Response365 Legal

Privacy Policy

Last updated: June 28, 2026

AI Response 365 S.R.L ("Response365", "we", "us", or "our") operates the Response365 Enterprise Resource Planning & Business Management Platform, available at app.response365.ai (the "Service"), together with our marketing website at response365.fi.

This Privacy Policy explains how we collect, use, disclose, and protect Personal Data. It is written to comply with the EU General Data Protection Regulation (GDPR) and equivalent data-protection laws.

Please read the section "Our two roles: Controller and Processor" carefully, because it determines which parts of this Policy apply to you and who you should contact about your Personal Data.

1. Our two roles: Controller and Processor

Response365 is a multi-tenant platform. Each customer organisation that subscribes to the Service (a "Tenant") maintains its own isolated workspace. Depending on the data involved, we act in one of two distinct roles under the GDPR.

1.1 When we are a Processor (most data inside a Tenant's account)

The business records and personal data that a Tenant and its Authorized Users enter into, upload to, or generate within the platform — for example customer and contact records, employee and payroll files, patient/clinical records, invoices, communications, and similar content ("Customer Data") — are processed by us only as a data Processor, acting on the documented instructions of the Tenant. In this relationship the Tenant is the data Controller and is responsible for the lawfulness of that data, including for establishing a legal basis, providing notices, and handling the rights of the individuals concerned.

This processing is governed by our Data Processing Agreement (DPA), not primarily by this Privacy Policy.

If your personal data is held in a Tenant's Response365 account (for example, because you are an employee, patient, customer, or contact of a business that uses Response365), that business — not Response365 — is the Controller of your data. To exercise your rights or ask how your data is used, please contact that organisation directly. We will refer requests we receive about Customer Data to the relevant Tenant and assist them as required by the DPA.

1.2 When we are a Controller (this Policy's main subject)

We act as the data Controller for the Personal Data we collect to provide, secure, bill, support, and improve the Service itself. This includes data about:

This Privacy Policy primarily describes our processing in this Controller role. The remaining sections below apply to that processing.

2. Who we are (Controller identity)

3. Personal Data we collect as Controller

CategoryExamplesSource
Account & identityName, username, job title, organisation, role, password (hashed), account preferences, UI languageYou / your Tenant administrator
ContactEmail address, phone number, business addressYou
OAuth / sign-in profileProfile details returned when you sign in or connect via Microsoft / Office 365, Google, LinkedIn, or Facebook (e.g. name, email, profile identifier)The identity provider you choose
Billing & subscriptionStripe customer and subscription IDs, plan/tier, billing email, payment-method metadata such as card brand and last 4 digits — we never receive or store full card numbersYou, via Stripe
Usage & technicalIP address, device and browser type, pages and features used, timestamps, session and diagnostic logsAutomatically
Support communicationsMessages, attachments, and correspondence you send to support@response365.ai or our other contact channelsYou

We do not seek to collect special-category (sensitive) Personal Data in our Controller role. Special-category data that arises within Tenant workspaces is processed only as a Processor — see section 9.

4. Purposes and legal bases (GDPR Art. 6)

We process the Controller-role data above for the following purposes and on the following legal bases.

PurposeLegal basis (Art. 6 GDPR)
Creating and administering your account; providing and operating the ServicePerformance of a contract (Art. 6(1)(b))
Authenticating users and securing accounts (incl. OAuth sign-in)Performance of a contract; legitimate interests in securing the Service (Art. 6(1)(b), (f))
Processing subscriptions, invoicing and payments via StripePerformance of a contract; legal obligation for tax/accounting records (Art. 6(1)(b), (c))
Providing customer support and responding to enquiriesPerformance of a contract; legitimate interests (Art. 6(1)(b), (f))
Monitoring, maintaining, securing and improving the Service; preventing fraud and abuseLegitimate interests in running a safe and reliable service (Art. 6(1)(f))
Complying with legal, tax, and accounting obligationsLegal obligation (Art. 6(1)(c))
Sending service/transactional messages (e.g. security, billing, account notices)Performance of a contract; legitimate interests (Art. 6(1)(b), (f))
Sending marketing communications about our productsConsent, or legitimate interests for existing-customer soft opt-in where permitted (Art. 6(1)(a) / (f)) — you can opt out at any time

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing (see section 8).

5. Recipients and Sub-processors

We share Personal Data only as needed to run the Service. Categories of recipients include:

We also disclose Personal Data in connection with a corporate transaction (merger, acquisition, or asset sale), subject to appropriate safeguards.

For the complete, current list of the third parties we engage, including their function and location, see our Sub-processor List. Note that several providers (voice, certain AI features) are engaged only if the corresponding module is enabled.

We do not sell your Personal Data, and we do not use third-party advertising networks.

6. International data transfers

We are based in the EU, and our primary hosting is on Microsoft Azure. However, some of our Sub-processors — including certain AI, email, and communications providers — are established in the United States or other countries outside the European Economic Area (EEA).

Where Personal Data is transferred outside the EEA, we rely on an appropriate transfer safeguard under Chapter V of the GDPR, namely:

You can request more information about the safeguards in place by contacting privacy@response365.ai.

7. Data retention

We keep Controller-role Personal Data only for as long as necessary:

Deletion is performed as part of our routine processes; we do not operate a fully automated, instantaneous one-click erasure mechanism, so deletion takes effect within a reasonable period after the applicable window.

8. Your rights

Subject to GDPR and applicable law, you have the right to:

How to exercise your rights (Controller-role data): email privacy@response365.ai or use our GDPR data-subject request form within the Service. We may need to verify your identity. We respond within one month (30 days) of a valid request, as permitted by Art. 12 GDPR (extendable for complex requests). Please note that fulfilment may be partly handled manually, as we do not provide a fully automated export/erasure tool.

For data held inside a Tenant's account (Processor-role data): we are not able to grant these requests directly. Please contact the Tenant organisation that controls your data (section 1.1). We will assist that Tenant in responding, as required by our DPA.

You may also lodge a complaint with [PLACEHOLDER: competent data protection supervisory authority in the home jurisdiction] or with the supervisory authority in your country of residence.

9. Special-category (sensitive) data

The platform includes modules — notably the healthcare module (actively used by live customers) and HR/payroll — through which Tenants may process special-category data under Art. 9 GDPR, such as clinical diagnoses, vital signs, lab results, allergies, care plans, and health/sick-leave records.

Response365 processes such data solely as a Processor, on the documented instructions of the Tenant, under the DPA. The Tenant is the Controller and is solely responsible for establishing a valid Art. 9 legal basis (e.g. explicit consent or a healthcare/employment exemption), providing the required notices, and ensuring lawful processing. We apply appropriate technical and organisational security measures to all data, including this category.

10. Security

We implement technical and organisational measures appropriate to the risk, including:

No system is completely secure. While we work to protect your Personal Data, we cannot guarantee absolute security.

11. Cookies

We use a small number of strictly necessary cookies and similar technologies to operate the Service (for example, to keep you signed in and protect against cross-site request forgery). We do not use third-party advertising or tracking cookies. For full details, see our Cookie Policy.

12. Children

The Service is a business tool intended for use by organisations and their staff. It is not directed at children under 16, and we do not knowingly collect Personal Data from children in our Controller role. Any personal data about minors that a Tenant processes through the platform (e.g. in a healthcare or HR context) is handled by that Tenant as Controller.

13. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify account administrators. Your continued use of the Service after an update constitutes acknowledgement of the revised Policy.

14. Contact us

For any question about this Policy or your Personal Data:

Related documents: Terms of Service · Cookie Policy · Acceptable Use Policy · Data Processing Agreement · Sub-processor List · Service Level Agreement · AI / Automated Features Addendum