachments, and correspondence you send to support@response365.ai or our other contact channels | You |
We do not seek to collect special-category (sensitive) Personal Data in our Controller role. Special-category data that arises within Tenant workspaces is processed only as a Processor — see section 9.
4. Purposes and legal bases (GDPR Art. 6)
We process the Controller-role data above for the following purposes and on the following legal bases.
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and administering your account; providing and operating the Service | Performance of a contract (Art. 6(1)(b)) |
| Authenticating users and securing accounts (incl. OAuth sign-in) | Performance of a contract; legitimate interests in securing the Service (Art. 6(1)(b), (f)) |
| Processing subscriptions, invoicing and payments via Stripe | Performance of a contract; legal obligation for tax/accounting records (Art. 6(1)(b), (c)) |
| Providing customer support and responding to enquiries | Performance of a contract; legitimate interests (Art. 6(1)(b), (f)) |
| Monitoring, maintaining, securing and improving the Service; preventing fraud and abuse | Legitimate interests in running a safe and reliable service (Art. 6(1)(f)) |
| Complying with legal, tax, and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Sending service/transactional messages (e.g. security, billing, account notices) | Performance of a contract; legitimate interests (Art. 6(1)(b), (f)) |
| Sending marketing communications about our products | Consent, or legitimate interests for existing-customer soft opt-in where permitted (Art. 6(1)(a) / (f)) — you can opt out at any time |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing (see section 8).
5. Recipients and Sub-processors
We share Personal Data only as needed to run the Service. Categories of recipients include:
- Cloud hosting & storage — Microsoft Azure.
- Payments — Stripe (subscription billing; Stripe is PCI-DSS compliant and processes all card data).
- Transactional email — Mailchimp Transactional (Mandrill) for system emails.
- AI / LLM providers — for AI-assisted features, where enabled, content may be sent to providers such as OpenAI, Anthropic, and optionally Google (Gemini) or Microsoft Azure OpenAI. These providers act under contractual terms that do not permit them to use the data to train their models.
- Voice & call-centre providers — only if a Tenant enables the relevant module (e.g. Twilio, Vonage, Deepgram, ElevenLabs, Azure Speech, Google Speech-to-Text).
- Identity providers — when you choose to sign in via Microsoft, Google, LinkedIn, or Facebook.
- Professional advisers and authorities — where required by law or to protect our rights.
We also disclose Personal Data in connection with a corporate transaction (merger, acquisition, or asset sale), subject to appropriate safeguards.
For the complete, current list of the third parties we engage, including their function and location, see our Sub-processor List. Note that several providers (voice, certain AI features) are engaged only if the corresponding module is enabled.
We do not sell your Personal Data, and we do not use third-party advertising networks.
6. International data transfers
We are based in the EU, and our primary hosting is on Microsoft Azure. However, some of our Sub-processors — including certain AI, email, and communications providers — are established in the United States or other countries outside the European Economic Area (EEA).
Where Personal Data is transferred outside the EEA, we rely on an appropriate transfer safeguard under Chapter V of the GDPR, namely:
- the European Commission's Standard Contractual Clauses (SCCs); and/or
- an adequacy decision of the European Commission covering the destination country or certification framework, where one applies.
You can request more information about the safeguards in place by contacting privacy@response365.ai.
7. Data retention
We keep Controller-role Personal Data only for as long as necessary:
- Account data is retained for as long as your account is active.
- After termination of a subscription, the associated account and Customer Data are available for export for 30 days, after which they are scheduled for deletion (see the DPA for Customer Data specifics).
- Billing, tax, and accounting records are retained for the longer statutory periods required by law.
- Data subject to a legal hold, dispute, or regulatory requirement is retained until that obligation ends.
Deletion is performed as part of our routine processes; we do not operate a fully automated, instantaneous one-click erasure mechanism, so deletion takes effect within a reasonable period after the applicable window.
8. Your rights
Subject to GDPR and applicable law, you have the right to:
- access the Personal Data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- data portability (receive your data in a structured, commonly used, machine-readable format);
- object to processing based on legitimate interests, and to object to direct marketing at any time;
- withdraw consent at any time where processing is based on consent (without affecting prior processing);
- lodge a complaint with a supervisory authority.
How to exercise your rights (Controller-role data): email privacy@response365.ai or use our GDPR data-subject request form within the Service. We may need to verify your identity. We respond within one month (30 days) of a valid request, as permitted by Art. 12 GDPR (extendable for complex requests). Please note that fulfilment may be partly handled manually, as we do not provide a fully automated export/erasure tool.
For data held inside a Tenant's account (Processor-role data): we are not able to grant these requests directly. Please contact the Tenant organisation that controls your data (section 1.1). We will assist that Tenant in responding, as required by our DPA.
You may also lodge a complaint with [PLACEHOLDER: competent data protection supervisory authority in the home jurisdiction] or with the supervisory authority in your country of residence.
9. Special-category (sensitive) data
The platform includes modules — notably the healthcare module (actively used by live customers) and HR/payroll — through which Tenants may process special-category data under Art. 9 GDPR, such as clinical diagnoses, vital signs, lab results, allergies, care plans, and health/sick-leave records.
Response365 processes such data solely as a Processor, on the documented instructions of the Tenant, under the DPA. The Tenant is the Controller and is solely responsible for establishing a valid Art. 9 legal basis (e.g. explicit consent or a healthcare/employment exemption), providing the required notices, and ensuring lawful processing. We apply appropriate technical and organisational security measures to all data, including this category.
10. Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption in transit using TLS for connections to the Service;
- encrypted storage of sensitive credentials, such as Tenant-configured SMTP/IMAP email credentials (using application-level field encryption);
- role-based access controls, authentication, and tenant data isolation;
- hosting on Microsoft Azure, benefiting from its physical and infrastructure security and, where available, Azure-provided storage encryption;
- logging, monitoring, and audit trails.
No system is completely secure. While we work to protect your Personal Data, we cannot guarantee absolute security.
11. Cookies
We use a small number of strictly necessary cookies and similar technologies to operate the Service (for example, to keep you signed in and protect against cross-site request forgery). We do not use third-party advertising or tracking cookies. For full details, see our Cookie Policy.
12. Children
The Service is a business tool intended for use by organisations and their staff. It is not directed at children under 16, and we do not knowingly collect Personal Data from children in our Controller role. Any personal data about minors that a Tenant processes through the platform (e.g. in a healthcare or HR context) is handled by that Tenant as Controller.
13. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify account administrators. Your continued use of the Service after an update constitutes acknowledgement of the revised Policy.
14. Contact us
For any question about this Policy or your Personal Data:
- Privacy & data-subject requests: privacy@response365.ai
- General / legal: legal@response365.ai
- Support: support@response365.ai
- Postal address: [PLACEHOLDER: registered office address]
Related documents: Terms of Service · Cookie Policy · Acceptable Use Policy · Data Processing Agreement · Sub-processor List · Service Level Agreement · AI / Automated Features Addendum